Laserfiche WebLink
REV: 01-05-26 LR <br />unauthorized access or use of City Data or City Solution Data at any time. To this <br />end, Consultant shall safeguard the confidentiality, integrity and availability of City <br />Data and City Solution Data and comply with the following conditions: <br />13.4.1 Consultant shall implement and maintain appropriate administrative, <br />technical and organizational security measures to safeguard against <br />unauthorized access, disclosure or theft of City Data and City Solution Data. <br />Such security measures shall comply with the following standards: ISO <br />27701, ISO 27017 and ISO 27018. <br />13.4.2 All data obtained by Consultant in the performance of this Agreement <br />shall become and remain property of the City. <br />13.4.3 At no time shall any City Data or processes - that either belong to or <br />are intended for the use of the City or its officers, agents or employees - be <br />copied, disclosed, sold, or retained by Consultant or any party related to <br />Consultant for subsequent use in any transaction that does not include the <br />City without the City's express written consent. <br />13.4.4 Consultant shall not use City Data for any purpose other than fulfilling <br />the Services without the City’s express written consent. <br />13.5 Data Location. Consultant shall provide Services to City solely from data <br />centers in the United States. Storage of City Data and Solution Data at rest shall <br />be located solely in data centers in the United States. Consultant shall permit its <br />personnel and subcontractors to access City Data remotely only as required to <br />provide the Services or offer technical support or other support specifically <br />requested by the City. Consultant shall not allow its personnel or contractors to <br />store City Data on portable devices, including personal computers, except for <br />devices that are used and kept only at its U.S. data centers. <br />13.6 Security Incident or Data Breach Notification. Consultant shall inform the <br />City within 24 hours or sooner, unless shorter time is required by applicable law, <br />of any Security Incident or Data Breach, cooperate with the City in addressing the <br />matter, promptly implement measures to cure the breach, and implement breach <br />notification and reconciliation protocols in accordance with NIST-approved <br />methods. <br />13.6.1 Incident Response. Consultant may need to communicate with <br />outside parties regarding a Security Incident, which may include contacting <br />law enforcement, fielding media inquiries, and seeking external expertise <br />as mutually agreed upon, defined by law, or contained in this Agreement. <br />Discussing Security Incidents with the City should be handled on an urgent <br />as-needed basis, as part of communication and mitigation processes as <br />mutually agreed upon, defined by law, or contained in this Agreement. <br />ATTY/AGR.2026.001/EnSight Technologies (Parking Access and Revenue Control System (PARCS)) (Page 11 of 167)