|
City of Everett
<br /> Cloud and/or Offsite Hosting Terms and Conditions
<br /> Contract#2021-129, Appendix A between City of Everett and LeaseQuery LLC dated 07/11/2022
<br /> This document shall become part of the final contract.
<br /> Terms and Conditions listed below are mandatory for every engagement. Exceptions will be
<br /> considered non-compliant and non-responsive.
<br /> Tiered Coverage Schedule
<br /> Level Number of PII records Level of cyber liability insurance required (occurrence=data breach)
<br /> 1 1-10,000 $2,000,000 per occurrence
<br /> 2 10,001 —50,000 $3,000,000 per occurrence
<br /> 3 50,001 —100,000 $4,000,000 per occurrence
<br /> 4 100,001 —500,000 $15,000,000 per occurrence
<br /> 5 500,001 —1,000,000 $30,000,000 per occurrence
<br /> 1,000,001 —
<br /> 6 10,000,000 $100,000,000 per occurrence
<br /> The policy shall comply with the following requirements:
<br /> • Valid for the entire term of the contract, inclusive of any term extension(s).
<br /> • Liability limits will be calculated based on the maximum system record count and the Ponemon
<br /> Institute average Public Sector Breach cost per record (currently$154). Refer to the Tiered
<br /> Coverage Schedule above.
<br /> • The Service Provider shall be responsible for any deductible or self-insured retention contained in
<br /> the insurance policy.
<br /> • The coverage under the policy shall be primary, and not excess,to any other insurance carried by
<br /> the Service Provider.
<br /> • In the event contractor fails to keep in effect at all times the insurance coverage required by this
<br /> provision,the City may, in addition to any other remedies it may have,terminate the contract
<br /> upon the occurrence of such event,subject to the provisions of the contract.
<br /> 5. Breach Notification and Recovery: City of Everett requires public breach notification when
<br /> citizens' personally identifiable information is lost or stolen.Additionally, unauthorized access or
<br /> disclosure of non-public data is considered to be a breach. The Service Provider will provide
<br /> notification without unreasonable delay and all communication shall be coordinated with the City
<br /> of Everett. When the Service Provider or their subcontractors are liable for the loss, subject to
<br /> the terms of the Contract,the Service Provider shall bear costs associated with the investigation,
<br /> response and recovery from the breach including but not limited to credit monitoring services with
<br /> a term of at least 3 years, mailing costs,website,and toll free telephone call center services.
<br /> 6. Notification of Legal Requests: The Service Provider shall contact the City of Everett upon
<br /> receipt of any electronic discovery, litigation holds, discovery searches, and expert testimonies
<br /> related to, or which in any way might reasonably require access to the data of the City. The
<br /> Service Provider shall not respond to subpoenas, service of process, and other legal requests
<br /> related to the City of Everett without first notifying the City unless prohibited by law from providing
<br /> such notice,
<br /> 7. Termination and Suspension of Service: In the event of termination of the contract, the
<br /> Service Provider shall implement an orderly return of City of Everett data in CSV or XML or
<br /> another mutually agreeable format upon written request of the City of Everett. Upon written
<br /> request of the City of Everett,the Service Provider shall guarantee the subsequent secure
<br /> disposal of City of Everett data, except that the Service Provide may retain such data for archival,
<br /> backup or disaster recovery purposes or in anticipation of litigation.
<br /> 2IPage
<br />
|