Laserfiche WebLink
Attachment B <br /> Permissible Use Requirements <br /> 1. DATA USE <br /> Licensee must institute and maintain written policies and procedures to ensure Data is only <br /> used as authorized herein. At a minimum the policies and procedures will include, training <br /> requirements for all personnel with access to Confidential Information on the Permissible <br /> Use(s) of Data. Licensee must be capable of demonstrating the training and education was <br /> delivered to all applicable personnel who have are an Authorized User, employees and <br /> agents. <br /> 2. APPROPRIATE USE DECLARATION <br /> Licensee must require all Authorized Users to sign an Appropriate Use Declaration prior to <br /> accessing DRIVES. The Declaration must include a statement that the Authorized User <br /> understands and acknowledges: <br /> 1. His/her obligations and responsibility to use Confidential Information only to <br /> accomplish his/her official job duties; <br /> 2. He/she will maintain the confidentiality and privacy of the information accessed; <br /> 3. He/she will not share Confidential Information with unauthorized persons; <br /> 4. He/she will not use Data access for personal reasons or benefit; and <br /> 5. Misuse of any Confidential Information may be considered a felony and may be <br /> punishable by fine or imprisonment. <br /> Licensee must maintain the signed declaration. Licensee must provide copies of signed <br /> Appropriate Use Declaration upon request by DOL. <br /> 3. PERMISSIBLE USE EVALUATIONS <br /> • At least annually, Licensee must conduct a review of all Authorized Users' access and use <br /> of Confidential Information to ensure that such access and use is within official job duties. <br /> 4. SECURE USE <br /> Licensee must maintain and support administrative, technical or physical methods used to <br /> monitor compliance with the Permissible Use(s) authorized in this Agreement across all <br /> Licensee business practices. Methods may include any of the following: <br /> a) View only access to Data <br /> b) System limitations or controls <br /> c) Confidentiality agreements <br /> 5. NON-CONFORMING PERMISSIBLE USE NOTIFICATION <br /> Licensee shall notify DOL personnel in the event of confirmed unauthorized use of Data. <br /> Licensee must perform the following: <br /> a) Notify the DOL by e-mail at DataServices(c�dol.wa.gov of such an event within 24 hours <br /> of discovery <br /> Identify the Data and non-conforming use of the Data. <br /> b) if the misuse is a criminal offense requiring notification to individuals, cooperate and <br /> facilitate with the notification of all affected individuals. At DOL's discretion, Licensee <br /> may be required to directly perform notification requirements, or if DOL elects to perform <br /> the notifications, Licensee may have to reimburse DOL for all costs associated with the <br /> notification. <br /> • <br /> Page 12 <br /> 21 <br />