Loading...
HomeMy WebLinkAboutCC Reso No 2015-086 City Council Reso.RESOLUTTON NO. 2015-086 A RESOLUTION OF THE CITY COUNCIL OF THE CITY OF LAKE ELSINORE, CALIFORNIA MAKING CERTAIN FINDINGS OF NECESSITY OF INFORMATION FROM THE STATE OF CALIFORNIA EMPLOYMENT DEVELOPMENT DEPARTMENT (EDD) AND AUTHORIZING THE CITY MANAGER TO EXECUTE DOCUT',ENTS TO ACQUIRE AND APPROPRIATELY SECURE SAID INFORMATION WITH BOTH EDD AND DEVELOPMENT MANAGEMENT GROUP, INC. WHEREAS, The City of Lake Elsinore is in the process of creating an economic development strategic plan to guide efforts to increase economic investment in the community; and WHEREAS, As part of the economic development strategic plan, it is vital to understand such information as number of jobs held within the City of Lake Elsinore, total payroll, average/median earnings and industry clusters; and WHEREAS, The State of California Employment Development Department (EDD) allows cities to acquire payroll and industry information for economic development purposes with appropriate agreements governing the use of the information and security of data. NOW, THEREFORE, THE CITY COUNCIL OF THE CITY OF LAKE ELSINORE HEREBY RESOLVE, DETERMINE AND ORDER AS FOLLOWS: Section 1. The payroll and industry information available through the State of California Employment Development Department is of significant importance in the generation and execution of an economic development strategic plan. Section 2. The City Manager is hereby authorized to enter into a Service/Security Agreement (EDD Attachment A-1) with Development Management Group, lnc. Section 3. The City Manager is hereby authorized to enter into EDD Exhibit A "Standard Agreement" Section 4. The City Manager is hereby authorized to enter into EDD Exhibits D-1, D-2 and D-3 "Confidentiality Agreement", "lndemnity Agreement" and "lnformation Security Agreement" respectively noting that Jason Simpson, Administrative Services Director and Michael Bracken, Development Management Group, lnc. (economic development consultant to the City of Lake Elsinore) shall be authorized to receive and view confidential information. City Council Resolution No. 2015-086 Page 2 of 2 SECTION 5. The City Clerk shall certify to the adoption of this Resolution. SECTION 6. This Resolution shall take effect from and after the date of its passage and adoption. PASSED, APPROVED AND ADOPTED at a special meeting of the City Council of the City of Lake Elsinore, California on this 1sfulay of December, 2015. san M. Domen,-City Clerk { rbara Leibold, City Attorney EDD Agreement No. M EDD/ Page 1 of 5 EXHIBIT A (Standard Agreement) SCOPE OF WORK This Agreement is entered into by and between the Employment Development Department, hereinafter referred to as EDD, and , hereinafter referred to as . lt sets forth the terms and conditions for the release and use of EDD confidential information. ,I. PURPOSE This Agreement is established for the purpose of EDD producing and providing with confidential Quarterly Census of Employment and Wages (OCEW data as specified herein. will use the confidential information provided by EDD for the purpose of 2. LEGALAUTHORITY EDD shall make the specified information available to under the authority of Section 1095(r) of the California Unemployment lnsurance Gode (CUIC). shall request and use the specified information pursuant to CUIC 1095(r) as established by dated 3. SUBCONTRACTOR EDD agrees that the confidential information provided to may be disclosed to a contractor of , for the specific purpose described in this Agreement and as entered into under the Service Agreement between and , attached hereto as Attachment A-1 and incorporated herein by this reference. 4. CONTRACTREPRESENTATIVES a) EDD contact person shall be: CINDYWONG Confidential Data Coordinator Employment Development Department Labor Market lnformation Division 800 Capitol Mall, MIC 57 Sacramento, CA 95814 Phone: (916) 651-5743 Fax: (916) 651-5780 b) contact person shall be: EDD Agreement No. M EDD/ Page 2 of 5 EXHIBIT A (Standard Agreement) c) Either party may make changes to the Contract Representatives information above by giving written notice to the other party. Said changes shall not require an amendment to this Agreement. 5. EDDRESPONSIBILITIES EDD agrees to: a) Prepare and provide with QCEW data files consisting of employers within the boundaries of as defined by b) Provide the quarterly data files for the period beginning with Year Quarter c) lnclude in the data files the following QCEW data elements for each employer (if available): d) Provide the data files in format. e) Provide a record layout for the data output. f) Transmit the data files to through the OTech Secure File Transfer (SFT) system. The EDD shall: i. Set up a Basic User Account and password for to access the SFT system. ii. Provide user account admlnistration to reset password, unlock user account, and/or modify user account. To request user account support, submit an email message to: cmwono@edd.ca.oov. iii. Retain the output data file for a period of seven (7) calendar days in the SFT temporary file repository. On the 8rh day, the data file is automatically deleted. 6. RESPONSIBILITIES agrees to: a) Request only EDD information specifically authorized under this Agreement. b) Use the specified EDD information only for the following purposes: Any other use is prohibited. c) Comply with the CUIC on any matters pertaining to the access, use, and/or release of data under this Agreement. Failure to comply with this provision shall be deemed a breach of this Agreement and shall be grounds for cancellation of this Agreement. d) Oversee and contractor/subcontractor staff in their use of confidential information received from EDD. h) k) e) lnstruct all EDD Agreement No. M EDDi Page 3 of 5 EXHIBIT A (Standard Agreement) and contractor/subcontractor staff with access to the information provided by EDD under this Agreement regarding the: ('l) the confidential nature ofthe information; (2) the requirements of this Agreement; (3) the need to adhere to the security and confidenliality provisions outlined in Exhibit D - Protection of Confidentiality Provisions; and (3) the sanctions and penalties against unauthorized use or disclosure found in CUIC Sections 1094 and 2'111, the California Civil Code Section 1798.55, and the California Penal Code Section 502. f) Ensure that all contracls established with other private and/or public contractors and/or subcontractors with access to EDD confidential information disclosed under this Agreement include all EDD confidentiality provisions specified herein. g) Ensure that all and contractor/subcontractor staff assigned to work with the information provided by EDD have signed the EDD Confldentiality Agreement - Attachment D'l [Rev 05/14114]. Comply with Title 20, Code of Federal Regulations Section 603.7 with respect to any of the EDD confidential information. Cooperate with the EDD's authority to monitor this Agreement in accordance with Exhibit D, Section ll, paragraphs (e) and (0. Not release EDD confidential information to any entity which is a private collection agency (CUlC, Section '1095(u)). Not release EDD confidential information to any other public or private entity without EDD's prior written consent. Not disclose any individually identifiable EDD information when publishing information. Any summarized industry level data, when published, must contain three or more firms. ln those instances where there are three or more firms and the employment of a single firm represents more than 80 percent of the total, the number must be rolled up to a larger total in order to mask identification of such firms. Allow EDD to review any publication which uses EDD information 15 working days prior to publication. A copy shatl be provided to EDD at no cost. Adhere to the following procedures when retrieving EDD information from the OTech SFT system: i. Establish a new password at first logon to the Basic User Account established for to access the OTech SFT system. The SFT Password Policy syntactical requirements are:. Password must contain at least I characters. . At least one of the characters must be a number. . At least one of the characters must be a symbol (for example: !@#$%). . At least one ofthe characters must be an uppercase alpha character. ii. Change the Basic User Account password every 90 days. A limit of five attempts to enter the password is allowed after which the account will be locked. To request User Account support, submit an email message to: cmwono@edd.ca.oov. m) n) EDD Agreement No. M EDD/ Page 4 of 5 EXHIBIT A (Standard Agreement) iii. Retrieve the response data file from the SFT temporary file storage repository within seven (7) calendar days from submission. On the 8th day, the data file is automatically deleted. Download the EDD confidential data to properly secured and encrypted Data Storage Devices (including laptops, usb drives, cd's, dvd, tapes and similar devices and media) for specific business use when absolutely necessary. Ensure encryption meets current National lnstitute of Standards and Technology (NIST) standards. Dispose of the EDD's confidential information using an approved method of confidential destruction. Pursuant to federal law, if fails to comply wlth any provision of this Agreement, including timely payment of EDD's costs under this Agreement,lhis Agreement shall be suspended and no further disclosures will be made untal EDD is satisfied that conective action has been taken and there will be no further breach. ln the absence of prompt and satisfactory corrective action, this Agreement will be cancelled, and shall surrender to EDD all confidential information obtained under this Agreement which has not been previously returned to EDD, and any other information relevant to the Agreement (20 C. F.R., Part 603.1 0(c)( 1)). 7. JOINT RESPONSIBILITIES Both parties agree to: a) Designate staff to have primary responsibility for program liaison, coordination of activities, and to meet, when necessary, to further redefine specific program procedures. b) Not disclose any of EDD or the information to any person or agency other than those authorize specifically under this Agreement. c) Cooperate fully and furnish such assistance as may be mutually agreed upon by the parties hereto as being necessary and appropriate for proper performance of this Agreement. 8. ACCURACYASSESSMENT The lndividual employers and claimants report the information in EDD's files- Since EDD is not the originator of the information disclosed, EDD cannot guarantee the accuracy of the information. 9. DISPUTES In the event of a dispute between EDD and the over any part of this Agreement, the dispute may be submitted to nonbinding arbitration upon the consent of both EDD and the . An election for arbitration pursuant to this provision shall not preclude either party from pursuing any remedy for relief otherwise available. o) p) q) EDD Agreement No. M EDD/ Page 5 of 5 EXHIBIT A (Standard Agreement) 10. TERMINATION CLAUSE This Agreement may be terminated by either party by giving written notice 30 days prior to the effective date of such termination. EDD Agreement No. M EDD/ Page 1 of 3 EXHIBIT D (Standard Agreement) PROTECTION OF CONFIDENTIALITY Federal and state confidentiality laws, regulations, and administrative policies classify all the Employment Development Department (EDD) information provided under this Agreement as confidential. The federal and state laws prohibit disclosure of the EDD'S confidential information to the public and mandate its protection against loss and against unauthorized access, use, disclosure, modification, or destruction. must therefore, agree to the following security and confidentiality requirements: I. ADMINISTRATIVESAFEGUARDS a. Adopt policies and procedures to ensure use ofthe EDD'S confidential information solely for purposes specifically authorized under this Agreement that meet the requirements of Title 20, Code of Federal Regulations 5603.10. b. Warrant by execution of this Agreement, that no person or selling agency has been employed or retained to solicit or secure this Agreement upon agreement or understanding for a commission, percentage, brokerage, or contingent fee. lntheeventof a breach or violation of this warranty, lhe EDD shall have the right to annul this Agreement without liability, in addition to other remedies provided by law. c. Warrant and certify that in the performance of this Agreement will comply with all applicable statutes, rules and/or regulations, and Agreement information security requirements, including but not limited to the following: . California Unemployment lnsurance Code S1094 (Disclosure Prohibitions) o Title 20, Code of Federal Regulations 5603.9 and 5603.10 (Federal Unemployment Compensation Safeguards and Security Requirements) . California Civil Code S1798, et seq. (lnformation Practices Act) . California Penal Code $502 (Computer Fraud Act ) . Title 5, U.S. Code $552a (Federal Privacy Act Disclosure Restrictions) o Title 42, U.S. Code $503 (Social Security Act) . Title 18, U.S. Code S1905 (Disclosure of Confidential lnformation) d. Except for state agencies, agree to indemnify the EDD against any loss, cost, damage or liability resulting from violations of these applicable statutes, rules and/or regulations, and Agreement information security requirements. e. Protect the EDD's information against unauthorized access, at all times, in all forms of media. Access and use the information obtained under this Agreement only to the enent necessary to assist in the valid administrative needs of the program receiving such information, and only for the purposes defined in this Agreement. f. Keep all the EDD'S confidential information completely confidential. Make this information available to authorized personnel on a "need-to-know" basis and only for the purposes authorized under this Agreement. "Need{o-know" refers to those authorized personnel who need information to perform their official duties in connection with the use of the information authorized by this Agreement. Confidentiality Requirements STD . lRev 111121'l4l EDD Agreement No. M EDD/ Page 2 of 3 EXHIBIT D (Standard Agreement) g. Notify the EDD lnformation Security Office (lSO) at (916) 654-6231, immediately upon discovery, that there may have been a breach in security which has or may have resulted in compromise to the confidential information. For purposes of this section, immediately is defined within 24 hours of discovery of the breach. The notification shall be by phone and the caller shall speak directly with a person in the EDD lSO. lt is not sufficient to simply leave a message. The notification must include a detailed description ofthe incident (such as time, date, location, and circumslances) and identifying responsible personnel (name, title and contact information). The verbal notification shall be followed with an email notification to <lnformationSecurityOffice@edd.ca.gov>. II. MANAGEMENT SAFEGUARDS a. Acknowledge that the confidential information obtained by under this Agreement remains the property of the EDD. b. lnstruct all personnel assigned to work with the information provided underthis Agreement regarding the following: . Confidential nature ofthe EDD information. . Requirements of this Agreement. . Sanctions specified in federal and state unemployment compensation laws and any other relevant statutes against unauthorized disclosure of confidential information provided by the EDD. c. Require that all personnel assigned to work with the information provided by the EDD complete the EDD Confidentiality Agreement (Attachment D l): d. Return the following completed documents to the EDD Contract Services Group: o The EDD lndemnity Agreement (Attachment D2): Required to be completed by the Chief Financial Officer or authorized Management Representative. o The EDD Statement of Responsibility lnformation Security Certification (Attachment D3): Required to be completed by the lnformation Security Officer and authorized Management Representative. e. Permit the EDD to make on-site inspections to ensure that the terms of this Agreement are being met. Make available to the EDD staff, on request and during on-site reviews, copies of the EDD Confidentiality Agreement (Attachment D1) completed by personnel assigned to work with the EDD's confidential information, and hereby made a part of this Agreement. f. Maintain a system of records sufficient to allow an audit of compliance with the requirements under subsection (d) of this part. Permit the EDD to make on-site inspections to ensure that the requirements of federal and state privacy, confidentiality and unemployment compensation statutes and regulations are being met including but not limited to Social Security Act $ l 137(a)(5)(B). III. USAGE, DUPLICATION, AND REDISCLOSURE SAFEGUARDS a. Use the EDD's confidential information only for purposes specifically authorized under this Agreement. The information is not admissible as evidence in any action or special proceeding except as provided under 51094(b) of the California Unemployment lnsurance Code (CUIC). Section 1095(u) of theCU|C does not authorize the use of the EDD's confidential information by any private collection agency. b. Extraction or use of the EDD information for any purpose outside the purposes stated in this Agreement is strictly prohibited. The information obtained under this Agreement shall not be reproduced, published, sold, or released in original or any other form not specifically authorized under this Agreement. Confidentiality Requirements STD. lRev 11 l12l14l EDD Agreement No. M EDDi Page 3 of 3 EXHIBIT D (Standard Agreement) c. Disclosure of any of the EDD information to any person or entity not specifically aulhorized in this Agreement is shictly prohibited. Personnel assigned to work with the EDD's confidential information shall not reveal or divulge to any person or entity any of the confidential information provided under this Agreement except as authorized or required by law. IV. PHYSICAL SAFEGUARDS a. Take precautions to ensure that only authorized personnel are given access to physical, electronic and on-line files. Store electronic and hard copy information in a place physically secure from access by unauthorized persons. Process and store information in electronic format, such as magnetic tapes or discs, in such a way that unauthorized persons cannol retrieve the information by means of computer, remote lerminal, or other means. b. Secure and maintain any computer systems (network, hardware, and software applications) that will be used in the performance of this Agreement. This includes ensuring that all security patches, upgrades, and anti-virus updates are applied as appropriate to secure data that may be used, transmitted, or stored on such systems in the performance of this Agreement. c. Store all the EDD'S confidential documents in a physically secure manner at all times to prevent unauthorized access. d. Store the EDD's confidential electronic records in a secure central computer facility. Where in-use on a shared computer system or any shared data storage system, ensure appropriate information security protections are in place. shall ensure that appropriate security access controls, storage protectlons and use restrictions are in place to keep the confidential information in the strictest confidence and shall make the information available to its own personnel on a "needto-knov/' basis only. e. Store the EDD's confidential data in encrypted format when recorded on removable electronic storage media, or on mobile computing devices, such as a laptop computer. f. Maintain an audit trail and record data access of authorized users and authorization level of access granted to the EDD'S data, based on job function. g. Direct all personnel permitted to use the EDD's data to avoid leaving the data displayed on their computer screens where unauthorized users may view it. Personnel should retrieve computer printouts as soon as they are generated so that the EDD'S data is not left unattended in printers where unauthorized personnel may access them. h. Dispose of confidential information obtained from the EDD, and any copies thereof made by after the purpose for which the confidential information is disclosed is served. Disposal means return of the confidential information to the EDD or destruction of the information utilizing an approved method of confidential destruction, which includes electronic deletion (following Department of Defense specifications) shredding, burning, or certified or witnessed destruction. Confidentiality Requirements STD. lRev'111121141 11)l'-" ffi&&trF E mpl oyrne n t Develnprnent I)e;rarLm*nl EDD Agreement No. EDD/ ATTACHMENT NO. DI 1ot1 EMPLOYMENT DEVELOPMENT DEPARTMENT CONFIDENTIALITY AG REEM ENT lnformation resources maintained by the State of Califomia Employment Development Department (EDD) and provided to your agency may be confidential or sensitive. Confidential and sensitive information are not open to the public and require special precautions to protect it from wrongful access, use, disclosure, modification, and destruction. The EDD strictly enforces information security. lf you violate these provisions, you may be subject to administrative, civil, and/or criminal action. an employee of PRINT YOUR EtilPLOYER's NAI/E hereby acknowledge that the confidential and/or sensitive records of the Employment Development Department are subject to strict confidentiality requirements imposed by state and federal law include the California Unemployment lnsurance Code (UlC) $$1094 and 21 'l 1, the California Civil Code (CC) 51798 et seq., the California Penal Code (PC) 5502, Title 5, USC $552a, Code of Federal Regulations, Title 20 part 603, and Titte 18 USC 51905. acknowledge that my supervisor and/or the Contract's Confidentiality and Data Security Monitor reviewed with me the confidentiality and security requirements, policies, and administrative processes of my organization and of the EDD. acknowledge responsibility for knowing the classification of the EDD information I work with and agree to refer questions about the classification of the EDD information (public, sensitive, confidential) to the person the Contract assigns responsibility for the security and confidentiality of the EDD's data. acknowledge responsibility for knowing the privacy, confidentiality, and data security laws that apply to the EDD information I have been granted access to by my employer, including UIC $S1094 and 2111, California Govemment Code $ 15619, CC S 1798.53, and PC $ 502. acknowledge that wrongful access, use, modification, or disclosure of confidential information may be punishable as a crime and/or result in disciplinary and/or civil action taken against me-including but not limited to: reprimand, suspension without pay, salary reduction, demotion, or dismissal-and/or flnes and penalties resulting from criminal prosecution or civil lawsuits, and/or termination of contract. acknowledge that wrongful access, inspection, use, or disclosure ofconfidential information for personal gain, curiosity, or any non-business related reason is a crime under state and federal laws. acknowledge that wrongful access, use, modification, or disclosure of confidential information is grounds for immediate termination of my organization's Contract with the EDD. agree to protect the following types of the EDD confidential and sensitive information: INII1AL ItllnAL . Wage lnformation. Employer lnformation. Claimant lnformation . Applicantlnformation. Proprietarylnformation. Operational lnformation (manuals, guidelines, procedures) . Tax Payer lnformation hereby agree to protect the EDD's information on either paper or electronic form by: rNrrrAL . Accessing or using the EDD supplied information only as specified in the Contract for the performance of the specific work I am assigned. . Never accessing information for curiosity or personal reasons. . Never showing or discussing sensitive or confidential information to or with anyone who does nol have the need to know. . Placing sensitive or confidential information only in approved locations. . Never removing sensitive or confidential information from the work site without aulhorizalion. . Following encryption requirements for all personal, sensitive, or confidential information in any portable device or media. "l certify that I have read and initialed the confidentiality statements printed above and will abide by them." Print Full Name (last, first, Ml)Signature Print Name of Requesting Agency ! Employee E Subcontractor I otner n Student n Volunteer Attachment D1 [Rev 0514141 Explain PRINT YOUR MI,E .-.,..Datg$igned =:, :r:.r,, r Checkt-tt_Jppiiipriste...!.-.L.:. .,. -_ - -__;_: -. _-----: Ilrrplr:vnrrnl -FDIEJ- D*,-;..,i-=..;; Sf.rt* "f Ca!iiurni.r EDD Agreement No. EDD/ ATTACHMENT NO. D2 1of 1 EMPLOYMENT DEVELOPMENT DEPARTMENT INDEMNITY AGREEMENT ln consideration of access to the EDD information which is personal, sensitive, or confidential, (Enter name of Chief Financial Officer or authorized Management Representative) agrees to indemnify the EDD against any and all liability costs, damages, attorney fees, and other expenses the EDD may incur by reason of or as a result of any unauthorized use of the personal, sensitive, or confidential information or any violation of the "Confidentiality Agreement" by any and all employees of: (Enter Requesting Agency/Entity Name) This obligation shall be continuous and may not be changed or modified unless agreed to in writing. ln addition, I understand that the following penalties may be incurred for any such misuse of the EDD lnformation: 1. Any individual who has access to retums, reports, or documents maintained by the EDD who fails to protect the confidential information from being published or open to the public may be punished by imprisonment in the county jail for up to one year or a fine of $20,000,00 or both, (California Unemployment lnsurance Code $$ 2111and2122). 2. Any person who intentionally discloses information, not otherwise public, which they knew or should have known was obtained from personal information maintained by a state agency, shall be subject to civil action for invasion of privacy by the individual to whom the information pertains. (California Civil Code S1798.53), 3. Any unauthorized access to the EDD computer data, computer systems, or unauthorized use of the EDD data is punishable by a fine or imprisonment in the coung jail or both. (California Penal Code s502) I certify that I have read, understand, and agree with the above terms. Print Full Name (last, first, Ml) Print Title Date Signed En@Print Name of Requesting Entity Attachment D2 [Rev 0514141 SIGNED BY REQUESTING ENTITY REPRESENTATIVE I nr g.rl *ym en I EDD Agreement No. EDD/ ATTACHMENT NO. D3 Eg,{G}Deve lnp*rent ilcpartrzrerrt t.tlilorn!a 1of1 EMPLOYMENT DEVELOPMENT DEPARTMENT STATEMENT OF RESPONSIBILITY INFORMATION SECURITY GERTIFICATION We, the lnformation Security Officer and <Enter title of authorized official: Agency Chief lnformation Officer, Confidentiality Officer, Disclosure Officer, or other individual with delegated signature authority> hereby certify that <Enter Name of the requesting entity/agency>has in place the safeguards and security requirements stated in this lnteragency Agreement. We therefore accept responsibility for ensuring compliance with these requirements, as set forth in Exhibit .D' of the EDD Contract No. M<Enter the EDD Contract Numbep. SIGNATURE SIGNATURE PRINT NAME lnformation Security Officer PRINT NAME PRINT TITLE PRINT TITLE TELEPHONE NUMBER TELEPHONE NUMBER E-MAIL ADDRESS E.MAIL ADDRESS DATE SIGNED DATE SIGNED NOTE: Retum this lnformation Security Ceftification to the EDD Contract Managerwith the signed copies of the Contract. 1. lnformation Security Certification received by. EDD CONTMCT I,IAMGER NAME 2. The EDD information asset access approved by: DATE RECEIVED CONTMCT MANAGER OR DISCLOSURE COORDINATOR DATE APPRoVED (AFF, EMATL, ETC.) NOTE: The EDD must have a signed "lnformation Security Ceftification" rn lts possession pior to disclosure of any personal, confidential, or sensitive information to the Attachment D3 [Rev 0514'l4l FOR THE EDD USE ONLY STATE OF CALIFORNIA COUNTY OF RIVERSIDE CITY OF LAKE ELSINORE ) )ss ) l, Diana Gir6n, Deputy City Clerk of the City of Lake Elsinore, California, do hereby certify that Resolution No. 2015-086 was adopted by the City Council of the City of Lake Elsinore, California, at a special meeting held on the 1st day of December 2015, and that the same was adopted by the following vote: AYES: Council Member Johnson, Council Member Magee, Mayor Pro Tem Tisdale, and Mayor Manos NOES: None ABSENT: None ABSTAIN: None