Written Information Security Program (Wisp) For Protection Of Personal Information Template Page 3

ADVERTISEMENT

our business practices that may implicate the security or integrity of
records containing Personal Information.
E.
Limits on Collection and Storage of Personal Information at the Corporation
1. The Corporation is in possession of Personal Information of
Massachusetts residents both as an employer and as a nonprofit
organization.
2. As an employer, the Corporation possesses Personal Information for
its employees. The Personal Information that is collected and stored
from each employee shall be limited to: that information which is
necessary for employment, such as tax forms; that information which
is voluntarily provided to obtain certain benefits of employment, such
as pension, health, life and disability insurances; and that information
which is necessary for the Corporation to comply with state or federal
laws and regulations.
3. As part of its legitimate organizational purpose, the Corporation
possesses Personal Information of Massachusetts residents obtained
during the course of the Corporation’s activities. The Personal
Information that is collected and stored shall be limited to: that
information which is reasonably necessary to accomplish the
Corporation’s legitimate organizational purpose; and that information
which is necessary for the Corporation to comply with state or federal
laws and regulations.
F.
Review of WISP and Procedures
The Corporation’s WISP and all security measures and procedures shall be
reviewed at least annually and, in addition, whenever there is a material
change in the Corporation’s business practices that may reasonably
implicate the security or integrity of records containing Personal
Information. The Data Security Coordinator shall be responsible for this
review and shall fully apprise the Organization’s Board of the results of
that review and any recommendations for improved security arising out of
that review.
II. PROTECTIONS AGAINST INTERNAL DATA SECURITY BREACH
To combat internal risks to the security, confidentiality, and/or integrity of any
electronic, paper or other records containing Personal Information, and evaluating and
improving, where necessary, the effectiveness of the current safeguards for limiting such
risks, the following measures are mandatory and are effective immediately:
3

ADVERTISEMENT

00 votes

Related Articles

Related forms

Related Categories

Parent category: Life