Contract Language PCI

Data Privacy & Breach Notification Contract Language (PCI)

All contracts entered into by Middlebury College, including payment card data, must contain the following language:

Middlebury requires that [vendor] shall at all times maintain compliance with the most current Payment Card Industry Data Security Standards (PCI DSS).  [vendor] will be required to provide written confirmation of compliance annually.  [vendor] acknowledges responsibility for the security of cardholder data, to the extent that they could impact the security of the customer's cardholder data, as defined within PCI DSS.  [vendor] acknowledges and agrees that cardholder data may only be used for completing the contracted services as described in the full text of this document, or as required by the PCI DSS, or as required by applicable law.  

In the event of a breach or intrusion or otherwise unauthorized access to cardholder data stored at or for [vendor], [vendor] shall immediately notify Middlebury's Office of the VP for Administration and Treasurer to allow the proper PCI DSS compliant breach notification process to commence.  [vendor] shall provide appropriate payment card companies, acquiring financial institutions and their respective designees access to the [vendor]'s facilities and all pertinent records to conduct a review of the [vendor]'s compliance with the PCI DSS requirements.

In the event of a breach or intrusion [vendor] acknowledges any/all costs related to breach or intrusion or unauthorized access to cardholder data entrusted to [vendor] deemed to be the fault of [vendor] shall be the liability of [vendor].  [vendor] agrees to assume responsibility for informing all such individuals in accordance with applicable law and to indemnify and hold harmless Middlebury and its officers and employees from and against any claims, damages or other harm related to such breach."