Skip to main content
CMIS by Construction Management Enterprises ®
  • Home
  • Why CMIS
  • Products
  • Customers
  • Product Overview See the CMIS modules that support the project record. Solutions by Role Find views for owners, inspectors, engineers, and delivery teams. Customers Browse agencies, cities, counties, and partners using CMIS. Security & Trust Review hosting, access control, encryption, and data safeguards. Accessibility Read CMIS website accessibility commitments. Contact CMIS Reach the team for product, procurement, or support questions.
    Resource Hub Choose what your team needs next. Product fit, proof points, trust details, and support paths are organized here.
  • Request a Demo
  • Log In

Data Breach Policy

How CMIS responds when sensitive information may be at risk.

Last modified: 10/19/2022

CMIS treats potential incidents as a response process, not a guessing exercise: investigate, contain, assess, notify where required, and reduce future risk.

Incident Response CMIS
Detect
Contain
Assess
Notify
Response log active

Response Focus

Investigate quickly

Suspected incidents are reviewed promptly with access limited to the personnel needed to investigate.

Contain and assess

CMIS evaluates what happened, what information may be involved, and what steps reduce risk.

Notify responsibly

Notifications are handled based on legal requirements, verified facts, and the nature of the incident.

Purpose

This policy establishes how Construction Management Enterprises responds in the event of a data breach or suspected data breach. It outlines the process to investigate potential breaches, mitigate damage, and provide appropriate notice to affected parties when required.

Scope

This policy applies to incidents where Construction Management Enterprises could reasonably suspect or confirm a breach of customer, employee, contractor, or other personal identifying information handled by CMIS.

Definitions

Personal Identifying Information (PII) means information that could be used to distinguish or trace an individual's identity. Examples may include Social Security numbers, tax identification numbers, payment card information, payroll information, medical information, biometric records, dates of birth, addresses, phone numbers, maiden names, customer numbers, or similar personal information.

A breach means a situation where PII is accessed by someone other than an authorized user, or for a purpose that is not authorized.

Upon Learning of a Breach

Construction Management Enterprises will promptly investigate a breach or suspected breach of PII. Because PII is confidential, information about the investigation will be shared only with personnel who need it to perform the investigation and response.

The investigation will document available facts, including when the incident happened, how it happened, what types of information may have been involved, how many individuals may be affected, who was involved in the response, and what discoveries were made during the review.

Risk Assessment

If Construction Management Enterprises verifies and contains a breach, the response team will perform a risk assessment based on the sensitivity of the information, the volume of information involved, the number of individuals affected, whether the information is likely usable, whether the information appears to have been intentionally targeted, the strength of protections in place, and the ability to mitigate harm.

The response team will compile the findings, summarize the risk assessment, and provide the information to management and other appropriate advisors for review.

Notifying Affected Parties

Notification decisions are based on applicable legal requirements, the nature of the information involved, the number of individuals affected, and the facts developed through the investigation and risk assessment. Construction Management Enterprises may consult legal counsel to determine whether notice is required and what form the notice should take.

When notice is required, Construction Management Enterprises will notify affected parties in a timely and appropriate manner. Notice may be delayed if needed to avoid incomplete or misleading information, to support an active investigation, or to comply with applicable law enforcement or legal requirements.

Notification Content

A notification may include a brief description of the incident, the general types of information involved, what Construction Management Enterprises is doing to investigate and mitigate the incident, steps affected individuals can take to reduce potential harm, and contact information for follow-up questions.

Mitigating Risk

Based on the risk assessment, Construction Management Enterprises will develop and carry out an incident-specific mitigation plan. The plan may include containment actions, access review, credential changes, monitoring, communication with affected parties, additional safeguards, or other steps intended to reduce the impact of the incident and prevent similar incidents from recurring.

When appropriate, Construction Management Enterprises may provide affected individuals with practical steps they can take, such as monitoring accounts, reporting suspicious activity, contacting credit bureaus, watching for phishing attempts, filing a report with local law enforcement, or using identity-theft resources provided by government agencies.

Contact CMIS

Questions about this policy can be sent to contact@c-mis.com.

CMIS by Construction Management Enterprises ®

CMIS is a purpose-built SaaS platform for public agency construction management, document control, field reporting, progress payments, and project compliance.

Elk Grove office 9245 Laguna Springs Drive, #200
Elk Grove, CA 95758

+1 (530) 207-0083
contact@c-mis.com

Explore

  • Home
  • Why CMIS
  • Products
  • Customers

Company

  • About CMIS
  • Contact
  • Security & Trust
  • Accessibility
  • Request a Demo

Legal

  • Privacy Policy
  • Cookie Policy
  • Terms
  • Software License Agreement
  • AI Product Disclaimer

© 2026 Construction Management Enterprises, DBA CMIS. California DBE #52672. All rights reserved.

LinkedIn Facebook Medium X

Privacy choices

Choose how CMIS uses cookies

Necessary cookies support security and core site operation. Optional categories stay off unless you allow them.

Privacy Policy and Cookie Policy