Establishing secure connection…Loading editor…Preparing document…

Criminal Justice Information Services Agreement

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

Criminal Justice Information Services Agreement

This Criminal Justice Information Services Agreement (the Agreement) is entered into as of by and between Provider Agency: with mailing address ("Provider"), and Recipient Agency: with mailing address ("Recipient").

RECITALS

WHEREAS, Provider operates and administers criminal justice information systems including criminal history record information, fingerprint-based identification services, and related data (collectively, the Services) and maintains custody and control over criminal justice information subject to statutory and regulatory restrictions;

WHEREAS, Recipient seeks access to the Services for legitimate criminal justice purposes, as defined under applicable law and the policies and procedures established by Provider, and agrees to meet the security and handling requirements necessary to protect the integrity and confidentiality of the criminal justice information;

WHEREAS, the parties desire to set forth their respective obligations, conditions of access, and remedies with respect to Recipient's access to and use of the Services.

NOW, THEREFORE, in consideration of the mutual promises contained herein and other good and valuable consideration, the parties agree as follows:

1. DEFINITIONS

1.1 "Criminal Justice Information" means criminal history record information, fingerprint data, disposition information, protective orders, and other records maintained and distributed by Provider that are subject to legal restrictions.

1.2 "Authorized User" means an individual employed by or under contract with Recipient who has completed required background checks and training and who has been granted access by Provider pursuant to the terms of this Agreement.

2. GRANT OF ACCESS

2.1 Subject to the terms and conditions of this Agreement, Provider grants Recipient a non-exclusive, non-transferable right to access and use the Services solely for authorized criminal justice purposes. Access is limited to the level and scope expressly authorized in writing by Provider.

2.2 Recipient shall not permit use of the Services for non-criminal-justice purposes, including commercial solicitation, private investigations for hire, or any purpose inconsistent with applicable statutes or regulations.

3. AUTHORIZED USERS; BACKGROUND CHECKS

3.1 Recipient shall maintain a list of Authorized Users and provide such list to Provider upon request. Recipient must ensure each Authorized User undergoes fingerprint-based background checks, employment verification, and any clearance required by Provider prior to being granted access.

3.2 Recipient represents that it will not allow any individual to be an Authorized User who has not met the background check standards or who has disqualifying convictions as established by Provider.

4. SECURITY AND DATA PROTECTION

4.1 Recipient shall implement and maintain technical, administrative, and physical safeguards reasonably designed to protect Criminal Justice Information from unauthorized access, disclosure, alteration, or destruction. Safeguards shall include, at a minimum, role-based access controls, unique user authentication, encrypted transmission where required by Provider, and maintenance of audit logs.

4.2 Recipient shall not store Criminal Justice Information on portable media or personal devices unless expressly authorized in writing by Provider and secured in accordance with Provider's requirements.

5. USE AND DISSEMINATION RESTRICTIONS

5.1 Recipient shall use Criminal Justice Information only for authorized purposes and shall not redisclose such information except as permitted by law and as expressly authorized by Provider. Any permissible redisclosure shall be on a need-to-know basis and subject to Recipient's written policies consistent with Provider's policies.

5.2 Recipient shall maintain records of all disclosures and shall make such records available to Provider for inspection upon request.

6. AUDIT AND MONITORING

6.1 Provider reserves the right to audit, monitor, and review Recipient's systems, personnel, policies, and practices to verify compliance with this Agreement. Recipient shall cooperate and provide reasonable access to facilities, systems, and personnel.

7. INCIDENT RESPONSE; BREACH NOTIFICATION

7.1 In the event of any actual or suspected security incident, unauthorized access, or disclosure involving Criminal Justice Information, Recipient shall notify Provider immediately and in no event later than hours of discovery. Notification shall describe the nature of the incident, data affected, steps taken to mitigate harm, and corrective actions planned.

7.2 Recipient shall cooperate with Provider's incident response investigations, remediation efforts, and any required notices to affected individuals or authorities.

8. TRAINING AND COMPLIANCE

8.1 Recipient shall require Authorized Users to complete initial and periodic refresher training concerning the proper handling of Criminal Justice Information, privacy obligations, and security procedures. The training must be documented and retained for inspection by Provider.

9. FEES

9.1 If applicable, Recipient shall pay fees for access or services as specified by Provider. Fees are due within the timeframe set forth in Provider's billing notification and are non-refundable unless expressly provided otherwise.

10. TERM AND TERMINATION

10.1 The term of this Agreement commences on and shall continue until , unless earlier terminated in accordance with this Agreement.

10.2 Provider may suspend or terminate access immediately upon notice if Recipient or any Authorized User materially breaches this Agreement or if continued access would jeopardize the integrity of the Services or violate law.

11. CONFIDENTIALITY

11.1 Recipient shall treat all Criminal Justice Information as confidential and shall not disclose such information except as permitted by law and this Agreement. Recipient shall implement policies to ensure confidentiality and shall require third-party vendors to adhere to equivalent confidentiality obligations.

12. INDEMNIFICATION; LIMITATION OF LIABILITY

12.1 Recipient shall defend, indemnify, and hold Provider harmless from and against any claims, liabilities, losses, or expenses (including reasonable attorneys' fees) arising from Recipient's breach of this Agreement, misuse of Criminal Justice Information, or unauthorized disclosures.

12.2 Except to the extent caused by Provider's gross negligence or willful misconduct, Provider's liability under this Agreement shall be limited to direct damages and shall not include consequential, incidental, punitive, or special damages.

13. GOVERNING LAW

This Agreement shall be governed by and construed in accordance with the laws of without regard to conflict of law principles.

14. ENTIRE AGREEMENT

This Agreement constitutes the entire agreement between the parties with respect to the subject matter and supersedes all prior and contemporaneous agreements, representations, and understandings, whether written or oral.

15. SEVERABILITY

If any provision of this Agreement is held to be invalid or unenforceable, the remaining provisions shall remain in full force and effect to the maximum extent permitted by law.

16. NOTICES

All notices required or permitted under this Agreement shall be in writing and delivered to the addresses set forth below or to such other address as a party may designate by notice in accordance with this section. Notices shall be deemed effective upon receipt.

17. AMENDMENTS; WAIVER; COUNTERPARTS

17.1 No amendment or modification of this Agreement shall be effective unless made in writing and signed by authorized representatives of both parties.

17.2 No failure or delay by either party in exercising any right or remedy shall operate as a waiver of that right. This Agreement may be executed in counterparts, each of which shall be an original and all of which together shall constitute one instrument.

18. MISCELLANEOUS PROVISIONS

18.1 Remedies under this Agreement are cumulative and in addition to any remedies available at law or in equity, including injunctive relief. Recipient acknowledges that unauthorized access to or disclosure of Criminal Justice Information may cause irreparable harm for which monetary damages may be inadequate.

Provider Agency:

By:

Date:

Recipient Agency:

By:

Date:

Enter text✕

What a Criminal Justice Information Services Agreement Is

A Criminal Justice Information Services Agreement (CJIS Agreement) is a written contract that governs access to criminal justice information, sets security obligations, and assigns responsibilities among agencies, contractors, and vendors. It documents permitted uses, data handling rules, background check requirements, encryption and access controls, auditing duties, and incident reporting procedures. Agencies use CJIS Agreements to meet state and federal standards for handling criminal history and other sensitive records and to establish operational, technical, and personnel safeguards before granting system or data access.

Why the CJIS Agreement Matters for Access and Compliance

A CJIS Agreement confirms who can access criminal justice data, how that data must be protected, and the penalties for misuse. It is a core control for legal and operational compliance.

Why the CJIS Agreement Matters for Access and Compliance

Who Typically Completes and Signs a CJIS Agreement

Coordination across legal, IT, and compliance teams ensures accurate scope, required attachments, and timely approval before access is granted.

  • State or local criminal justice agencies and records custodians who control access to criminal history data.
  • Third-party vendors or contractors providing IT, analytics, background-check, or data-hosting services.
  • System administrators, security officers, and human resources representatives responsible for controls and personnel clearances.

Common Signatory Roles

Agency Authorizing Official

Typically a records custodian, chief information officer, or designated official who has the authority to grant system access and sign on behalf of the agency. This person confirms security controls, approves background checks, and accepts contractual responsibilities for data protection.

Vendor Executive

A senior representative (CEO, COO, or general counsel) authorized to accept contractual obligations for a vendor or contractor. This signer certifies that the vendor will meet technical safeguards, personnel screening, audit reporting, and any state-specific CJIS requirements.

Core Elements to Include in a Professional CJIS Agreement

A complete CJIS Agreement should clearly allocate responsibilities, specify security controls, and attach required supporting documents so that auditors and auditors’ designees can verify compliance.

Purpose and Scope

Define the exact data types, systems, and purposes for which criminal justice information may be accessed and processed; limit use to authorized functions only and list exclusions.

Access and Background Checks

Specify background-screening requirements, frequency of rechecks, disqualifying criteria, and who bears the cost and scheduling of required checks.

Technical Safeguards

List encryption standards, network segmentation, multifactor authentication, logging and monitoring obligations, and retention requirements for audio/video recordings if applicable.

Audit and Reporting

Describe audit trail contents, reporting cadence, retention of logs, and agency rights to inspect or audit vendor systems and compliance evidence.

Incident Response

Define incident notification timelines, responsibilities for containment and remediation, and regulatory reporting obligations including law enforcement notification.

Termination and Sanctions

State grounds for suspension or termination of access, remedies for noncompliance, and procedures for secure return or destruction of data after contract end.

Security and Compliance Controls to Document

Encryption: AES-256 at rest
Transport Security: TLS 1.2/1.3
Audit Trail: Immutable logging required
Certifications: SOC 2 Type II
HIPAA: BAA required when PHI present
21 CFR Part 11: Compliant controls available

Key Risks and Penalties for Noncompliance

Access Suspension: Immediate loss of system access
Contract Termination: Agreement may be voided
Civil Liability: Damages and injunctive relief
Criminal Liability: Prosecution for misuse
Regulatory Fines: Fines under applicable statutes
Reputational Harm: Loss of future contracts

Common Preparation Errors to Avoid

  • Using imprecise party names or entity types that do not match government records, which can delay verification and background checks.
  • Failing to attach required security plans, SSAE/SOC reports, or BAA addenda when handling protected personal or health information.
  • Omitting clear effective and expiration dates, which complicates auditability and can create scope ambiguity for ongoing access.
  • Not designating a named agency point of contact for audits and incident response, which slows breach handling and regulatory reporting.

Step-by-Step: Completing a CJIS Agreement

Follow these sequential steps to prepare, review, and execute a CJIS Agreement accurately and efficiently.

  • 01
    Assemble Parties: Identify official legal names and authorized signers.
  • 02
    Define Scope: List specific data types, systems, and permitted uses.
  • 03
    Attach Controls: Include security plans, background-check policies, and certifications.
  • 04
    Authorize Signatures: Obtain signatures from authorized officials and retain executed copies.

How to Configure an Online CJIS Agreement Workflow

Configure fields and routing to match internal approval steps and audit requirements before sending for signature.

Field Configuration
Signer Order Set role-based, sequential signing for agency then vendor
Authentication Enable email verification plus SMS or SSO where available
Attachments Require SOC reports, security plans, and BAA as mandatory uploads
Retention Set automatic archival and exportable audit trail retention

Where to Send and How Access Is Granted

After execution, distribute executed copies and coordinate account provisioning, background checks, and technical onboarding.

  • Executed Copies: Send signed PDFs to agency records and vendor legal teams
  • Background Checks: Initiate checks per agreement timelines and verify clearance
  • Provisioning: Grant system credentials only after all controls validated
  • Audit Handover: Provide audit artifacts and access logs on request

Technical and Platform Requirements for Digital Execution

Choose a platform that supports strong audit trails, secure storage, and exportable logs for agency audits and regulatory review.

  • Integrations: Salesforce, Microsoft 365, NetSuite
  • File Formats: PDF, DOCX supported
  • Authentication: Email + SMS or SSO

Typical Timelines and Processing Expectations

Expect several coordinated timelines: legal review, background checks, technical onboarding, and provisioning each follow defined windows.

Legal Review:

Allow 5–10 business days for legal and compliance review

Background Screening:

Standard checks complete in 7–21 days depending on scope

Technical Onboarding:

Provisioning and configuration typically 3–10 business days

Incident Reporting:

Report breaches per agreement timelines, often within 72 hours

Audit Response:

Provide requested artifacts within 10–30 business days

Popular eSignature Options for Executing CJIS Agreements

Compare common pricing and capability criteria for eSignature platforms; select a vendor that meets required security, audit, and BAA needs.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Yes, trial available Yes, trial available Yes, limited trial Yes, limited trial
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No
Envelope Cap No envelope cap 100 envelopes/user/year Varies by plan Varies by plan Varies by plan

Frequently Asked Questions and Troubleshooting

Answers to common questions about completing, signing, and maintaining CJIS Agreements.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users