Sec. 113. Privacy by design
136 words·~1 min read·
/bill/115/s/2187/is/section-113A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
Each covered entity shall, in a manner proportional to the size, type, and nature of the covered information that it collects, implement a comprehensive information privacy program by— incorporating necessary development processes and practices throughout the product life cycle that are designed to safeguard the personally identifiable information that is covered information of individuals based on— the reasonable expectations of such individuals regarding privacy; and the relevant threats that need to be guarded against in meeting those expectations; and maintaining appropriate management processes and practices throughout the data life cycle that are designed to ensure that information systems comply with— the provisions of this title; the privacy policies of a covered entity; and the privacy preferences of individuals that are consistent with the consent choices and related mechanisms of individual participation as described in section 122.