Sec. 7. Privacy protection officers
129 words·~1 min read·
/bill/116/hr/8749/ih/section-7A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
Each covered entity with annual revenue in excess of $25,000,000 the prior year shall designate at least 1 appropriately qualified employee as a privacy protection officer who shall— educate employees about compliance requirements; train employees involved in data processing; conduct regular, comprehensive audits to ensure compliance and make records of the audits available to enforcement authorities upon request; maintain updated, clear, and understandable records of all data security practices undertaken by the covered entity; serve as the point of contact between the covered entity and enforcement authorities; and advocate for policies and practices within the covered entity that promote individual privacy.
The privacy protection officer shall not be dismissed or otherwise penalized by the covered entity for performing any of the tasks assigned to the person under this section.