(1) Any controller or processor in custody or possession of agricultural data shall establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of such agricultural data.
(2) Such security practices shall be appropriate for the volume and nature of the agricultural data and protect against unauthorized access, use, disclosure, modification, or loss.