I had a discussion about this and the consensus was you're probably on better legal and usability ground to just use a shorter passcode timeout (like 30 minutes).