A bill for an act relating to app store provider and app developer requirements concerning minor users, and providing civil penalties, and including applicability provisions.
SF 2197 creates a new chapter in Iowa law governing app store providers and app developers when their services are used by minors. The bill requires app stores to ask for and verify an account holder’s age category when an account is created, and if the user is a minor, to link the account to a parent account and obtain verifiable parental consent before allowing app downloads, app purchases, or in-app purchases. It also requires renewed parental consent after a “significant change” to an app, such as changes to data practices, age ratings, monetization features, functionality, or user experience.
The bill also imposes parallel obligations on developers. Developers must use app-store-shared age category data and parental-consent status to enforce age-based restrictions, safety defaults, and legal compliance, and they may request age data in limited circumstances. Developers are prohibited from sharing age category data, and both developers and app store providers are barred from misrepresenting parental-consent disclosures or enforcing terms of service against minors without the required consent. The attorney general is directed to adopt rules for age-verification processes, and the bill becomes applicable to the core provider and developer requirements on December 1, 2026.
The bill would add a new chapter, Iowa Code chapter 554J, and make a conforming amendment to Iowa’s consumer fraud/unfair practices law, section 714.16, to classify violations of chapter 554J as unlawful practices. It creates new compliance duties for app store providers and app developers, establishes privacy and data-handling limits for age-category information, and authorizes both private lawsuits and attorney general enforcement. Remedies include actual damages or $1,000 per violation, punitive damages in egregious cases, attorney fees, civil penalties up to $7,500 per violation, and injunctive relief.
The available legislative history suggests the bill was moving forward in committee, with a subcommittee recommending amendment and passage. Based on the bill’s structure, the overall tone appears protective of minors and supportive of parental oversight, while also attempting to preserve app functionality and limit unnecessary data collection. No recorded floor debate or vote totals are provided, so the broader chamber sentiment cannot be measured from the supplied materials.
The main points of contention are likely to center on age verification, parental consent, and data privacy. The bill requires app stores to collect and share age-category data with developers, which may raise concerns about privacy, data security, and the burden of verifying users’ ages. Developers and app store providers may also object to the operational complexity of renewed consent after app changes and the risk of liability for misclassification or disclosure errors. At the same time, the bill includes safe harbors, emergency-service exceptions, and limits on data sharing, reflecting an effort to balance child protection with privacy and practical implementation.