ARIZONA HOUSE OF REPRESENTATIVES

57th Legislature, 2nd Regular Session

Majority Research Staff

 

☐ Prop 105 (45 votes)	     ☐ Prop 108 (40 votes)      ☐ Emergency (40 votes)	☐ Fiscal Note


HB 2920: software applications; minors; requirements

Sponsor: Representative Way, LD 15

Committee on Science & Technology

Overview

Outlines app store provider (Provider) and developer verification requirements for minor users.

History

In existing statute commercial entities that knowingly or intentionally publish or distribute more than one-third sexual content material on the internet, including social media platforms, are required to obtain reasonable age verification methods to determine if a user attempting to access the website is at least 18 years old. These commercial entities are required to obtain a form of digital identification or comply with a commercial age verification system, neither of these methods will allow the information to be transmitted to any federal, state or local government entity (A.R.S. § 18-701). 

Several states have enacted legislation that require an app store to verify the individuals age or obtain age verification to ensure the user is of proper age to be accessing the material, including:

1)   Texas passed SB2420, effective January 1, 2026, that requires the app store to use commercially reasonable method of verification to verify the users age to put the user into predetermined age categories;

2)   Louisiana passed HB570, effective July 1, 2026, that requires an app store to request age information from the user and that the app store verify the individuals age category using commercially available methods, also this act requires the account be affiliated with a parent account; and

3)   Utah passed the Utah's App Store Accountability Act that requires an app store provider to request age information and verify the persons age category using commercially available methods. This is also required if the app is significantly changed, for notification to be sent to the account holder and if the account holder is a minor for attached parent account to be notified.

Provisions

Provider Requirements

1.   Requires a Provider to request and verify the age category information of an individual who creates an account with the Provider. (Sec. 1)

2.   Instructs a Provider, if the Provider determines the individual is a minor, to:

a.   require the minors account to be affiliated with a parent account;

b.   obtain verifiable parental consent from the holder of the affiliated parent account each time before allowing the minor to  download or purchase an application or make an in-application purchase;

c. provide a mechanism for the parent account holder to withdraw consent and notify the developer when a parent withdraws consent; and

d.   protect age category and associated verification data as specified. (Sec. 1)

3.   Requires a Provider, after receiving notice of a significant change from a developer to:

a.   notify the parent account holder of the significant change; and

b.   for a minor account, notify the parent account of the significant change and obtain renewed parental consent before providing access to the changed version of the application.

4.   Instructs a Provider, in response to a request from a developer, to provide the age category data for an account holder and the status of verifiable parental consent for a minor. (Sec. 1)

5.   Requires a Provider, for preinstalled applications, to:

a.   provide available age category information in case of a request from a developer; and

b.   take reasonable measures to facilitate verifiable parental consent for use of the application in response to a request from a developer. (Sec. 1)

6.   Restricts a Provider from any of the following:

a.   enforcing a contract or terms of service against a minor unless a Provider has obtained verifiable parental consent;

b.   knowingly misrepresents the information in the parental consent disclosure; or

c. share age category data and any associated data except as required. (Sec. 1)

Developer Requirements

7.   Requires a developer to do the following;

a.   verify through the app stores data sharing methods the age category data of the account holder and, for a minor, whether verifiable parental consent was obtained;

b.   notify each Provider about a significant change to an application;

c. use age category data received through the app store's data sharing methods to:

i. enforce any developer-created, age-related restrictions or safety-related feature; and

ii.   ensure compliance with applicable laws and regulations. (Sec. 1)

8.   Instructs a developer to request age category data or verifiable parental consent at the time an account holder does any of the following:

a.   downloads or purchases an application;

b.   launches a preinstalled application for the first time;

c. implements a significant change to the application; or

d.   complies with an applicable law. (Sec. 1)

9.   Allows a developer to request age category data not more than once during a 12-month period to verify:

a.   the accuracy of the data;

b.   whether continued account use is within the proper age category;

c. when there is reasonable suspicion of an account transfer or misuse outside of the age category; or

d.   at the time an account holder creates a new account. (Sec. 1)

10.  Instructs a developer to use the lowest age category indicated by the data received through the app store's data sharing method or the age data collected by the developer to implement any developer-created age-related restrictions or safety-related features. (Sec. 1)

11.  Prohibits a developer from doing any of the following:

a.   enforcing a contract or terms of service against a minor unless the developer has verified through the app store that verifiable parental consent has been obtained;

b.   knowingly misrepresented any information in the parental consent disclosure; or

c. sharing age category data with any person. (Sec. 1)

12.  Instructs the Attorney General to adopt rules to establish processes and means by which a Provider may verify an account holder's age category. (Sec. 1)

13.  Allows a minor or a parent of a minor who has been harmed by a violation to bring a  against a Provider or a developer. (Sec. 1)

14.  Grants a court of competent jurisdiction to award a prevailing plaintiff:

a.   the greater of either the actual damages amount or $1,000 per violation;

b.   punitive damages if the violation was egregious;

c. reasonable attorney fees; and

d.   litigation costs. (Sec. 1)

15.  Asserts a violation is a consumer fraud violation. (Sec. 1)

16.  Allows the Attorney General to bring an action against a Provider or developer to:

a.   recover a civil penalty of not more than $75,000 for each violation;

b.   restrain or enjoin the app store provider or developer from violations;

c. seek injunctive relief;

d.   recover reasonable attorney fees; and

e. recover litigation costs and reasonable costs for investigating the violations. (Sec. 1)

17.  Exempts the developer from liability for a violation if the developer demonstrates they relied in good faith in the age category data that was collected and complied with specified requirements. (Sec.1)

18.  Stipulates if the developer determined the age category and content description in good faith, the developer is not liable for a violation. (Sec. 1)

19.  Prescribes immunity that applies only to actions brought under by this act and does not limit a developer or a Provider's liability under any applicable existing law. (Sec.1)

20.  Asserts this act does not replace any other available remedy or right in state or federal law. (Sec. 1)

21.  Specifies that this legislation does not prevent a Provider or developer from taking  reasonable measures to:

a.   block, detect or prevent distribution to minors of;

i. unlawful material;

ii.   obscene material;

iii.  other harmful material

b.   block of filter spam;

c. prevent criminal activity; and

d.   protect an app store or app security. (Sec. 1)

22.  Specifies that a Provider does not have disclose user information to a developer beyond age category data or status of parental consent. (Sec. 1)

23.  Prohibits a Provider or developer from implementing measures in a manner that are arbitrary, capricious, anticompetitive or unlawful. (Sec. 1)

24.  Prohibits a developer to collect, retain, reidentify or link any information that is not necessary to verify age category data or in the developer ordinary course of business. (Sec. 1)

25.  Prohibits a Provider or developer from blocking access to an application that an account holder has downloaded or installed before the effective date except if there has been a significant change to the application or a parent account revokes verifiable consent for the minor account. (Sec. 1)

26.  Defines key terms. (Sec. 1)

27.  Makes the legislation effective on November 30, 2026. (Sec. 2)

28.  Contains a severability clause. (Sec. 3)

29.   

30.   

31.  ---------- DOCUMENT FOOTER ---------

32.  Initials TM                       HB 2920

33.  2/4/2026    Page 0 Science & Technology

34.   

35.  ---------- DOCUMENT FOOTER ---------