4 | 9 | | |
---|
5 | 10 | | |
---|
6 | 11 | | A BILL TO BE ENTITLED |
---|
7 | 12 | | AN ACT |
---|
8 | 13 | | relating to the regulation of platforms for the sale and |
---|
9 | 14 | | distribution of software applications for mobile devices. |
---|
10 | 15 | | BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF TEXAS: |
---|
11 | 16 | | SECTION 1. Subtitle C, Title 5, Business & Commerce Code, is |
---|
12 | 17 | | amended by adding Chapter 121 to read as follows: |
---|
13 | 18 | | CHAPTER 121. SOFTWARE APPLICATIONS |
---|
14 | 19 | | SUBCHAPTER A. GENERAL PROVISIONS |
---|
15 | 20 | | Sec. 121.001. SHORT TITLE. This chapter may be cited as the |
---|
16 | 21 | | App Store Accountability Act. |
---|
17 | 22 | | Sec. 121.002. DEFINITIONS. In this chapter: |
---|
18 | 23 | | (1) "Age category" means information collected by the |
---|
19 | 24 | | owner of an app store to designate a user based on the age |
---|
20 | 25 | | categories described by Section 121.021(b). |
---|
21 | 26 | | (2) "App store" means a publicly available Internet |
---|
22 | 27 | | website, software application, or other electronic service that |
---|
23 | 28 | | distributes software applications from the owner or developer of a |
---|
24 | 29 | | software application to the user of a mobile device. |
---|
25 | 30 | | (3) "Minor" means a child who is younger than 18 years |
---|
26 | 31 | | of age who has not had the disabilities of minority removed for |
---|
27 | 32 | | general purposes. |
---|
28 | 33 | | (4) "Mobile device" means a portable, wireless |
---|
29 | 34 | | electronic device, including a tablet or smartphone, capable of |
---|
30 | 35 | | transmitting, receiving, processing, and storing information |
---|
31 | 36 | | wirelessly that runs an operating system designed to manage |
---|
32 | 37 | | hardware resources and perform common services for software |
---|
33 | 38 | | applications on handheld electronic devices. |
---|
34 | 39 | | (5) "Personal data" means any information, including |
---|
35 | 40 | | sensitive data, that is linked or reasonably linkable to an |
---|
36 | 41 | | identified or identifiable individual. The term includes |
---|
37 | 42 | | pseudonymous data when the data is used by a person who processes or |
---|
38 | 43 | | determines the purpose and means of processing the data in |
---|
39 | 44 | | conjunction with additional information that reasonably links the |
---|
40 | 45 | | data to an identified or identifiable individual. The term does not |
---|
41 | 46 | | include deidentified data or publicly available information. |
---|
42 | 47 | | SUBCHAPTER B. DUTIES OF APP STORES |
---|
43 | 48 | | Sec. 121.021. DUTY TO VERIFY AGE OF USER; AGE CATEGORIES. |
---|
44 | 49 | | (a) When an individual in this state creates an account with an app |
---|
45 | 50 | | store, the owner of the app store shall use a commercially |
---|
46 | 51 | | reasonable method of verification to verify the individual's age |
---|
47 | 52 | | category under Subsection (b). |
---|
48 | 53 | | (b) The owner of an app store shall use the following age |
---|
49 | 54 | | categories for assigning a designation: |
---|
50 | 55 | | (1) an individual who is younger than 13 years of age |
---|
51 | 56 | | is considered a "child"; |
---|
52 | 57 | | (2) an individual who is at least 13 years of age but |
---|
53 | 58 | | younger than 16 years of age is considered a "younger teenager"; |
---|
54 | 59 | | (3) an individual who is at least 16 years of age but |
---|
55 | 60 | | younger than 18 years of age is considered an "older teenager"; and |
---|
56 | 61 | | (4) an individual who is at least 18 years of age is |
---|
57 | 62 | | considered an "adult." |
---|
58 | 63 | | Sec. 121.022. PARENTAL CONSENT REQUIRED. (a) If the owner |
---|
59 | 64 | | of the app store determines under Section 121.021 that an |
---|
60 | 65 | | individual is a minor who belongs to an age category that is not |
---|
61 | 66 | | "adult," the owner shall require that the minor's account be |
---|
62 | 67 | | affiliated with a parent account belonging to the minor's parent or |
---|
63 | 68 | | guardian. |
---|
64 | 69 | | (b) For an account to be affiliated with a minor's account |
---|
65 | 70 | | as a parent account, the owner of an app store must use a |
---|
66 | 71 | | commercially reasonable method to verify that the account belongs |
---|
67 | 72 | | to an individual who: |
---|
68 | 73 | | (1) the owner of the app store has verified belongs to |
---|
69 | 74 | | the age category of "adult" under Section 121.021; and |
---|
70 | 75 | | (2) has legal authority to make a decision on behalf of |
---|
71 | 76 | | the minor with whose account the individual is seeking affiliation. |
---|
72 | 77 | | (c) A parent account may be affiliated with multiple minors' |
---|
73 | 78 | | accounts. |
---|
78 | 82 | | (1) download a software application; |
---|
79 | 83 | | (2) purchase a software application; or |
---|
80 | 84 | | (3) make a purchase in or using a software |
---|
81 | 85 | | application. |
---|
82 | 86 | | (e) The owner of an app store must: |
---|
83 | 87 | | (1) obtain consent for each individual download or |
---|
84 | 88 | | purchase sought by the minor; and |
---|
85 | 89 | | (2) notify the developer of each applicable software |
---|
86 | 90 | | application if a minor's parent or guardian revokes consent through |
---|
87 | 91 | | a parent account. |
---|
88 | 92 | | (f) To obtain consent from a minor's parent or guardian |
---|
89 | 93 | | under Subsection (d), the owner of an app store may use any |
---|
90 | 94 | | reasonable means to: |
---|
91 | 95 | | (1) disclose to the parent or guardian: |
---|
92 | 96 | | (A) the specific software application or |
---|
93 | 97 | | purchase for which consent is sought; |
---|
94 | 98 | | (B) the rating under Section 121.052 assigned to |
---|
95 | 99 | | the software application or purchase; |
---|
96 | 100 | | (C) the specific content or other elements that |
---|
97 | 101 | | led to the rating assigned under Section 121.052; |
---|
98 | 102 | | (D) the nature of any collection, use, or |
---|
99 | 103 | | distribution of personal data that would occur because of the |
---|
100 | 104 | | software application or purchase; and |
---|
101 | 105 | | (E) any measures taken by the developer of the |
---|
102 | 106 | | software application or purchase to protect the personal data of |
---|
103 | 107 | | users; |
---|
104 | 108 | | (2) give the parent or guardian a clear choice to give |
---|
105 | 109 | | or withhold consent for the download or purchase; and |
---|
106 | 110 | | (3) ensure that the consent is given: |
---|
107 | 111 | | (A) by the parent or guardian; and |
---|
108 | 112 | | (B) through the account affiliated with a minor's |
---|
109 | 113 | | account under Subsection (a). |
---|
110 | 114 | | (g) If a software developer provides the owner of an app |
---|
111 | 115 | | store with notice of a change under Section 121.053, the owner of |
---|
112 | 116 | | the app store shall: |
---|
113 | 117 | | (1) notify any individual who has given consent under |
---|
114 | 118 | | this section for a minor's use or purchase relating to a previous |
---|
115 | 119 | | version of the changed software application; and |
---|
116 | 120 | | (2) obtain consent from the individual for the minor's |
---|
117 | 121 | | continued use or purchase of the software application. |
---|
118 | | - | (h) The owner of an app store is not required to obtain |
---|
119 | | - | consent from a minor's parent or guardian for: |
---|
120 | | - | (1) the download of a software application that: |
---|
121 | | - | (A) provides a user with direct access to |
---|
122 | | - | emergency services, including: |
---|
123 | | - | (i) 9-1-1 emergency services; |
---|
124 | | - | (ii) a crisis hotline; or |
---|
125 | | - | (iii) an emergency assistance service that |
---|
126 | | - | is legally available to a minor; |
---|
127 | | - | (B) limits data collection to information: |
---|
128 | | - | (i) collected in compliance with the |
---|
129 | | - | Children's Online Privacy Protection Act of 1998 (15 U.S.C. Section |
---|
130 | | - | 6501 et seq.); and |
---|
131 | | - | (ii) necessary for the provision of |
---|
132 | | - | emergency services; |
---|
133 | | - | (C) allows a user to access and use the software |
---|
134 | | - | application without requiring the user to create an account with |
---|
135 | | - | the software application; and |
---|
136 | | - | (D) is operated by or in partnership with: |
---|
137 | | - | (i) a governmental entity; |
---|
138 | | - | (ii) a nonprofit organization; or |
---|
139 | | - | (iii) an authorized emergency service |
---|
140 | | - | provider; or |
---|
141 | | - | (2) the purchase or download of a software application |
---|
142 | | - | that is operated by or in partnership with a nonprofit organization |
---|
143 | | - | that: |
---|
144 | | - | (A) develops, sponsors, or administers a |
---|
145 | | - | standardized test used for purposes of admission to or class |
---|
146 | | - | placement in a postsecondary educational institution or a program |
---|
147 | | - | within a postsecondary educational institution; and |
---|
148 | | - | (B) is subject to Subchapter D, Chapter 32, |
---|
149 | | - | Education Code. |
---|
209 | 164 | | Sec. 121.027. CONSTRUCTION OF SUBCHAPTER. Nothing in this |
---|
210 | 165 | | subchapter may be construed to: |
---|
211 | 166 | | (1) prevent the owner of an app store that operates in |
---|
212 | 167 | | this state from taking reasonable measures to block, detect, or |
---|
213 | 168 | | prevent the distribution of: |
---|
214 | 169 | | (A) obscene material, as that term is defined by |
---|
215 | 170 | | Section 43.21, Penal Code; or |
---|
216 | 171 | | (B) other material that may be harmful to minors; |
---|
217 | 172 | | (2) require the owner of an app store that operates in |
---|
218 | 173 | | this state to disclose a user's personal data to the developer of a |
---|
219 | 174 | | software application except as provided by this subchapter; |
---|
220 | 175 | | (3) allow the owner of an app store that operates in |
---|
221 | 176 | | this state to use a measure required by this chapter in a manner |
---|
222 | 177 | | that is arbitrary, capricious, anticompetitive, or unlawful; |
---|
223 | 178 | | (4) block or filter spam; |
---|
224 | 179 | | (5) prevent criminal activity; or |
---|
225 | 180 | | (6) protect the security of an app store or software |
---|
226 | 181 | | application. |
---|
227 | 182 | | SUBCHAPTER C. DUTIES OF SOFTWARE APPLICATION DEVELOPERS |
---|
228 | 183 | | Sec. 121.051. APPLICABILITY OF SUBCHAPTER. This subchapter |
---|
229 | 184 | | applies only to the developer of a software application that the |
---|
230 | 185 | | developer makes available to users in this state through an app |
---|
231 | 186 | | store. |
---|
232 | 187 | | Sec. 121.052. DESIGNATION OF AGE RATING. (a) The developer |
---|
233 | 188 | | of a software application shall assign to each software application |
---|
234 | 189 | | and to each purchase that can be made through the software |
---|
235 | 190 | | application an age rating based on the age categories described by |
---|
236 | 191 | | Section 121.021(b). |
---|
237 | 192 | | (b) The developer of a software application shall provide to |
---|
238 | 193 | | each app store through which the developer makes the software |
---|
239 | 194 | | application available: |
---|
240 | 195 | | (1) each rating assigned under Subsection (a); and |
---|
241 | 196 | | (2) the specific content or other elements that led to |
---|
242 | 197 | | each rating provided under Subdivision (1). |
---|
243 | 198 | | Sec. 121.053. CHANGES TO SOFTWARE APPLICATIONS. (a) The |
---|
244 | 199 | | developer of a software application shall provide notice to each |
---|
245 | 200 | | app store through which the developer makes the software |
---|
246 | 201 | | application available before making any significant change to the |
---|
247 | 202 | | terms of service or privacy policy of the software application. |
---|
248 | 203 | | (b) For purposes of this section, a change is significant if |
---|
249 | 204 | | it: |
---|
250 | 205 | | (1) changes the type or category of personal data |
---|
251 | 206 | | collected, stored, or shared by the developer; |
---|
252 | 207 | | (2) affects or changes the rating assigned to the |
---|
253 | 208 | | software application under Section 121.052 or the content or |
---|
254 | 209 | | elements that led to that rating; |
---|
255 | 210 | | (3) adds new monetization features to the software |
---|
256 | 211 | | application, including: |
---|
257 | 212 | | (A) new opportunities to make a purchase in or |
---|
258 | 213 | | using the software application; or |
---|
259 | 214 | | (B) new advertisements in the software |
---|
260 | 215 | | application; or |
---|
261 | 216 | | (4) materially changes the functionality or user |
---|
262 | 217 | | experience of the software application. |
---|
263 | 218 | | Sec. 121.054. AGE VERIFICATION. (a) The developer of a |
---|
264 | 219 | | software application shall create and implement a system to use |
---|
265 | 220 | | information received under Section 121.024 to verify: |
---|
266 | 221 | | (1) for each user of the software application, the age |
---|
267 | 222 | | category assigned to that user under Section 121.021(b); and |
---|
268 | 223 | | (2) for each minor user of the software application, |
---|
269 | 224 | | whether consent has been obtained under Section 121.022. |
---|
270 | 225 | | (b) The developer of a software application shall use |
---|
271 | 226 | | information received from the owner of an app store under Section |
---|
272 | 227 | | 121.024 to perform the verification required by this section. |
---|
273 | 228 | | Sec. 121.055. USE OF PERSONAL DATA. (a) The developer of a |
---|
274 | 229 | | software application may use personal data provided to the |
---|
275 | 230 | | developer under Section 121.024 only to: |
---|
276 | 231 | | (1) enforce restrictions and protections on the |
---|
277 | 232 | | software application related to age; |
---|
278 | 233 | | (2) ensure compliance with applicable laws and |
---|
279 | 234 | | regulations; and |
---|
280 | 235 | | (3) implement safety-related features and default |
---|
281 | 236 | | settings. |
---|
282 | 237 | | (b) The developer of a software application shall delete |
---|
283 | 238 | | personal data provided by the owner of an app store under Section |
---|
284 | 239 | | 121.024 on completion of the verification required by Section |
---|
285 | 240 | | 121.054. |
---|
286 | 241 | | Sec. 121.056. VIOLATION. (a) Except as provided by this |
---|
287 | 242 | | section, the developer of a software application violates this |
---|
288 | 243 | | subchapter if the developer: |
---|
289 | 244 | | (1) enforces a contract or a provision of a terms of |
---|
290 | 245 | | service agreement against a minor that the minor entered into or |
---|
291 | 246 | | agreed to without consent under Section 121.054; |
---|
292 | 247 | | (2) knowingly misrepresents an age rating or reason |
---|
293 | 248 | | for that rating under Section 121.052; or |
---|
294 | 249 | | (3) shares or discloses the personal data of a user |
---|
295 | 250 | | that was acquired under this subchapter. |
---|
296 | 251 | | (b) The developer of a software application is not liable |
---|
297 | 252 | | for a violation of Section 121.052 if the software developer: |
---|
298 | 253 | | (1) uses widely adopted industry standards to |
---|
299 | 254 | | determine the rating and specific content required by this section; |
---|
300 | 255 | | and |
---|
301 | 256 | | (2) applies those standards consistently and in good |
---|
302 | 257 | | faith. |
---|
303 | 258 | | (c) The developer of a software application is not liable |
---|
304 | 259 | | for a violation of Section 121.054 if the software developer: |
---|
305 | 260 | | (1) relied in good faith on age category and consent |
---|
306 | 261 | | information received from the owner of an app store; and |
---|
307 | 262 | | (2) otherwise complied with the requirements of this |
---|
308 | 263 | | section. |
---|
309 | 264 | | SUBCHAPTER D. ENFORCEMENT |
---|
310 | 265 | | Sec. 121.101. CIVIL ACTION; LIABILITY. (a) The parent or |
---|
311 | 266 | | guardian of a minor may bring an action against the owner of an app |
---|
312 | 267 | | store or the developer of a software application for a violation of |
---|
313 | 268 | | this chapter. |
---|
314 | 269 | | (b) Notwithstanding Sections 41.003 and 41.004, Civil |
---|
315 | 270 | | Practice and Remedies Code, a parent or guardian who prevails in an |
---|
316 | 271 | | action under this section is entitled to receive: |
---|
317 | 272 | | (1) injunctive relief; |
---|
318 | 273 | | (2) actual damages; |
---|
319 | 274 | | (3) punitive damages; |
---|
320 | 275 | | (4) reasonable attorney's fees; |
---|
321 | 276 | | (5) court costs; and |
---|
322 | 277 | | (6) any other relief the court considers appropriate. |
---|
323 | 278 | | (c) A violation of this chapter constitutes an injury in |
---|
324 | 279 | | fact to a minor. |
---|
325 | 280 | | Sec. 121.102. DECEPTIVE TRADE PRACTICE. A violation of |
---|