It would also be nearly impossible to enforce. How would Apple be able to verify that a company is complying with these terms? I don't think many companies would be happy to let Apple poke around in their backend, just as I don't think Apple wants to spend the resources to do that.

Edit: "impossible" -> "nearly impossible"

Write in compliance requirements with provisions for regular third party audits.

If personal data companies don’t start regulating themselves they will get it forced on them by the government. Financial, medical, and defense companies already do it.

