Privacy Enters the Game: Spain and Belgium Publish New Guidance for the Video Game Industry

The Spanish Data Protection Agency (AEPD) and the Belgian Data Protection Authority (APD) have recently published joint Recommendations and Best Practices for Data Protection in Video Games.

The guidance reflects the growing regulatory focus on the gaming industry and provides a comprehensive framework for applying the GDPR throughout the lifecycle of a video game. Rather than simply reiterating existing legal principles, it addresses many of the privacy challenges unique to modern gaming environments, including telemetry, behavioural profiling, children’s data, AI-driven functionalities, monetisation mechanisms and the allocation of GDPR roles across increasingly complex gaming ecosystems.

While the recommendations are not legally binding, they offer valuable insight into regulatory expectations and are likely to influence how supervisory authorities assess compliance in future investigations and enforcement actions.

Below are five of the key takeaways for organisations operating in the gaming sector.

1. Privacy starts at the design stage

Perhaps the guidance’s most important message is that GDPR compliance cannot be left until a game is ready for launch.

The regulators expect privacy considerations to be integrated throughout the entire development lifecycle, from concept and design through production, release and post-production support. Data protection by design and by default is presented as an ongoing process, requiring developers to consider privacy whenever introducing new features, mechanics or technologies.

For developers and publishers, this means that gameplay mechanics, monetisation models, telemetry, AI features and player interactions should all be assessed from a privacy perspective before implementation.

2. Video games process far more personal data than many realise

One of the clearest messages from the guidance is that gameplay data should no longer be viewed as merely technical information.

Modern video games routinely process telemetry, behavioural analytics, voice communications, geolocation, gameplay recordings and profiling data. Individually or collectively, these datasets may reveal behavioural patterns, preferences and other characteristics capable of identifying or evaluating individual players.

Organisations should therefore carefully assess the purposes for which gameplay data is collected and ensure that collection remains proportionate to those purposes.

3. Children’s data deserves enhanced protection

Reflecting broader European regulatory trends, the guidance places particular emphasis on protecting children.

Games that are likely to be accessed by minors should incorporate age-appropriate design, child-friendly transparency, appropriate parental involvement where necessary and additional safeguards around profiling, targeted advertising and monetisation mechanisms. The guidance also highlights risks associated with dark patterns, public chat functions, location-based features and certain in-game purchasing models when children are involved.

This reflects the increasing convergence between GDPR compliance, online safety and responsible game design.

4. GDPR roles are rarely straightforward

One of the most useful parts of the guidance is its analysis of the different actors participating in the gaming ecosystem.

Rather than assuming a single controller or processor role for an entire product, organisations are encouraged to assess GDPR roles on a processing-by-processing basis. The same organisation may perform different GDPR roles depending on the specific processing activity involved.

For organisations operating across multiple jurisdictions and technologies, this reinforces the importance of carefully documenting data flows and allocating responsibilities contractually.

5. Governance matters as much as technology

Although the guidance discusses emerging technologies such as AI, behavioural analytics and sophisticated telemetry, its underlying message remains clear: effective compliance still depends on robust governance.

Effective compliance still depends on robust governance. Organisations should maintain clear records of processing activities, conduct DPIAs where appropriate, implement appropriate technical and organisational measures, define retention policies, ensure meaningful transparency and establish effective procedures for handling data subject rights. Regular reviews and cross-functional governance are presented as essential components of responsible game development.

More than guidance for the gaming industry

Although the recommendations do not create new legal obligations, they provide valuable insight into how European supervisory authorities are likely to assess privacy risks and GDPR compliance in the gaming sector.

More broadly, the guidance reflects an emerging regulatory trend. European supervisory authorities are increasingly moving beyond general GDPR principles and publishing sector-specific guidance tailored to particular industries and technologies. The video game industry is simply the latest example.

For developers, publishers and technology providers operating in this space, the message is clear: privacy is no longer a compliance exercise undertaken shortly before launch. It is becoming an integral part of game design, governance and long-term product strategy.

Cornerstone Counsel regularly advises developers, publishers, technology companies and organisations on GDPR compliance, privacy governance, AI and digital regulation. If you would like to discuss how this guidance may affect your organisation – or any other data protection matter – we would be delighted to hear from you.

Ceyhun Necati Pehlivan

Meet the Founder →

Subscribe to Cornerstone Counsel

Insights on technology, data, and digital law

 

Leading publications

Editor and co-author of leading publications in artificial intelligence, privacy and technology law.

Editor-in-Chief, Global Privacy Law Review · Co-editor, and co-author of two seminal books on AI, spanning more than 2,000 pages and bringing together over 90 leading experts, including academics, judges, regulators and practitioners.

Wolters Kluwer

View Publications →