The New Reality of Gaming GDPR
In 2025, gaming is barely private anymore. Even in single-player mode, your actions can be tracked, stored, and analyzed. Voice chat monitoring, mandatory accounts, server-side storage — all of this has become standard. But gaming GDPR is coming into sharper focus: regulatory pressure is growing across Europe.
Recent cases involving Nintendo, Ubisoft, and 2K show that the industry is at a turning point between innovation, security, and data protection.
Ubisoft vs. NOYB: When Mandatory Online Play Becomes a Data Protection Problem
In April 2025, the NGO NOYB (None of Your Business) filed a formal GDPR complaint against Ubisoft — one of the most discussed gaming GDPR cases of the year.
The allegation: Ubisoft forces users to be online even for purely single-player games (e.g., Assassin's Creed, Far Cry, Prince of Persia). This allows the company to collect data on start times, play behavior, and session duration. Within ten minutes, the games established up to 150 server connections — including to Google, Amazon, and Datadog.
NOYB sees this as a clear violation of Art. 6(1) GDPR: no consent, no necessity. Particularly explosive: a hidden offline mode exists.
With revenue of over €2 billion, Ubisoft could face fines of up to €92 million under the GDPR fine framework.
A symbolic case for a growing trend: games as data pipelines — whether it's necessary or not.
Nintendo GameChat: Safety or Surveillance?
In May 2025, Nintendo came into focus with the Switch 2. The new GameChat feature allows video and audio sharing — and, according to the updated privacy policy, recordings "for user safety" as well.
Nintendo states that recordings are manually triggered and limited to three minutes. Even so, audio and video data are personal data. Processing them requires clear, freely given consent.
Further GDPR aspects:
- GameChat requires Nintendo Online and a verified phone number.
- Users under 16 need parental consent.
- It remains unclear whether users can fully opt out of recording.
Under gaming GDPR strict principles apply:
data minimization, purpose limitation, and transparency. Players need to know when they're being recorded, why, for how long, and who gets access. "Safety" alone is not a sufficient legal basis. Without a clear opt-in, data collection may be unlawful.
Nintendo thus illustrates a central problem: many games collect data without offering real control or freedom of choice.
Borderlands & 2K: When Anti-Cheat Becomes a Data Protection Trap
Also in May 2025, 2K Games sparked outrage with its Borderlands series. A new EULA (End User License Agreement) reportedly granted the publisher root access to players' computers — along with extensive data collection (hardware, browser activity, personal information).
The community responded with review bombing and accusations of spying.
Even though some allegations were exaggerated, the case makes one thing clear: opaque privacy practices undermine trust.
Under gaming GDPR, the following applies:
- Anti-cheat software may only collect necessary data.
- "Consent" in EULAs is not freely given if you can't use the game otherwise.
- Without a clear statement of purpose and an opt-out, the legal basis is missing.
The pattern repeats: data protection is hidden in EULAs instead of being communicated transparently.
When Gaming GDPR Becomes an Afterthought
The Ubisoft, Nintendo, and 2K cases show: data protection is often an afterthought — even though gaming GDPR sets clear limits.
Whether server-side pings, audio recordings, or root access — much of this happens without clear necessity or transparency.
The GDPR requires:
- Necessity: data only when it's essential for the function.
- Data minimization & purpose limitation: no data hoarding without a clear purpose.
- Legal basis: genuine consent (opt-in) or demonstrable legitimate interest with an opt-out.
- Transparency: players must understand what's happening.
In practice, however, much remains unclear, and consent is often just a click without real choice. This contradicts the spirit of the GDPR — and puts the community's trust at risk.
Conclusion: Privacy by Design Instead of Data by Default
Public pressure is growing, and regulators will follow.
For studios, the message is clear: gaming GDPR doesn't mean bureaucracy — it means trust.
Now is the time to embrace privacy by design — building data protection into game design from the very start.
Data protection compliance isn't a checkbox — it's a competitive advantage.
Learn more about our All-in-One Compliance Solution and how to easily implement data protection in gaming.
FAQ
Are games allowed to track me offline?
Are games allowed to track me offline?
Not always. Under the GDPR, data minimization applies: only what's necessary for functionality may be collected. Offline tracking without consent can be a violation.
Are games allowed to record my voice or video without permission?
Are games allowed to record my voice or video without permission?
No. Audio and video are personal data. Without clear, voluntary consent, recording isn't permitted.
Can I decline a privacy policy and still play?
Can I decline a privacy policy and still play?
Many games force you to consent. This bundled consent is problematic. You're allowed to refuse the processing of non-essential data (e.g., analytics, advertising).
What do developers need to do for GDPR compliance?
What do developers need to do for GDPR compliance?
Privacy by design, clear opt-ins, collecting only necessary data, and full transparency about purpose, duration, and data categories.
Does the GDPR also apply to studios outside the EU?
Does the GDPR also apply to studios outside the EU?
Yes. Gaming GDPR applies as soon as games target EU players or process their data.
Are publishers allowed to deny access if I reject tracking?
Are publishers allowed to deny access if I reject tracking?
Only if the tracking is strictly necessary. For non-essential data, a block can violate the voluntariness of consent.







