This register is the product baseline for V2 account, gameplay, commerce, moderation, AI, and esports data. Legal review owns final jurisdictional interpretation; engineering owns keeping the product surfaces and audit events aligned with this register.
Lawful Basis Register#
| Data category | Examples | Primary basis | Consent layer | Default residency |
|---|---|---|---|---|
| Account identity | account id, platform id, email hash, 2FA state | contract | no | subject home zone |
| Profile and settings | handle, locale, accessibility settings, privacy choices | contract | optional choices only | subject home zone |
| Entitlements and commerce | purchases, receipts, refund status, cosmetic inventory | contract / legal obligation | no | purchase region plus platform record |
| Gameplay records | match ids, fighters, ruleset, results, replay metadata | legitimate interest / contract | no for core service | subject home zone |
| Optional telemetry | performance, balance, feature-use, heatmaps | consent where required; legitimate interest where permitted | yes | regional telemetry ingest |
| Personalized ads and profiling | ad segments, churn propensity, personalization features | consent | yes | subject home zone |
| Chat and UGC | lobby chat, custom decals, CAW outfits, reports | contract / legitimate interest / legal obligation | no for safety review | subject home zone with moderation queue |
| Moderation and appeals | reports, evidence, decisions, Statement of Reasons, appeal records | legal obligation / legitimate interest | no | moderation region with audit retention |
| Security and anti-cheat | device risk, cheat signals, sanctions, integrity events | legitimate interest / legal obligation | no | security region with restricted access |
| AI system records | model cards, classifier disclosure, opt-out status, audit evidence | legal obligation / legitimate interest | opt-out where supported | EU AI Act record store |
| Minor account controls | age band, parental restrictions, consent receipts | legal obligation / contract | parental consent where required | subject home zone |
| Esports public results | event, player display name, fighter, bracket, replay link | legitimate interest / contract | no for public event records | public archive after privacy review |
| Cosmetic wager records | Drop-currency stake, odds display state, outcome, audit trail | legal obligation / legitimate interest | participation choice | subject home zone plus event audit |
| Sensitive categories | precise geolocation, racial or ethnic origin, religion, health, sex life or orientation | explicit consent or disabled | separate explicit consent | subject home zone only |
Data Rights Surface#
The in-game privacy settings and linked web DSR form expose Access,
Rectification, Erasure, Portability, Restriction, and Objection. Requests
require account 2FA before submission. The canonical workflow remains
@themis/privacy plus @oshun/data-residency, with V2 publishing DSR audit
events through @oshun/audit-platform.
Access and portability exports use standardized JSON covering player profile, match records, telemetry, cosmetic inventory, friend list, replay metadata, consent receipts, and moderation status visible to the requester. Erasure preserves anonymized statistical aggregates only where identifiers are removed and a lawful basis remains.
Erasure requests record request -> action -> confirmation in the
@oshun/audit-platform privacy export. The per-erasure scope is account,
profile, replay anonymization, telemetry purge, and cosmetic ledger, with
anonymized audit retention under v2-dsr-erasure-audit-retention.
Consent Management#
Consent is granular by processing purpose: telemetry, analytics, personalized ads, profiling, voice processing, ghost sharing, sensitive data, and cookie or web tracking categories. Consent receipts are versioned, revocable, and stored outside ordinary save data so a save reset cannot erase privacy choices.
Breach And Transfer Rules#
Potential personal-data breaches are triaged immediately and escalated for supervisory authority notification within 72 hours when notification is required. Cross-region transfers use the subject-home route by default; approved transfers require a documented Article 46 mechanism such as Standard Contractual Clauses or Binding Corporate Rules.
Review Cadence#
The DPO reviews this register quarterly, after material feature launches, and
whenever a supported jurisdiction changes privacy, AI, child-safety, DSA, or
wagering rules. The rolling state-law registry updates at least every 30 days.
The section 94 privacy-by-design register at
V2/docs/legal/privacy-by-design-dpia.md is attached to every release gate.