# V2 Privacy-By-Design And DPIA Register

This register is the release-gate source for section 94. Each feature row must
be updated before content lock when a launch surface changes collected data,
lawful basis, retention, DSR impact, or transfer mechanism.

## Gate Rules

- Every feature must document data collected, lawful basis, retention, subject
  rights impact, and cross-border transfer mechanism.
- Features touching identifiable data require privacy review before release
  candidate signoff.
- Features touching sensitive data, minor data, profiling, AI inference,
  moderation evidence, biometric-adjacent media, or cross-region transfers
  require a DPIA before the release gate.
- The release gate blocks when the DPIA status is `required-missing`,
  `legal-review-open`, or `processor-contract-open`.

## Feature Register

| Feature                                  | Data collected                                                          | Lawful basis                                                | Retention                                                          | Subject rights impact                                               | Cross-border transfer mechanism                                             | DPIA            |
| ---------------------------------------- | ----------------------------------------------------------------------- | ----------------------------------------------------------- | ------------------------------------------------------------------ | ------------------------------------------------------------------- | --------------------------------------------------------------------------- | --------------- |
| Account identity and 2FA                 | Account id, platform id, email hash, age band, 2FA state                | Contract, legal obligation for minors and security          | Account life plus fraud/legal retention                            | Access, rectification, erasure, portability, restriction, objection | Subject home zone; SCCs/BCRs for approved support transfer                  | Required        |
| Profile and privacy settings             | Handle, avatar choice, locale, accessibility settings, consent receipts | Contract; consent for optional processing                   | Account life; consent receipts retained for audit                  | Access, rectification, erasure, portability                         | Subject home zone only unless support transfer approved                     | Required        |
| Match records and replay metadata        | Match id, fighters, ruleset, result, replay metadata, opponent ids      | Contract, legitimate interest                               | Match history window; public esports records after review          | Access, erasure by anonymization, portability                       | Subject home zone; public exports privacy-reviewed                          | Required        |
| Ghost and replay sharing                 | Ghost files, replay ids, sharing scope, friend/global visibility        | Consent and contract                                        | Until consent revocation or content expiry                         | Access, erasure/anonymization, portability                          | Subject home zone; cross-region discovery only after consent                | Required        |
| Optional telemetry and balance analytics | Feature use, performance, crashes, move frequency, aggregate heatmaps   | Consent where required; legitimate interest where permitted | Aggregated after identifier purge; raw windows limited by ops need | Access, erasure purge, restriction, objection                       | Regional telemetry ingest; SCCs/BCRs for approved analysis                  | Required        |
| Commerce and cosmetic ledger             | Purchases, receipts, entitlements, cosmetic inventory, refund state     | Contract, legal obligation                                  | Platform/legal tax retention; account ledger while active          | Access, erasure where not legally retained, portability             | Platform owner DPA plus regional commerce records                           | Required        |
| Social, chat, and UGC                    | Friend links, party ids, lobby chat, decals, CAW outfits, reports       | Contract, legitimate interest, legal obligation             | Moderation/legal retention by case                                 | Access, erasure/redaction, objection, appeal rights                 | Moderation region with restricted reviewer access                           | Required        |
| Moderation and safety appeals            | Report evidence, decision, Statement of Reasons, appeal record          | Legal obligation, legitimate interest                       | Case retention plus DSA/regional audit period                      | Access to own decisions, rectification where appropriate, appeal    | Restricted transfer under SCCs/BCRs when reviewer is outside home zone      | Required        |
| AI and anti-cheat systems                | Classifier outputs, model cards, opt-out status, anti-cheat risk facts  | Legal obligation, legitimate interest                       | Audit record life; sanctions by policy                             | Access, objection, appeal, AI transparency                          | EU AI record store and security region, no model training on minor profiles | Required        |
| Minor account protections                | Age band, parental settings, consent status, jurisdiction detection     | Legal obligation, contract, parental consent where required | Account life plus audit evidence                                   | Guardian access, erasure, privacy defaults, profiling objection     | Subject home zone; no behavioral ad transfer                                | Required        |
| Esports public results                   | Display name, event, fighter, bracket, result, replay link              | Contract, legitimate interest                               | Public archive after privacy review                                | Access, correction, removal review for private identifiers          | Public only after minimization review                                       | Review required |
| Web legal and sub-processor pages        | Public page analytics only if strictly necessary; no account data       | Legitimate interest or disabled                             | Aggregate-only web telemetry                                       | Cookie/consent rights where tracking exists                         | No personal-data transfer for page view beyond necessary hosting logs       | Review required |

## DPIA Completion Evidence

A completed DPIA must include:

- feature owner and release owner
- data-flow diagram
- risk to minors and vulnerable players
- profiling or automated decision analysis
- sensitive-data and special-category assessment
- cross-border transfer assessment
- sub-processor and DPA status
- security controls and audit events
- mitigation owner and due date
- legal signoff and DPO signoff

## Release-Gate Packet

Each release gate must attach the latest version of this register, the extended
privacy compliance contract, the sub-processor delta, DSR routing validation,
and privacy ops on-call contact. The release manager records the gate result as
`privacy-approved`, `privacy-approved-with-conditions`, or `privacy-blocked`.
