Fighting Game · Guides & deep dives

V2 Privacy Ops On-Call Runbook

The on-call schedule is reviewed weekly and before each release gate.

7sections2 minread1table

On this page

Privacy ops maintains 24/7 breach-response coverage for launch services. The rotation is owned by the DPO delegate, supported by security incident command, legal, customer support, platform relations, and regional counsel.

Rotation#

Role Primary duty Backup
Privacy incident commander Opens the incident, starts the legal clock, owns the decision log DPO delegate
DPO delegate Determines privacy impact, regulator path, and DSR implications Privacy counsel
Security incident lead Preserves evidence, scopes systems, coordinates containment SRE lead
Legal escalation Applies privilege where appropriate, approves notices Regional counsel
Player communications Drafts player notices and support macros Support director
Platform relations Notifies Sony, Microsoft, Nintendo, Steam, Epic, and cloud partners as required Release manager

The on-call schedule is reviewed weekly and before each release gate. Any gap in commander, DPO, security, or legal coverage blocks release promotion.

Breach SLA#

The breach clock starts when the privacy incident commander confirms that a security incident involves personal data. The default notification target is 72 hours for GDPR-style obligations. Local rules can be stricter or use a different clock, so the commander records the applicable framework in the incident brief before any external notice is sent.

Brazil incidents that create relevant risk or damage route to ANPD review under the LGPD incident workflow. Quebec incidents route to Quebec CAI and affected persons where Law 25 criteria are met. Platform incidents also follow the applicable platform DPA and security addendum.

First Hour#

  1. Create the privacy incident record in the audit platform.
  2. Assign incident commander, DPO delegate, security lead, and legal escalation.
  3. Freeze routine deletion jobs for potentially relevant evidence.
  4. Identify affected systems, data categories, regions, age bands, and sub-processors.
  5. Capture the initial risk statement, containment status, and decision log.

First 24 Hours#

  1. Complete data-subject impact scoping.
  2. Determine whether minor accounts, sensitive categories, authentication data, payment data, or moderation evidence are involved.
  3. Validate cross-border processor involvement and DPA notice duties.
  4. Draft regulator, platform, and player notices.
  5. Decide whether staged notification is required because facts remain incomplete.

First 72 Hours#

  1. Send required regulator and player notifications or record why notification is not required.
  2. Publish support macros and account-protection steps.
  3. Add the incident to the quarterly privacy review packet.
  4. Create remediation owners, due dates, and verification evidence.

Erasure And DSR Hold#

When an incident intersects with active erasure, access, portability, or rectification requests, privacy ops records whether legal hold limits fulfillment. The subject receives the normal DSR confirmation plus any legally required explanation of delayed or partial fulfillment.

Closeout#

Closeout requires DPO and legal approval, audit-platform export, player/support communications signoff, and a post-incident review. Sanitized learnings feed the public quarterly privacy summary when disclosure does not create security, privacy, or privilege risk.