Fighting Game · Guides & deep dives

V2 Data Categories And Lawful Basis

The in-game privacy settings and linked web DSR form expose Access, Rectification, Erasure, Portability, Restriction, and Objection.

5sections3 minread1table

On this page

This register is the product baseline for V2 account, gameplay, commerce, moderation, AI, and esports data. Legal review owns final jurisdictional interpretation; engineering owns keeping the product surfaces and audit events aligned with this register.

Lawful Basis Register#

Data category Examples Primary basis Consent layer Default residency
Account identity account id, platform id, email hash, 2FA state contract no subject home zone
Profile and settings handle, locale, accessibility settings, privacy choices contract optional choices only subject home zone
Entitlements and commerce purchases, receipts, refund status, cosmetic inventory contract / legal obligation no purchase region plus platform record
Gameplay records match ids, fighters, ruleset, results, replay metadata legitimate interest / contract no for core service subject home zone
Optional telemetry performance, balance, feature-use, heatmaps consent where required; legitimate interest where permitted yes regional telemetry ingest
Personalized ads and profiling ad segments, churn propensity, personalization features consent yes subject home zone
Chat and UGC lobby chat, custom decals, CAW outfits, reports contract / legitimate interest / legal obligation no for safety review subject home zone with moderation queue
Moderation and appeals reports, evidence, decisions, Statement of Reasons, appeal records legal obligation / legitimate interest no moderation region with audit retention
Security and anti-cheat device risk, cheat signals, sanctions, integrity events legitimate interest / legal obligation no security region with restricted access
AI system records model cards, classifier disclosure, opt-out status, audit evidence legal obligation / legitimate interest opt-out where supported EU AI Act record store
Minor account controls age band, parental restrictions, consent receipts legal obligation / contract parental consent where required subject home zone
Esports public results event, player display name, fighter, bracket, replay link legitimate interest / contract no for public event records public archive after privacy review
Cosmetic wager records Drop-currency stake, odds display state, outcome, audit trail legal obligation / legitimate interest participation choice subject home zone plus event audit
Sensitive categories precise geolocation, racial or ethnic origin, religion, health, sex life or orientation explicit consent or disabled separate explicit consent subject home zone only

Data Rights Surface#

The in-game privacy settings and linked web DSR form expose Access, Rectification, Erasure, Portability, Restriction, and Objection. Requests require account 2FA before submission. The canonical workflow remains @themis/privacy plus @oshun/data-residency, with V2 publishing DSR audit events through @oshun/audit-platform.

Access and portability exports use standardized JSON covering player profile, match records, telemetry, cosmetic inventory, friend list, replay metadata, consent receipts, and moderation status visible to the requester. Erasure preserves anonymized statistical aggregates only where identifiers are removed and a lawful basis remains.

Erasure requests record request -> action -> confirmation in the @oshun/audit-platform privacy export. The per-erasure scope is account, profile, replay anonymization, telemetry purge, and cosmetic ledger, with anonymized audit retention under v2-dsr-erasure-audit-retention.

Consent is granular by processing purpose: telemetry, analytics, personalized ads, profiling, voice processing, ghost sharing, sensitive data, and cookie or web tracking categories. Consent receipts are versioned, revocable, and stored outside ordinary save data so a save reset cannot erase privacy choices.

Breach And Transfer Rules#

Potential personal-data breaches are triaged immediately and escalated for supervisory authority notification within 72 hours when notification is required. Cross-region transfers use the subject-home route by default; approved transfers require a documented Article 46 mechanism such as Standard Contractual Clauses or Binding Corporate Rules.

Review Cadence#

The DPO reviews this register quarterly, after material feature launches, and whenever a supported jurisdiction changes privacy, AI, child-safety, DSA, or wagering rules. The rolling state-law registry updates at least every 30 days. The section 94 privacy-by-design register at V2/docs/legal/privacy-by-design-dpia.md is attached to every release gate.