Reshaping the game - 2026 report
Data protection: the fuel for personalised experiences
Personalisation, model training and vendor data flows are three separate GDPR purposes - each needs its own legal basis and its own transparency.
Section 7 in three theses
- Real-time personalisation built on player behaviour is deep profiling: it demands fairness and transparency about how the game uses in-game conduct (Articles 5(1)(a), 13 GDPR).
- Training AI models on player data is a separate processing purpose that needs its own legal basis (Article 6(1) GDPR), and a commercial market for player data is emerging.
- Third-party AI tools mean player data leaves the studio: vendor due diligence and data-processing agreements are mandatory, not optional (Article 28 GDPR).
AI increases the collection and processing of player data, and the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) provides the governing framework. Three areas concentrate the risk.
Real-time personalisation
Features such as difficulty adjustment, dynamic content and targeted offers are built on a continuous analysis of the player's actions, choices and communication patterns. That is deep profiling. It demands fairness and transparency: players must be able to understand, in plain language, how the game observes and uses their in-game behaviour (Articles 5(1)(a), 13 GDPR). Where the profiling feeds monetisation, the analysis overlaps with the AI Act's manipulation ban (Section 4.3) — the two regimes apply cumulatively and satisfying one does not satisfy the other.
Training as a separate purpose
Using player data to train or fine-tune AI models, whether to improve an in-game agent or to develop future systems, is a processing purpose of its own. It therefore requires its own legal basis and clear communication to players (Article 6(1), Article 13(1)(c) GDPR). A privacy policy written for matchmaking and analytics does not cover it.
Which basis can carry training is itself in motion: The Commission's pending Digital Omnibus on data (COM(2025) 837, 19 November 2025) would expressly permit reliance on legitimate interests for AI model training and systems in certain circumstances. As of July 2026, however, the proposal remains in first reading, so it changes nothing yet, and studios should not build on it.
The question has meanwhile gained commercial weight: as of mid-2026, a market is emerging in which game companies license gameplay data to AI model builders as training material. Whatever position a company takes in that market, seller, buyer or abstainer, the GDPR analysis comes first, because behavioural gameplay data will regularly qualify as personal data, and a licensing purpose is yet another purpose requiring its own basis and transparency.
Vendor data flows
Few studios build every AI capability in-house. The use of third-party tools and cloud AI services means that player data is shared with external providers. This requires due diligence on those partners and solid data-processing agreements (Article 28 GDPR), including clarity on whether the vendor may use the data to train its own models.
The mobile ecosystems have contractualised the same point from the platform side: disclosure and consent before personal data reaches an external AI service (Section 5.1). The vendor contract, the privacy policy and the platform disclosure must tell one consistent story.
Contacts

© 2026 Bird & Bird


