Sector
Data protection in esports
Four questions shape esports practice. Who is responsible for which data where club, federation and league act together. Where the age limit in Art. 8 GDPR applies and where it does not. How streaming relates to image rights. And whether an automatically issued ban is a decision within the meaning of Art. 22 GDPR.
A tournament across three outside platforms
A club enters a squad in the league, the tournament runs on an organiser’s platform, the stream sits with a third party, and three of the five players are fifteen. After the tournament the anti-cheat system bans one of them. None of these four questions is answered in the rules.
Three bodies, one player, and nobody has settled the roles
Who is responsible for which data follows from Art. 4(7) GDPR and therefore from the decision on purposes and means, not from technical possession. In esports the two come apart, because the club keeps the squad, the federation grants eligibility and the league generates the tournament data.
Three processing operations, three attributions
Squad records at the club
The club decides on purpose and means alone. The legal basis is usually Art. 6(1)(b) GDPR through the membership relationship.
Eligibility at the federation
The federation determines which particulars it needs. That is not processing on behalf but a controllership of its own, with a legal basis of its own.
Tournament operations at the league
Here league and platform often decide together. Art. 26(1) GDPR then applies, and the essence of the arrangement has to be made available under paragraph 2.
On that attribution hangs who answers an access request and who notifies in an incident. It arises from the processing and not from the organisation chart.
The age limit applies to consent and to nothing else
What follows from Art. 8 GDPR is overstretched in both directions. The provision covers only consent under Art. 6(1)(a) GDPR for an information society service offered directly to a child. Where the processing rests on a contract or on a balancing exercise, it does not apply.
Three steps, and the age limit appears only in the second
Determine the legal basis
Where the processing rests on the membership relationship or on a balancing exercise, Art. 8 GDPR does not apply.
Only go further for consent
Only where it comes down to Art. 6(1)(a) GDPR, for instance for marketing, does Art. 8(2) GDPR call for reasonable efforts to verify. A tick box confirming an age is unlikely to suffice.
Check protection and language
Regardless of basis and age, the weight of recital 38 in the balancing and the child-appropriate language of Art. 12(1) GDPR remain.
3 von 3
The Regulation governs the stream, and image rights come on top
How streaming relates to image rights is usually answered by halves. The recognisable image of a person is personal data under Art. 4(1) GDPR and needs a legal basis under Art. 6 GDPR. Consent under section 22 KUG does not replace it.
Two regimes on the same picture
| The Regulation | Merkmal | The German image rights act |
|---|---|---|
| Every processing operationCollecting, storing, transmitting and archiving, each with its own legal basis. | What it attaches to | Distribution and displayThe taking of the picture itself is not covered by sections 22 and 23 KUG. |
| BalancingArt. 6(1)(f) GDPR, with the weight recital 38 gives to minors. | Exception without consent | Four categoriesSection 23(1) KUG, among them pictures of assemblies and similar events in which those shown took part. |
| At any timeArt. 7(3) GDPR, with effect for the future. | Withdrawal | Only on serious grounds |
| Always applies | Relationship | Survives through Art. 85 GDPRIn so far as the processing serves journalistic, artistic or literary purposes. For a plain club stream that is doubtful. |
For marketing this means a second step of analysis rather than a second form. A sponsor clip featuring a minor needs a basis under the Regulation, and the balancing comes out differently there than for an adult professional.
An automated ban is a decision
Whether a ban falls under Art. 22 GDPR turns on two features that anti-cheat systems regularly satisfy. The suspension is issued solely by automated means, and it significantly affects the player where it removes access to a competition or to a game they bought.
What a ban procedure has to contain under Art. 22(3) GDPR
Liste zu erledigender Punkte
- A named route on which a person on the controller’s side can intervene, with a deadline
- The opportunity to express a point of view before the suspension becomes final
- A contest procedure that does not run through the same automation again
- Information under Art. 13(2)(f) GDPR on the logic involved and the significance
- Retention of the detection data long enough for review and no longer
Access to the device is a separate matter. It is a question of sec. 25 TDDDG, and it is hardest to justify where the system reads processes that have nothing to do with the game.
How we support you in e-sports
All four questions can be answered in one document, and that document is not the privacy notice. What is needed is an overview of the processing operations, each with an attribution, a legal basis and a note whether minors are involved. Without it the arrangement, the notices and the ban procedure each come into being separately and inconsistently.
Frequently asked questions
Does an esports club need a data protection officer?
That is decided not by legal form but by section 38(1) BDSG and Art. 37(1) GDPR. What matters is the number of people constantly engaged in automated processing and whether a core activity consists in regular monitoring on a large scale. Volunteers count in so far as they are constantly engaged.
May result tables be published with real names?
Only with a legal basis. An arrangement in the rules together with Art. 6(1)(b) GDPR comes into consideration, or a balancing exercise under point (f). With minors the balancing is weighted in their favour under recital 38, and a player handle instead of the real name is the less intrusive measure.
How far may anti-cheat reach into the device?
Access to terminal equipment is measured against sec. 25 TDDDG, and the exemption in paragraph 2 no. 2 requires strict necessity for a service the user expressly requested. The processing that follows needs a legal basis under Art. 6 GDPR in addition, and reading the entire process list is unlikely to be necessary.
Does the age limit of sixteen apply in Germany?
Yes. Art. 8(1) GDPR allows member states to lower the limit to as low as thirteen, and Germany has not done so. For services offered to users in Germany it remains sixteen.
Get in touch!
Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!
Contact usAlternatively you can request a call back.