AMLEGALS — Strategic Lawyering

Player Telemetry, Behavioural Data and DPDPA

Player Telemetry, Behavioural Data and DPDPA

Every event you log is a sentence in a file about a person.

The scene

Telemetry recorded every tap, pause and purchase, keyed to device ID. The monetisation team built ‘whale prediction’ from it. Three of the top ten predicted whales were fourteen.

Where the thinking breaks

The unclear thought What it breaks The clearer thought

Telemetry is anonymous.

Data keyed to an account or device ID relates to an identifiable person.

Treat telemetry as personal data by default.

Monetisation models are internal.

Using child behaviour to drive offers is targeting directed at children.

Exclude likely-minor accounts from monetisation models.

Two streams

Split telemetry into gameplay tuning, which can be aggregated early, and commercial targeting, which must exclude children and respect consent.

Monday morning

01 List every telemetry event.

02 Mark which feed monetisation.

03 Exclude likely minors from those models.

Questions, answered plainly

Is game telemetry personal data under DPDPA? +

Where it is linked to an account, device identifier or other data that identifies a player, it is personal data and subject to DPDPA.

Can games use behavioural data to target in-game offers to children? +

Section 9(3) bars tracking, behavioural monitoring and targeted advertising directed at children, subject to exemptions. Targeting offers based on a child's behaviour is high risk.

Sector · Gaming Your fastest-growing segment may legally be children. Read →

Gaming · Deep dive Twelve-year-olds learn to type 2001 in a week. Read →

Gaming · Deep dive Dormant players are not future revenue. Read →

Tell us where your data sits. We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner →

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).