Sponsored- In-game advertising, the compliance perspective

Presented by OneTrust

With the increase of mobile device users and not to mention, a global pandemic with stay-at-home guidelines, the gaming industry is growing rapidly. In fact, there are an estimated 2.7 million gamers around the world using mobile games which will impact gaming revenue of $77.2 billion in 2020, growing +13.3% year-over-year.

With more than a quarter of the world’s population playing games across PC, console and mobile, we'll take a deep dive into how, when and why you should be looking towards leveraging a Consent Management Platform such as the OneTrust Unity SDK.

The free-to-play (FTP) model, games that give players access to a significant portion of their content without paying, is the new battleground, especially when talking about the mobile gaming space. Because of this, the two most common revenue streams are In-App purchases and advertising with more creative data brokering peppered in. These are obviously not mutually exclusive options with many games offering both to generate revenues. That said, the most prevalent by far is advertising. According to App Annie, nearly 90% of all games across iOS and Google Play currently contain advertising SDKs. That’s an impressive number and you can see why when we as players see advertising as the revenue model of choice as seen in App Annie’s recent U.S. study below.

So what are the regulatory impacts of choosing to serve ads as part or all of your revenue model?

There are too many regulations to cover all of them in this article, so we’ll focus primarily on the GDPR and touch on the CCPA for now and focus solely on the consent aspect – when do you need it? How do you obtain it? What model do you need to follow?

General Data Protection Regulation (GDPR)

The first thing to note when thinking about the regulatory impact and your exposure is that the process of showing an advert/creative to your players does not require consent. Consent only becomes a requirement when Personal Data is being processed and shared and this will absolutely be the case if you are showing any form of personalised advertisements. This is because the ad-tech eco-system will be identifying the individual and their behaviours, preferences and details such as gender with this then being shared throughout the real-time bidding (RTB) process. This makes the advertising inventory much more appealing for Advertisers as they can target specific audiences thereby increasing the cost-per-millie (CPMs) for Publishers.

All of this however constitutes as the processing of Personal Data under GDPR and therefore a lawful bases is required in order to do this in a compliant manner. Legitimate interests is not something that you can rely on, you can see decisions and guidance on this from the Supervisory Authorities such as the ICO and CNIL (authorities for the UK and France, respectively). Therefore, if you are serving personalised ads you must gather consent from the individual.

Consent itself is specifically defined in the GDPR. Article 4(11) states:

“any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her”

While Article 7 further defines conditions for valid consent such as:

  • keeping records to demonstrate consent;

  • prominence and clarity of consent requests;

  • the right to withdraw consent easily and at any time; and

  • freely given consent if a contract is conditional on consent.

This is all very specific and extremely complex when thinking about the different vendors within the eco-system, so from the gaming perspective how can you ensure you are compliant?

The good news is that the Ad-tech industry has already addressed this challenge, something you likely have seen when browsing a publisher’s sites. It’s called the Transparency and Consent Framework (TCF) and it’s been built by the Interactive Advertising Bureau’s European Chapter (IAB Europe). The framework allows for the gathering of consent against specific purposes of processing that align with the requirements of the ad-tech ecosystem and is heavily used today in the web space – even Google have recently signed up to it. There are three main players in the TCF; the Publisher, Consent Management Platform (CMP), and the Vendors. Each of these has individual responsibilities in order to work together:

  •  The CMP must provide a complaint TCF banner & preference center that allows users to provide consent and it’s also their responsibility to make that consent available to the wider ad-tech ecosystem to check, something that is done via public APIs.

  • The Publisher is responsible for implementing a CMP, whether internal or via a third-party provider.

  • The ad-tech vendors are in charge of checking for the user’s consent and preferences prior to processing any personal data.

The advantage of the TCF here is that it makes this whole process seamless removing the need for numerous manual dev integrations.

California Consumer Privacy Act (CCPA)

The important distinction between the CCPA and GDPR is the difference in the required consent model. While the GDPR specifically requires consent to be ‘opt-in’, the CCPA requires companies to allow individuals to ‘opt-out’ of the sale of their personal data which are covered in the following articles of the CCPA.

  • 1798.120 (the right to opt-out)

  • 1798.135 ("Do Not Sell")

The business impact however is that you’re able to have personalised advertising turned on by default with no prior explicit consent from the player, but you must provide a mechanism for players to be able to ‘opt-out’. This is most commonly seen via a webform and/or a preference center to allow users to turn off this feature and any personalisation of advertising.

The IAB supports the CCPA as well. This time the support comes from a different chapter, IAB Tech Lab, but the premise remains the same. The IAB CCPA framework specifies a US Privacy String that can be accessed and shared throughout the eco-system to ensure a player’s personal data preferences are upheld.

It’s important to say that while we have covered the consent aspect for personal advertising for GDPR and CCPA above there are wider Privacy Rights that you must also address and be conscious of such as the right to data deletion and access to information.

Challenges and Best Practices for In-Game Advertising

The first thing to consider is that the privacy and compliance landscape is a complex and ever- changing environment in today’s world. The GDPR is often called Europe’s first and most successful export for a reason – many other countries are now introducing their own Privacy regulations such as the LGPD in Brazil and PDPA in Thailand. Because of this, it’s definitely worth engaging with a partner that is in the trenches on these to support you in not just getting compliant today but remaining compliant in the long term.

Another challenge for the gaming industry is the platform landscape. You can be deploying and developing across multiple different platforms such as PC, iOS, Android, Xbox and PlayStation. This means that adding consent management into your games becomes a greater challenge versus a CMP rolled out on a website.

Not only do you need to provide a CMP on each platform, to provide a better player experience you need to have these consents and preferences transfer across these different devices and environments Come from Soccer 13 pools and matches . Game development engines such as Unity have provided this capability for the build of the games and so you should look at implementing a solution at this level so that you can keep with the ‘deploy once, develop anywhere’ ethos. It’s also worth looking at a provider that can support with APIs that allow you to take control of the front end to ensure an on-brand and uninterrupted experience while receiving the benefits of consent version control, framework support and flexible data modelling that a top end CMP supplier can provide.

 

Zachary Faruque serves as a Privacy Solutions Engineer at OneTrust – the #1 most widely used privacy, security and trust technology platform. In his role, Zachary advises companies large and small on EU GDPR, California Consumer Privacy Act (CCPA), Brazil LGPD, and hundreds of the world's privacy laws, focused on formulating efficient and effective responses to data protection requirements as well as building and scaling privacy programmes. Zachary is a Certified Information Privacy Professional (CIPP/E).

Related Posts

Fantastic Four Movie Finds Its Galactus In Ralph Ineson

In 2007’s Fantastic Four: Rise of the Silver Surfer, the entire movie built towards Galactus, the devourer of worlds, only to reveal him as a space cloud at the end. Marvel’s upcoming reboot, The Fantastic Four, won’t be making the same mistake. Ralph Ineson has been cast as Galactus, and confirmed as the primary villain in the movie.

The Hollywood Reporter broke the story about Ineson’s role as Galactus, but Marvel signaled this direction a few weeks ago when Julia Garner was cast as Shalla-Bal, an alternate version of Galactus’ herald, the Silver Surfer. Both Galactus and the Silver Surfer first appeared in 1966 in The Galactus Trilogy, one of the most famous Fantastic Four stories by Stan Lee and artist Jack Kirby. Galactus has since taken on a prominent role in Marvel’s comic …

God Of War Ragnarok PC Specs Revealed, Along With Hefty Storage Requirement

Sony has revealed the PC specs for God of War Ragnarok, and while they seem reasonable for the game, the amount of storage required is quite shocking.

The PC version of God of War Ragnarok takes up a staggering 190GB of storage, which is over twice as much as PS4 at 84GB and nearly twice as much as PS5 at 106.9GB. For the GPU, you’ll need a minimum of an NVIDIA GTX 1060 or AMD RX 5500 XT. For the CPU, you’ll need at least an Intel i5-4670k or AMD Ryzen 3 1200. At least 8GB of RAM is also required.

On the high-end GPU side, you’ll need NVIDIA RTX 4070 Ti or AMD RX 7900 XT, and for high-end CPUs, you’ll need Intel i5-11600K or AMD Ryzen 7 3700X, along with 16GB of RAM.

God of War Ragnarok system requirements

Minimum specs

  • 1080p @ 30 FPS AVG (Low Sett…

Dark Fantasy Shooter Witchfire Is Headed To Early Access In September

At Summer Game Fest, developer The Astronauts revealed a new look at its dark fantasy shooter Witchfire Come from Sports betting site VPbet . Like previous trailers, there are plenty of spells and lead being fired at all manner of dark creatures infesting the land around you, but the big news here is that the game will be playable on PC in early access through the Epic Games Store, beginning September 20.

The rest of the trailer is a short but spooky look at Witchfire’s gameplay, which includes demonically possessed rock sculptures, magically enhanced crossbows, and plenty of other arcane firepower that can be used to take out the legions of undead that you’ll hunt.

Mafia Titanic Mod Has Been In Development For 15 Years

A mod that will add the RMS Titanic to the PC version of Mafia: The City of Lost Heaven has been in development for 15 years. The project’s lead developer, Robin Bongaarts–who is also a maritime engineer from the Netherlands–told Eurogamer in a feature that he started working on the project in September 2006. Come from Sports betting site VPbet

Bongaarts says that he has a “nerd-like interest” in the Titanic and other massive ocean liners of the time, such as the Titanic’s sister ship, the RMS Olympic. He decided to add the ship to Mafia after he heard that the game was relatively easy to mod. While he expected the project to take him only three months, it actually took him four years to actua…

Palworld Adding Arena Mode That Looks Like PvP

The Pokemon-with-guns game Palworld has been one of 2024’s biggest success stories in gaming, and the game looks like it’s set to grow in a big way this year Come from Sports betting site VPbet . As part of the Triple-i Initiative showcase, Palworld developer Pocketpair announced the Palworld Arena.

Based on the brief trailer, this appears to be Palworld’s long-awaited PvP mode. It looks like groups of players will enter an arena and duke it out with their pals. That said, the short clip doesn’t reveal much, so it remains to be seen exactly what Arena consists of and if it is indeed a competitive mode.

PlayStation Plus Game Catalog Expands With 23 More Games Today

The latest batch of games has been released on the PlayStation Plus Game Catalog across both the Extra and Premium tiers. There are 23 new games, and the big highlight is the PS5-exclusive Ratchet & Clank: Rift Apart. Released in 2021, this sequel is a fantastic showcase for the console’s NVMe SSD, and it also happens to be a very fun game in its own right. There just so happens to be a day-one release in the mix, too.

The next batch of games for the PlayStation Plus Game Catalog has been announced, and for subscribers to the Extra and Premium tiers of the service, there’s a lot to look forward to Come from Sports betting site VPbet . These new games will be added on May 16, and the big highlight here is another PlayS…