Privacy: GDPR and ATT/IDFA
The mechanism: how the data was cut off
GDPR (2018) — consent and minimization
GDPR (in force from May 2018) made personal data a regulated thing: you need explicit consent to collect, purpose limitation and minimization (take only what you need), a right of access and erasure, a DPO, and fines up to 4% of global revenue. For game telemetry that is a direct conflict with the instinct to "log everything up front": now you need consent, you cannot collect on spec, and an EU player can demand their history be wiped. The visible artifact is the consent banners for cookies and tracking.
ATT/IDFA (2021) — the death of per-user attribution
The IDFA (Identifier for Advertisers) is a cross-app device identifier that let ad networks recognize one person across apps: attribute an install to a specific campaign, build LTV by source and retarget. App Tracking Transparency (iOS 14.5, April 2021) required a prompt — "Allow this app to track you?" — with "Ask App Not to Track" highlighted by default. Few accept: games see ~18–25% (immediate opt-in), and the industry average is ~15–25%. Without consent the IDFA is unavailable, and the only route to attribution is SKAdNetwork (SKAN): aggregated, delayed, threshold-noised conversions. The share of iOS traffic measurable per user:
where is the opt-in rate. Which means that for 4 out of 5 iOS players you no longer know where they came from or what they will bring in at the level of a person — only a rough, delayed aggregate estimate.
What exactly broke
The whole UA flywheel from analytics rested on per-user measurement: "I can see that source X gives an LTV above its CPI → pour more into X". ATT cut off the measurement — and UA decisions became noisy and blind. The numbers: −21% ad revenue from Apple users for publishers, trackable impressions costing ~51% more than untrackable ones (meaning the untrackable ones collapsed), and Meta publicly estimating the loss at ~$10B/year (2022). Hit hardest were small studios whose model lived on precise cheap UA; the giants, with first-party data and ecosystems of their own, weathered it more easily.
What replaces it
- First-party data: own your players (accounts, cross-promotion inside your own portfolio) — data you actually have consent to collect.
- Probabilistic / MMM: a return to aggregate econometrics — media mix modeling estimates each channel's contribution without per-user data (the very thing the 2010s moved away from is back).
- Contextual targeting: aim at the content rather than the person (ads in a chess app go to chess players), with no surveillance.
- SKAN / AdAttributionKit and Google Privacy Sandbox (Android is heading the same way: the Topics API, aggregate measurement) — platform-provided "private" replacements for tracking.
🕹 What to notice
This topic is visible not in a game but in the consent interfaces you walk through every day.
"Allow this app to track your activity?" with "Ask App Not to Track" highlighted is the IDFA switch itself. Your answer decides whether you land in the ~20% measurable per user or the 80% who are "SKAN only".
🎮 Notice: next time you install an app, look closely at the ATT prompt — which option is highlighted by default, how the wording nudges you toward refusing. You are literally pressing the button that costs the industry $10B a year.
The nagging "Accept all / Manage" dialogs are a direct consequence of GDPR (and ePrivacy): collection requires consent. Dark patterns in those banners ("Accept" large and bright, "Reject" hidden) are a regulatory battlefront of their own.
🎮 Notice: on any site or in any game open the consent banner and judge the design: is accepting as easy as refusing? This is where privacy intersects with the dark patterns from the previous lesson.
GDPR granted a right of access and erasure — decent games expose it in the account settings (export/delete my data).
🎮 Notice: go into the privacy settings of a game you like and look for "delete my data / withdraw consent". Is it there at all, and how deeply is it buried? Its presence and convenience are an indicator of how the studio treats GDPR (compliance versus a formality).
Deep end · infra and compliance: consent, SKAN and private replacementsskippable
The engineering of consent
GDPR requires consent management: granular consent per purpose, a record of who agreed to what and when, and the technical ability to delete a user's data on request (which is hard when events are smeared across a warehouse, backups and third-party SDKs). Minimization hits "log everything": now you decide what you need, not what you can have.
How SKAN works
SKAdNetwork returns an aggregated signal: the device sends Apple an encrypted "conversion value" with a delay (a randomized timer) and a privacy threshold (if a campaign is small the data is not returned at all, so it cannot be de-anonymized). The result: no per user, no fast feedback, no retargeting — only a rough estimate that "this campaign brought in roughly this much". It is a deliberately differential-privacy-like design: noise and thresholds in the name of non-identifiability.
The return of MMM
When per-user measurement disappeared, the industry pulled media mix modeling out of mothballs — a regression of revenue on spend by channel with lags and seasonality. It is twentieth-century aggregate causality, back because micro-attribution became impossible. Analytics retreated from "track everyone" to "econometrics on average".
Deep end · economics: who lost and why the giants held upskippable
The ATT blow landed extremely unevenly — and that is a lesson about depending on someone else's identifiers.
- Small F2P studios: they lived on precise cheap UA (buy an install, measure LTV, scale what is profitable). Without measurement the flywheel broke, and many did not survive.
- Ad networks (Meta and others): their targeting was built on cross-app tracking; Meta estimated the loss at ~$10B/year and had to rebuild its AI targeting on aggregate signals.
- Giants with first-party ecosystems (Apple, Google, big publishers with portals and accounts): they have their own consented data — they suffered less, and Apple, by introducing ATT, also strengthened its own advertising position (a conflict of interest regulators pointed out).
The structural conclusion: building a business on somebody else's identifier or data is a platform dependency the platform can cut off unilaterally (exactly like the Unity Runtime Fee: the rules are changed by whoever holds the switch). First-party data is the "open source" equivalent: nobody can take it away from you.
ML / AI (your domain): the death of per-user tracking is a direct driver of privacy-preserving ML. SKAN, with its noise and thresholds, ≈ differential privacy (aggregates with a non-identifiability guarantee); "compute on the user's device, do not centralize the raw data" = federated learning and on-device models (the same pivot Apple/Google made — see on-device LLMs); contextual instead of behavioral = fewer personal data points in your features. The return of MMM = aggregate causality when individual data is unavailable. And a thread running through it: regulation or a platform can rug-pull your data source — training on someone else's identifiers or data is a data-dependency and data-governance risk you have to budget for. Plus the ethics: the F2P model itself provoked the regulatory backlash through total tracking — "is this collection justified?" is now a first-class design question, not an afterthought.
Advertising / marketing: the deprecation of cookies and the IDFA, clean rooms, the MMM renaissance, contextual targeting — the entire measurement industry rebuilt itself around aggregates and first-party data.
Any data product: data governance, consent, the right to erasure, minimization by default; "log everything" is no longer the default — it is a legal and ethical risk.
The principle: data about people is a regulated and revocable resource, not free raw material. Design measurement for privacy (aggregates, on-device, consent) and do not build a business on an identifier somebody else owns.
Why did ATT hit harder than GDPR, when GDPR is stricter on paper?
Why not just "ask for consent better" and get tracking back?
Are contextual targeting and MMM a real replacement or a palliative?
Who did ATT hurt most — and why is that a lesson about dependency?
Are ATT/GDPR good or bad for the industry?
- Apple — the ATT / SKAdNetwork / AdAttributionKit documentation (the primary source on the mechanics).
- AppsFlyer, Adjust, GameAnalytics — post-ATT guides to measurement (SKAN, MMM, incrementality).
- GDPR — the official text plus ICO/EDPB guidance on consent and minimization for games.
- Analyses of ATT's impact on Meta (~$10B/year, 2022) and the −21% ad revenue for publishers.
- Module 6, "GDPR (May 2018) — the regulation that reshaped game telemetry" (
06-mobile-f2p-live-service-2012-2018.md).