Nintendo's privacy policy was updated on March 19, 2026 with several revisions to language describing data collection, retention practices, and third-party certifications. The policy now states it collects error information from both users and devices (previously only devices), removed specific examples of location data uses like checking into Nintendo locations, simplified retention language to reference only 'applicable law' without detailing sensitivity-based practices, eliminated detailed disclosure of persistent identifiers collected from child users, and changed its privacy certification from CARU (Children's Advertising Review Unit) to ESRB (Entertainment Software Rating Board). These changes alter how Nintendo describes its data practices and child data handling, though the operational scope of collection and use remains largely similar.
Consumers: Parents and children no longer see a detailed list of the specific types of identifiers Nintendo collects from child accounts or why it collects them.
The revised policy simplifies how Nintendo describes data retention, now stating information is retained only as long as reasonably necessary in accordance with applicable law, without prior detail about sensitivity-based retention practices. For child users, the policy no longer explicitly lists persistent identifiers (IP addresses, device identifiers) that Nintendo and service providers collect, removing specific disclosure language that previously detailed collection purposes for child accounts. The policy now indicates it collects error information from both users and devices, broadening the prior language focused on device errors only. The privacy certification body changed from CARU to ESRB, meaning independent audits and enforcement are now administered by the Entertainment Software Rating Board rather than the Children's Advertising Review Unit.
→ Review updated certification seal on Nintendo websites to confirm ESRB rather than CARU oversight
→ Contact Nintendo using provided contact information if you wish to review, modify, or delete child account information
Removed detailed disclosure of IP addresses, device identifiers, and other unique identifiers collected from child users and the stated purposes for collection.
Simplified from detailed sensitivity-based retention framework to general statement that information is retained only as long as reasonably necessary in accordance with applicable law.
Changed independent audit and enforcement body from CARU to ESRB, altering which organization conducts compliance reviews.
This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology
Nintendo modified child privacy disclosures and certification oversight on March 19, 2026. The policy removed explicit language detailing persistent identifiers collected from child users and simplified data retention descriptions. This change may affect compliance assessment …
Regulatory exposure, obligation change, escalation trigger, board-ready language, and recommended action for legal and compliance teams.
Unlock the full institutional analysis — InsightConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-001881.
Nintendo updated its privacy policy to clarify how it collects and uses data from children and shifted its third-party privacy …
Nintendo updated its privacy policy to clarify how it collects error data, expanded where it uses location information to include …
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Get alerted when this policy changes again, including what changed and why it matters.