Nintendo updated its privacy policy to clarify how it collects and uses data from children and shifted its third-party privacy certification from ESRB to CARU. The policy now explicitly states that persistent identifiers like IP addresses and device IDs are collected from child users for specific operational purposes, and parents can now see a named list of third-party apps authorized to access their child's account. The company also expanded its disclosure of location data use to include check-ins at Nintendo locations and events.
Parents: Parents now have explicit visibility into which apps have been authorized to receive their child's account information.
Consumers: The policy now openly states what kinds of identifiers are collected from children and why.
Vendors: Service providers working with Nintendo are contractually bound to use child data only for the stated purposes.
Nintendo now explicitly discloses that it collects persistent identifiers (IP addresses, device IDs) from child users for operational, security, fraud prevention, and service improvement purposes, and states that contractual restrictions limit how service providers can use this data. Parents gain enhanced transparency by being able to view a named list of third-party games and applications authorized to access their child's account, rather than just managing access through settings. The policy also clarifies that location information may be used for check-ins at Nintendo locations and events in addition to location-based games. You can review and manage which third-party apps have access to your child's account through your Nintendo Account profile settings.
→ Review the named list of third-party applications authorized to access your child's Nintendo Account by visiting your Nintendo Account profile settings.
→ Remove access for any apps your child no longer uses or that you do not want to have access to your child's account information.
ConductAtlas has recorded 3 material changes to this document (since March 2026).
Policy now explicitly permits collection of IP addresses and device identifiers from child users for internal operations, security, fraud prevention, advertising, and legal compliance, with stated contractual restrictions on service provider use.
Parents can now view a named list of third-party applications authorized to receive child account information, expanding visibility beyond access management settings.
Nintendo shifted from ESRB Privacy Certified Program to CARU Privacy Certified Program, changing the independent auditor and enforcement body governing compliance.
This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology
Nintendo transitioned its child privacy certification from the Entertainment Software Rating Board (ESRB) to the Children's Advertising Review Unit (CARU), both of which are self-regulatory programs with independent audit and enforcement mechanisms. The policy now …
Regulatory exposure, obligation change, escalation trigger, board-ready language, and recommended action for legal and compliance teams.
Unlock the full institutional analysis — InsightConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-001094.
Nintendo updated its privacy policy to clarify how it collects error data, expanded where it uses location information to include …
Nintendo's privacy policy was updated on March 19, 2026 with several revisions to language describing data collection, retention practices, and …
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Get alerted when this policy changes again, including what changed and why it matters.