Riot Games · Riot Games Privacy Notice · View original document ↗

Data Retention Policy

Medium severity Common · 65 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Riot Games Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

Riot retains your personal data for as long as your account is active or as needed to provide services, and may keep certain data for longer periods for legal, business, or security reasons.

This analysis describes what Riot Games's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes the operational framework governing how long Riot Games maintains user personal data across multiple institutional functions including legal compliance, fraud prevention, and dispute resolution, creating a retention standard tied to service provision and legitimate business purposes rather than fixed time intervals.

Recent Activity

This document changed recently

Medium Apr 14, 2026

Riot Games has restructured how it presents information about data collection and use in its privacy notice. The company narrowed its third-party disclaimer by removing the phrase 'we don't own or control,' replacing it with 'we don't control'—a distinction that may affect which entities the company is claiming it has no privacy responsibility for. For California residents, the notice now consolidates information about categories of personal information and their purposes into a single section rather than splitting them across the document. The practical implication depends on how Riot Games operationally interprets 'control' in relation to its business relationships and how California regulators view this language under CCPA notice requirements.

View change record →

Consumer impact (what this means for users)

Your data may be retained well beyond your active use of Riot's services, potentially for years, unless you proactively request deletion. You can request account deletion and data erasure through the Riot privacy portal at https://www.riotgames.com/en/privacy-notice.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Submit a data deletion request through the Riot Games privacy portal. Select 'Delete My Data' or 'Close My Account' and follow the prompts. Note that some data may be retained for legal or security purposes even after deletion.

How other platforms handle this

OpenAI Medium

We retain personal data for as long as needed to provide our services, comply with our legal obligations, resolve disputes, and enforce our policies. Retention periods will vary depending on the type of data and the purposes for which we use it.

Microsoft Azure Medium

Microsoft retains personal data for as long as necessary to provide the products and fulfill the transactions you have requested, or for other legitimate purposes such as complying with our legal obligations, resolving disputes, and enforcing our agreements. Because these needs can vary for differen...

Meta Ads Medium

We keep information as long as we need it to provide our products and services and fulfil the purposes described in this policy. This is a case-by-case determination that depends on things like the nature of the information, why it is collected and processed, relevant legal or operational retention ...

See all platforms with this clause type →

Monitoring

Riot Games has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
We generally retain the related personal info as long as your account is active or as is otherwise necessary to provide the Riot Services, operate our business (including for legitimate purposes like complying with our legal obligations, managing internal books and records, preventing fraud, resolving disputes, and enforcing our contracts and terms, such as this Notice and the Terms of Service), or to achieve the purposes set out in this Notice, unless a longer retention period is permitted or required by law.

— Excerpt from Riot Games's Riot Games Privacy Notice

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

Vague retention periods may conflict with GDPR Article 5(1)(e)'s storage limitation principle, which requires data to be kept no longer than necessary for its stated purpose. Compliance teams should assess whether Riot's retention schedule is sufficiently specific and documented for GDPR accountability purposes.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable agencies

  • State AG
    State attorneys general may investigate retention practices that violate state privacy law data minimisation or deletion requirements.
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN

Provision details

Document information
Document
Riot Games Privacy Notice
Entity
Riot Games
Document last updated
May 5, 2026
Tracking information
First tracked
March 20, 2026
Last verified
March 20, 2026
Record ID
CA-P-001568
Document ID
CA-D-00310
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
39702142b1ff9de41afd68c3620684a1be0bc3bef47100050658a43adbd5eca3
Analysis generated
March 20, 2026 11:13 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Riot Games
Document: Riot Games Privacy Notice
Record ID: CA-P-001568
Captured: 2026-03-20 11:13:03 UTC
SHA-256: 39702142b1ff9de4…
URL: https://conductatlas.com/platform/riot-games/riot-games-privacy-notice/data-retention-policy/
Accessed: May 20, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Riot Games's Data Retention Policy clause do?

This provision establishes the operational framework governing how long Riot Games maintains user personal data across multiple institutional functions including legal compliance, fraud prevention, and dispute resolution, creating a retention standard tied to service provision and legitimate business purposes rather than fixed time intervals.

How does this clause affect you?

Your data may be retained well beyond your active use of Riot's services, potentially for years, unless you proactively request deletion. You can request account deletion and data erasure through the Riot privacy portal at https://www.riotgames.com/en/privacy-notice.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 65 platforms. See the full comparison.

Is ConductAtlas affiliated with Riot Games?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Riot Games.