Riot Games · Riot Games Privacy Notice · View original document ↗

Kernel-Level Anti-Cheat (Vanguard) Data Collection

High severity Medium confidence Explicitdocumentlanguage Unique · 0 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Riot Games recorded 3 documented changes in the last 30 days.
Start monitoring updates
Monitor governance changes for Riot Games Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

Riot's Vanguard anti-cheat software installs at the deepest level of your computer's operating system and may collect data about your hardware and other software running on your PC, including when you are not playing.

This analysis describes what Riot Games's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

Kernel-level software has privileged access to your entire system. The fact that it may run and collect data even when the game is not active means your device is being monitored outside of gameplay sessions, which is a meaningful expansion of the typical software data collection scope.

Interpretive note: The notice does not specify which exact data fields Vanguard transmits, the retention period for that data, or the precise conditions under which background operation occurs, leaving meaningful gaps in what users can assess about the actual scope of collection.

Recent Activity

This document changed recently

Medium Apr 14, 2026

Riot Games has restructured how it presents information about data collection and use in its privacy notice. The company narrowed its third-party disclaimer by removing the phrase 'we don't own or co…

Consumer impact (what this means for users)

If you play Valorant or other Riot games using Vanguard, a kernel-level program may be running on your computer and collecting system information even when you are not gaming. Users should be aware that uninstalling the game may be required to stop this background process.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Submit a data deletion request at https://privacyrequest.riotgames.com specifying that you want data collected by Vanguard deleted. Additionally, uninstall Valorant and Vanguard from your device to stop ongoing collection.

How other platforms handle this

PlanetScale Medium

When you visit the Careers portion of our websites, we collect the information that you provide to us in connection with your job application. This includes but is not limited to business and personal contact information, professional credentials and skills, educational and work history and other in...

American Airlines Medium

American does not knowingly collect personal information directly from children – persons under the age of 13, or another age if required by applicable law – other than when required to comply with the law or for safety and security reasons. Due to the nature of our Services, we may collect travel i...

GOAT Medium

We may collect information about your location, including precise geolocation information, when you use our Services. We use this information to provide location-based services, such as showing you products available in your area, and for other purposes described in this Privacy Policy.

See all platforms with this clause type →

Monitoring

Riot Games has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
To maintain the integrity of our games, we use anti-cheat software, including software that may run at a kernel level on your device. This software collects information about your computer hardware and software, including information about other software running on your computer, and reports this information to us. This software may run in the background even when you are not actively playing our games.

— Excerpt from Riot Games's Riot Games Privacy Notice

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

REGULATORY LANDSCAPE: Persistent kernel-level software that collects hardware and software inventory data implicates GDPR Article 5 data minimization and purpose limitation principles, as well as the requirement for a clear lawful basis under Article 6. In the US, the FTC's unfair practices authority under Section 5 of the FTC Act may apply if the scope of collection and background operation are not adequately disclosed. The Computer Fraud and Abuse Act (CFAA) may be relevant depending on the scope of system access. CCPA's definition of personal information includes device identifiers and inferences drawn from them. GOVERNANCE EXPOSURE: High. Background operation of kernel-level software that collects system information outside of active gameplay is operationally distinct from typical game telemetry. The notice discloses this practice but does not detail what specific data is collected, how long it is retained, or how users can verify the scope of collection. This creates transparency gaps that may not satisfy GDPR's transparency requirements under Articles 13 and 14. JURISDICTION FLAGS: EU/EEA users have the right under GDPR to receive specific information about automated data collection; the current disclosure may not meet the specificity required. California residents have rights to know and delete personal information collected by software, including device identifiers. Illinois BIPA may apply if biometric data were incidentally collected, though the notice does not suggest this currently. CONTRACT AND VENDOR IMPLICATIONS: Enterprise procurement or esports organization IT teams deploying Riot games on managed devices should assess whether kernel-level software installation is consistent with their endpoint security policies and corporate device management frameworks. The software's access to system information could conflict with data loss prevention or security monitoring tools. COMPLIANCE CONSIDERATIONS: Compliance teams should assess whether the disclosure of Vanguard's scope and background operation is presented with sufficient specificity to satisfy GDPR transparency obligations. A data protection impact assessment (DPIA) may be warranted given the systemic and persistent nature of the data collection. Users' right to erasure under GDPR may be difficult to operationalize for hardware-level identifiers that have already been collected and transmitted.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has authority to investigate whether background kernel-level data collection practices are adequately disclosed and whether they constitute unfair or deceptive acts under Section 5 of the FTC Act.
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
COPPA
United States Federal
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
ePrivacy Directive
European Union
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Riot Games Privacy Notice
Entity
Riot Games
Document last updated
May 5, 2026
Tracking information
First tracked
May 10, 2026
Last verified
May 10, 2026
Record ID
CA-P-005349
Document ID
CA-D-00310
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
2a840e744c4ccacedb5da002bc88e924c17e42553d102c3755b4b0f1d26ccb44
Analysis generated
May 10, 2026 05:42 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Riot Games
Document: Riot Games Privacy Notice
Record ID: CA-P-005349
Captured: 2026-05-10 05:42:08 UTC
SHA-256: 2a840e744c4ccace…
URL: https://conductatlas.com/platform/riot-games/riot-games-privacy-notice/kernel-level-anti-cheat-vanguard-data-collection/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Related Analysis

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Riot Games's Kernel-Level Anti-Cheat (Vanguard) Data Collection clause do?

Kernel-level software has privileged access to your entire system. The fact that it may run and collect data even when the game is not active means your device is being monitored outside of gameplay sessions, which is a meaningful expansion of the typical software data collection scope.

How does this clause affect you?

If you play Valorant or other Riot games using Vanguard, a kernel-level program may be running on your computer and collecting system information even when you are not gaming. Users should be aware that uninstalling the game may be required to stop this background process.

Is ConductAtlas affiliated with Riot Games?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Riot Games.