Roblox has appointed a GDPR representative in the EU and a Data Protection Officer as required by European law, and provides specific contact details for EU, UK, Swiss, and Brazilian users to exercise their privacy rights.
This analysis describes what Roblox's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The provision creates a procedural framework for regulatory compliance in jurisdictions requiring organizations to designate representatives for data subject inquiries and supervisory authority communications. Designating these contacts fulfills mandatory GDPR requirements and establishes the formal channels through which regulatory and individual data protection requests must be routed.
The updated policy restricts personalized advertising based on age. Users under 18 will see only nonpersonalized ads on the platform, while users 18 and older may see personalized ads if they provide consent where required. The revised language also removes the previous statement that the platform collects personal information from under-13 accounts for advertising purposes, clarifying that such data is not used for marketing. Users 18 or older can control whether they see personalized ads through Roblox account settings.
View change record →The updated policy clarifies that parent email addresses constitute the only personal information collected from child accounts under COPPA, rather than listing persistent identifiers. The policy now states that personalized ads are not enabled until age 18, rather than leaving this ambiguous when a child turns 13. These clarifications affect how parents and children understand what data Roblox collects and when advertising becomes personalized; however, the underlying data practices do not appear to have changed operationally. The policy removed detailed descriptions of collection purposes (such as internal operations), which means parents now have less granular explanation of data uses, though stated practices remain.
View change record →If you are in the EU, UK, or Switzerland, Roblox has designated specific contacts for privacy requests under GDPR, making it easier for you to exercise your data subject rights. EU users can contact roblox@gdpr-rep.com and the DPO at roblox@dp-officer.com for privacy concerns.
How other platforms handle this
If you choose to reveal any personal information about yourself to other users, you do so at your own risk. We strongly encourage you to use caution in disclosing any personal information online.
When you are asked to provide information, you may decline to do so; but if you choose not to provide information that is necessary to provide some of our Services, you may not be able to use those Services.
to object to profiling activities based on our own legitimate interests
"If you're in the European Economic Area (EEA), the United Kingdom, or Switzerland: contact roblox@gdpr-rep.com (Our representative according to Articles 27 EU and UK GDPR in the European Union). Our data protection officer in the EU according to Art. 37 GDPR can be reached via: DP Dock DPO Services GmbH - Roblox, Grüffkamp 10, 24159 Kiel, Germany, roblox@dp-officer.com.Excerpt from Roblox's Privacy and Cookie Policy
REGULATORY LANDSCAPE: GDPR Article 27 requires non-EU controllers processing EU personal data to appoint a representative in the EU.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The provision creates a procedural framework for regulatory compliance in jurisdictions requiring organizations to designate representatives for data subject inquiries and supervisory authority communications. Designating these contacts fulfills mandatory GDPR requirements and establishes the formal channels through which regulatory and individual data protection requests must be routed.
If you are in the EU, UK, or Switzerland, Roblox has designated specific contacts for privacy requests under GDPR, making it easier for you to exercise your data subject rights. EU users can contact roblox@gdpr-rep.com and the DPO at roblox@dp-officer.com for privacy concerns.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Roblox.