Track 1 platform and get the weekly governance digest. No credit card required.
This page describes what the document states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability may vary by jurisdiction. Methodology
Steam's Privacy Policy establishes the categories of personal data Valve collects from platform users, including account identifiers, payment information, gameplay statistics, device data, and communication records. The policy authorizes Valve to share collected data with Valve group companies, third-party game developers, payment processors, and service partners for purposes including game delivery, platform operation, and marketing personalization. Users may configure cookie preferences at store.steampowered.com/account/cookiepreferences/ and adjust Steam Client interface settings to control content recommendations.
This document governs Valve Corporation's collection, processing, storage, and sharing of personal data across the Steam platform and associated services, asserting legal bases including contractual necessity, legal obligation, legitimate interests, and user consent consistent with GDPR Article 6 framing. The policy states that Valve collects a broad range of data categories including account credentials, payment information, device identifiers, game statistics, playtime, browser and behavioral tracking data, chat communications, and voice data from Steam's communication features, and the terms authorize sharing this data with Valve group companies, third-party game developers, payment processors, and other service partners. Notably, the policy discloses collection of hardware survey data and voice data from Steam communication features, asserts the right to process anonymized aggregated data and share it with third parties without restriction, and permits behavioral tracking across Steam websites and applications for marketing and analytics purposes, though several of these asserted rights may be constrained by GDPR, UK GDPR, or CCPA requirements depending on the legal basis applied. The policy expressly engages GDPR, UK GDPR, CCPA, and the EU-U.S. Data Privacy Framework, and Valve certifies adherence to the DPF Principles, which govern in case of conflict with this policy; EU and UK users hold specific rights including access, rectification, erasure, and objection, while California residents are entitled to CCPA disclosure and opt-out rights. Material compliance considerations include ensuring adequate legal bases for each processing activity, verifying that third-party data sharing arrangements meet applicable transfer mechanism requirements, and confirming that consent mechanisms for optional cookies and marketing communications meet applicable standards.
Institutional analysis available with Professional
Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.
Start Professional free trial2 important changes detected
2 versions captured · Last updated: April 2026
Monitoring
Steam has updated this document before.
Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.
Professional Governance Intelligence
Need provision-level monitoring and regulatory mapping?
Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.
Start Professional free trialCross-platform context
See how other platforms handle Legal Bases for Personal Data Processing and similar clauses.
Compare across platforms →Governance Monitoring
Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.