The policy defines the data controller as Epic Games, Inc. and its subsidiaries and affiliates that provide the Epic Services, with specific controller identity determined by Section 12. This structure means the applicable data controller may vary depending on the Epic Service the user is accessing.
This analysis describes what Unreal Engine's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The policy's use of a group-level data controller definition, with the specific responsible entity identified only in Section 12, is operationally significant under GDPR, which requires clear identification of the data controller and their contact details in privacy notices. Users and compliance teams must consult Section 12 to determine which entity holds data controller responsibility for a specific service or jurisdiction.
Under this provision, the data controller responsible for personal information varies across Epic Services and subsidiaries, with the specific entity identified in Section 12 of the policy. This structure means the applicable privacy rights mechanism, complaint jurisdiction, and legal entity may differ depending on which Epic Service a user is accessing.
How other platforms handle this
Where ZipRecruiter processes your Personal Data in the capacity of a service provider (data processor), and you seek access, or want to correct, amend, or delete your Personal Data...we will provide you with the data controller's contact information, so you can contact them directly.
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
"When we refer to "Epic" (or any similar terms like "we," "us," or "our") in this Policy, we mean the Epic entity that controls and is responsible for your information, such as Epic Games, Inc. and its subsidiaries and affiliates that provide the Epic Services. This Policy applies when Epic acts as a data controller of your information. You can find details about the data controller responsible for your information in Section 12 (How Can You Contact Us?).Excerpt from Unreal Engine's Epic Games Privacy Policy
1) REGULATORY LANDSCAPE: GDPR Articles 4 and 13 require clear identification of the data controller and their contact details in privacy notices.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The policy's use of a group-level data controller definition, with the specific responsible entity identified only in Section 12, is operationally significant under GDPR, which requires clear identification of the data controller and their contact details in privacy notices. Users and compliance teams must consult Section 12 to determine which entity holds data controller responsibility for a specific service or …
Under this provision, the data controller responsible for personal information varies across Epic Services and subsidiaries, with the specific entity identified in Section 12 of the policy. This structure means the applicable privacy rights mechanism, complaint jurisdiction, and legal entity may differ depending on which Epic Service a user is accessing.
ConductAtlas has identified this type of provision across 289 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Unreal Engine.