← Module 6/Privacy: GDPR and ATT/IDFA
RU
Module 6 · Mobile / F2P (2012–2018)

Privacy: GDPR and ATT/IDFA

The whole F2P machine of the previous lessons — traffic targeting, measuring LTV by source, A/B tests on user data — rested on the right to follow a person between apps. Regulation cut that off: GDPR (2018) and Apple's ATT (2021) killed per-user measurement, and the "cheap accurate UA plus a measured LTV" model started flying blind.
~16 min⚖ regulation + 💰 UA
The gist in 30 seconds
The F2P flywheel (buy traffic → measure LTV by source → pour more into the profitable one) rested on per-user tracking. GDPR (May 2018) introduced consent, data minimization and the right to erasure — reshaping telemetry (you cannot "log everything", an EU user can demand deletion; fines up to 4% of global revenue). Apple's ATT (iOS 14.5, April 2021) finished measurement off: an "Allow tracking?" prompt that only ~15–25% accept effectively killed the IDFA (the cross-app advertising identifier). Without it there is no per-user attribution — all that is left is SKAdNetwork (aggregated, delayed, threshold-gated). The result: precise targeting and LTV-by-source measurement degraded, publishers saw −21% ad revenue from iOS, and Meta lost ~$10B/year (2022), with small studios that lived on precise UA hit hardest. The shift: first-party data, probabilistic/aggregate measurement (a return to media mix models), contextual targeting, Privacy Sandbox on Android. The end of "free analytics on other people's data".

The mechanism: how the data was cut off

GDPR (2018) — consent and minimization

GDPR (in force from May 2018) made personal data a regulated thing: you need explicit consent to collect, purpose limitation and minimization (take only what you need), a right of access and erasure, a DPO, and fines up to 4% of global revenue. For game telemetry that is a direct conflict with the instinct to "log everything up front": now you need consent, you cannot collect on spec, and an EU player can demand their history be wiped. The visible artifact is the consent banners for cookies and tracking.

ATT/IDFA (2021) — the death of per-user attribution

The IDFA (Identifier for Advertisers) is a cross-app device identifier that let ad networks recognize one person across apps: attribute an install to a specific campaign, build LTV by source and retarget. App Tracking Transparency (iOS 14.5, April 2021) required a prompt — "Allow this app to track you?" — with "Ask App Not to Track" highlighted by default. Few accept: games see ~18–25% (immediate opt-in), and the industry average is ~15–25%. Without consent the IDFA is unavailable, and the only route to attribution is SKAdNetwork (SKAN): aggregated, delayed, threshold-noised conversions. The share of iOS traffic measurable per user:

ftrack=o≈0.15–0.25 ⇒ 75–85% → SKAN only (aggregate)

where o is the opt-in rate. Which means that for 4 out of 5 iOS players you no longer know where they came from or what they will bring in at the level of a person — only a rough, delayed aggregate estimate.

What exactly broke

The whole UA flywheel from analytics rested on per-user measurement: "I can see that source X gives an LTV above its CPI → pour more into X". ATT cut off the measurement — and UA decisions became noisy and blind. The numbers: −21% ad revenue from Apple users for publishers, trackable impressions costing ~51% more than untrackable ones (meaning the untrackable ones collapsed), and Meta publicly estimating the loss at ~$10B/year (2022). Hit hardest were small studios whose model lived on precise cheap UA; the giants, with first-party data and ecosystems of their own, weathered it more easily.

What replaces it

🕹 What to notice

This topic is visible not in a game but in the consent interfaces you walk through every day.

The ATT prompt you decide whether you are trackable

"Allow this app to track your activity?" with "Ask App Not to Track" highlighted is the IDFA switch itself. Your answer decides whether you land in the ~20% measurable per user or the 80% who are "SKAN only".

🎮 Notice: next time you install an app, look closely at the ATT prompt — which option is highlighted by default, how the wording nudges you toward refusing. You are literally pressing the button that costs the industry $10B a year.

Cookie/consent banners GDPR made visible

The nagging "Accept all / Manage" dialogs are a direct consequence of GDPR (and ePrivacy): collection requires consent. Dark patterns in those banners ("Accept" large and bright, "Reject" hidden) are a regulatory battlefront of their own.

🎮 Notice: on any site or in any game open the consent banner and judge the design: is accepting as easy as refusing? This is where privacy intersects with the dark patterns from the previous lesson.

A game's privacy settings the right to erasure

GDPR granted a right of access and erasure — decent games expose it in the account settings (export/delete my data).

🎮 Notice: go into the privacy settings of a game you like and look for "delete my data / withdraw consent". Is it there at all, and how deeply is it buried? Its presence and convenience are an indicator of how the studio treats GDPR (compliance versus a formality).

Deep end · infra and compliance: consent, SKAN and private replacementsskippable

The engineering of consent

GDPR requires consent management: granular consent per purpose, a record of who agreed to what and when, and the technical ability to delete a user's data on request (which is hard when events are smeared across a warehouse, backups and third-party SDKs). Minimization hits "log everything": now you decide what you need, not what you can have.

How SKAN works

SKAdNetwork returns an aggregated signal: the device sends Apple an encrypted "conversion value" with a delay (a randomized timer) and a privacy threshold (if a campaign is small the data is not returned at all, so it cannot be de-anonymized). The result: no per user, no fast feedback, no retargeting — only a rough estimate that "this campaign brought in roughly this much". It is a deliberately differential-privacy-like design: noise and thresholds in the name of non-identifiability.

The return of MMM

When per-user measurement disappeared, the industry pulled media mix modeling out of mothballs — a regression of revenue on spend by channel with lags and seasonality. It is twentieth-century aggregate causality, back because micro-attribution became impossible. Analytics retreated from "track everyone" to "econometrics on average".

Deep end · economics: who lost and why the giants held upskippable

The ATT blow landed extremely unevenly — and that is a lesson about depending on someone else's identifiers.

  • Small F2P studios: they lived on precise cheap UA (buy an install, measure LTV, scale what is profitable). Without measurement the flywheel broke, and many did not survive.
  • Ad networks (Meta and others): their targeting was built on cross-app tracking; Meta estimated the loss at ~$10B/year and had to rebuild its AI targeting on aggregate signals.
  • Giants with first-party ecosystems (Apple, Google, big publishers with portals and accounts): they have their own consented data — they suffered less, and Apple, by introducing ATT, also strengthened its own advertising position (a conflict of interest regulators pointed out).

The structural conclusion: building a business on somebody else's identifier or data is a platform dependency the platform can cut off unilaterally (exactly like the Unity Runtime Fee: the rules are changed by whoever holds the switch). First-party data is the "open source" equivalent: nobody can take it away from you.

Analogy
F2P's UA engine ran on "free GPS": every user could be followed across the whole map (the IDFA) and you could see exactly which advertising intersection they had come from. Privacy (GDPR + ATT) put up walls and switched the GPS tracking off: now all you get are aggregated, delayed and blurred reports of where the cars went (SKAN/MMM). You can still drive — but you are navigating by blind dead reckoning rather than by GPS. A model built on precise tracking suddenly found itself flying by guesswork.
Why it matters
This is the end of the module's arc: the whole F2P machine — retention analytics, LTV measurement, precise UA — stood on per-user data, and regulation knocked that foundation out. The lesson is double. Engineering: privacy is now a first-class design constraint, and measurement has to be aggregate/private rather than "watch everyone". Strategic: a business built on someone else's data or identifiers is a dependency the platform owner can cut. Both transfer directly to ML, where privacy and personalization are the central conflict.
🔁 Beyond games — where this transfers
The lesson is the conflict between privacy and personalization and the fragility of measurement built on other people's data.

ML / AI (your domain): the death of per-user tracking is a direct driver of privacy-preserving ML. SKAN, with its noise and thresholds, ≈ differential privacy (aggregates with a non-identifiability guarantee); "compute on the user's device, do not centralize the raw data" = federated learning and on-device models (the same pivot Apple/Google made — see on-device LLMs); contextual instead of behavioral = fewer personal data points in your features. The return of MMM = aggregate causality when individual data is unavailable. And a thread running through it: regulation or a platform can rug-pull your data source — training on someone else's identifiers or data is a data-dependency and data-governance risk you have to budget for. Plus the ethics: the F2P model itself provoked the regulatory backlash through total tracking — "is this collection justified?" is now a first-class design question, not an afterthought.

Advertising / marketing: the deprecation of cookies and the IDFA, clean rooms, the MMM renaissance, contextual targeting — the entire measurement industry rebuilt itself around aggregates and first-party data.

Any data product: data governance, consent, the right to erasure, minimization by default; "log everything" is no longer the default — it is a legal and ethical risk.

The principle: data about people is a regulated and revocable resource, not free raw material. Design measurement for privacy (aggregates, on-device, consent) and do not build a business on an identifier somebody else owns.

🔧 Run it and poke at it — on your home machine
What to look at is above (🕹). This part is about walking the data switches yourself.
🔧 Poke at it (a data audit) ~40 min
Take a game or app you like and follow its data trail: open the App Privacy "label" in the App Store (what it collects), find its ATT status, look through the settings for data export/deletion. Then design: if you were building its UA measurement today, what would you measure traffic payback with, without the IDFA (SKAN? MMM? first-party? context)?
🧪 Test it (compliance/ethics) ~15 min
Judge one game's consent banner for dark patterns: is accepting as easy as refusing, are consents pre-selected, is the refusal hidden? Then a mini DPIA: which data does the game actually need for its core function, and which is collected "just in case"? What would minimization cut?
Checklist: followed an app's data trail (App Privacy + ATT + deletion); designed UA measurement without the IDFA; judged a consent banner for dark patterns; ran a "need versus can" minimization pass.
Connections
foundation
Analytics — the per-user data that cohorts, attribution and A/B rest on; this lesson is about how it was cut off.
foundation
Distribution and UA — measuring traffic payback (LTV>CPI) broke without per-user attribution.
contrast
Engines and vendor risk — Apple changed the rules unilaterally (ATT) just as Unity did (the Runtime Fee): a platform dependency is revocation risk.
Questions worth asking
Why did ATT hit harder than GDPR, when GDPR is stricter on paper?
GDPR regulates how you collect and store data (consent, minimization, erasure) — painful, but workable through consent flows and compliance. ATT technically cut off the identifier itself (the IDFA) that cross-app attribution rested on, and did it at the OS level with "do not track" as the default. So GDPR added friction and risk, while ATT switched measurement off for ~80% of iOS users in a single update. Regulation changes the rules; a platform changes what is possible. That is why the −21% revenue and Meta's $10B are about ATT, not GDPR.
Why not just "ask for consent better" and get tracking back?
You can raise opt-in with pre-prompts (top apps get 50–70%), but the ceiling is low: the OS default highlights refusal, the wording is alarming, and people in general do not want to be followed. Even 50% is half the signal lost, and the average app sees 15–25%. On top of that GDPR requires refusal to be as easy as consent — you cannot herd people into "yes". The default fundamentally changed: tracking used to be on by default (opt-out) and is now off (opt-in), and experience shows defaults decide almost everything. Restoring the old coverage through consent is impossible.
Are contextual targeting and MMM a real replacement or a palliative?
They are a different tool, not a restoration of the old precision. Contextual (target the content, not the person) and MMM (an aggregate regression of revenue on spend) give a coarse, averaged picture — enough for large budgets and strategic decisions, but not for micro-optimizing "this user from this creative is worth $3.40". The precision of per-user attribution is not coming back; the industry adapted to aggregates with more variance: more modeling, more uncertainty, less surgical precision. It is a step backward in measurement resolution, imposed by a privacy requirement.
Who did ATT hurt most — and why is that a lesson about dependency?
Hardest hit were small F2P studios running precise cheap UA: their "measure LTV → scale the profitable source" flywheel broke, and many did not survive. Giants with first-party data (their own accounts, portals, consents) held up, and Apple, in introducing ATT, also strengthened its own advertising — a conflict of interest regulators pointed out. The lesson is structural: studios built businesses on somebody else's identifier (Apple's IDFA), and the owner of the switch turned it off. It is the same platform dependency as the Unity Runtime Fee: convenient today, revoked tomorrow. First-party data is insurance against a rug pull.
Are ATT/GDPR good or bad for the industry?
It depends whose side you are on, and the honest answer is "both". For players it is a privacy win: less surveillance, a right to erasure, transparency about collection (many consider it long overdue). For F2P businesses it was a painful blow to measurement and UA, especially for the small, plus higher traffic costs and more uncertainty. Structurally it shifted power toward platforms with first-party data (Apple/Google) and hurt ad intermediaries. There is no clean "good/bad": it is a redistribution between user privacy, studio profitability and platform power. Regulators aimed at excessive tracking and incidentally strengthened the giants. Your verdict depends on what you weigh — user rights, indie survival or platform competition.
Further reading