Summary
- European and UK digital regulation is now reshaping video game distribution, payments, advertising, moderation, and age assurance at the same time.
- The DMA and DSA change how game publishers reach players, while GDPR and consumer protection rules sharpen scrutiny of data, targeting, and monetisation.
- Smaller studios may face heavier compliance pressure, although developers that adapt quickly could gain more control over payments, storefronts, and player relationships.
By Chris Hewish, President of Xsolla
The global video game industry, once largely unregulated, now finds itself at the centre of sweeping digital legislation. Across Europe, a cluster of laws, the European Union’s Digital Markets Act (DMA) and Digital Services Act (DSA), GDPR, consumer protection rules, new age verification requirements, and the UK’s Online Safety Act, are converging on the industry at once, reshaping how games are built, marketed, and monetised.
The Digital Markets Act: Rebalancing distribution and payments
Apple and Google have long shaped mobile gaming through app store policy. The DMA changes this by designating certain platforms as “gatekeepers” and forcing them to allow alternative app stores and payment systems and to let developers advertise offers available elsewhere. That opens the door for publishers to avoid a meaningful share of app store fees by running their own payment methods, and has fuelled renewed interest in web shops, storefronts outside app ecosystems where players buy currency or items directly. Within the EU, gatekeepers must now permit links to these external offers, giving developers more control over pricing and the purchase experience. Compliance isn’t simple: developers must navigate obligations around app updates, data portability, and payment processing, and platform-specific technical constraints still shape how smoothly external payments actually work.
The Digital Services Act: Content, conduct, and accountability
Where the DMA reshapes market structure, the DSA governs how services handle content and user conduct, and it applies directly to games with social features. Titles with chat, user-generated content, marketplaces, or avatars fall within its scope depending on their size and function. The DSA requires clearer terms of service, accessible reporting mechanisms, moderation transparency, and, for the largest platforms, risk assessments covering the protection of minors. It also restricts targeted advertising, including limits on advertising to children. Studios monetising through in-game ads or social features must rethink moderation workflows and how ads are served to younger players.
GDPR: The data backbone
GDPR predates the newer laws but remains foundational. Games collect data on play behaviour, purchases, and, increasingly, age-estimation signals used for verification. GDPR demands a lawful basis, data minimisation, clear consent, and extra protection for children’s data. As age verification spreads across both the DMA/DSA framework and the UK’s Online Safety Act, GDPR compliance becomes more consequential, not less, as techniques like facial age estimation introduce sensitive biometric data that regulators scrutinise closely. Getting age verification right on safety grounds but wrong on data protection can still mean significant fines.
Consumer protection and monetisation scrutiny
General EU consumer protection law is increasingly applied to monetisation design. Loot boxes, limited-time offers, and premium currencies that obscure real cost have drawn attention from consumer authorities on the grounds that they may mislead players or exploit behavioural biases, concerns sharpened where younger players are involved. Requirements on clear pricing, withdrawal rights for digital purchases, and transparent currency conversion are pushing developers toward more legible monetisation, even without a law that names loot boxes explicitly.
The UK’s Online Safety Act: Safety and access
The UK’s Online Safety Act fundamentally recalibrates how games operate, particularly where under-18s are concerned. It requires services that likely reach children to implement proportionate age verification, content filtering, and moderation, affecting multiplayer chat, user-generated content, and avatars. Games can no longer be safe only “at launch”: studios must run formal risk assessments and publish clear reporting mechanisms. Ofcom holds substantial powers, including fines tied to global revenue, and in serious cases involving harm to children, executives can face personal legal exposure. Some argue this will professionalise gaming environments over time; in the short term, it’s creating real uncertainty for studios operating across both UK and EU frameworks that don’t always align.
A landscape in flux
Together, these laws signal that gaming’s unregulated era is over. Compliance will be hard for smaller studios without dedicated legal resources, while others, especially those quick to adapt payments, data handling, and age assurance, may find a more open, competitive market ahead. Regulation can no longer be an afterthought: how games are sold, how player data is handled, and how younger players are protected now matter as much as how the games are played.





