Don’t Feed the Algorithm | NZGDC 2025

Don’t Feed the Algorithm | NZGDC 2025

🎙 Melanie Langlotz and Tyrone Mills 👥 1K 📅 October 9, 2025 ⏱ 30 min 👁 48 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

VRARprivacybiometricGDPRdata breachinsuranceethical game design

Summary

In this NZGDC 2025 talk, Melanie Langlotz and Tyrone Mills from Geo AR Games discuss the hidden privacy and security risks of VR and AR technologies. They highlight that biometric data, such as eye tracking, facial expressions, and body movements, is now a valuable currency for identity theft and profiling. They review major headsets (Meta Quest, Apple Vision Pro, HTC Vive, Pico) and the data they collect, noting that GDPR classifies this as biometric information. They cite recent data breaches, including the ‘Inception attack’ on Apple Vision Pro, and emphasize the 72-hour breach notification rule and potential fines. They provide practical advice for developers: conduct risk assessments, document data collection, only collect necessary data, implement user consent controls, and consider insurance implications. They stress the importance of ethical game design, especially for vulnerable audiences, and recommend avoiding North American release to reduce insurance costs. The talk concludes with a call for New Zealand to adopt stronger privacy standards similar to GDPR.

161 words

Critical Evaluation

Value of the Information & Strength of the Argument

The talk offers valuable, practical insights for game developers and studios, especially those new to VR/AR. It raises awareness about the often-overlooked privacy risks of biometric data collection and provides actionable steps for compliance and risk mitigation. The argumentation is persuasive, using real-world examples like data breaches and insurance costs to underscore the seriousness of the issue. However, some claims lack detailed evidence, and the presentation is more of an expert opinion than a rigorous scientific analysis.

Scientific Rigor, Source Quality, Title Accuracy

The speakers cite specific regulations (GDPR, COPPA) and data breaches (e.g., Meta fines, Inception attack) but do not provide detailed references. The title accurately reflects the content, focusing on the risks of feeding data to algorithms. The talk is well-structured and practical, though it could benefit from more formal citations.

142 words

Title / Content Match

The title is catchy and relevant, as the talk focuses on privacy risks and ethical considerations in immersive tech, warning against feeding data to algorithms.

Quality & Reliability

7/10

The talk provides a practical overview of privacy and security risks in VR/AR, based on the speakers' industry experience and research. It cites specific data breaches and regulations, but lacks detailed citations and some claims are anecdotal.

Key Moments

Cited Sources

  • GDPR — Referenced as the main privacy regulation for biometric data.
  • COPPA — Mentioned as a key regulation for kids' games.

Concurring Sources

  • GDPR — The talk's emphasis on GDPR aligns with its status as the strictest privacy regulation.
  • COPPA — The talk's mention of COPPA is consistent with its importance for children's data protection.

Contribution & Novelties

The talk provides a practical, developer-focused perspective on privacy in VR/AR, highlighting the often-overlooked risks of biometric data collection and offering concrete steps for compliance and risk management. It bridges the gap between technical implementation and legal/insurance considerations, making it valuable for studios.

Pour aller plus loin :

  • GDPR — The core regulation for data protection in Europe, covering biometric data.
  • COPPA — US regulation for children’s online privacy, relevant for kids’ games.
  • Inception Attack — A report on the Inception attack on Apple Vision Pro.
  • Meta GDPR fine — News article about Meta’s GDPR fine.
  • Eye tracking password inference — Study on how eye tracking can infer passwords.

109 words

Radar Profile

The radar profile shows high scores in information quantity and quality, with moderate technical depth and reliability. This indicates a well-rounded talk that is informative and practical, though not highly technical or deeply sourced.

Reliability 7/10