DATA PROTECTION IMPACT ASSESSMENT (DPIA) — MeyerLive3D
Version 1.1 — Effective 4 June 2026 (last updated 26 June 2026)
Project: MeyerLive3D – Real-time Video/Audio Relay
Data Controller: Owner of ocimvm.com
1. DESCRIPTION OF PROCESSING
The application facilitates a multiplayer card/dice game. Users may enable their camera and microphone to engage with other players.
- Nature of data: Live video/audio streams (temporary), IP addresses (for connection), and Boolean flags indicating camera/mic status.
- Scope: Real-time relay via LiveKit.
- Context: Web-based game, high frequency of sessions, global user base.
2. ASSESSMENT OF NECESSITY AND PROPORTIONALITY
- Necessity: Real-time video/audio is central to the user experience (social interaction).
- Proportionality: We limit processing to relay only. We do not perform analysis, do not record, and do not store streams. This is the minimum processing required to provide the requested service.
3. RISK ASSESSMENT AND SAFEGUARDS
a) Unauthorized interception of video/audio during transit.
Impact: High
Mitigation: End-to-end/transport security — all data is encrypted in transit (TLS/DTLS).
b) Data leakage due to server-side recording.
Impact: High
Mitigation: Hard-coded policy — the system is architected with no storage/recording capabilities at the backend/relay level.
c) Unintended exposure (user error, e.g., leaving camera on).
Impact: Medium
Mitigation: UI indicators — the app provides clear, persistent visual UI cues when the camera/mic is active.
d) External exploitation of the relay server.
Impact: High
Mitigation: Processor vetting — using a dedicated, enterprise-grade relay provider (LiveKit) that adheres to strict security protocols.
4. TECHNICAL ARCHITECTURE
The data flow is designed so that privacy safeguards are applied at every stage: video/audio streams pass directly between the user's browser and the LiveKit relay, with no recording, storage, or analysis performed by the backend at any point.
5. SUMMARY OF SAFEGUARDS
- Encryption: All communication channels between the user's browser and the relay server are encrypted using standard web protocols.
- Data minimization: We record only a boolean flag (camera on/off) for abuse monitoring; no pixel or sound data is ever persisted.
- Anonymization: Any metadata associated with the relay is purged immediately upon session termination.
- Third-party oversight: We are bound by LiveKit's Data Processing Agreement (incorporated into LiveKit's Terms of Service), which prohibits them from accessing or recording our users' traffic for their own purposes.
6. CONCLUSION
The processing of real-time video/audio data in MeyerLive3D is low risk to the rights and freedoms of individuals because:
1. There is no storage of personal biometric or audio data.
2. Technical measures (encryption) are implemented according to industry best practices.
3. The controller has transparent policies and in-app controls for the user.
Decision: The processing is compliant with GDPR requirements. No further high-risk mitigations are deemed necessary at this time.