What began as entertainment has evolved into infrastructure. Consider applications in robotics (such as delivery robots), AR navigation and smart cities. The way data is created is also shifting: it increasingly arises outside the traditional organisational context.
The key question is no longer just which data your organisation collects, but also:
- What latent value might already exist within my data?
- How transparent am I about this vis-à-vis users and stakeholders?
- Is my data use still compatible with the original purpose for which it was collected?
On paper, much appears to be in order. Users provide consent for data processing through general terms and opt-in functionalities (such as scanning PokéStops).
Legally, however, the picture is more nuanced. Under the GDPR, valid consent must be freely given, specific, informed and unambiguous, and based on a clear, active indication of the user’s wishes.
In addition:
- Data reuse for new purposes (such as AI training) must be compatible with the original purpose;
- Transparency towards users is essential.
In practice, this is where friction arises. While scanning may technically qualify as an opt-in mechanism, many users will not have anticipated that their contribution could become part of a global AI infrastructure.
Three key lessons from the Pokémon GO case
1. Data has a second life
Data that is operational today may become strategic tomorrow. This requires boards to take responsibility for how data is used—not only within its original context, but also beyond it.
2. Reputational risk outweighs legal risk
The LinkedIn hype around Pokémon GO demonstrates how quickly perception can shift—from innovation to “users as the product”. What is legally defensible is not automatically socially acceptable. This calls for deliberate steering on both reputation and data use.
3. AI requires explainable data use
Organisations must be able to clearly explain:
- which data is used in AI systems,
- for what purpose (including when that purpose evolves), and
- how that data contributes to the functioning and outcomes of the system.
This aligns with the AI Act’s strong emphasis on transparency and explainability: organisations must, for example, inform users when they interact with AI and disclose the use of AI-generated content.
In conclusion
In a world where almost every interaction generates data, not only the role of the organisation changes, but also that of its leadership. The focus shifts from facilitating data collection to taking responsibility for how that data fuels future AI systems. This requires more than compliance—it requires control. Control over what you collect, why you collect it, and—crucially—how you can explain it.
Have questions about this topic? Please feel free to contact Reny Stark, Partner Technology & Data, at Lexence.
Roadmap
Would you like to gain a clear overview of the bigger picture and determine which digital obligations truly matter for your organisation?
Download the Digital Compliance Roadmap 2026 below and discover where to focus your strategic efforts today.
Sources