Launch Crisis · Legal & Regulatory Analysis
CLICK ANYWHERE TO BEGIN
Wizard Games, Inc. · Legal & Regulatory Crisis Analysis
Click each node to explore the escalation chain
Users performed full body scans in minimal clothing. These can uniquely identify individuals and recreate their likeness with high accuracy.
High resolution video captured during the scanning process. May contain intimate imagery given the minimal clothing requirement.
Voice models generated from user speech samples. Can synthesize new dialogue in the user voice, creating deepfake potential.
ModuForm extracted additional physical attributes from scan data for future features. Nature and scope of these inferences remains unclear.
Camera permissions granted under the assumption of local processing. Actual transmission to third party servers was not clearly disclosed.
Nearly all data categories qualify as biometric or sensitive under GDPR Article 9. Processing required explicit consent that was never properly obtained. ModuForm additional analysis of physical attributes compounds the violation.
The current analysis frames this situation as a breach of an otherwise functional system. That framing understates the problem.
Users consented to local, on device processing only. The moment Wizard routed their biometric data to ModuForm's servers in France, the company was operating entirely outside the scope of that consent. Under GDPR Articles 6 and 9, there was no valid lawful basis for this processing from day one.
This is not a case where a compliant system suffered a security failure. Wizard never had legal authority to process the data in the manner it chose. That distinction matters in three ways:
Regulatory fines increase because the violation is systemic, not incident based
The breach notification analysis becomes more urgent because the underlying data was collected unlawfully
The talent and consumer exposure increases because consent was never validly obtained for the actual processing that occurred
The moment TechCrunch surfaced the internal Slack message, Wizard's legal team became obligated to issue a litigation hold across all internal communications platforms, including Slack, email, and any messaging tools. ModuForm must be instructed to do the same for all correspondence related to the Wizard relationship.
If Slack messages are deleted through automatic retention policies before the hold is in place, that constitutes spoliation of evidence, which creates additional legal exposure and adverse inference risks in any future litigation.
"Fully secure, processed locally on your device, no images, videos, or voice recordings are stored or transmitted."
WIZARD GAMES MARKETING MATERIALS
Select each option to visualize its risk profile across four dimensions
Demonstrates good faith. May satisfy GDPR 72hr requirement. Controls narrative before TechCrunch publishes.
May overstate risk if no data was actually exfiltrated. Jeopardizes Sunday launch. Sponsorship fallout.
Partial Disclosure with Feature Pause offers the strongest balance of regulatory compliance, reputational protection, and commercial viability.
Engage external forensic investigators to assess ModuForm breach scope immediately
Preserve all internal communications and ModuForm correspondence for legal hold
Disable the avatar scanning feature in the beta build pending investigation
Engage outside counsel specializing in data privacy and crisis response
Notify affected beta participants individually, prioritizing high profile talent
Brief Zendaya and Cavill representatives with specifics and protective measures
Prepare holding statement for TechCrunch acknowledging the investigation
Brief Netflix, sponsors, and streaming partners on modified launch plans
File preliminary GDPR breach notification with relevant supervisory authority
Prepare state level notifications under CCPA and applicable biometric laws
Issue public statement acknowledging the incident and corrective measures
Announce that Sunday event will proceed with the scanning feature disabled
Complete forensic investigation and issue comprehensive breach report
Terminate or renegotiate ModuForm agreement with proper data processing terms
Implement true on device processing before re enabling the avatar feature
Commission independent security audit and publish results transparently
The question is not whether to disclose but when and how. Delayed disclosure is the highest risk path given the 48 hour threat timeline, TechCrunch inquiry, and GDPR notification requirements. A controlled, proactive partial disclosure with the scanning feature paused preserves the launch event, demonstrates good faith to regulators, and allows Wizard to shape the narrative rather than react to it.
If the threatened data release occurs before Wizard's planned disclosure:
The phased timeline collapses. Wizard must issue an immediate public statement within hours, not days.
The "partial disclosure" option is no longer available. Full disclosure becomes the only defensible path.
Talent notifications must happen before the data becomes public. If Zendaya or Cavill learn about their compromised scans from a news article rather than from Wizard directly, the reputational and legal fallout escalates dramatically.
The Sunday launch event must be reassessed in real time based on the scope and nature of the released data.
This contingency should be treated as a live possibility, not a hypothetical, given the 48 hour threat window.