On this page
For an in-scope online game service, the NPPA’s 2021 notice reaches all the way into runtime architecture. Real-name account state and permitted service times affect whether the server allows play, what the client displays, how support resolves disputes, and what evidence the operator keeps.
Determine the current rules, scope, operator, implementation responsibilities, and later guidance for the actual mainland service. Do not assume the same architecture applies merely because an international build supports Simplified Chinese.
Turn the time rule into an authoritative server path
The notice says online-game companies may provide one hour of service to minors from 20:00 to 21:00 on Fridays, Saturdays, Sundays, and statutory holidays, and not at other times. It requires real-name registration and login using valid identity information and connection to the NPPA’s real-name verification system for anti-addiction work. It states that no service, including a guest-experience mode, may be provided to users who are not registered and logged in with real identity information. It defines minors as citizens under 18 and includes platforms providing online-game services in the term “online-game companies.”
Engineering therefore needs an authoritative decision path through account, identity, time, session, and service systems.
Design the unavailable path first
Ask the qualified mainland operator to draw the live flow with engineering:
- where identity is collected and who processes it;
- how verification state enters the game account;
- which server is authoritative for eligibility and time;
- how statutory holidays and authoritative clocks are maintained;
- what happens before, during, and at the end of a permitted session;
- how reconnects, suspended clients, offline modes, queues, and clock manipulation behave;
- what the player sees when verification is unavailable or disputed;
- how support handles false matches, recovery, guardians, and escalation;
- what logs demonstrate correct behavior without retaining unnecessary identity data.
Write tests around boundaries, not just the happy path. Exercise a session approaching the end of a window, reconnect after forced exit, stale client state, verification timeout, account switching, maintenance, network loss, and update rollback. The player message should be clear, localized, and consistent with support.
Track the partner SDK as a versioned dependency with an owner, test environment, failure policy, privacy review, and incident contact. Make the team answer what the game does when the SDK times out; “the SDK handles it” leaves that path undefined.
Apply the architecture only to the service in scope
The operator and studio still have to design the system, assign each component to the correct contracting party, and use current integration documentation. The notice covers only part of the publishing, data, cybersecurity, payment, content, and platform picture. Later rules or technical requirements may also matter.
Apply this flow only where the route and qualified review require it. Forcing every Chinese-language player in a worldwide Steam build through mainland identity controls can create new product and privacy risks. Formal mainland operation and international-storefront visibility remain different routes.
Put engineering in the official-source review
Read the NPPA minor-protection notice in full. Ask the operator and qualified advisers to map every applicable sentence to a service, owner, test, player message, and incident response. If the requirement changes runtime behavior, engineering must review the mapping.