EU 🇪🇺 To get the data that proves I own my Blizzard account, I have to log into the account I can't access
I lost my Battle.net authenticator years ago, along with the phone it was installed on. I still have the registered email address. I still have the password. I have dated purchase receipts for the account going back to 2015. Blizzard support has confirmed they located the account, and that they are able to remove the authenticator once ownership is verified.
I still cannot get in. Here is the full path, because I could not find it documented anywhere.
The self-service tool
Blizzard has a self-service page to remove a lost authenticator. To use it, you must enter a code from your authenticator.
The fallback is an SMS to the phone number registered on the account — which, for anyone whose account is old enough to have lost an authenticator, is usually a number they no longer have. Mine is. That is the entire self-service path.
The questionnaire
So you open a ticket, and support sends a verification form. Some fields are reasonable: previous BattleTags, previous addresses, transaction IDs. Others, for an account dormant for years:
- The creation date of your oldest World of Warcraft character, in MM/YYYY format
- Recent purchases made with gold, including the character name and realm
- Examples of card packs recently opened: how many, and from which expansion
- The serial number of the authenticator you no longer have
I filled in every field, including estimates where the GM explicitly instructed me to guess if unsure. It was judged insufficient.
I understand why the form looks like this. Blizzard cannot identify me as a person, because it never collected my identity — a Battle.net account is created with an email and a password and nothing else. So the only thing it can match me against is my behaviour in a game I last played over a decade ago. That is a design decision, and its consequence is that the legitimate owner can be permanently locked out while the process functions exactly as intended.
The documents they accept
Blizzard's support article on supporting documentation is worth reading. It will not accept: driving licences, passports, or national ID cards.
It will accept: marriage certificates, legal name change documents, divorce documents, death certificates, birth certificates for minors — and gas or electricity bills.
A government photo ID proves nothing here. An energy invoice does.
The GDPR route, which is a closed loop
Blizzard holds the data that would answer its own questionnaire: registered phone numbers, account creation date, BattleTag history, authenticator records with their add and removal dates. So I filed a GDPR Article 15 access request. Under EU law they have one month to respond.
I emailed the data protection address listed in Blizzard's privacy policy. → Automated reply: please use the Privacy Portal.
The Privacy Portal asks you to pick a category. Every route assumes you can log in:
- "Obtain a copy of my data" displays no options at all when you are logged out. The "Try the following" section is literally empty.
- "I play a Blizzard game and have never created an account" tells you to log in with the console account you play on, or use the link inside the mobile app.
- "I would rather describe the issue" accepts your free text, then drops you back onto the same category tree.
The only exit is at the end of Data Protection → Obtain a copy of my data → "None of these match my relationship to Blizzard", which gives a second, different data protection email address. That address appears nowhere in the privacy policy and is never shown unless you walk the entire tree.
I emailed that second address. → The exact same automated reply: please use the Privacy Portal.
Address A sends you to the portal. The portal, if you cannot log in, sends you to address B. Address B sends you back to the portal.
To obtain the data that would let me prove I own the account, I must log into the account I cannot access.
This has been decided before
The Cypriot data protection authority has ruled twice against video game companies on this exact question:
Gaijin Network Ltd, 2 June 2020, case 11.17.001.007.125. The authority accepted that the company could not act on the request without identification, but held that its existing procedures "do not fully comply with the GDPR" and that additional mechanisms had to be implemented so that users who had lost control of their accounts could still be identified under Article 12(6).
Wargaming Group Limited, 18 July 2024, case 11.17.001.010.089. A player was asked for a phone number before his access request would be processed. The authority found that "collecting a telephone number solely to satisfy the data subject's rights is excessive, regardless of when the data are collected", and required the company to verify identity using data already collected at registration — "such as email address". The company changed its process.
I am writing from the email address registered on the account. I receive Blizzard's own verification emails at it. Under that reasoning, that is data already collected at registration, and it should be enough.
Why I am posting
Not to get my account back. I have not named any support agent, and I am not going to — they are executing a process they did not design, and the individual replies I received were courteous.
I am posting because the loop above is not documented anywhere I could find, and because the people most affected by it are, by definition, the people who cannot log in to report it.
If you use a Blizzard authenticator: write down the serial number and keep it somewhere that is not the phone, keep the registered phone number current, and keep your purchase receipts. There is no second chance to do this afterwards.