ARTICLES

The gamification trap: how Łódź wanted to activate residents with data it cannot protect

Author: Maciej Lesiak Published on: words: 4259 minutes read: 20 minutes read

The city commissioned an idea at a hackathon to increase resident engagement in its app. It didn't set any data protection boundaries. The winning project rewards trips, purchases, and presence in specific locations with points, while an AI model tailors daily tasks to the user. The resident would pay with privacy for city discounts. I talk to the person who designed this module.

On August 26, 2026, halfway through the second week of the Oakland trial, Meta reached a settlement with the states that accused it of deliberately designing Facebook and Instagram to addict children. I don’t know anyone who wouldn’t be interested in this. Zuckerberg was supposed to testify but didn’t make it. Up to 17.1 billion dollars, spread over ten years, the claims of 47 states were settled in bulk. The case had been ongoing since 2023, with whistleblower Arturo Béjar testifying among others. Jędrzej Winiecki wrote about it in the piece Lajki za fajki [Likes for smokes] in “Polityka”.

The money is the least interesting part here. With about 60 billion dollars in annual net profit, the installment is less than three percent and is merely a cost of doing business. Just like in the case of Omenah and Brzoska, any costs are acceptable given billions in profits. What is interesting here, however, is what Meta had to promise besides money to avoid public scrutiny of its toxic system: strict time limits in the app, disabling notifications during school hours, a nighttime block, and the end of beautifying filters. The very mechanics of engagement. Not ads, not data, not content. The way the product keeps the user attached to it became the subject of a multi-billion dollar settlement.

I am writing about this because it seems to me that I now see this same mechanic under the coat of arms of Łódź.

Where do we stand on the aggressive processing of residents’ data in city services?

Let’s recap where we are after over a year, for the sake of order, because this is another text in this series that forms a coherent whole. I conducted an audit of the city services and filed a notification with the UODO (Personal Data Protection Office), which has been sitting there since November 6, 2025. Most of the examined domains were sending data to Google and other entities without the user’s consent. On June 30, 2026, Deputy Mayor Tomasz Piotrowski, responding to an interpellation by city councilors, admitted to the disputed parameter and did not rule out the situation I described. On August 12, 2026, Deputy Commissioner for Human Rights (RPO) Stanisław Trociuk sent six questions to the Mayor of Łódź, including questions about the public-private partnership agreement under which the city granted a private entity a concession to build an application, creating a mechanism for monetizing residents’ data in the process, and whether the city had even reported the breach under Article 33 of the GDPR.

Meanwhile, the city has replaced the cookie banners and policies that had hung there for years pretending to be features, but the most important thing is something else. Piotrowski admits to the problem, announces changes, and informs that an external audit is being “considered”. This is beautiful window dressing where the cause and effect have been swapped. To my knowledge, you first do an audit, identify irregularities, point out directions for repair, and only then do you fix things. Here, the deputy mayor first admits the problem exists, announces repairs, and leaves the investigation for the end as an option. On what basis, then, did the city decide on the corrections if not based on an audit? Either someone in the office did a quiet audit and got scared because they knew perfectly well what was wrong before anything was formally investigated, or the corrections are blind and the city itself doesn’t know what it’s fixing. Unfortunately, I don’t see a third option.

Let’s remind ourselves by the way what the previous version of the banner registering consent for data processing operating within city services was. In the BIP (Public Information Bulletin), we had a dummy consent mechanism that did nothing. There was no withdrawal of consent, no consents were processed or recorded as required by the GDPR, so they might as well have displayed a naked lady to click on, and the legal effect would have been identical. Maybe even funnier. This dummy is exactly what they decided to powder up with new solutions.

I also described what “Łódź.pl” really is: a brand under which sits a portal, a mobile app, the Karta Łodzianina (Łódź Resident Card) program, and modules glued to it, namely news, tickets, resident services, and waste management. A simple discount card has quietly morphed into a super-app and information portal, a local monopoly funded by the city budget, which is called a government gazette in the press and criticized by the Commissioner for Human Rights among others. Its task is to aggregate traffic. Is this knowledge used for electoral micro-targeting? I don’t know. A million unique visits, three hundred fifty thousand program participants, a database of 174 thousand email addresses and 170 thousand phone numbers. Detailed information about education, but also knowledge about who does not visit city services and lodz.pl - one could negatively select, for example, people reluctant to the current authorities. That’s why, in my opinion, an audit is rather necessary, along with full transparency about what was going on there. For now, it looks more like panicked cleaning.

What would any marketer do with a surplus of data?

By getting deeper into the ecosystem and tracking all the actions of the UMŁ (Łódź City Hall) on an ongoing basis, I slowly realize why the local government needs its own gazette, a silo aggregating traffic for various queries and the attention of internet users. Over time, however, I started asking myself different questions, no longer as someone writing about city problems, but as a marketer: what would I do with such an excess of data. Such an amount of information is tempting, very tempting. This is golden marketing data, because it doesn’t come from an anonymous cookie, but from a logged-in and verified resident about whom it is known where they live, what they use, and what discounts they are entitled to, along with their entire internet activity history, of course. The answer practically came by itself and is probably a consequence of the development of this designed silo into which residents are pushed. The TEMU model is a natural consequence here.

I described this model in the analysis of the AI-driven marketing of TEMU and SHEIN. In short: recommendation algorithms do not work on small datasets, so first you need to collect a massive amount of them, and the city has built itself a silo where it keeps residents and is most likely looking for ways to collect data on an even larger scale - obviously for the purpose of “improving service” or, if we prefer to package it differently, “satisfaction”, or as was evident from many letters inquiring about this problem, “the city is not a party”… The cheapest way to tighten this screw is to turn the use of the application into a game, training the user with rewards. Points, streaks, rankings, a timer, a wheel of fortune. The European Commission called this forced gamification in TEMU and brought charges against the platform in November 2024. For those who want the details of this mechanic, I refer you to that text, because today we only need one thing: to recognize the pattern. Personally, I see this model under the coat of arms of the city, as the brand I write about. Whether it will be so, we shall see, and I hope I’m wrong.

Hackathon. Towards the TEMU model?

On December 3 and 4, 2025, at the Zatoka Sportu of the Lodz University of Technology, the first edition of the #lodz_hack hackathon took place. Organizer: The FinTech Central Poland Foundation, an environment that, as it writes about itself on its website, was formed in October 2021 on the initiative of the Łódź City Hall. Strategic partnership: The City of Łódź and MakoLab. Nearly 50 participants, 11 teams, 24 hours.

There was only one theme for the edition: the development and improvement of the Karta Łodzianina app. In announcements on kartalodzianina.pl and in the uml.lodz.pl calendar, the task was stated outright. The participant is to design and implement new functionalities that will make the city tool “more friendly, modern, and useful,” and the local community more engaged.

The winning team was GitPushers with the “Moje Osiedle” (My Neighborhood) project: a gamification module, points tied to discounts, user rankings, and reward redemption. An honorable mention from the Łódź ICT Cluster went to the “Nazwa Robocza” team for a student guide with an AI assistant. The summary on the Młodzi w Łodzi portal ends with the sentence that the organizers hope the best solutions will soon expand the portfolio of capabilities of the Karta Łodzianina.

Now let’s read this competition task again, okay? The city, through a foundation it brought to life itself, challenged dozens of programmers to create a mechanism that increases engagement in an app where the logged-in resident is identified by first name, last name, and privileges. Neither in the announcement on kartalodzianina.pl nor in the uml.lodz.pl events calendar is there a word about data minimization, impact assessment, or the legal basis for profiling. I am asking the Łódź City Hall and the FinTech Central Poland Foundation about the competition regulations and the full content of the task in a press inquiry described in the note at the end of the text. The teams were given one goal: more engagement. And they delivered exactly what was asked. From a conversation with one of the participants, it clearly emerges that any element of GDPR or concern for data minimization was not the subject of their considerations; they were given a goal: to increase engagement.

Interview with Kacper from the GitPushers team about the “Moje Osiedle” app

I contacted Kacper Kleczaj from the GitPushers team. I thank him for his written answers for the purpose of this publication and thank him for his trust. I want to state this clearly: this text is not about him or his team. They are young, ambitious people who, in a completely natural way as professionals, want to build their portfolios and get involved in new projects, and glory to the Lodz University of Technology for educating such people. I also support the idea of hackathons; there should be as many of them as possible. I read the answers given as honest and open, even where it would have been easier to evade, and these very places are the most interesting in this whole matter.

I asked what was the diagnosis of the problem that was at the core of their idea.

“The problem really came from life - we ourselves and our friends kept repeating that »there is nothing to do in Łódź«. And if there are any discounts from the card, they are so small that they don’t move anyone. The rest evolved from this for us: people don’t feel they belong anywhere, they know their own city poorly, they don’t engage in its affairs, and money doesn’t go to local, small businesses.”

What exactly would a resident get points for?

“You collect points for normal, everyday things - riding the MPK (public transit), renting a bike, shopping at local partners, visiting interesting places and events, taking a photo in a recommended place. Added to this are daily challenges generated by AI.”

Editorial comment: it’s worth reading this list a second time, not as a catalog of rewards, but as a list of events recorded in a database. Taking public transport. Renting a bike. A transaction at a partner. Presence in a specific place. A photo taken in a specific spot. Each of these events has a timestamp and an assigned user. This is, in a technical sense, a log of the resident’s movement and consumption, updated in real time. For an advertiser, such a collection is worth much more than declarations from a survey, because it allows estimating income, daily routine, and family situation from the behavior itself: the choice between public transit and a bike, the time of travel, the class of commercial partners, and for entrance tickets, even the use of the Large Family Card.

How would the ranking and reward redemption work?

“We made it hybrid. You collect points for yourself, but they also go into your district’s pool. Thanks to this, you unlock some rewards individually, and some go to the whole neighborhood. The redemption is trivial - you scan a code or give your phone number at the checkout.”

Why competition between districts and not an individual goal?

“Competition between districts was a conscious decision, not a coincidence. We wanted people to feel a connection to the place they live - »my neighborhood« appeals to the imagination much more strongly than an individual goal or some general goal for all of Łódź.”

And now the question for which I conducted this conversation. What data would be needed and was the principle of minimization considered?

“We will be honest here - we didn’t touch the issue of data or its minimization at all. A hackathon is too short a format to sit down for such talks. This is something that would only have to be thought through at the stage of real implementation.”

I followed up about privacy by design and GDPR compliance.

“The topic of GDPR didn’t come up for us. But »Moje Osiedle« is a module for the existing Łódź.pl app, not a separate app - and Łódź.pl already has its regulations and data processing rules. So it’s more a matter of adapting the module to what already works in the app, rather than building everything from scratch.”

Editorial comment: This is, in my opinion, the most important sentence in the whole interview. From the perspective of a team at a hackathon, it is completely reasonable. Young people assume that since the city has a working app with regulations and an information clause, everything is legally processed, the compliance layer is on the city’s side and simply exists. Someone checked it and someone is responsible for it.

I asked about abuses and how to avoid inequalities between districts.

Racking up points is difficult because each point is tied to a real event - scanning a ticket, renting a bike, a transaction at a partner. And so that smaller or older districts are not in a losing position from the start, the ranking can be calculated not in total points, but e.g., per resident, or by dividing neighborhoods into leagues with a similar profile.

Editorial comment: any anti-fraud mechanism in public services, if it is not based on cryptography, for example on zero-knowledge proofs, forces the mass logging of real events and creates a surveillance log. Exactly like the Chinese system, i.e., a model of evaluating citizen engagement, and also punishing according to the subtle method of “divide and conquer”.

Let’s note that the resistance of such a system to fraud is a direct function of how deeply it reaches into the user’s real life. The harder the event, the more difficult it is to forge and the more it says about a person. This is not a flaw of the project; it is a feature of any loyalty system based on verifiable behavior.

I also asked how the team would measure whether such a solution actually serves residents, and not just boosts app usage statistics.

We would measure success not by the number of scans, but by the real effect - how many new places people visited, how much money went to local partners, how many went to city events and whether they stay in the app longer, or just dropped in to “hunt for points”.

Editorial comment: this is an answer that does not fit the simple thesis of an engagement machine, and that is why I am quoting it here. The team itself rejects the metric of the number of scans and looks for a measure of effect, not activity. The problem is that all the listed metrics - places visited, money at partners, attendance at events, time in the app - require exactly the same event log as the point system. Even a good intention of measurement leads here to the same database.

I asked about AI separately, because the hackathon strongly emphasized this thread.

“Yes, AI has been with us from the beginning - it arranges daily challenges for a specific user. Naturally, this could be developed further: stronger personalization, analysis of data from districts, catching abuses.”

I asked about the risks directly, giving three examples in the question: exclusion, social pressure, and a feeling of excessive monitoring of activity. The team confirmed all three and added a fourth, which was not in the question:

“You can exclude people without a smartphone or older people who are less familiar with technology. The competition can become tiring and turn into pressure. Some people will feel tracked. And there is a risk that instead of equalizing, we will deepen the differences between districts.”

Editorial comment: a perfectly diagnosed risk of digital exclusion, i.e., that the model of discounts and participation in the city rewards system is restricted to people who have the app. Probably on newer smartphones that comply with store security policies and have the appropriate libraries and security features.

The last question of the second stage concerned a retrospective. What would they change today and what questions about processing residents’ data would they ask themselves now, after everything.

In retrospect, we would do two things differently. Firstly - we would map out the target groups much more thoroughly and choose a form so as not to leave behind people less familiar with technology. Secondly - we would go for even stronger personalization of tasks for a specific person in a given neighborhood.

Editorial comment: the question was the last in a whole series - after data minimization, after privacy by design, after GDPR. It explicitly contained a phrase about processing residents’ data. The answer does not touch upon this thread with a single sentence. The first reflection goes to accessibility for people less familiar with technology, the second to stronger personalization of tasks for a specific person. This is not a reproach to the team, but an observation about what happens to a project that no one set boundaries for.

What after the hackathon? Did anyone from the city reach out?

“After we won, no one reached out to us. And if this were to really go into the card app, a decision from the City would be needed, agreements with operators (MPK, bikes, partners) etc.”

And the last question I had to ask. Did the idea come from the team, or was it suggested from the outside?

“It was our idea.”

No one forced anything on this team. Five people were given the task “increase engagement in the city app”, locked themselves away for a day, and independently recreated the canonical mechanics of AI-driven marketing.

And this is precisely why it is more interesting than any conspiracy. You don’t need to order anyone to do anything; the solutions suggest themselves. All you have to do is provide a mass of data about users, set a goal without boundaries, and the model will write itself. The winning project is completely correct in relation to the competition task. The task was incomplete.

What was missing in all this

The city has an app in which the resident is logged in and verified, sometimes with documents from ZUS (Social Insurance Institution), tax documents, or a certificate of disability. It has a database of addresses and phone numbers and a portal with a million-strong traffic that sells advertising. It has a clause in a 2020 PPP agreement that the private partner uses the User Database for marketing purposes at the request of the Public Entity, i.e., at the request of the city. It has a confirmation from the deputy mayor of sending data to Google without consent, a notification lying in the UODO since November 2025, and questions from the RPO since August 2026.

In this state of mess, which has lasted for years, the city organizes a competition on how to increase engagement in this app by processing residents’ data using AI. The winner is a module rewarding trips, transactions, and presence in places, where an AI model arranges daily tasks for a specific user. To the best of my knowledge, there is not a word about GDPR in the task. After the competition, no one contacts the winners, but the organizer publicly hopes that the best solutions will expand the portfolio of the Karta Łodzianina.

I draw a clear line. “Moje Osiedle” has not been implemented and I have no proof that the city has made a decision to implement it. This is a dangerous direction and a concept from a hackathon. I am writing about it not because it works, but because it shows what the city was looking for and with what data protection framework it released this order into the world.

I wonder what the President of UODO will say to this?

The question remains for the authority. Proceedings in this office drag on for years, everyone knows it, and the President of UODO himself regularly explains this by a lack of staff and an avalanche of complaints.

The President of UODO has known about the case of Łódź services since November 6, 2025; at the beginning of 2026 he announced an audit of BIPs throughout Poland, and in the case of my notification, for over ten months he has not brought about a halt to the defective processing. This was done only by an interpellation of several councilors, after which the City in its response from June 2026 informed that it had not recorded any notifications, so from the perspective of the audited entity, nothing happened during that time that could be recorded. The evidence I requested to secure may during this time be overwritten by cleanup work. PUODO has instruments of action, and some of the allegations I presented with evidence can be verified without reaching for PPP agreements or correspondence with parties.

The same office simultaneously runs an extensive section dedicated to artificial intelligence: webinars “From AI Act to national regulations”, open expert lectures, a subgroup on AI at the Social Team of Experts, speeches at congresses and economic forums, materials on how institutions should use AI in accordance with the law. It’s impressive. One can be impressed. Substantively, I have no objections to these materials and no one is likely to question them. They are needed, just as warnings against glasses with a hidden camera are needed. Both are more pleasant to read about than a consent banner in the BIP.

The juxtaposition, however, is ruthless. The authority very actively trains how to implement AI in accordance with the GDPR. And it very ineffectively enforces the GDPR where the administrator himself admitted the disputed parameter, and the matter concerns hundreds of thousands of people. Education without enforcement is not data protection, it is merely a training offer.

But I have a proposal for the President of the Personal Data Protection Office - here you go, here is a ready-made case for the next webinar. The Łódź City Hall wants to activate residents using the data it aggregates about them, and hook an AI model generating personalized tasks up to it. It does this having behind it a year of denials, confirmed sending of data to Google without consent, a consent mechanism from an abandoned repository from a decade ago, and questions from the Commissioner for Human Rights.

I do not pass judgments and I do not claim that anyone is acting in bad faith here. I claim something worse! No one in this chain had to act in bad faith to create a system that the resident does not control and knows nothing about. All it took was the goal of “greater engagement”, a lack of a legal framework in the task, and a regulator looking the other way pretending the topic is complicated. Simply put, in this city system, probably no one is really thinking about data protection, but precisely about increasing engagement, and this is what is most painful for me.

We should be aware of this before someone announces it as a success of digital transformation and the introduction of AI to offices.

To be continued already on September 9 and September 25… important dates are reserved only for important matters, and I’ve been preparing for this for half a year.


EDITORIAL NOTE. At the same time, at the beginning of the week, I am sending formal press inquiries to the Łódź City Hall and the FinTech Central Poland Foundation. I ask, among other things, whether the principles of Privacy by Design (Art. 25 GDPR) were taken into account in the competition task and whether the city plans to implement the module and has previously conducted a Data Protection Impact Assessment (Art. 35 GDPR). I am waiting for answers. After the deadline expires, I will publish the full content of the questions along with the institutions’ positions or information about their absence.


Sources

  • Jędrzej Winiecki, Lajki za fajki [Likes for smokes], “Tygodnik Polityka”
  • Meta settlement, 26.08.2026, statement of the Attorney General of California and AP, NPR, and CNBC reports from the Oakland trial
  • FinTech Central Poland, About us, fintechcentral.pl/o-nas/
  • FCP Hackathon: Łódź_Hack, Młodzi w Łodzi, mlodziwlodzi.pl/fcp-hackathon-lodz_hack/
  • Announcement of the hackathon on kartalodzianina.pl and in the uml.lodz.pl events calendar
  • AI-driven marketing, e-commerce revolution
  • European Commission and the CPC network, charges against TEMU, November 2024
  • UODO, Artificial Intelligence, uodo.gov.pl/pl/p/sztuczna-inteligencja
  • Own interview with Kacper Kleczaj (GitPushers), correspondence from June and August 2026
Maciej Lesiak

Amplify the Signal

Best support is sharing articles and tagging dadalo.pl on social media.