Compliance
GDPR
Definition
The EU's General Data Protection Regulation, applied since May 2018 and retained in UK law as the UK GDPR, which governs how personal data is collected, used, shared and kept. For gambling operators and affiliates it regulates tracking, profiling, marketing consent and data sharing.
Key takeaways
- GDPR governs how gambling operators and affiliates collect, use, share and keep personal data; every processing activity needs a lawful basis.
- Anti-money-laundering and safer-gambling duties require more data than minimisation suggests; they are recognised legal obligations.
- Marketing needs consent or legitimate interest plus the e-privacy rules; affiliate tracking is profiling that needs a basis.
- Data-protection authorities enforce separately from gambling regulators, with turnover-based fines.
Why it matters
Online gambling is a data business, and GDPR is the law on the data. An operator holds identity documents, financial records, betting histories, behavioural profiles and health-adjacent inferences (markers of harm) on every customer, shares slices of that data with payment providers, identity vendors, game studios, affiliates and regulators, and markets to customers on the basis of what it knows. Every one of those activities needs a lawful basis, a purpose, a retention period and a privacy notice under GDPR, and the regulation's requirements for consent, transparency, data minimisation, security and individual rights sit alongside the gambling regulator's rules and sometimes pull against them.
The tensions are specific. Anti-money-laundering and safer-gambling rules require operators to collect and retain more data (source of funds, affordability, behavioural monitoring) than data minimisation would suggest, and the reconciliation is that those are legal obligations and legitimate interests that GDPR recognises. Marketing requires consent or a legitimate-interest basis, and the e-privacy rules on cookies and direct marketing sit on top; Britain's opt-in-by-product-and-channel rule for gambling marketing is a gambling regulation implemented through GDPR-style consent. Affiliates track people across sites, which is profiling that needs a basis and disclosure. Sharing customer-level data with affiliates, or between operators for a single customer view, needs an agreement and a basis, and operators have moved toward aggregated and pseudonymised sharing for exactly that reason.
Enforcement comes from data-protection authorities, separately from gambling regulators, with fines calculated on global turnover; gambling operators have been fined for retention, security and marketing failures. Data protection is therefore a compliance function in its own right within every operator and larger affiliate, with a data protection officer, a record of processing and impact assessments for the profiling that the business runs on.
Sources
Frequently asked questions
Does GDPR apply to gambling operators outside the EU?
Yes, if they offer services to people in the EU or monitor their behaviour, regardless of where the operator is established. British operators are subject to the retained UK version.
Can an operator share customer data with affiliates?
Only with a lawful basis, a data-sharing agreement and disclosure to the customer, and only what is necessary. Most operators share aggregate or pseudonymised event data with affiliates rather than customer-level records.
How does GDPR interact with responsible-gambling monitoring?
Monitoring for markers of harm is profiling, which GDPR regulates, but it is carried out to meet a legal obligation under gambling regulation, which is a recognised basis. Operators document it in an impact assessment.