Skip to content
iGaming Times

Independent industry intelligence in your inbox. Unsubscribe any time - every newsletter carries a one-click link.

Lesson 3 of 7 · 15 min

Targeting, Suppression and Data

Enforcement is moving from what an ad said to who saw it. The suppression failures that keep recurring, why lookalike audiences are a problem, and what actually evidences the control.

In this lesson

  • Identify the four audiences that must be excluded and the systems each exclusion depends on
  • Diagnose the recurring suppression failures, from list-level checks to migration re-imports
  • Assess lookalike and retargeted audiences for the risks the operator cannot see
  • Evidence targeting control with the four records a regulator will ask for

The shift from what to who

Gambling advertising regulation began as a set of rules about content. The growth area is targeting: who the advertisement reached, who it should not have reached, and whether the operator can evidence the difference.

That shift moves the compliance burden from the people who make creative to the people who build audiences, and those teams are generally less prepared for it. A creative review will never catch a lookalike audience that reached self-excluded customers.

The audiences that must be excluded

Four categories recur across frameworks, in roughly descending order of how universally they apply.

People below the legal age. An absolute requirement everywhere. It applies to direct marketing, to paid media audience construction, and in several frameworks to the placement of advertising in media with a significant under-age audience.

Self-excluded customers. Where a customer has self-excluded, marketing must stop, and where a national register exists the obligation extends to anyone on it, not only the operator's own excluders. This is the single most common technical failure in the whole subject.

Customers displaying risk indicators. An increasing number of frameworks require marketing suppression for customers the operator's own systems have flagged. This is harder than it sounds because it requires the risk system and the marketing system to be joined, and in many operators they are not.

Customers who have opted out. Ordinary marketing preference law, which in most jurisdictions requires consent for electronic direct marketing and an unambiguous opt-out route.

Suppression that survives a system boundary

Suppression fails in predictable places, and every one of them has been a published finding somewhere.

Suppression applied to a list rather than at the point of send. A list is a snapshot. If a customer self-excludes after the list was built and before the campaign goes out, a list-level suppression misses them. The fix is to check status at dispatch.

Channel gaps. Email suppressed, push notification not. In-app messaging treated as product communication rather than marketing. SMS handled by a separate vendor with its own list.

Brand and platform gaps. A customer excluded on one brand still marketed by a sister brand in the same group. This is the group identity resolution problem in another costume, and it is entirely within the operator's own control.

Third-party lists. Audiences uploaded to an advertising platform months ago and never refreshed. A customer who self-excluded last week is still in a custom audience sitting on someone else's server.

Migration and re-import. A platform change re-imports a segment from an older source and resurrects suppressed contacts. This is the failure that catches operators who had it right, and it is why testing has to be repeated after every platform change rather than done once.

The reactivation campaign. A dormant-customer campaign that pulls from a historical table rather than the live customer record. Dormant and excluded look identical in a poorly built query, and the excluded population is disproportionately represented among the dormant.

The control that catches all of these is the same: a seeded test account taken through exclusion and then monitored across every channel and every brand, repeated after every material system change. It takes a day to set up and it is the highest-value test in marketing compliance.

Lookalike and modelled audiences

Modelled audiences are where targeting compliance gets genuinely difficult, because the operator does not choose the individuals.

A lookalike audience is built by giving a platform a seed list and asking it to find similar people. Two problems follow directly.

You cannot exclude who you cannot see. If the platform builds an audience of people resembling your best customers, and some of those people are self-excluded elsewhere or below the legal age, you have no visibility and no suppression route beyond whatever the platform offers.

The seed list determines what is amplified. A lookalike built from your highest-spending customers is, definitionally, a model of the characteristics of heavy gambling. Whether that amounts to targeting vulnerability is a live regulatory question in several markets, and the honest position is that an operator using such a model should be able to explain what it is optimising for.

The practical mitigations: build seed lists from a broad customer base rather than from the top spenders, apply every available platform-side exclusion, verify the platform's own age-gating controls rather than assuming them, and document the reasoning. The documentation is not bureaucracy; it is the difference between a defensible practice and an unexplained one.

Retargeting and frequency

Retargeting follows a user who visited but did not convert. Two compliance dimensions apply.

Who is in the pool. A visitor who did not register was never identified, so you do not know their age or their exclusion status. Age-gating the site before any pixel fires is the control, and it is frequently not implemented because it costs conversion.

How often they are reached. Repeated prompting engages the undue-pressure rules, and frequency capping is the control. A retargeting campaign with no frequency cap, following a non-converting visitor across the internet for weeks, is the pattern most likely to generate a complaint.

Consent, lawful basis and data protection

Direct marketing sits on data protection law as well as gambling rules, and the two interact.

Electronic direct marketing generally requires consent, with a narrow exception in several jurisdictions for existing customers and similar products, subject to an opt-out having been offered at collection.

Consent has to be specific and evidenced. A pre-ticked box is not consent in most frameworks, and neither is a bundled permission covering everything. The operator must be able to show what the customer agreed to and when.

Opt-out must be honoured promptly and across channels. An opt-out from email that leaves SMS running is a failure customers notice and complain about.

Profiling for marketing engages additional obligations in several regimes, including transparency about the logic involved.

The conflict worth flagging: gambling record-keeping requirements can require retention of customer data for years, while data protection requires deletion when the purpose ends. The resolution is a documented lawful basis and a retention schedule that distinguishes regulatory retention from marketing use, not a choice between the two. A customer can be retained for gambling record purposes and simultaneously removed from every marketing audience, and that is the correct configuration.

Evidencing targeting

The question a regulator asks is not whether you intended to exclude someone. It is whether you can show that you did.

Four records make that answer possible: the audience definition for each campaign, including the exclusions applied; the suppression check performed at dispatch, with a timestamp; the platform-side settings used for paid media, including age and audience restrictions; and the results of the seeded exclusion tests, with dates.

An operator holding those four can demonstrate the control. One holding a policy document stating that suppression is applied cannot.

Key terms

Suppression at point of send
Checking exclusion status at dispatch rather than when the audience list was built, so a customer who excluded in between is not reached.
Lookalike audience
An audience a platform builds by finding people resembling a seed list. The operator cannot see the individuals, so cannot suppress them directly.
Seeded exclusion test
A controlled account taken through self-exclusion and then monitored across every channel and brand to prove marketing actually stopped.
Migration re-import
A platform change pulling a segment from an older source and resurrecting suppressed contacts. The failure that catches operators who had it right.
Regulatory retention versus marketing use
The resolution to the conflict between gambling record-keeping and data protection deletion: a customer can be retained for record purposes and removed from every marketing audience.

Key takeaways

  • Suppression applied to a list is a snapshot; it must be checked at the point of send, on every channel and every brand.
  • Custom audiences uploaded to an ad platform months ago still contain people who have since self-excluded.
  • A lookalike built from your highest-spending customers is, definitionally, a model of the characteristics of heavy gambling.
  • Age-gate the site before any pixel fires, or your retargeting pool contains people whose age and exclusion status you do not know.
  • A seeded test account taken through exclusion and monitored across every channel, repeated after every system change, is the highest-value test in marketing compliance.

Check your understanding

3 questions · answer them all, then check.

  1. 1. Which suppression design actually protects a customer who self-excludes on a Tuesday from a campaign built the previous Friday?

  2. 2. Why is a lookalike audience built from an operator’s highest-spending customers a regulatory concern?

  3. 3. A regulator asks whether excluded customers were reached by a campaign. What demonstrates the control?

Sign in to track your progress through the course.

Cookie Preferences

Choose which cookies you want to accept. Essential cookies are required for the website to function properly.

Required

Necessary for the website to function. Cannot be disabled.

Help us understand how visitors interact with our website.

Used to deliver relevant advertisements and track ad performance.

Remember your preferences and settings for a better experience.

Targeting, Suppression and Data - Learning hub | iGaming Times