The Dutch Regulator Acts After a Broadcaster Walked In on a Fake ID
By Antonina Tupikova · Founder, iGaming Times2 min read
PowNed sent someone registered on Cruks into gaming venues using another person's identification, and got in. One of the three venues under scrutiny is a state-owned Holland Casino site in Eindhoven.
- The Kansspelautoriteit will take action against gaming halls and casinos examined by the Dutch broadcaster PowNed, after the investigation showed Cruks checks being bypassed
- Cruks is the Netherlands' central self-exclusion register, and the investigation demonstrated that another person's identification was enough to get past the check at certain venues
- Three venues are under scrutiny, one of them a site of the state-owned Holland Casino in Eindhoven
- The regulator said it "should not have happened that someone registered in Cruks enters an arcade using another person's identification", adding that venues "are required to carry out thorough checks, and the KSA monitors this"
- Separately, the KSA has said its most urgent request is a change in the law allowing it to create false identities in order to test whether operators are complying
A Television Programme Did the Regulator's Testing For It
The Dutch gambling authority has said it will act against gaming halls and casinos featured in an investigation by the broadcaster PowNed, which showed that entry checks against Cruks were not working at some venues.
Cruks is the national self-exclusion register. A person who registers on it is barred from land-based venues and licensed online sites, and the control that makes it real is the identity check at the door. The investigation showed that presenting another person's identification was sufficient to get a Cruks-registered individual inside.
Three venues are under scrutiny. One is a site operated by Holland Casino in Eindhoven, which matters because Holland Casino is state-owned, so the failure sits with a venue the Dutch state runs itself.
The KSA's statement was unambiguous about the standard: it should not have happened that someone registered in Cruks enters an arcade using another person's identification, arcades and casinos are required to carry out thorough checks, and the regulator monitors this.
The authority has separately said that its most urgent legislative request is the power to create false identities, so that it can test operator compliance directly rather than relying on complaints or, as here, on journalists.
Self-Exclusion Is Only as Good as the Door
This is the second failure of the same control in two days. Yesterday Colorado fined Fanatics $20,000 for sending promotional offers to a self-excluded customer, and required a twenty-six month audit to find out how many others received them. The Dutch case is the physical version of the same problem. A register is a list; what makes it an intervention is the check performed against it, and both cases show the check being the weak point rather than the list. A player who has registered has already done the difficult part. Everything after that is the operator's obligation, which is why regulators treat these failures more seriously than their financial scale suggests.
The Regulator Is Asking for the Power to Do This Itself
The most consequential line is not about the three venues. It is the KSA saying it wants the law changed so it can create false identities to test compliance. That is mystery shopping with legal cover, and it is the difference between a regulator that audits paperwork and one that can test whether a control works in practice. Several jurisdictions already permit something like it for age verification. If the Netherlands grants it, venues should expect the next fake identification presented at a door to belong to the regulator, and the standard of proof for "we carry out thorough checks" will move from policy documents to results. Operators elsewhere should watch whether it is granted, because it is the kind of power other regulators copy once one of them has it.
A broadcaster found the gap. The regulator has now asked for permission to look for the next one itself.


