The data protection requirements that apply to online gambling operators rarely come from one statute. An operator licensed in Malta, taking players in Germany, Canada and the United Kingdom, answers to the GDPR, the UK GDPR and PIPEDA at the same time, and to a gambling regulator that treats weak information security as a licensing failure rather than a privacy one. GICNT-DS assumes the strictest of those obligations governs everywhere.
Which Data Protection Regimes Reach an Online Gambling Operator
Article 3 of the GDPR ties application to the player, not to the company. An operator incorporated in Curacao that offers services to residents of an EU member state, or monitors their behaviour, processes personal data under the GDPR in full. A licence tells you which gambling regulator supervises the business. It says nothing about which privacy authority can open a file.
Compliance with the GDPR across an online gambling estate therefore runs in parallel with two or three other regimes, each with its own supervisor and its own ceiling. Certification cuts across all of them at once, which is why the data protection and cybersecurity requirements under GICNT-DS are written to the strictest applicable standard rather than to a single market.
| Regime | What brings an operator into scope | Supervisor | Maximum exposure |
|---|---|---|---|
| GDPR | Offering services to, or monitoring the behaviour of, people in the EU or EEA | National data protection authority, lead authority under the one-stop-shop | EUR 20 million or 4% of worldwide annual turnover |
| UK GDPR and Data Protection Act 2018 | Offering services to, or monitoring, people in the United Kingdom | Information Commissioner’s Office | The same tiered structure as the GDPR, expressed in sterling |
| PIPEDA | Commercial handling of personal information across a provincial or national border | Office of the Privacy Commissioner of Canada | No administrative fines. Findings, Federal Court applications and offence provisions |
| Quebec Law 25 | Personal information on Quebec residents, wherever the operator sits | Commission d’accès à l’information | Administrative penalties to CAD 10 million or 2% of worldwide turnover, penal fines to CAD 25 million or 4% |
Federal Canadian law carries the weakest direct penalty of the four and the loosest deadline, which is why operators most often treat it as the soft option.
Establishing a Lawful Basis for Player Data Before Collection
Under Article 6, each purpose needs its own lawful basis for the player data it involves, and the basis is recorded before collection rather than reconstructed during an investigation. Consent is the wrong answer for most of what an operator does, because a player who withdraws it cannot then be kept on the platform. Czech practice makes the point plainly: checking the national register of excluded persons is a statutory duty under section 17 of the Czech Gambling Act, so consent would be neither necessary nor valid as a basis.
- Identity and age verification, sanctions screening, customer due diligence. Article 6(1)(c), legal obligation, anchored in national gambling and anti-money laundering law.
- Account administration, deposits and withdrawals. Article 6(1)(b), performance of a contract with the player.
- Transaction monitoring and suspicious activity reporting. Article 6(1)(c), with the national AML statute as the source of the duty.
- Responsible gambling monitoring. Legal obligation where licence conditions mandate intervention, legitimate interests where they do not.
- Fraud prevention, device fingerprinting and security telemetry. Article 6(1)(f), supported by Recital 49.
- Marketing and promotional profiling. Consent, and nothing else. France has tightened this further: from 11 August 2026, Law No. 2025-594 of 30 June 2025 requires explicit consent for all telephone prospecting, and operators passing player data to commercial partners must identify those partners at the point of collection.
Errors here surface at onboarding, before any downstream control runs. Documented KYC onboarding standards should therefore record the basis for every field collected, not only the outcome of the check.
When Player Behaviour Becomes Health Data Under Article 9
The Autorité nationale des jeux (ANJ), the French gambling regulator, adopted a sector guide on personal data at its board meeting on 19 May 2026 and published it, prepared with the data protection authority CNIL, later that month. The CNIL announced it on 2 July 2026. The document runs to 59 pages and is guidance rather than binding regulation. Its most consequential passage concerns risk scoring.
Deposit frequency, stake size and session length are not health data on their own. The output of combining them can be. Once an operator classifies a player as engaging in excessive or pathological play, that classification may reveal a behavioural addiction recognised as a disorder in the DSM-5, which brings it inside Article 9. Czech supervisory commentary reaches a similar conclusion about inferred problem gambling.
Three consequences follow. The Article 9(1) prohibition applies unless a condition in Article 9(2) is met, usually substantial public interest supported by member state law. A data protection impact assessment becomes hard to avoid. And the score needs access controls tighter than those on the behavioural data feeding it, which is awkward for operators holding the risk flag as one more column in a general analytics table. The same output drives the intervention duty, so the privacy analysis and the detection of markers of harm belong to one design, not to two teams working separately.
How Long KYC Records Must Be Kept, and When They Must Be Deleted
Retention requirements attached to KYC data come from AML law rather than privacy law, and they set a floor with a ceiling above it, not a licence to keep files indefinitely.
| Regime | Clock starts | Period | Deletion duty |
|---|---|---|---|
| United Kingdom, MLR 2017 reg 40 | End of the business relationship, or completion of an occasional transaction | Five years. Transaction records inside a continuing relationship are capped at ten years | Reg 40(5) requires deletion of the personal data on expiry, with narrow exceptions for legal proceedings or consent |
| EU, Directive (EU) 2015/849 art 40 | Same | Five years, with national extensions where a member state justifies them | Member states must ensure deletion on expiry unless national law provides otherwise |
| EU from 10 July 2027, AMLR art 77 | Same | Five years, harmonised and directly applicable | Extension only on a case-by-case basis, decided by a competent authority |
| Spain and Luxembourg, current national rules | Same | Ten years | Set by national transposition until the AMLR displaces it |
| Canada, PIPEDA | No AML clock. The principle governs | No fixed period. Only as long as the identified purpose requires | Breach records kept 24 months whether or not individuals were notified |
An operator serving Spain, France and the Netherlands today runs three different clocks off the same passport scan. The EU AML package closes that gap from 10 July 2027, and a transitional rule in Article 77(4) lets an obliged entity holding material relevant to proceedings pending on that date retain it for a further five years.
Where AML Retention Collides With the Right to Erasure
AML retention obligations run against the right to erasure the moment a player closes an account and asks for the file to be deleted. Article 17(3)(b) settles it: erasure does not apply where processing is necessary for compliance with a legal obligation. The Gambling Commission made the mirror argument to British licensees in 2018 and has not moved from it, saying it would not accept a licensee simply stating that the GDPR prevented compliance with a gambling duty. Neither instrument yields. The operator splits the record instead.
- Segment at schema level. Identity documents, verification results and transaction history sit under legal obligation. Marketing preferences, promotional profiles and optional profile fields sit under consent.
- Answer inside one month under Article 12(3). A two-month extension is available for complex requests and has to be notified within the first month.
- Delete what falls outside the AML perimeter and say so. Refusing the request in full is the common failure.
- State the ground of refusal and the date on which the retained data will be destroyed.
- Diarise that destruction. Holding customer due diligence documents past the statutory window is a breach in its own right under reg 40(5), not a cautious hedge.
- Keep the AML file out of analytics and marketing systems. Reg 41 bars processing data obtained for MLR purposes for anything else.
Because the mapping between the two regimes lives inside the AML documentation, the AML and KYC requirements and the retention schedule should be reviewed on the same cycle rather than by different owners at different times.
What the 72-Hour Breach Notification Clock Requires in Each Regime
The 72-hour clock for notifying a data breach comes from the GDPR and from almost nothing else an operator is subject to.
| Regime | Trigger | Deadline to the authority | Records and individuals |
|---|---|---|---|
| GDPR, Articles 33 and 34 | A personal data breach, unless unlikely to result in a risk to rights and freedoms | Without undue delay and, where feasible, within 72 hours of becoming aware. Later notification requires a reasoned justification | Individuals notified without undue delay where the breach is likely to result in high risk. Article 33(5) requires an internal record of every breach |
| PIPEDA | A breach of security safeguards creating a real risk of significant harm | As soon as feasible after the organisation determines the breach occurred. No hour count in the statute | Individuals notified as soon as feasible, directly unless the regulations permit indirect notice. Records of all breaches kept 24 months |
| Quebec Law 25 | A confidentiality incident presenting a risk of serious injury | Promptly, with no statutory hour count | Individuals notified promptly. Register of all incidents kept five years |
The Canadian threshold turns on the sensitivity of the information and the probability of misuse, and a KYC file sits near the top of that scale. The Office of the Privacy Commissioner cannot levy fines, which flatters the risk on paper. Reform is moving again: Bill C-36, the Protecting Privacy and Consumer Data Act, received first reading on 15 June 2026 and would repeal Part 1 of PIPEDA, rename what remains the Electronic Documents Act and shift private sector enforcement to a new commission whose creation depends on Bill C-34. Until it passes, a statute drafted in 2000 governs. Operators reading Canadian obligations for the first time also tend to underestimate the provincial layer, the same feature that makes online gambling in Canada a licensing question with no single federal answer.
Why GICNT-DS Fixes a Single 72-Hour Standard
PIPEDA sets its breach reporting requirements without a number. That works for a business in one market and stops working for one holding player files in six.
- One clock rather than five. An incident response plan that branches by jurisdiction fails during the incident, when nobody has time to establish which players sit under which regime.
- A number can be tested. An assessor compares the detection timestamp against the notification timestamp. Neither side can audit a judgement about what was feasible.
- The stricter deadline already binds any operator with EU or UK players. Extending it to Canadian players costs process discipline and nothing else.
- Meeting 72 hours in Canada exceeds PIPEDA rather than satisfying it. Certified operators should describe it that way internally, because claiming a legal deadline that does not exist creates its own accuracy problem.
The domain looks for the artefacts around the deadline as much as for the deadline itself: a named incident owner, a severity classification that starts the clock at detection rather than at confirmation, notification templates cleared in advance, and a post-incident review that changes something. GICNT-DS runs on an annual security assessment, and the certification audit cycles differ across the six domains because the underlying risk profiles differ.
Security Testing Obligations That Sit Alongside Privacy Law
Article 32 tells an operator to apply appropriate technical and organisational measures without naming any. Gambling regulators are more specific. Licence condition 2.3.1 of the LCCP requires British remote licensees to comply with the Remote Gambling and Software Technical Standards, and section 4 of the RTS sets security requirements drawn from ISO/IEC 27001. The Commission moved those requirements from the 2013 version of the standard to the 2022 version with effect from 31 October 2024, adding control 5.23 on information security for cloud services, and required all relevant licensees to complete an audit against the updated controls by 31 October 2025.
The ISO 27001-based security audit that gambling licensees commission in Britain is annual, carried out by an independent and suitably qualified auditor, and scoped to systems that hold sensitive customer information and systems that generate or process the random numbers behind game outcomes. Licensees keep the report on file. They submit it within seven days of a request from the Commission, and they must notify the Commission where the auditor records a major non-conformity. A newly licensed operator completes its first audit within six months of the grant.
That audit is narrower than full certification to the standard, and it is not a penetration test. GICNT-DS treats the two as separate obligations, and the penetration testing scope it expects is defined against the player-facing estate rather than against a sampled control set.
Common Questions on Gambling Data Protection Compliance
Does PIPEDA give operators 72 hours to report a data breach?
No. PIPEDA requires a report to the Office of the Privacy Commissioner and notification of affected individuals as soon as feasible after the organisation determines that a breach creating a real risk of significant harm has occurred. The statute contains no hour count. The 72-hour figure comes from Article 33 of the GDPR, and GICNT-DS applies it as a certification requirement that runs stricter than Canadian law.
Can a player force deletion of their KYC documents through an erasure request?
Not while an AML retention period is running. Article 17(3)(b) disapplies the right to erasure where processing is necessary for compliance with a legal obligation, and customer due diligence records fall inside that. Marketing data held on the same player still has to go. A blanket refusal covering the entire account file is the wrong response.
Is gambling behaviour data a special category under Article 9?
Play data on its own generally is not. The guide the ANJ published with the CNIL in May 2026 treats the derived classification of a player as an excessive or pathological gambler as health data, on the basis that it may reveal a behavioural addiction recognised as a disorder. Operators should hold that score under Article 9 conditions even where the inputs sit under Article 6.
How long will EU operators have to keep CDD records after 2027?
Five years from the end of the business relationship or the date of an occasional transaction, under Article 77 of Regulation (EU) 2024/1624, which applies from 10 July 2027. The regulation replaces national retention periods directly, so the ten-year rules currently in force in Spain and Luxembourg fall away for obliged entities in scope.
Does an offshore licence put an operator outside the GDPR?
No. Article 3 attaches to the location of the player and to the monitoring of behaviour, not to the place of incorporation or the licensing jurisdiction. An operator holding a Curacao licence and accepting registrations from Germany processes personal data under the GDPR on the same terms as a Malta licensee.