GICNT Registry · Certified Operators · Compliance Reports · Standards
EST. 2019
gicnt.org
Global iGaming Compliance & Trust
Independent Standards & Certification Authority
ISO 27001 Aligned FATF Observer UN Global Compact
GICNT's mission is to establish and uphold global standards for responsible, transparent and fair iGaming operations — protecting players, enabling regulators, and certifying operators who meet the highest standards of compliance. Our certification is not paid. It is earned.

GICNT-DS: Data Protection and Cybersecurity Requirements

Data protection and cybersecurity requirements in iGaming carry a weight that few consumer sectors face, because one operator database holds identity documents, payment histories and behavioural records that together describe a person’s financial vulnerability. GICNT-DS is the certification domain that tests those controls. It sets one technical floor across every market an operator serves, then assesses it annually against the live environment rather than the written policy.

What GICNT-DS Assesses in an Operator’s Security Posture

GICNT-DS is one of the six mandatory compliance domains in Framework v4.2, and the one reviewed through an Annual Security Assessment. The domain does not restate the text of any single privacy statute. It fixes a floor that a certified operator holds everywhere it accepts players, so a licensee operating where data protection law is thin is not assessed on a weaker basis than one operating under the GDPR.

Five areas carry the assessment:

  • Lawful basis mapping for every category of player data, covering KYC records, transaction logs and the output of responsible gambling profiling
  • Encryption in transit and at rest, with key material held separately from the data store and rotation documented
  • Breach notification within 72 hours of the operator becoming aware, to the certification body and to every competent supervisory authority
  • A tested incident response plan with named roles, escalation thresholds and evidence that it has been exercised
  • An annual independent penetration test, with a remediation record for every finding rated high or above

Certification under GICNT-DS is not a licence and does not displace a regulator’s own security audit. Where a licensing authority already mandates an independent assessment, the two run in parallel and the statutory obligation is unaffected.

Which Data Protection Law Applies to Which Player

GDPR compliance for an online casino operator is settled by where the player sits, not by where the company is registered. An operator licensed in Curaçao and accepting players in Germany falls inside the Regulation; a Malta licensee falls inside it twice over, as an EU entity and as a processor of EU residents’ data. PIPEDA covers data protection for iGaming businesses engaged in commercial activity involving Canadian players, with Quebec layering its own statute on top. GICNT-DS therefore requires an operator to hold its GDPR and PIPEDA obligations as a mapped matrix rather than as one privacy notice written for the largest market.

RegimeApplies whenReport to the authorityMaximum exposure
GDPRThe player is in the EU or EEA, whatever the operator’s place of establishmentWithin 72 hours of awareness, Article 33EUR 20 million or 4% of worldwide annual turnover
UK GDPR with the Data Protection Act 2018The player is in the United KingdomWithin 72 hours of awarenessGBP 17.5 million or 4% of worldwide annual turnover
PIPEDA, federal CanadaCommercial activity involving the personal data of Canadian playersAs soon as feasible once the operator determines a real risk of significant harm, with no hour count in the statuteProsecution for knowingly failing to report, with fines up to CAD 100,000 per offence
Law 25, QuebecThe player is in QuebecPromptly, to the Commission d’accès à l’informationCAD 10 million or 2% as an administrative penalty, CAD 25 million or 4% on penal prosecution
NIS2 as transposed nationallyThe operator or its supplier meets the size and service thresholds in the national implementing act24-hour early warning, 72-hour notification, final report within one monthEUR 10 million or 2% of worldwide turnover for essential entities

Gambling is not named among the sectors listed in the annexes to Directive (EU) 2022/2555, so NIS2 scope turns on the entity rather than the industry. Several member states have nonetheless captured licensed operators expressly during transposition, which makes the national implementing act, not the directive, the document to read.

Encryption Standards for Player Data in Transit and at Rest

Encryption standards for player data at a casino platform are usually written into operator documentation in language that has aged badly. References to 256-bit SSL still appear across the industry, and in some certification schemes, although SSL was deprecated long ago and TLS 1.0 and 1.1 are accepted by no current payment or information security standard. GICNT-DS reads that requirement in its modern form.

  • TLS 1.2 as a hard minimum on every player-facing and administrative endpoint, with TLS 1.3 preferred and weak cipher suites disabled rather than deprioritised
  • AES-256 at rest for identity documents, payment instruments and transaction records
  • Identity documents captured during KYC onboarding verification held in encrypted storage with retrieval logged per access, not per session
  • Card data handled under PCI DSS v4.0.1, the only active version since 31 December 2024, with all 51 future-dated requirements mandatory since 31 March 2025 and no remaining transition phase
  • Multi-factor authentication on all non-console access into the cardholder data environment, for every role and from every location

The assessment looks at configuration, not at claims. An operator that advertises bank-grade encryption while terminating TLS at an edge node and passing plaintext to an internal service has an architecture problem, not a marketing problem.

How the Breach Notification Clock Differs Across GDPR, PIPEDA and NIS2

The 72-hour breach notification deadline that gambling operators tend to treat as universal is not universal. It comes from Article 33 of the GDPR, which requires the controller to notify the competent supervisory authority without undue delay and, where feasible, no later than 72 hours after becoming aware, unless the breach is unlikely to result in a risk to individuals. Where that window is missed, the notification has to carry written reasons for the delay. Article 34 is a separate obligation with a higher threshold: where the breach is likely to result in high risk, the affected players must be told without undue delay, and prior encryption that renders the data unintelligible can lift that duty.

PIPEDA sets no hour count at all. The obligation is to report to the Office of the Privacy Commissioner of Canada and to notify affected individuals as soon as feasible once the organisation determines that a breach of security safeguards creates a real risk of significant harm. Records of every breach, including those below the reporting threshold, must be kept for 24 months. Applying 72 hours to Canadian players is therefore a stricter internal rule than Canadian law imposes, and GICNT-DS treats it as exactly that: a certification uplift, not a restatement of the statute.

The practical consequence for a multi-market operator is that one incident can start three clocks at once. A confirmed compromise touching EU and Canadian players at a licensee in NIS2 scope runs a 24-hour early warning, a 72-hour supervisory notification and a report to the Canadian privacy commissioner, on three different forms, with three different thresholds for what counts as awareness.

Annual Penetration Testing and the Scope GICNT-DS Expects

Penetration testing at a gambling operator is assessed on scope, independence and remediation, never on the existence of a certificate. A test that covers the public marketing site and stops there satisfies nothing. The penetration testing scope that GICNT-DS expects reaches the systems a regulator would call critical.

  • Player-facing web and mobile clients, including authentication, session handling and account recovery
  • Cashier and payment flows end to end, covering deposit, withdrawal and any third-party redirect
  • Back-office and administrative interfaces, which are where privilege escalation findings cluster
  • APIs exposed to game aggregators, affiliate platforms and identity verification suppliers
  • External perimeter and internal segmentation, tested separately rather than inferred from a network diagram

Frequency is at least once in every twelve-month certification period, plus a further test after any material change to payment flows, authentication or platform architecture. Findings rated high or above need a documented remediation record and a retest that closes them. An unremediated high finding carried forward from the previous cycle is a certification failure in itself.

Writing an Incident Response Plan a Regulator Will Accept

An incident response plan at an online gambling business rarely fails because it does not exist. It fails because nobody has run it. The recurring pattern in enforcement across sectors is the same: the technical team detects the incident, and the data protection officer learns of it several days later, by which point the notification window has closed and the delay itself is a separate infringement.

What holds up under review has six parts.

  1. Detection and internal escalation with named roles, an out-of-hours contact chain and an explicit instruction that the data protection officer is informed immediately, not after triage
  2. A risk assessment template mapped to Article 33(3), so the nature, categories, approximate numbers, likely consequences and proposed measures are captured in one pass
  3. Pre-drafted notification forms for each authority the operator answers to, covering the common scenarios of credential theft, lost device, system compromise and accidental disclosure
  4. Processor contracts that state the notification window in hours and name out-of-hours escalation contacts, because a supplier who reports slowly consumes the controller’s deadline
  5. A breach register that records every incident, including those below any reporting threshold, satisfying both Article 33(5) and the Canadian 24-month record obligation
  6. An annual exercise with a written record of who took part, what broke and what was changed as a result

The register is the part operators most often skip, and the part an assessor reaches for first. A register with no low-severity entries in it does not read as a clean year. It reads as an organisation that is not detecting anything.

How Gambling Regulators Audit Information Security

ISO 27001 in a gambling licence security audit is not a certificate the regulator collects. It is the yardstick the auditor works against, and the distinction matters when an operator budgets for compliance. The UKGC licence conditions make the audit the obligation, and accept a certificate as evidence rather than requiring one.

AuthorityInstrumentWhat it obliges
UK Gambling CommissionRTS section 4 and the testing strategy for complianceAn annual independent security audit against BS ISO/IEC 27001:2022. A newly licensed operator provides its first audit within 6 months of grant, the report goes by email within 7 days of the due date, and major non-conformities are reported without delay.
Malta Gaming AuthorityGuidelines on technical infrastructure hosting gaming and control systemsHosting environments must sit under an information security management system at ISO/IEC 27001 level for the term of the licence, with PCI DSS Level 1 sought where payment data is stored or processed.
AGCO, OntarioRegistrar’s Standards for Internet Gaming, standards 5.08 to 5.10A secure physical environment, protection of gaming systems, infrastructure, data and activity logs from threats and breaches, authentication of all users, regular reassessment of hardening, current patching, and security monitoring logged auditably and escalated.

The UK guidance is unusually direct about method. The Commission does not accept that a good audit can be conducted remotely on documentation alone, and expects all three of enquiry, evidence gathering and observation to appear in the report, along with the names and titles of the people interviewed. Where a third-party data centre or a B2B supplier sits in scope, reliance on their own audit work is permitted, but it does not transfer the licensee’s responsibility.

Where AML Retention Collides with Data Minimisation

The sharpest tension inside GICNT-DS is not with an attacker. It is with the AML requirements for operators that sit in a neighbouring domain: one standard compels retention, the other compels deletion, and both are mandatory.

France mapped the conflict in unusual detail in May 2026, when the Autorité nationale des jeux (National Gaming Authority) published a 59-page guide with the Commission nationale de l’informatique et des libertés (National Commission on Informatics and Liberty). Player account data is retained for six years from account closure under Article 31 of Decree No. 2010-518. AML records run on two separate five-year periods, one from the end of the customer relationship for due diligence documents and one from execution for individual transactions. Prospecting data may be held until consent is withdrawn or for three years from last contact, and that shorter period does not force deletion where the six-year gambling obligation still attaches to the same records for a different purpose.

Where processing rests on a legal obligation, the player cannot demand erasure, object to the processing or claim portability. AML data is further insulated: access requests route through the supervisory authority rather than the operator, and the player has no right to learn whether a suspicious transaction report has been filed.

The same guidance produced a conclusion with direct engineering consequences. Classifying a player as an excessive or pathological gambler may reveal a behavioural addiction recognised as a disorder, which makes the classification health data under Article 9. Where that applies, the file attracts multi-factor authentication, a mandatory data protection impact assessment and access restricted to the staff responsible for problem gambling prevention. Algorithmic risk scoring stays permitted, but a human must review the case before any measure that restricts a high-risk player’s access, and that review has to be more than a sign-off. GICNT-DS treats responsible gambling profiling output as a special category by default for exactly this reason, rather than waiting for a national authority to say so market by market.

Frequently Asked Questions on GICNT-DS Compliance

Does PIPEDA require breach notification within 72 hours?

No. PIPEDA requires a report to the Office of the Privacy Commissioner of Canada and notice to affected individuals as soon as feasible once the organisation determines that a breach creates a real risk of significant harm. No hour count appears in the statute. The 72-hour figure comes from Article 33 of the GDPR, and an operator applying it to Canadian players is applying a stricter rule than Canadian law requires.

Is ISO 27001 certification mandatory to hold a remote gambling licence?

Not in the United Kingdom. The Gambling Commission requires an annual independent audit against BS ISO/IEC 27001:2022 and accepts a certificate from an accredited body as evidence, but the obligation is the audit rather than the badge. Operators moving to full certification for the first time must tell the Commission the start date, the stage reached, the accredited body and the date the certificate was awarded.

Are online gambling operators inside the scope of NIS2?

Gambling is not listed among the sectors in the annexes to Directive (EU) 2022/2555, so scope depends on the entity rather than the industry. Operators and their suppliers can be captured as digital service providers or managed service providers once they meet the size thresholds, and several member states have swept licensed operators in expressly during transposition. The answer that binds is the national implementing act.

How often must a certified operator commission a penetration test?

At least once in every twelve-month certification period, and again after any material change to payment flows, authentication or platform architecture. Findings rated high or above require a documented remediation record and a retest that closes them before the next assessment.

Does GICNT-DS certification replace a security audit required by a regulator?

No. GICNT is an independent certification body, not a licensing authority, and its assessment carries no statutory effect. Where a regulator mandates its own audit, that obligation stands untouched. GICNT-DS is built to sit alongside it and to hold one consistent floor in markets where the local requirement is lighter.