Home  /  News  /  Compliance & AML
Compliance & AMLJanuary 28, 2026

GDPR Player Data Protection: A Weekly Checklist for Casino Operators

A practical GDPR compliance checklist for casino operators covering data mapping, consent, breach response and vendor oversight. Apply it this week.

GDPR Player Data Protection: A Weekly Checklist for Casino Operators

Player data is one of the most valuable and most regulated assets a casino operator holds. GDPR fines issued by European supervisory authorities reached record levels in 2025, and operators in the iGaming sector continue to appear on enforcement lists, often for failures that a structured weekly review would have caught before they became reportable incidents. The checklist below is designed for compliance officers and operations managers who need a concrete starting point, not a theoretical framework.

Why Casino Operators Face Elevated GDPR Risk

Online casinos collect a dense category of personal data: identity documents, payment details, behavioural patterns, self-exclusion records and, in some jurisdictions, biometric verification outputs. Several of these categories attract stricter handling obligations under Articles 9 and 10 of the GDPR. At the same time, the player journey spans multiple third-party systems, including CRM platforms, payment processors, affiliate tracking tools and KYC providers, each representing a potential point of non-compliance in your processing chain.

Regulators have made clear that outsourcing a function does not outsource the liability. The operator remains the data controller and is accountable for what its processors do with player data.

The Weekly Compliance Checklist

1. Audit Your Data Map

  • Confirm that your Records of Processing Activities (RoPA) under Article 30 reflects any new data flows added in the past seven days, including new game providers or marketing integrations.
  • Check that a lawful basis is documented for every processing activity. Consent, contract performance and legitimate interest each carry different obligations; verify the correct one is assigned.
  • Identify any personal data leaving the EEA and confirm that a valid transfer mechanism, such as Standard Contractual Clauses, is in place and current.

2. Review Consent and Privacy Notices

  • Verify that marketing consent captured at registration is granular, freely given and recorded with a timestamp and version of the privacy notice shown.
  • Confirm that your cookie banner blocks non-essential cookies prior to acceptance, not after.
  • Check that your privacy notice accurately describes the retention periods currently in use across all player data categories.

3. Test Your Data Subject Rights Workflow

  • Run a simulated Subject Access Request through your process and confirm the clock starts correctly and that the response would be ready within 30 days.
  • Verify that a Right to Erasure request triggers a hold check: AML and responsible gambling records carry their own mandatory retention periods and cannot simply be deleted on request.
  • Confirm that your team knows who handles requests when the primary contact is absent.

4. Inspect Vendor Data Processing Agreements

  • List every sub-processor that touches player data and confirm a signed Data Processing Agreement (DPA) is on file for each one.
  • Check that DPAs require sub-processors to notify you of breaches within a timeframe that allows you to meet your own 72-hour reporting obligation to the supervisory authority.
  • Flag any vendor contract due for renewal and schedule a DPA review alongside the commercial negotiation.

5. Breach Detection and Response Readiness

  • Review your incident log for the past seven days and confirm no unresolved anomalies exist that could constitute a personal data breach.
  • Confirm that staff responsible for breach identification have had training in the past 12 months and know the internal escalation path.
  • Verify that your breach notification template to the supervisory authority is current and that you know which authority has jurisdiction for your player base.

The Intersection of AML and GDPR

Casino operators navigate a genuine tension between GDPR erasure rights and AML retention mandates. Under most European AML frameworks, transaction records and customer due diligence files must be retained for five years from the end of the business relationship. A player's right to erasure does not override this obligation, but your privacy notice must explain that conflict clearly, and your systems must be able to suppress marketing use of that data while retaining the compliance record.

Operators who document the legal basis for each retention decision, and can demonstrate that decision in a regulator audit, are in a fundamentally stronger position than those relying on general retention policies.

Practical Next Steps for Operators

Assign ownership of each checklist item to a named individual rather than a team. Set a 72-hour internal deadline for the first pass this week. Where gaps are identified, prioritise the items that involve third-party data transfers and consent records, as these are the areas drawing the most regulatory attention across EU and EEA jurisdictions entering 2026.

If your operation lacks an in-house Data Protection Officer with iGaming-specific experience, consider whether a specialist managed-services partner can provide that function with the operational context your compliance programme requires.

FAQ

Frequently asked questions

What personal data categories make casino operators high-risk under GDPR?

Casino operators process identity documents, payment details, behavioural data, self-exclusion records and, increasingly, biometric verification outputs. Several of these fall under special category data or criminal conviction data under Articles 9 and 10 of the GDPR, attracting stricter processing obligations. The volume and sensitivity of this data, combined with the number of third-party systems involved, places iGaming operators in a higher scrutiny tier for supervisory authorities.

Can a casino operator delete player data when a customer requests erasure under GDPR?

Not always. The right to erasure under GDPR Article 17 does not apply where the operator has a legal obligation to retain the data. AML frameworks in most European jurisdictions require transaction records and customer due diligence files to be kept for five years after the relationship ends. Operators must document this conflict in their privacy notices and ensure their systems can isolate compliance records from marketing use while the retention period runs.

How should a casino operator manage GDPR obligations when using third-party vendors?

The operator is the data controller and remains accountable for how its processors handle player data, even when those functions are outsourced. A signed Data Processing Agreement must be in place with every sub-processor that touches personal data. That agreement should require breach notification within a timeframe allowing the operator to meet its own 72-hour reporting obligation to the relevant supervisory authority. DPAs should be reviewed at every contract renewal.

What is the most common GDPR failure seen among iGaming operators?

Regulators consistently identify inadequate consent mechanisms and incomplete Records of Processing Activities as leading failure points. Operators frequently add new integrations, such as affiliate trackers or game providers, without updating their data maps or confirming a lawful basis for the new processing activity. A weekly review of any data flows added or changed in the previous seven days is a practical control that catches these gaps before they become reportable issues.

Keep reading

Related articles

Show us one brand.
We will find the leaks.

Book a 30-minute teardown. We walk through one of your brands and show you exactly where revenue, retention or compliance is slipping, no obligation.