Data Protection (GDPR in iGaming)
The obligations governing how operators collect, use, secure and retain the large volumes of personal and financial data their compliance duties generate.
Definition
Data protection governs how gambling operators handle personal data, and in the EU and comparable regimes this is shaped by the General Data Protection Regulation. iGaming is unusually data-intensive because AML, age and identity verification, affordability and safer-gambling monitoring all require collecting sensitive personal and financial information. Operators must have a lawful basis for processing, minimise and secure the data, honour individuals' rights, and set retention periods, all while meeting compliance obligations that may compel them to keep or share data. This creates real tension: identity and monitoring duties push toward collecting more, while data-protection principles push toward collecting and keeping less.
Worked example
An operator retains verification and transaction records to satisfy AML requirements, but must justify the retention period, secure the data, and be able to respond when a customer exercises rights such as access to their personal data.
Why it matters
For learners it shows compliance is not only about collecting data but also about protecting it. For professionals, reconciling AML retention duties with data-protection minimisation is a genuine and recurring balancing act.
Related
Note: GDPR applies in the EU and EEA, with closely related regimes elsewhere; specific lawful bases and retention periods depend on jurisdiction and the processing purpose.