Privacy advice built around the player journey
An iGaming business processes personal data across account registration, verification, payments, gameplay, customer support, marketing and account closure. The information can move through a platform provider, identity service, payment processor, game supplier, CRM system and external advisers. A privacy notice alone does not explain or control that full chain.
iGaming Firm helps operators, suppliers and affiliate businesses understand their data flows and organise practical privacy controls. We can support data mapping, documentation, supplier reviews, rights-request procedures, incident planning and the privacy aspects of platform migrations and business acquisitions.
Establish whether and how GDPR applies
GDPR can apply because of an organisation's establishment in the EU or EEA, and in some circumstances to organisations outside that area offering goods or services to people in the EU or monitoring their behaviour there. The assessment concerns the relevant processing activity, not simply the location printed on a gaming licence. The EDPB's data protection basics explain this starting point.
A business should map the entities involved and distinguish controller, joint-controller and processor roles according to what they actually decide and do. Calling a platform a processor in a contract does not settle the question if its real activities differ. UK data protection and electronic marketing requirements also need separate consideration where relevant.
Map information before writing policies
A data inventory should show the information collected, its source, purpose, users, systems, recipients and intended retention. For a gaming operator, that may include contact details, identity documents, transaction records, device information, support correspondence, marketing preferences and records created during risk reviews.
The inventory should follow the real journey. Ask what happens when a player submits a document, opens a complaint, changes a payment method, self-excludes or closes an account. Identify any copies in inboxes, spreadsheets and third-party dashboards. These operational details often reveal the gap between a policy and the way personal data is actually handled.
We can turn the findings into a record of processing activities, a supplier list, a retention matrix and an implementation plan. These are useful working documents for the team, not simply attachments to a compliance folder.
Legal bases and transparent information
Different uses of data may rely on different legal bases. A business should identify the applicable basis for each purpose rather than seek one broad consent for everything. The GDPR's framework includes contract, legal obligation, consent and legitimate interests, subject to the conditions of each. The EDPB's lawful processing guidance provides the starting framework.
A privacy notice should then explain the processing in language the intended reader can understand. It should accurately describe the relevant entity, purposes, data categories, recipients, retention approach, rights and contact route. Claims about encryption, deletion or restricted sharing should match the systems and contracts in place.
For onboarding, we help align the notice with the registration journey and document requests. For marketing, we examine how preferences are captured and passed to downstream systems. For risk processes, we consider whether the information given to individuals is sufficiently clear without undermining lawful confidentiality obligations.
Player access and deletion requests
Requests can arrive through support tickets, email or other ordinary channels. A procedure should help staff recognise them, route them promptly, verify identity proportionately and coordinate searches across systems. The response should address the request rather than rely on a standard refusal or refer the customer between suppliers.
Under GDPR, the usual response period is one month, with a possible extension of up to two further months where the conditions for complexity or number of requests are met. The individual must be informed of an extension and its reasons within the initial month. The EDPB's guidance on individuals' rights explains the framework.
Erasure is not absolute. Specific records may need to be retained for a legal obligation or for the establishment, exercise or defence of legal claims. That does not justify a blanket refusal covering unrelated information. We help separate records to delete, records to restrict or retain, the reason for retention and the follow-up review date. See our AML compliance guidance for the connected record-keeping questions.
Retention and account closure
Closing an account, ending marketing and erasing personal data are different operations. A retention schedule should define the trigger and period for each record category, identify any legal hold and explain what happens in backups and connected suppliers. A customer should not remain on a campaign list simply because a separate compliance record must be retained.
We can help design a closure workflow that coordinates support, compliance, marketing and technical teams. The workflow should leave enough evidence to demonstrate the action taken without recreating the same unnecessary data collection the business is trying to reduce.
Platform providers, processors and international transfers
Supplier reviews should cover permitted processing, security, sub-processors, incident support, rights-request assistance and return or deletion of data at the end of the relationship. The operator should understand whether it can export the information it needs and what happens if the platform contract is terminated.
Making personal data available to another organisation outside the EEA can require a Chapter V transfer mechanism in addition to a lawful basis for the processing. Depending on the circumstances, this may involve an adequacy decision or appropriate safeguards such as standard contractual clauses, with the necessary assessment and supplementary measures. See the EDPB's international transfer guidance.
We help map the relevant transfers and coordinate the privacy terms with the main supplier agreement. Signing a standard document without understanding the recipient, systems and data flows is not a complete review.
Security, DPIAs and new features
Access controls, secure document handling, audit logs, supplier access and staff training should reflect the risks to individuals. A privacy review should be built into new product decisions, particularly where profiling, identity technology or extensive monitoring is involved. A data protection impact assessment is required before processing likely to result in a high risk to individuals' rights and freedoms; not every new feature automatically meets that threshold.
The EDPB's DPIA guidance helps frame the assessment. We can support the description of the processing, necessity and proportionality review, risk identification and proposed safeguards, working with the technical team on implementation.
Personal data breaches and response planning
The response plan should explain how an incident is reported internally, who assesses it and which evidence is preserved. Under GDPR, a controller must notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of awareness unless the breach is unlikely to result in a risk to individuals. Communication to affected individuals is a separate high-risk assessment, subject to the applicable exceptions. Processors must notify the controller without undue delay.
We can help prepare the escalation process, assessment template and decision record using the EDPB's breach guidance. The business should record incidents and the reasoning behind notification decisions, including when notification is not required.
Affiliate tracking and direct marketing
Affiliate identifiers, pixels, analytics tools and CRM audiences should be included in the data map. The team needs to understand what is collected, who receives it and how individual choices affect later processing. Cookie and electronic marketing rules must be assessed alongside GDPR and the relevant national requirements.
Our affiliate marketing support can be coordinated with privacy review so attribution requirements and partner reporting are planned with proportionate data access. We also help identify privacy issues when an affiliate website is bought or sold, including the difference between transferring a domain and transferring a subscriber database.
How we can help
An initial project may focus on a specific issue, such as a deletion request procedure, supplier contract or privacy notice. A broader programme can include data mapping, records of processing, retention, transfers, incident response and team training. We scope the work around the actual systems, markets and responsibilities of the business.
Does an offshore gaming licence remove GDPR obligations?
No. The applicability of GDPR must be assessed separately against the organisation and processing activity. A gaming licence does not determine the entire privacy position.
Do all gaming companies need a DPO?
The need for a data protection officer depends on the GDPR criteria and applicable national rules, including the nature and scale of relevant monitoring or sensitive processing. The answer should follow a documented assessment of the business.
Official sources & further reading
- EDPB data protection basics ↗
- EDPB lawful processing ↗
- EDPB individual rights ↗
- EDPB international transfers ↗
- EDPB DPIAs ↗
- EDPB data breaches ↗
Sources checked on 29 September 2026. Requirements and regulatory positions can change; confirm the current position for your project.
This page provides general information and describes potential advisory support. It is not a legal opinion on a particular business, product or market. Scope and any specialist local advice are agreed for each engagement.