Dispatch № 2162 min read

GDPR and Online Casinos: What European Players Should Know

GDPR grants European players data rights that American players do not have. A casino holding your betting data must disclose it to you. Few European players exercise this right.

GDPR and Online Casinos: What European Players Should Know
File / gdpr-online-casinos-european-playersGamble24 · Editorial
Share

The General Data Protection Regulation took effect in May 2018. It applies to any organization processing personal data of European residents, including online casinos. The practical implication: an online casino operating in the EU must allow players to request and receive a copy of all data the casino holds on them.

The data includes obvious things: name, email, address, payment methods used, KYC documents submitte

The data includes obvious things: name, email, address, payment methods used, KYC documents submitted. It also includes operational data: every bet you have placed, every hand of blackjack you have played, every spin of roulette you have made. The casino's analytics systems track this data continuously. Under GDPR, you have the right to request it.

How many players exercise this right? The data is limited, but available figures suggest fewer than 1 percent of regulated European casino players have requested their data. Why would they? A few reasons. First, the request is administratively burdensome. You need to identify the operator's Data Protection Officer, submit a formal GDPR access request, and wait up to 30 days for the response. Second, the data is uncomfortable to see. Reviewing 18 months of daily betting history is a confrontation with pattern that many players avoid. Third, most players do not realize this right exists.

But for the players who have used it, the data reveals patterns that are hard to deny. A player might have assumed they lost 3,000 euros to a casino over a year. The data shows 47,000 euros wagered against a 2.7 percent house edge, which projects to 1,269 euros in expected losses. The actual loss is 1,847 euros. The data maps reality in a way that intuition does not.

The casinos acknowledge this. Several EU operators have quietly published data on GDPR access requests. On average, players request access once per 5,000 active accounts. When players do request access, 4 percent of them subsequently close their accounts within 30 days. This suggests the data access is having an effect: confronting players with their own statistics produces some behavioral change.

GDPR also grants the right to erasure. A player can request that the casino delete all data within a defined period. Casinos are required to comply with this within 30 days, except where data retention is required by law (which applies to most of the data that casinos hold, due to AML and KYC regulations). In practice, erasure requests are mostly denied, and players appeal the denials, and the cases take months to resolve.

The policy implication is that GDPR gives European players transparency that American players lack. An American player at DraftKings has no legal right to review their betting history on their own terms. The operator can track it, sell insights derived from it, and use it to optimize their targeting. A European player at an EU-licensed casino has the right to review and the right to understand what the casino knows about them.

This transparency has not prevented gambling disorder in European jurisdictions. It has increased player awareness of their own behavior. Whether awareness translates to reduced gambling is unclear. The data shows only that some players, upon confronting their own statistics, choose to reduce exposure.

End of Dispatch № 216
Continue reading

Next in the archive

Browse all →