The latest news from the Casino world!
Gambling club ai ia

What the GDPR requires of casinos 

Gambling operators handle a significant amount of personal data every day. Between the requirements of the General Data Protection Regulation (GDPR) and the obligations specific to the gambling sector, compliance can quickly become complex. To address this challenge, the National Gaming Authority (ANJ), in consultation with the National Commission for Information Technology and Civil Liberties (CNIL), published a guide on 2 July 2026 designed to help professionals apply data protection rules correctly. 

A dual obligation for operators 

Behind every player account lies a wealth of personal information. In particular, operators process players’ identities, contact details, banking information, financial transactions and gaming history. However, this data processing is not solely for commercial purposes. It must also comply with particularly strict legal obligations, notably regarding the prevention of problem gambling, the fight against money laundering and the financing of terrorism. 

How can personal data be effectively protected whilst fulfilling these public interest tasks? It is precisely this question that the new guide, drawn up by the ANJ with the active involvement of the CNIL, seeks to address. Both authorities emphasise, however, that this document is not binding. It is, above all, a set of practical recommendations designed to help operators achieve better compliance. 

A guide limited to activities related to gambling 

The document does not cover all data processing carried out by companies in the sector. Its scope is limited solely to the processing of personal data directly linked to gambling and games of chance falling within the ANJ’s remit. 

Traditional business management activities, such as human resources, accounting or financial management, remain subject to the standard rules of the GDPR but are not addressed in this guide. 

The main recommendations focus on three areas 

The guide first sets out the fundamental principles of the GDPR before offering concrete recommendations across three main areas. 

The first concerns the management of player accounts and marketing activities. 

The second focuses on the prevention of excessive or pathological gambling. 

Finally, the third deals with obligations relating to the prevention of money laundering and the financing of terrorism. 

For each of these areas, the document sets out the applicable legal bases, the rights of data subjects and the conditions for ensuring that processing remains proportionate to the purposes pursued. 

An appropriate legal basis for each processing operation 

Not all data collected serves the same purpose. The guide emphasises the need to identify an appropriate legal basis for each processing operation carried out as part of the relationship with players. 

This applies in particular to the opening and management of accounts, the handling of complaints, loyalty programmes, statistics and the management of disputes. 

Specific rules on data retention 

The guide reiterates that certain data must be retained for six years after the closure of a player’s account where required by sector-specific regulations. 

For other processing activities, particularly those relating to marketing, loyalty programmes, disputes or statistics, the recommendations are based on the guidance already published by the CNIL regarding the management of commercial activities. 

Preventing problem gambling whilst protecting privacy 

The prevention of problem gambling is one of the most sensitive aspects of the guide. 

Operators have a legal obligation to put in place measures to identify players at risk of developing excessive or pathological gambling behaviour. However, this monitoring does not mean that all data can be collected without restriction. 

The guide strongly emphasises the principles of necessity, proportionality and data minimisation. In particular, it recommends against systematically collecting all available information on a player. 

Certain data should only be collected when a specific event occurs. This applies in particular to information relating to a player’s behaviour, which may only be recorded if their behaviour is atypical. 

The guide also recommends that exchanges with a player’s relatives should not be included in their file. Instead, operators are advised to record only the existence of the alert and its general nature, such as financial difficulties, family conflicts, isolation or particular vulnerability. 

According to the document, identifying a player at risk of excessive or pathological gambling constitutes the processing of health data within the meaning of the GDPR. This classification automatically triggers stricter requirements. 

Algorithms cannot decide on their own 

Algorithmic tools are playing an increasingly important role in detecting risky behaviour. 

The guide points out, however, that the use of these technologies must comply with the provisions of Article 22 of the GDPR, which governs fully automated decisions that produce legal effects or have significant consequences for individuals. 

The document does, however, specify that certain situations fall outside this framework. Where a player receives only preventative messages, without any decision having legal or significant effects being taken, the rules of Article 22 do not apply. Conversely, as soon as a restriction on the ability to gamble is being considered, human intervention becomes essential. 

Enhanced vigilance against money laundering 

Obligations relating to the fight against money laundering and the financing of terrorism also feature prominently in the document. Data processing carried out in this context is primarily based on a legal obligation. It relates in particular to player due diligence measures, the detection of unusual transactions, reports of suspicious activity and asset freezing measures. 

Operators must collect only the information strictly necessary to assess the risk posed by each player. Enhanced data collection must not be systematic and must comply with the principle of data minimisation set out in the GDPR. 

A framework designed to facilitate compliance 

With this new guide, the ANJ and the CNIL aim, above all, to provide operators with practical guidance on how to apply both the GDPR rules and the specific obligations of the gambling sector simultaneously. 

By bringing together the requirements relating to data protection, the prevention of problem gambling and the fight against money laundering in a single document, the two authorities are offering a coherent framework designed to strengthen compliance whilst maintaining a high level of protection for players. 

What is the situation in Belgium? 

Whilst the guide published by the CNIL and the National Gaming Authority (ANJ) applies exclusively to operators subject to French regulation, Belgian operators are also subject to strict obligations regarding the protection of personal data. 

In Belgium, gambling operators must also comply with the General Data Protection Regulation (GDPR), which is directly applicable throughout the European Union. They are also required to comply with national legislation on gambling, under the supervision of the Gaming Commission (GC). As in France, they process sensitive data on a daily basis, such as players’ identities, payment details, betting histories and the data required for regulatory checks. 

 | 

Sarah has a sharp eye for trends in the gambling world. With a passion for sport, she covers everything from responsible gaming to casino legislation. Her writing makes complex topics accessible to readers.

Recommended

France bans betting on esports, but what is the situation in Belgium?  

2025 report from the Gaming Mediator 

Lack of player protection: €500,000 fine imposed by the ANJ 

Home Casinos Promos Promos