GDPR for iGaming: map data, purpose and responsibility
GDPR compliance starts with understanding which personal data the business processes, why it processes it and who is responsible. An iGaming operator should assess verification, payments, player protection and marketing separately rather than rely on one blanket consent statement.
iGaming Cyprus · Last updated:
Which processing activities should be mapped?
The EDPB describes lawfulness, purpose limitation, data minimisation and accountability among the core principles. Its legal-basis guidance identifies different possible bases depending on the processing context.
Create a processing map covering account creation, verification, transactions, risk monitoring, support, marketing and reporting. Record the data, purpose, lawful basis, recipients and retention rule. Where sensitive information is involved, assess the additional conditions rather than assuming the ordinary basis is enough.
Why is consent not a universal solution?
Different activities may rely on different lawful bases. A customer cannot meaningfully be told that every processing activity is optional if some is needed to comply with a legal obligation.
Explain the actual purposes in the privacy notice and operational procedures. Keep marketing permissions distinct from information required to operate or meet obligations. The classification must reflect the facts and applicable law, not whichever checkbox is easiest to implement.
How should supplier roles be assessed?
Identify whether each party acts as a controller, processor or in another relevant arrangement for the specific processing. A contract’s label should match the actual decisions and activities.
- List platform, verification, payments, support and analytics vendors.
- Identify what data each receives and where it is accessed.
- Document instructions, security and assistance responsibilities.
- Assess sub-processors and international transfers.
- Define return, deletion and access arrangements at termination.
How should customer rights work operationally?
Give requests a clear intake route, identity-check process and accountable owner. The team needs to find relevant records across systems while protecting other people’s data and respecting applicable exceptions.
For example, a deletion request may intersect with legal retention duties. The response requires an assessment of the particular records and obligations, not automatic deletion of everything or a blanket refusal. Record the reasoning and explain the outcome appropriately.
What should be tested?
Rehearse a rights request, a supplier change and an unauthorised-access incident. These exercises reveal whether the data map is usable and whether the business knows where information resides.
Keep privacy integrated with product changes. A new player-risk model or data-sharing arrangement can alter the assessment. Review the purpose, necessity, safeguards and any impact-assessment requirement before treating the change as a routine software release.
Frequently asked questions
Do not assume so. Assess each purpose and the appropriate lawful basis.
No. Determine roles and obligations for the actual processing arrangement.
Sources and scope
This guide was prepared with AI assistance using the linked sources. It provides general information and practical preparation suggestions, not a legal opinion for a particular business. No personal professional review is claimed.
Get the right structure for your case
Book a free, no-obligation consultation. We’ll confirm the right Cyprus company + licence setup and a fixed fee for your business.