Data Protection

Data Protection in Regulated Industries: The GDPR Obligations Operators Miss

GDPR compliance in regulated gaming and financial services is more complex than a privacy policy and a cookie banner. The obligations most operators are getting wrong — and the enforcement consequences when they do.

Data Protection 9 min read

The General Data Protection Regulation is now six years into its enforcement cycle, and the pattern of regulatory action is clear enough to draw reliable conclusions about where regulated businesses are most commonly failing. The volume and scale of fines has increased significantly since 2021. The sectors attracting most enforcement attention include financial services, telecoms, and — with increasing frequency — gaming and entertainment. The common thread in enforcement actions is not ignorance of GDPR; it is underestimation of its practical requirements.

Regulated gaming operators face a particular challenge. They are subject to GDPR obligations simultaneously with gaming regulatory CDD requirements and AML obligations — and those obligations overlap in ways that create tension without explicit resolution in most operators' data governance frameworks. Understanding where the conflicts arise, and how to manage them, is the starting point for meaningful GDPR compliance in a regulated gaming environment.

Lawful Basis: The Complexity Operators Miss

The most foundational GDPR concept — lawful basis — is also the most frequently mismanaged. Most regulated businesses identify a lawful basis for processing customer data at the account opening stage and do not revisit that question as the processing activities change throughout the customer relationship. This creates silent lawful basis gaps for processing activities that were added after initial framework development.

For regulated gaming operators, the relevant lawful bases and their common misapplication:

📝
Contract Performance
Covers processing necessary to deliver the gaming service. Commonly over-applied to processing that goes beyond operational necessity — marketing, analytics, and profiling that is not strictly necessary for the contracted service.
⚖️
Legal Obligation
Covers AML CDD, responsible gambling checks, and regulatory reporting — but only the specific processing required by the legal obligation. Does not automatically cover all processing associated with a regulatory framework.
🎯
Legitimate Interests
Requires a genuine legitimate interest, necessity for the processing, and a balancing test showing the interest is not overridden by the data subject's rights. The balancing test must be documented — not assumed.
Consent
Freely given, specific, informed, unambiguous. In a regulated business where consent is the only valid basis, pre-ticked boxes, bundled consent, and consent conditions on service access are all non-compliant.
AML and GDPR Tension

AML CDD obligations require collection and retention of identity, source of wealth, and transaction data for regulatory purposes. GDPR requires that data collected for one purpose (AML compliance) is not then used for a different purpose (targeted marketing, product development) without a separate lawful basis. Purpose limitation is one of the most common GDPR failures in regulated businesses — collecting data for compliance and then using it commercially without a distinct legal foundation.

Retention Schedules: The Paperwork That Prevents Enforcement

Data retention is a storage limitation obligation under GDPR Article 5(1)(e): personal data must not be kept for longer than necessary for the purpose for which it was collected. In regulated gaming, the retention question is complicated by overlapping obligations that impose minimum retention periods for different data categories — AML records, responsible gambling assessments, game play records, financial transaction records.

The practical failure in most operators is not that they retain data too long, but that they retain data indefinitely without a documented retention schedule, and they cannot demonstrate that the retention period for any specific data category has been assessed and justified. This is a consistent regulatory finding in ICO investigations and a pattern that enforcement actions across Europe have identified.

A defensible data retention framework covers:

€1.2B in GDPR fines issued across EU and EEA in 2023 — record year, with financial sector and gaming increasingly featured
72hrs maximum time to notify the supervisory authority of a personal data breach likely to result in risk to individuals — frequently missed
30 days deadline for responding to a data subject access request under GDPR — extendable by 2 months for complexity with reasons given

Data Subject Access Requests: The Operational Test

The volume of Data Subject Access Requests received by regulated gaming operators has increased significantly since 2020. The combination of politically charged departures, responsible gambling self-exclusion disputes, and AML-adjacent customer relationship terminations creates a specific pattern of DSARs that are more complex than typical consumer requests and carry higher litigation risk.

The operational failures in DSAR handling that most commonly create regulatory exposure:

"A DSAR from a recently self-excluded, recently exited, or recently SAR'd customer is not a routine administrative request. It is a legal process with a deadline, a disclosure obligation, and litigation potential. It needs to be treated accordingly from the moment it is received."

Breach Notification: The 72-Hour Clock

The 72-hour breach notification requirement under GDPR Article 33 is one of the most operationally demanding provisions of the regulation. Seventy-two hours from becoming aware of a breach is not enough time to fully investigate the incident, assess its scope, or determine its impact with certainty. The requirement is to notify with the information available at the time, updating the notification as further information becomes available.

Most regulated businesses have a documented incident response process that includes data breach identification and notification steps. The operational gap is typically in the triage layer — the process for identifying whether a security incident, data loss event, or unauthorised disclosure constitutes a "personal data breach" within the GDPR definition, and whether it is likely to result in "risk to the rights and freedoms of individuals" triggering the notification obligation.

The threshold question requires a documented assessment methodology. Not every data incident is a notifiable breach — but the assessment needs to be documented in every case, and notifications need to be made promptly in cases where the threshold is met. The ICO's enforcement record shows that late notification — notification beyond 72 hours without adequate justification — is treated as a distinct failure separate from the underlying breach.

Responsible Gambling Data: The Special Category Intersection

Responsible gambling data collected by gaming operators — self-exclusion records, spend limit settings, responsible gambling assessments, referrals to support services — may constitute special category personal data under GDPR Article 9. Data that reveals health condition, addiction vulnerability, or participation in addiction support services is health data, which attracts the highest level of protection under the regulation.

The practical implications for gaming operators are significant. Special category data requires an explicit legal ground for processing under Article 9 in addition to the Article 6 lawful basis. The processing must be documented with specific justification. Access controls must reflect the sensitivity of the data — responsible gambling records should not be accessible to operational staff who have no legitimate need to review them. Retention periods for health-adjacent data should be assessed against the specific sensitivity, not the generic player record retention schedule.

The intersection with responsible gambling regulatory obligations creates an additional tension: operators are required by gaming regulation to maintain and act on responsible gambling records, while GDPR requires that the same records are processed with specific legal grounds, strict access controls, and purpose limitation. Both obligations can be satisfied, but only if the compliance framework explicitly addresses the intersection.

GDPR compliance review for regulated operators

Wise Key Solutions provides data protection compliance reviews for regulated gaming businesses, covering lawful basis assessment, retention framework development, DSAR process review, and breach notification readiness. Contact us to discuss your requirements.

Speak to our team →

This article reflects the operational perspective of the Wise Key Solutions founding team, drawing on CIPP/E qualified experience in data protection compliance for regulated industries. It does not constitute legal advice. Operators should obtain qualified legal counsel for specific GDPR compliance questions.