EN RU
List your company
Compliance July 27, 2026 13 min read

Casino email compliance: GDPR rules explained for 2026

Email marketing to EU players sits at the intersection of two regulatory regimes that were not designed with each other in mind. GDPR wants short retention, minimal data, and revocable consent. Gambling law wants long retention for anti-money laundering checks, mandatory regulatory reporting, and responsible gambling monitoring. Operators who treat these as separate compliance tracks tend to fail both.

Email marketing to EU players sits at the intersection of two regulatory regimes that were not designed with each other in mind. GDPR wants short retention, minimal data, and revocable consent. Gambling law wants long retention for anti-money laundering checks, mandatory regulatory reporting, and responsible gambling monitoring. Operators who treat these as separate compliance tracks tend to fail both.

What GDPR demands from casino email programs

Three obligations drive most of the risk in casino email marketing: valid consent before sending, a working unsubscribe mechanism, and clear disclosure of how player data moves between the operator, its CRM vendor, and any affiliate or media partner.

None of these are new in 2026, but enforcement has moved from warning letters to nine-figure fines, and the interaction between GDPR and national gambling regulators has tightened. France offers the clearest example: in May 2026, the countrys gambling regulator ANJ published a 59-page compliance guide jointly with the data protection authority CNIL, covering exactly how GDPR applies to licensed betting, poker, and casino operators, and to the marketing companies and payment processors that process player data on their behalf.

Why this matters more than it did in 2025

Regulators are no longer treating marketing automation as a low-risk category. CNIL alone issued dozens of sanctions in 2024 tied to commercial prospecting, and by 2025 was fining companies in the tens and hundreds of millions of euros for sending marketing emails without valid consent or for ignoring cookie rejections. A casino running email campaigns through a third-party CRM platform is exposed to the same scrutiny as any other advertiser, with the added layer of gambling-specific obligations on top.

GDPR Article 4(11) requires consent to be freely given, specific, informed, and unambiguous. For gambling operators specifically, French regulation goes further: Decree No. 2010-518 requires operators to ask players separately, before an account is even opened, whether they agree to commercial prospecting. This separation from the general terms and conditions is not optional.

A pre-ticked box, a bundled "I agree to the terms and marketing" checkbox, or consent inferred from account signup does not meet the bar. Each of these has been the basis for fines against non-gambling companies in the past two years, and there is no reason to expect gambling regulators to apply a lower standard.

Consent requirement How to implement Common failure
Separate consent Standalone, unticked checkbox for marketing, apart from account terms Marketing consent bundled into general terms acceptance
Active choice Box unticked by default, no pre-selection Pre-checked boxes disguised as "preferences"
Specific purpose Clear statement of what the player is consenting to (email, SMS, phone) Vague "communications" language covering multiple channels
Documented consent Timestamp, method, and source of consent logged and retrievable No audit trail, or consent purchased from a third-party list
Partner disclosure Named list of any third parties who will receive the data for marketing Generic "our partners" language with no identification

That last row has become a specific enforcement point in France. From 11 August 2026, a new law extends explicit consent requirements to telephone prospecting and requires that any commercial partner receiving player data for marketing purposes be individually identified to the player at the point of collection, not described in general terms. Operators sharing data with affiliate networks or media buyers for retargeting should treat this as the direction regulators across the EU are heading, even outside France.

Cookie consent and email consent are increasingly treated as one continuous chain rather than two separate mechanisms. If a player rejects marketing cookies on a casino site, using data collected through other means to justify an email campaign to that same player is the kind of gap regulators have already fined companies for exploiting.

Unsubscribes and the right to be forgotten

GDPR Article 7(3) is explicit on this point:

"The data subject shall have the right to withdraw his or her consent at any time... It shall be as easy to withdraw as to give consent."

GDPR, Article 7(3)

In practice, that means a one-click unsubscribe link in every marketing email, immediate processing (same-day, not "within a few business days"), and a suppression list that actually prevents re-entry into future sends. Casinos running campaigns across multiple systems, an in-house CRM plus an affiliate network plus an SMS provider, need the unsubscribe to propagate across all of them, not just the system where the player clicked the link.

A player who unsubscribes but continues receiving promotional emails from a different internal system, or from a partner who was not informed of the withdrawal, is a documented GDPR violation regardless of intent. Regulators have shown no patience for "the systems werent synced" as an explanation.

Self-exclusion: where GDPR meets gambling law

This is the section where gambling regulation adds obligations GDPR does not contain on its own, and where the two regimes are hardest to reconcile.

Under GDPR alone, a self-excluded player who withdraws marketing consent should simply stop receiving promotional email. Gambling law adds two further requirements: the exclusion must be actioned quickly, and it must be verifiable to the regulator on request as part of responsible gambling reporting, which in turn requires retaining a record of the player and their exclusion status for longer than GDPR's data minimization principle would otherwise suggest.

The practical requirements operators should be building toward:

  • Self-exclusion requests actioned within a short, defined window. Two business days is the benchmark most compliance guidance still cites, though several licensing regimes now expect same-day suppression given that automated systems make same-day action technically straightforward.
  • Suppression applied across every channel simultaneously: email, SMS, push, and any affiliate or media partner who received the player's contact details for marketing.
  • A failsafe check before every campaign send that cross-references the current self-exclusion list, not a list that was accurate at the time consent was originally given.
  • A retained record of the exclusion event itself (date, method, channel) kept separately from general marketing data, justified under the gambling-law legal basis rather than the marketing consent basis.

The ANJ-CNIL guidance published in France in 2026 addresses this tension directly, confirming that operators are expected to run data protection impact assessments specifically where gambling-law retention (for AML and responsible gambling purposes) extends beyond what GDPR would permit for marketing data alone. The retention periods are not identical, and conflating them, keeping all player data for AML-length periods and using that same dataset for marketing, is a foreseeable audit finding.

Failure here carries the same maximum exposure as any other GDPR violation: up to €20 million or 4% of global annual turnover, whichever is higher. Gambling regulators can layer separate licensing sanctions on top, including fines issued directly by national gambling commissions for social responsibility and AML failings that are unrelated to the GDPR fine itself.

Data security requirements

The security baseline for any system handling player data for marketing has moved beyond SSL. TLS 1.3 is now the practical standard for data in transit, and operators still citing "256-bit SSL" in vendor contracts should confirm what is actually running under the hood, since SSL itself has been deprecated for years in favor of TLS.

Baseline requirements for any CRM or marketing automation platform handling EU player data:

  • TLS 1.3 (or a currently supported TLS version) for all data transfers, not legacy SSL
  • Multi-factor authentication on any system with access to player contact and consent data
  • Automated retention and deletion workflows tied to documented retention schedules, rather than manual, ad hoc deletion
  • Routine security audits and a documented incident response plan
  • Role-based access controls limiting who inside the organization, and at any vendor, can export or query the marketing database

Data Protection Impact Assessments are not a one-time exercise. Given the AML-retention overlap described above, casinos should be running a DPIA whenever a new data flow is introduced, a new marketing partner is added, or retention periods change.

GDPR enforcement in iGaming: 2025-2026 cases

Direct fines against gambling operators specifically for email or SMS marketing violations remain less publicly documented than fines against telecoms and ad tech companies, but the broader enforcement pattern is unambiguous and gambling operators sit squarely inside it.

In January 2025, the French regulator CNIL fined a telecommunications operator 50 million euros for sending marketing emails without valid consent and for continuing to place cookies on devices after users had rejected them, with an additional daily penalty for continued non-compliance. In May 2025, CNIL fined a data broker 80,000 euros for commercial prospecting without valid consent and for transferring data to partners without a proper legal basis, and separately fined a marketing services company 900,000 euros for the same combination: prospecting without consent, paired with an order to halt the practice entirely. In September 2025, CNIL fined Google 325 million euros over advertisements shown between Gmail users' emails without consent, alongside cookie violations.

Across the EU and UK, regulators have issued more than 2,500 fines totalling over 7 billion euros since GDPR took effect in 2018, with roughly 1.2 billion euros of that issued in 2025 alone, and 2025 breach notifications rose 22% year over year. The pattern in every marketing-related case above is the same one gambling operators are exposed to: consent that was bundled, inferred, or purchased from a third party rather than given directly and separately for marketing.

Outside CNIL, UK gambling-specific enforcement in 2025 shows the parallel track operators face regardless of GDPR: the Gambling Commission fined an online operator over 2 million pounds for anti-money laundering and social responsibility failings in May 2025, and separately fined another operator 375,000 pounds for similar social responsibility and AML failures. These are licensing sanctions, not GDPR fines, but they illustrate that a casino facing a data protection investigation is very often facing a parallel gambling-law investigation into the same underlying player records.

UK GDPR, DMA, and DSA: what else applies

UK GDPR has diverged from the EU version in emphasis rather than substance. The Information Commissioner's Office generally takes a similarly strict line on consent for direct marketing, enforced jointly with the Privacy and Electronic Communications Regulations (PECR) rather than GDPR alone. Operators licensed in both the UK and an EU member state need two separate compliance tracks: EU GDPR plus the relevant national implementation (in France, the CNIL and ANJ framework described above), and UK GDPR plus PECR, with no assumption that meeting one satisfies the other.

The EU's Digital Markets Act affects casinos indirectly but meaningfully where large third-party platforms are involved. Where an operator advertises through or shares data with a designated "gatekeeper" platform for retargeting or lookalike audience marketing, DMA data-combination restrictions can limit how that platform is allowed to merge the operator's player data with its own advertising profiles, independent of the consent the operator itself collected.

The Digital Services Act overlaps with GDPR most directly on targeted advertising to vulnerable users and on transparency for online advertising generally. For gambling specifically, DSA provisions restricting targeted advertising based on profiling of data revealing categories such as health (which can be read to include gambling-related harm indicators) are relevant wherever a casino's marketing segmentation touches responsible-gambling flags or self-exclusion history. Combining GDPR consent analysis with DSA advertising-transparency review is becoming standard practice for compliance teams handling EU player marketing.

A practical compliance pipeline for casino email teams generally covers four stages:

  1. Capture - separate, unticked marketing consent checkbox at signup, with the specific channel (email, SMS, phone) and any named third-party recipients disclosed at the point of collection.
  2. Storage - timestamped, retrievable consent record stored separately from general account data, with retention period documented and justified against a specific legal basis (marketing consent versus AML/gambling-law retention).
  3. Audit - scheduled review, at minimum annually, cross-referencing active marketing sends against the current consent and self-exclusion status of every recipient, plus a DPIA whenever a new data flow or partner is introduced.
  4. Deletion - automated purge of marketing consent and contact data once the documented retention period expires, separate from any AML-required retention of the underlying account record.

GDPR compliance checklist for casino email teams

Requirement How to implement Proof of compliance
Separate, explicit consent Standalone opt-in checkbox, unticked by default, apart from account terms Timestamped consent log with method and source
Named partner disclosure List any third party receiving data for marketing at point of collection Documented disclosure shown to the player, retained on file
Immediate unsubscribe One-click unsubscribe link, processed same day across all systems Suppression list update logs, cross-system propagation records
Self-exclusion suppression Cross-check exclusion list before every send, across all channels and partners Pre-send suppression check logs, exclusion event records
Data minimization Collect only what marketing sends require, separate from AML-required data Data inventory mapped to legal basis per field
Security baseline TLS 1.3, multi-factor authentication, access controls Security audit reports, access logs
Retention and deletion Automated deletion tied to documented schedule per legal basis Deletion logs, retention policy documentation
Regular audits At minimum annual review, DPIA on new data flows or partners DPIA records, audit reports

FAQ

1What is the maximum GDPR fine for email marketing violations?

The statutory maximum is €20 million or 4% of global annual turnover, whichever is higher, for the most serious violations, including unlawful processing and consent failures. Recent enforcement shows regulators willing to use the upper end of that range against companies of sufficient size, and gambling operators can face separate licensing fines from national gambling regulators on top of any GDPR penalty.

2Does GDPR apply to non-EU casino operators?

Yes, if the operator targets or processes the data of individuals located in the EU, regardless of where the company is incorporated or hosted. Regulators have confirmed jurisdiction over processors and controllers with no EU establishment where their marketing or profiling activity monitors the behavior of people in the EU.

3How long do casinos have to process an unsubscribe request?

GDPR requires that withdrawal be as easy and immediate as giving consent, which in practice means same-day processing rather than a multi-day window. Any delay that results in a further marketing email being sent after the unsubscribe request is a documentable violation.

4Can a casino email a player who self-excluded?

No. Self-excluded players must not receive promotional email, SMS, or other marketing communication through any channel, including from affiliate or media partners who received the player's data before exclusion. Suppression needs to be checked immediately before every send, not only at the point exclusion was recorded.

5What counts as valid consent under GDPR for casino marketing?

Consent must be freely given, specific, informed, and given through a clear affirmative action, typically a standalone, unticked checkbox separate from general account terms. Consent bundled into terms and conditions acceptance, inferred from account signup, or purchased from a third-party list without re-verification does not meet this standard.

6Do casino affiliates need to comply with GDPR?

Yes. Any affiliate or partner receiving player data to send marketing communications, or to build retargeting audiences, is processing personal data under GDPR and needs its own valid legal basis. Under French gambling-sector guidance, operators sharing data with such partners must individually identify those partners to the player at the point of collection rather than describing them generically.

7How often should casinos audit their email compliance?

At minimum annually, with a Data Protection Impact Assessment run whenever a new marketing partner, data flow, or retention change is introduced. Given the overlap between GDPR retention limits and gambling-law AML retention requirements, audits should specifically check that marketing use of player data does not extend beyond the marketing-specific legal basis and retention period.

more from blog

Keep reading

All articles