Push notifications remain one of the highest-engagement channels available to iGaming operators, with open rates far above email, but the regulatory picture behind that channel has become considerably more fragmented since 2025. Consent rules, enforcement bodies, and even the definition of what counts as a "commercial message" now differ sharply by region, and several regulators have specifically targeted gambling operators for push and SMS practices that would have gone unnoticed a few years ago.
EU: GDPR and push notification consent
Push notifications sent to EU-based players fall under the same consent standard as email under GDPR: freely given, specific, informed, and revocable at any time. For iGaming specifically, this consent needs to be separate from general account terms, and it needs to be documented with a timestamp and method, not inferred from account signup or app installation.
| Requirement | Implementation | Impact on operations |
|---|---|---|
| Data minimization | Collect only what push delivery requires | Limit stored data to device ID and consent status, avoid unnecessary personal identifiers |
| User control | Simple, working opt-out inside the app or device settings | One-click unsubscribe or in-app toggle, processed immediately |
| Data protection | Encryption in transit and at rest | TLS 1.3 for all data transfers, access controls on the push platform |
Age verification adds a further layer specific to gambling advertising. Operators sending promotional push notifications to EU players need age-verification processes in place before that player is added to any marketing segment, not just at account registration.
Cross-border considerations inside the EU
GDPR provides one baseline, but individual member states layer gambling-specific rules on top. France is the clearest example: in May 2026, the gambling regulator ANJ published a joint compliance guide with the data protection authority CNIL covering exactly how GDPR applies to licensed betting, poker, and casino operators, including marketing communications sent by push, SMS, and phone. A separate French law taking effect on 11 August 2026 extends explicit consent requirements to telephone prospecting and requires operators to individually name any third party receiving player data for marketing, rather than describing partners generically. Operators running EU-wide push campaigns should treat the strictest national interpretation as the practical baseline rather than relying on GDPR text alone.
UK GDPR and PECR: separate rules post-Brexit
The UK operates its own version of GDPR alongside the Privacy and Electronic Communications Regulations (PECR), enforced by the Information Commissioner's Office. PECR specifically governs electronic marketing, including push notifications and SMS, and requires consent before sending, plus a clear way to opt out, independent of the broader UK GDPR consent framework.
Meeting EU GDPR does not automatically satisfy UK requirements, and vice versa. An operator licensed in both the EU and the UK needs two separate compliance reviews: one against GDPR plus the relevant national gambling guidance (such as the French ANJ-CNIL framework), and one against UK GDPR plus PECR. The UK Gambling Commission adds its own responsible gambling messaging requirements on top of both.
United States: state-by-state patchwork
There is no federal iGaming statute in the US. Real-money online casino gambling is legal and regulated in eight states as of mid-2026: New Jersey, Pennsylvania, Michigan, West Virginia, Connecticut, Delaware, Rhode Island, and Maine, which became the eighth state after passing tribal-exclusivity legislation in early 2026. Each state regulator sets its own rules for player communications, and operators need a state-by-state compliance map rather than a single national policy.
Federal law plays a narrow, supporting role. The Unlawful Internet Gambling Enforcement Act of 2006 restricts payment processing tied to unlawful betting but defers the definition of "unlawful" to each state. The Federal Wire Act of 1961 has been read by federal courts to apply only to sports betting, not casino games, since a 2021 First Circuit ruling that the Department of Justice has not appealed.
For push notifications specifically, operators must:
- Use geolocation tools (GPS, IP address, and often cell-tower triangulation) to confirm the recipient is physically inside a licensed state before sending any promotional push
- Secure explicit consent and verify player age before enrolling anyone in a push marketing segment
- Include responsible gambling messaging in promotional communications, per state regulator requirements
- Maintain detailed, retrievable consent records for regulatory audit
States including New York, Massachusetts, Virginia, and Maryland have active but stalled iGaming legislation, and operators eyeing expansion should expect each new state to bring its own marketing and consent rules rather than adopting an existing state's framework wholesale.
Canada: provincial licensing and consent
Canada regulates online gambling provincially rather than federally, and Ontario is by far the most developed private-operator market, with more than 50 registered operators and roughly C$2.9 billion in gaming revenue in the 2024-25 fiscal year. The Alcohol and Gaming Commission of Ontario (AGCO) enforces the Registrar's Standards for Internet Gaming, which cover marketing, inducements, and protections for vulnerable players, while iGaming Ontario manages the commercial relationship with licensed operators.
A second layer of scrutiny arrived alongside the existing framework. From 1 January 2026, Ad Standards, the national self-regulatory advertising body, began accepting public complaints against gambling advertising under the Canadian Code for Responsible Gaming Advertising, published by the Canadian Gaming Association in October 2025. A single non-compliant push campaign or promotional message can now trigger both an AGCO regulatory inquiry and a separate Ad Standards complaint, a combination that did not exist before January 2026. Ontario also announced standards in December 2025 for a centralized, cross-operator self-exclusion program, moving away from the previous operator-by-operator model, which has direct implications for how suppression lists need to be checked before any push send.
Federally, Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) sets the general data protection baseline, but Quebec's Law 25 imposes stricter consent and breach-notification requirements that apply on top of PIPEDA for any operator handling Quebec residents' data, including push and email marketing consent.
Latin America: emerging frameworks
Brazil's regulated betting and iGaming market has moved from framework to active enforcement faster than most other emerging markets. Under Law No. 14,790/2023 and the licensing regime that took effect on 1 January 2025, only operators authorized by the Secretariat of Prizes and Bets (SPA) may operate or advertise in Brazil. New advertising rules taking effect in mid-2026 require mandatory responsible gambling warnings on every promotional message and extend legal liability to marketing agencies, affiliates, and traffic managers involved in distributing that content, not just the licensed operator itself.
On the data protection side, Brazil's General Data Protection Law (LGPD) requires a lawful basis, typically consent, for processing personal data used in push or SMS marketing, and the national telecoms regulator Anatel has separately issued rules requiring opt-in consent and a working opt-out for SMS-based marketing. State-level "do-not-spam" registries add another compliance layer that varies by state and can cover phone, SMS, and in some cases email.
Mexico's data protection law (LFPDPPP) requires a privacy notice and consent mechanism for marketing communications, though enforcement specific to gambling push notifications remains less developed than in Brazil. Operators expanding into Latin America should expect the region's regulatory intensity to keep increasing rather than plateauing, particularly around advertising content and third-party liability.
Asia-Pacific: Japan, India, Philippines, Australia
Asian and Pacific markets vary more widely than any other region covered here, from near-total prohibition to active, enforcement-driven frameworks.
Japan permits only a narrow set of state-sponsored betting activities, and casino-related promotional communications remain restricted to specific integrated resort areas. Broad consumer push marketing for online casino products targeting Japanese residents sits outside the legal framework entirely for most operators.
India's regulation is state-by-state under the general umbrella of the IT Act 2000 and IT Rules 2021, which restrict digital communications that promote gambling. Some states, including Tamil Nadu, have banned advertising for online gambling and real-money games of chance outright, which extends to push notifications and SMS.
The Philippines maintains a licensing framework for offshore operators through the Philippine Amusement and Gaming Corporation, with strict requirements for player communications tied to that license.
Australia has produced the clearest recent enforcement pattern specifically involving push notifications in gambling. The Spam Act 2003, enforced by the Australian Communications and Media Authority (ACMA), requires consent and a functional unsubscribe mechanism for any commercial electronic message, a category ACMA has confirmed explicitly includes push notifications. In April 2025, ACMA found that Tabcorp, a major gambling and entertainment operator, had breached the Spam Act by sending thousands of unlawful marketing push messages, including bonus bets, deposit matches, and event tickets, to VIP program customers without valid consent or a working unsubscribe path. ACMA ran parallel investigations into PointsBet and Buddybet covering similar conduct under both the Spam Act and the Interactive Gambling Act 2001, and has stated that Spam Act compliance remains one of its enduring enforcement priorities for 2025-26. Penalties under the Spam Act can reach roughly AUD 220,000 for a single breach and up to AUD 2.1 million for repeat breaches.
| Country | Key push notification requirement | Restriction |
|---|---|---|
| Japan | Limited to state-sponsored betting activity | No casino-related push outside integrated resort areas |
| India | State-specific compliance, IT Act and IT Rules | Full advertising bans in some states, including Tamil Nadu |
| Philippines | Licensed operator framework via PAGCOR | Strict regulatory requirements for player communications |
| Australia | Consent plus functional unsubscribe under the Spam Act | Active ACMA enforcement against gambling operators specifically |
Cross-border push: geolocation and suppression
Operators running push campaigns across multiple regulated markets face a practical problem GDPR, PECR, and state-level US rules all approach differently: a single player database that spans jurisdictions needs per-region suppression logic, not one global consent flag.
Practical requirements that hold across most regions:
- Geolocation checks before every promotional send in jurisdictions like the US, where physical presence inside a licensed state is a legal requirement, not just a marketing preference
- Consent status stored per channel and per region, since a player may have valid email consent in one jurisdiction's terms but not push consent, and vice versa
- Self-exclusion and suppression lists checked immediately before send, not at the time consent was originally granted, particularly given Ontario's move toward centralized self-exclusion and similar centralization trends elsewhere
- Regional legal basis mapped separately from a single global privacy policy, since Brazil, the EU, the UK, and individual US states each define acceptable consent differently
The EU's Digital Markets Act adds a further constraint where large gatekeeper platforms are involved: if a casino distributes push notifications or retargeting audiences through a designated gatekeeper's messaging or advertising infrastructure, DMA rules can restrict how that platform combines the operator's player data with its own profiles, independent of the consent the operator collected directly. The Digital Services Act's restrictions on advertising based on profiling from sensitive data categories are also relevant wherever push segmentation touches responsible-gambling flags or self-exclusion history.
Technical implementation: consent capture to deletion
Push notification consent differs meaningfully by platform and delivery method, and treating "push" as a single technical category across iOS, Android, and web is a common source of compliance gaps.
On iOS, Apple's App Tracking Transparency framework requires a separate permission prompt before an app can track a user across other apps and websites, which is distinct from the operating system's own notification permission prompt. A player who grants notification permission has not automatically consented to cross-app tracking for ad targeting, and casino apps building lookalike audiences from push engagement data need both permissions independently.
Android's notification permission model (required as a runtime permission since Android 13) covers only the technical ability to display a notification, not marketing consent under GDPR, PECR, or the Spam Act. Operators need a separate, logged marketing opt-in layered on top of the OS-level permission.
Web push (browser-based notifications) typically uses its own consent prompt, separate from both the account-level marketing consent and any app-store permission, and needs its own suppression and audit trail.
A practical workflow most compliance teams are converging on:
- Consent capture - separate, channel-specific opt-in (push, email, SMS) captured at the point most relevant to that channel, not bundled into account terms
- Frequency capping - documented limits on send volume per player per period, tied to responsible gambling obligations in markets like Ontario and Brazil where marketing intensity is itself a regulatory concern
- Suppression - real-time cross-check against self-exclusion, unsubscribe, and geolocation status immediately before every send
- Deletion - automated removal of consent and device-token data once the documented retention period expires, tracked separately from any longer AML-driven retention of the underlying account record
Push notification compliance checklist
| Requirement | How to implement | Proof of compliance |
|---|---|---|
| Channel-specific consent | Separate opt-in for push, distinct from email and account terms | Timestamped consent log per channel |
| Geolocation verification | Confirm player location before every regulated-market send | Geolocation check logs tied to each campaign |
| Working unsubscribe | In-app toggle or one-click opt-out, processed immediately | Suppression list update and propagation logs |
| Self-exclusion suppression | Real-time check against exclusion lists before send | Pre-send suppression check records |
| Age verification | Confirm player age before marketing segment enrollment | Age verification record linked to consent |
| Platform-specific permissions | Separate handling of OS notification permission versus marketing consent | Documented consent flow per platform (iOS, Android, web) |
| Data security | TLS 1.3, access controls, encrypted device tokens | Security audit reports |
| Regular audits | Scheduled review of consent, suppression, and retention practices | Audit reports, DPIA records for new data flows |
FAQ
1Do push notifications count as marketing communications under data protection law?
Yes, in every major jurisdiction covered here. Regulators including CNIL, the UK ICO, and Australia's ACMA have confirmed that push notifications promoting products, bonuses, or offers meet the definition of a commercial or marketing communication, regardless of whether the message arrives through email, SMS, or an app notification.
2What is the difference between OS notification permission and marketing consent?
Notification permission (granted through iOS or Android system settings) only allows an app to display notifications on the device. It is not the same as consent to receive marketing content, and it does not satisfy GDPR, PECR, or Spam Act consent requirements on its own. Operators need a separate, documented marketing opt-in layered on top of the device-level permission.
3Can operators send the same push campaign across all regulated markets?
Not without regional adaptation. Consent standards, unsubscribe requirements, geolocation obligations, and responsible gambling messaging rules differ by jurisdiction, and a single global campaign risks violating at least one region's requirements. Per-region suppression logic and consent tracking are standard practice for operators active in more than one market.
4What happened in the ACMA case against Tabcorp?
In April 2025, Australia's communications regulator found that Tabcorp had sent thousands of promotional push and marketing messages to VIP program customers without valid consent or a functional unsubscribe mechanism, in breach of the Spam Act 2003. The case is one of the clearest examples of a gambling-specific enforcement action targeting push notifications directly, rather than email or general advertising.
5How does geolocation compliance work for US iGaming push notifications?
Operators use GPS, IP address, and often cell-tower triangulation to confirm a player is physically located within a state where the operator is licensed before sending any promotional push. This applies per session, not just at account registration, since a player's physical location can change between logins.
6Are affiliates and marketing partners liable for push notification violations?
Increasingly, yes. Brazil's 2026 advertising rules extend legal liability to marketing agencies, affiliates, and traffic managers distributing non-compliant promotional content, not just the licensed operator. French gambling-sector guidance similarly requires operators to individually identify any third party receiving player data for marketing, making the chain of responsibility more traceable than a generic partner disclosure.
7How often should operators review push notification compliance across regions?
At minimum annually, with a dedicated review whenever entering a new jurisdiction or when a regulator issues new guidance, such as the ANJ-CNIL framework in France or Ontario's move to centralized self-exclusion. Given how quickly enforcement patterns have shifted since 2025, particularly in Australia and Brazil, a static annual review may not catch mid-year regulatory changes, and operators active in multiple regions should track regulator announcements on a rolling basis.