The General Data Protection Regulation (GDPR) is the European Union's data-protection law, in force since 2018, governing how organisations collect, use, store and share personal data about people in the EU and EEA.
Definition
The General Data Protection Regulation (GDPR) is the European Union's data-protection law, in force since 2018, governing how organisations collect, use, store and share personal data about people in the EU and EEA. It applies to any business that targets or monitors EU/EEA residents regardless of where the business is located, which brings most iGaming operators and many affiliates within its scope.
The UK has its own near-identical version (UK GDPR) after leaving the EU.
GDPR is built on principles: process data lawfully, fairly and transparently; collect it for specified purposes and no more; keep only what is necessary and only as long as needed; keep it accurate and secure; and be accountable, meaning able to demonstrate compliance. It also grants individuals enforceable rights over their data — access, correction, deletion, portability, objection, and restriction of processing.
In context
For iGaming, GDPR touches the whole data lifecycle. Every processing activity needs a lawful basis: contract (running the player's account), legal obligation (KYC and AML record-keeping), legitimate interests (fraud prevention, some analytics), or consent (marketing cookies, some profiling).
Consent must be freely given, specific, informed and as easy to withdraw as to give — so pre-ticked boxes and "consent walls" bundling marketing with service access do not qualify. Special care applies to profiling that affects players, and responsible-gambling monitoring has to be justified carefully as it processes behavioural data at scale.
Operationally, operators and affiliates must maintain records of processing, sign data-processing agreements with vendors (trackers, CRM, analytics, PSPs), run data-protection impact assessments for high-risk processing, honour data-subject requests within a month, report qualifying breaches to the regulator within 72 hours, and appoint a Data Protection Officer where required. International data transfers out of the EEA need a valid transfer mechanism.
For affiliates, the common failure points are dropping tracking and advertising cookies before consent, sharing player or lead data without a proper agreement and lawful basis, and email marketing to lists without demonstrable opt-in. Fines reach into the tens of millions of euros or a percentage of global turnover, and regulators in the sector have shown willingness to use them.
Worked example
An operator runs a data audit and finds its analytics and affiliate-tracking cookies fire on page load before the consent banner is answered. It re-implements the banner to block all non-essential cookies until the user opts in, adds a data-processing agreement with its tracker vendor, and documents a lawful basis for each processing purpose.
An affiliate emailing a bought list without opt-in evidence is dropped by the programme.
Related terms
Frequently asked questions
Browse the full iGaming & affiliate glossary — hundreds of EN/RU terms with examples.
← Back to glossary