Vuch logo

GDPR

Published: 2026-08-12Last updated: 2026-08-12

GDPR (General Data Protection Regulation, EU 2016/679) is the European Union's data protection law, governing how organizations collect, process, store and share the personal data of individuals in the EU and EEA — with extraterritorial reach over any company targeting those individuals.

iGaming sits in an awkward position under GDPR: operators are simultaneously required by gambling and AML law to collect extensive personal data — identity documents, financial records, behavioral profiles — and required by GDPR to minimize, secure and justify all of it. Key friction points:

  • Lawful basis mapping — KYC/AML processing rests on legal obligation; marketing rests on consent or legitimate interest, each with different revocation rules;
  • Retention conflicts — AML law may require keeping records for approximately five or more years even after a "right to erasure" request; operators need documented retention schedules reconciling the two;
  • Profiling — responsible gambling and fraud models are automated processing of behavioral data and must be disclosed and defensible;
  • Data subject requests — access and portability requests must pull data from PAM, CRM, payments and affiliate systems alike;
  • Processor contracts — every platform vendor, PSP and analytics tool touching player data needs a compliant DPA.

Fines reach up to 4% of global annual turnover.

Why it matters: player data flows through every layer of the stack, so GDPR compliance is inherited from platform architecture — data mapping, retention automation and request tooling — as much as from legal policy. See how the Vuch compliance suite supports it.

Related reading
See the Vuch platform in action
A 30-minute walkthrough of the back office, cashier, and compliance tooling — on your market’s terms.