
GDPR (General Data Protection Regulation, EU 2016/679) is the European Union's data protection law, governing how organizations collect, process, store and share the personal data of individuals in the EU and EEA — with extraterritorial reach over any company targeting those individuals.
iGaming sits in an awkward position under GDPR: operators are simultaneously required by gambling and AML law to collect extensive personal data — identity documents, financial records, behavioral profiles — and required by GDPR to minimize, secure and justify all of it. Key friction points:
Fines reach up to 4% of global annual turnover.
Why it matters: player data flows through every layer of the stack, so GDPR compliance is inherited from platform architecture — data mapping, retention automation and request tooling — as much as from legal policy. See how the Vuch compliance suite supports it.