The National Gaming Authority publishes a guide to apply the GDPR to player data processing
The National Gaming Authority (ANJ), in consultation with the Commission Nationale de l'Informatique et des Libertés (CNIL), has published a practical guide to assist gambling operators in applying the GDPR to their processing of player data.
This non-prescriptive guide provides recommendations to help operators reconcile GDPR requirements with their sector-specific obligations, notably regarding the prevention of excessive gambling and the fight against money laundering and terrorist financing (AML-CFT). The scope of the document covers only processing related to gaming activities under the ANJ's jurisdiction, excluding general company management. It details the appropriate legal bases and retention periods for managing player accounts, notably recalling the obligation to retain certain data for 6 years after account closure.
The document specifies that identifying a player at risk of excessive gambling constitutes processing of health data, requiring enhanced safeguards and a data protection impact assessment. It regulates the use of algorithmic tools, emphasizing that Article 22 of the GDPR does not apply if human review occurs before any significant decision, and reminds that any unilateral restriction on the ability to play must be subject to human oversight. For AML-CFT, processing is based on a legal obligation and must respect the principles of proportionality and data minimization, with specific safeguards such as access limitation and prohibition of data reuse.
This non-prescriptive guide provides recommendations to help operators reconcile GDPR requirements with their sector-specific obligations, notably regarding the prevention of excessive gambling and the fight against money laundering and terrorist financing (AML-CFT). The scope of the document covers only processing related to gaming activities under the ANJ's jurisdiction, excluding general company management. It details the appropriate legal bases and retention periods for managing player accounts, notably recalling the obligation to retain certain data for 6 years after account closure.
The document specifies that identifying a player at risk of excessive gambling constitutes processing of health data, requiring enhanced safeguards and a data protection impact assessment. It regulates the use of algorithmic tools, emphasizing that Article 22 of the GDPR does not apply if human review occurs before any significant decision, and reminds that any unilateral restriction on the ability to play must be subject to human oversight. For AML-CFT, processing is based on a legal obligation and must respect the principles of proportionality and data minimization, with specific safeguards such as access limitation and prohibition of data reuse.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire