Physically separate perimeter
The register runs on its own database and its own network perimeter, separate from the enforcement environment. It is not a table inside the enforcement system.
Platform
Mandatory player-protection measures are only real if someone checks that they exist and work. We verify them automatically, then give citizens a single place to exclude themselves from the entire licensed market.
Phase A
Promotional material is monitored against the advertising standards set by the regulator, with captures retained as evidence.
Phase B
Comparable national schemes
The register runs on its own database and its own network perimeter, separate from the enforcement environment. It is not a table inside the enforcement system.
Citizen identifiers are held pseudonymised, with the keys managed in a hardware security module rather than in application configuration.
The operator-facing API returns only a yes or no and, where applicable, an expiry date. It returns no name, no identity number and no history.
There is no path by which citizen data from the self-exclusion register flows into the enforcement environment. The separation is architectural, not procedural.
A self-exclusion register asks vulnerable citizens to hand the state a list of their own vulnerability. The privacy architecture is therefore the product, not a safeguard bolted onto it.