Skip to content

Platform

Player Protection & Responsible Gambling

Mandatory player-protection measures are only real if someone checks that they exist and work. We verify them automatically, then give citizens a single place to exclude themselves from the entire licensed market.

Phase A

Verifying that the tools are actually provided

Automated monitoring establishes, licensee by licensee, whether the mandatory measures required by the regulator are present, functional and correctly presented — rather than declared in an annual compliance return.

Operator obligations checked

  • Age restriction labelling is present and correct.
  • A responsible-gambling page exists and actually works.
  • Deposit, session and loss limits are offered and can be set.
  • A self-exclusion path is reachable without unreasonable friction.
  • Helpline contact details are published and current.
  • Risk warnings appear correctly on promotional material.

Advertising compliance monitoring

Promotional material is monitored against the advertising standards set by the regulator, with captures retained as evidence.

  • Creatives that promise guaranteed winnings.
  • Creatives that present gambling as a source of income.
  • Creatives that target, or are likely to appeal to, young audiences.

Phase B

A national self-exclusion register

One place where a citizen bars themselves from every licensed operator at once, instead of repeating the request operator by operator and hoping each one honours it.

Comparable national schemes

  • GAMSTOPUnited Kingdom
  • RGIAJSpain
  • Rejestr WykluczonychPoland

Physically separate perimeter

The register runs on its own database and its own network perimeter, separate from the enforcement environment. It is not a table inside the enforcement system.

Pseudonymised identifiers

Citizen identifiers are held pseudonymised, with the keys managed in a hardware security module rather than in application configuration.

Minimal API surface

The operator-facing API returns only a yes or no and, where applicable, an expiry date. It returns no name, no identity number and no history.

No reverse flow

There is no path by which citizen data from the self-exclusion register flows into the enforcement environment. The separation is architectural, not procedural.

A self-exclusion register asks vulnerable citizens to hand the state a list of their own vulnerability. The privacy architecture is therefore the product, not a safeguard bolted onto it.