Covered elsewhere
Data Protection
Data protection obligations are not covered in this report. They are not specific to gambling licensing: the controller and processor duties that apply to a licensee are the same ones that apply to any business handling personal data in this jurisdiction, so this report links to the specialist source rather than restating it. Gambling-specific privacy duties -- player data retention, age and identity verification, marketing consent -- are covered in the player protection and operational obligations sections above.
Architecture patterns
7 patternsSingle-hosting-facility monopoly underlying a multi-CPA ecosystem
Infrastructure Concentration
operational continuitysingle point of failure
B2B software supply via CSPA without direct player contact
B2B Supply Chain
supplier liabilitydownstream operator conduct
Offshore SRL/Ltd corporate vehicles holding CPAs for consumer-facing brands
Corporate Structuring
beneficial ownership opacityaml cdd complexity
Single CPA entity operating many branded consumer-facing domains
Multi Brand Operation
advertising consistencyplayer confusion risk
Pre-launch suitability screening with agreed continuous compliance program
Entry Gatekeeping
pre licensing due diligence
Public-advisory 'name-and-shame' response to unauthorized use of KGC branding
Enforcement Signalling
brand misuseconsumer deception
Community Decision-Making and Review Process (CDMRP) consultation cycle for all regulatory amendments
Governance Process
regulatory change predictability
Red Flags
6 flagsKGC's licensing authority rests on an asserted-and-unadjudicated legal basis in tension with Criminal Code s.207's delegation of lawful gaming to the provinces.
No source confirms Canadian federal or Quebec provincial recognition of KGC permits off-reserve or offshore, creating structural legal uncertainty for any operator or counterparty relying on a KGC licence outside the Territory.
highlicensing and regulation
A large number of CPA holders are offshore SRL/Ltd corporate vehicles, several operating many branded domains under a single holder.
This structuring pattern raises beneficial-ownership and customer-due-diligence complexity for AML/CFT compliance and for counterparty risk assessment.
mediumcompetitive landscape
Public advisory evidence shows KGC's enforcement tool against unlicensed operators impersonating its brand (e.g. the 'JetSetSpins' notice) is limited to a published warning, not a blocking or takedown power.
Limited enforcement reach against brand misuse signals constrained practical authority beyond the Territory and beyond its own licensees.
mediumenforcement
The Regulations' own enabling-provision citation is inconsistent: the Regulations index page cites Gaming Law s.35 while the Regulations PDF preamble cites s.24.1.
An unresolved discrepancy in the statutory basis for the Commission's core regulatory instrument undermines confidence in the instrument's documented legal pedigree.
mediumlicensing and regulation
The regulator's own 'Permit Holders' page text says 'four types' of licence while listing five, and the homepage separately states 'five types'.
Internal documentation inconsistency on the number of licence classes issued is a basic integrity signal for the regulator's public-facing materials.
lowlicensing and regulation
No GGR, market-size, or fee-schedule figures are published in any retrieved source despite a confirmed August 2026 fee increase.
Absence of published financial/market metrics limits independent verification of the regime's commercial scale and cost-to-operate.
lowmarket opportunity