Data & Privacy
Data localisation, KYC data handling, retention and cross-border transfer.
Cross-jurisdiction posture cluster
51 flags across 40 jurisdictions. Posture mass: Rules 26 · Risks 10 · Reality 15.
Worked examples
Each links back to the full jurisdiction page — the theme view is a projection of those country ledgers.
Participant must be within Michigan; geolocation is mandatory.
Operational continuity, territorial control and infrastructure are at risk.
Rules · Risks · Reality across the cohort
Participant must be within Michigan; geolocation is mandatory.
Participant must be within Michigan; geolocation is mandatory.
Participant must be within Michigan; geolocation is mandatory.
SAC entities under targeted OFAC sanctions (E.O. 14014).
Operational continuity, territorial control and infrastructure are at risk.
Ley 25.326 classifies biometric data as sensitive and restricts international transfers.
Downstream analyses using 15% mobile figure will be wrong.
Out-of-state wagers must be blocked at the device level.
Player data processing must meet GDPR and Estonian DPA.
Data-flow constraints under Act 843.
Players identifiable via national ID linkage.
Data tied to unlawful activity compounds criminal exposure.
Player-data handling rests on fragmented provisions.
APDATOS supervises data protection; non-compliance risks sanction.
Complete account history must be available to the government on request.
Daily automatic data transmission to MINCETUR Data Centre is required.
No interstate liquidity; breach risk under Wire Act.
Aid-threat and reputational pressure raise banking and macro risk for inbound investors.
PDPL and cybercrime exposure compound gambling-prohibition risk.
Decree 147/2024 requires cross-border providers to establish domestic operations.
Operators must geo-restrict and comply with foreign rules.
Operators must geo-restrict and comply with foreign rules.
Operators must geo-restrict and comply with foreign rules.
Software compliance with data protection law required.
Software compliance with data protection law required.
Software compliance with data protection law required.
GCGRA designates sensitive zones where access is blocked.
Domestic hosting / domain requirements add compliance friction.
Data handling is governed by FIPPA/PIPEDA.
Reliance on sectoral cyber/telecom laws creates compliance ambiguity.
Limited enforcement; not a gambling-specific framework.
Published specs do not confirm localisation requirements.
Player-data governance rests on an underdeveloped law.
Cybercrime Law Art. 2 mandates 180-day user-data retention.
Data transfers outside Kenya require adequate protection.
Confirm count against MLGCA database before commercial reliance.
Player-data handling adds technical compliance complexity.
Player-data handling adds technical compliance complexity.
Player-data handling adds technical compliance complexity.
Any future entrant must comply with stringent QC privacy law.
Technical geo-gating required for any compliant offering.
Domestic hosting expectation; data-localisation specifics not codified.
Adds compliance overhead for any data processing
Compliance overhead for player data handling.
URCDP obligations apply to entities operating locally.