Themes
Data & Privacy

Data & Privacy

Data localisation, KYC data handling, retention and cross-border transfer.

Flags
44
Jurisdictions
41
Read order
Theme-major

Cross-jurisdiction posture cluster

44 flags across 41 jurisdictions. Posture mass: Rules 20 · Risks 8 · Reality 16.

Worked examples

Each links back to the full jurisdiction page — the theme view is a projection of those country ledgers.

🇲🇲 Myanmar →
Junta-linked SOE engagement

SAC entities under targeted OFAC sanctions (E.O. 14014).

1 data & privacy flags on this jurisdiction · see full country page
🇺🇦 Ukraine →
Active war / martial law

Operational continuity, territorial control and infrastructure are at risk.

1 data & privacy flags on this jurisdiction · see full country page
Michigan — State →
Accepting out-of-state wagers

Participant must be within Michigan; geolocation is mandatory.

1 data & privacy flags on this jurisdiction · see full country page

Rules · Risks · Reality across the cohort

Lens · which facet of each jurisdiction’s flags:
Showing all facets.
Accepting out-of-state wagers

Participant must be within Michigan; geolocation is mandatory.

SRC-US-MI-002
Junta-linked SOE engagement

SAC entities under targeted OFAC sanctions (E.O. 14014).

SRC-MM-005
Active war / martial law

Operational continuity, territorial control and infrastructure are at risk.

SRC-UA-009
Mishandling biometric/sensitive data

Ley 25.326 classifies biometric data as sensitive and restricts international transfers.

SRC-AR-001
Tax-rate change conflicts with baseline spec

Downstream analyses using 15% mobile figure will be wrong.

SRC-US-MD-003
Non-GDPR-compliant processing

GDPR + Bulgarian DPA apply.

SRC-BG-002
GPS geo-gating required

Out-of-state wagers must be blocked at the device level.

SRC-US-CT-005
GDPR / AKI player-data enforcement

Player data processing must meet GDPR and Estonian DPA.

SRC-EE-013
DPC registration and cross-border transfer approval

Data-flow constraints under Act 843.

SRC-GH-005
NIK cross-checking of accounts

Players identifiable via national ID linkage.

SRC-ID-008
Holding PK player data for gambling

Data tied to unlawful activity compounds criminal exposure.

SRC-PK-002
No specific data-protection law

Player-data handling rests on fragmented provisions.

SRC-MZ-001
No DPO/NDPA registration

NDPA 2023 obligations and NDPC investigations

SRC-NG-002
Ignoring Ley 81/2019 obligations

APDATOS supervises data protection; non-compliance risks sanction.

SRC-PA-003
Incomplete transaction history

Complete account history must be available to the government on request.

SRC-PA-012
No real-time MINCETUR data access

Daily automatic data transmission to MINCETUR Data Centre is required.

SRC-PE-008
Mandatory in-state geolocation

No interstate liquidity; breach risk under Wire Act.

SRC-US-RI-003
Western scrutiny over DR Congo/M23

Aid-threat and reputational pressure raise banking and macro risk for inbound investors.

SRC-RW-008
Collecting Saudi player data for gambling

PDPL and cybercrime exposure compound gambling-prohibition risk.

SRC-SA-001
Improper personal data handling

Data protection embedded in licensing.

SRC-RS-008
Assuming no localisation/operation requirements

Decree 147/2024 requires cross-border providers to establish domestic operations.

SRC-VN-007
Serving players outside Spain on .es licence assumptions

Operators must geo-restrict and comply with foreign rules.

SRC-ES-006
Non-compliance with PDPA No. 9 of 2022

Software compliance with data protection law required.

SRC-LK-006
Operating in 'sensitive geographic areas'

GCGRA designates sensitive zones where access is blocked.

SRC-AE-004
Failing bettor data protection

Statutory confidentiality duty.

SRC-US-VA-001
Law 18-05 hosting/.com.dz requirements

Domestic hosting / domain requirements add compliance friction.

SRC-DZ-007
Ignoring FIPPA/PIPEDA obligations

Data handling is governed by FIPPA/PIPEDA.

SRC-CA-BC-001
No dedicated gambling data-protection rules

Reliance on sectoral cyber/telecom laws creates compliance ambiguity.

SRC-CM-001
Overreliance on PRODHAB protections

Limited enforcement; not a gambling-specific framework.

SRC-CR-002
Data localisation status not yet assessed

Published specs do not confirm localisation requirements.

SRC-US-DE-003
Weak data-protection regime (Ley 172-13)

Player-data governance rests on an underdeveloped law.

SRC-DO-008
Operating telecom-adjacent service

Cybercrime Law Art. 2 mandates 180-day user-data retention.

SRC-EG-002
KDPA 2019 cross-border transfer rules

Data transfers outside Kenya require adequate protection.

SRC-KE-010
Unauthorised customer-data transfers

A historic data-protection fine was recorded; cross-border data discipline matters.

SRC-CN-MO-009
Data retention duties S.L. 583.12

Compliance overhead for record retention.

SRC-MT-002
Active licensee count dynamic

Confirm count against MLGCA database before commercial reliance.

SRC-US-MD-004
GDPR/CNPD enforcement

Player-data handling adds technical compliance complexity.

SRC-PT-007
Law 25 data protection regime

Any future entrant must comply with stringent QC privacy law.

SRC-CA-QC-001
Geolocation confinement to QC residents

Technical geo-gating required for any compliant offering.

SRC-CA-QC-008
Hosting assumptions

Domestic hosting expectation; data-localisation specifics not codified.

SRC-CH-009
Unpublished fee point-figures

Budgeting uncertainty.

SRC-TZ-002
Cross-border data transfer authorisation (Law 2004-63)

Adds compliance overhead for any data processing

SRC-TN-002
Data Protection and Privacy Act 2019 obligations

Compliance overhead for player data handling.

SRC-UG-002
Mandatory database registration / breach notification

URCDP obligations apply to entities operating locally.

SRC-UY-006