Data & Privacy
Data localisation, KYC data handling, retention and cross-border transfer.
Cross-jurisdiction posture cluster
44 flags across 41 jurisdictions. Posture mass: Rules 20 · Risks 8 · Reality 16.
Worked examples
Each links back to the full jurisdiction page — the theme view is a projection of those country ledgers.
Operational continuity, territorial control and infrastructure are at risk.
Participant must be within Michigan; geolocation is mandatory.
Rules · Risks · Reality across the cohort
Participant must be within Michigan; geolocation is mandatory.
SAC entities under targeted OFAC sanctions (E.O. 14014).
Operational continuity, territorial control and infrastructure are at risk.
Ley 25.326 classifies biometric data as sensitive and restricts international transfers.
Downstream analyses using 15% mobile figure will be wrong.
Out-of-state wagers must be blocked at the device level.
Player data processing must meet GDPR and Estonian DPA.
Data-flow constraints under Act 843.
Players identifiable via national ID linkage.
Data tied to unlawful activity compounds criminal exposure.
Player-data handling rests on fragmented provisions.
APDATOS supervises data protection; non-compliance risks sanction.
Complete account history must be available to the government on request.
Daily automatic data transmission to MINCETUR Data Centre is required.
No interstate liquidity; breach risk under Wire Act.
Aid-threat and reputational pressure raise banking and macro risk for inbound investors.
PDPL and cybercrime exposure compound gambling-prohibition risk.
Decree 147/2024 requires cross-border providers to establish domestic operations.
Operators must geo-restrict and comply with foreign rules.
Software compliance with data protection law required.
GCGRA designates sensitive zones where access is blocked.
Domestic hosting / domain requirements add compliance friction.
Data handling is governed by FIPPA/PIPEDA.
Reliance on sectoral cyber/telecom laws creates compliance ambiguity.
Limited enforcement; not a gambling-specific framework.
Published specs do not confirm localisation requirements.
Player-data governance rests on an underdeveloped law.
Cybercrime Law Art. 2 mandates 180-day user-data retention.
Data transfers outside Kenya require adequate protection.
A historic data-protection fine was recorded; cross-border data discipline matters.
Confirm count against MLGCA database before commercial reliance.
Player-data handling adds technical compliance complexity.
Any future entrant must comply with stringent QC privacy law.
Technical geo-gating required for any compliant offering.
Domestic hosting expectation; data-localisation specifics not codified.
Adds compliance overhead for any data processing
Compliance overhead for player data handling.
URCDP obligations apply to entities operating locally.