GDPR and Data Transfer in Online Casinos: Rights, Risks, and OASIS

GDPR and data transfer in online casinos are subject to strict rules, as providers are only allowed to process personal data with a legal basis. According to Art. 15 GDPR, players have a right of access to stored data. The transfer to OASIS or payment service providers is required by law, while marketing data transfers without consent are inadmissible. Violations can lead to fines and repayment claims.

#1
🎰

FEZbet Casino

100% up to $580 and 200 extra spins

10.0
#2

WinGaga Casino

100% up to $580 and 200 extra spins

9.8
#3

GetSlots Casino

100% up to $580 and 100 extra spins

9.6
#4

WinSpirit Casino

100% up to $230 and 100 extra spins

9.3
#5 Exclusive

Fast One Casino

200% up to $1,000

LAP1B
9.1
#6

SG Casino

100% up to $580 and 200 extra spins

8.8
#7

Candy Spinz Casino

100% up to $580 and 100 extra spins

8.6
#8

Bruno Casino

100% up to $580 and 150 extra spins

8.3
#9 Exclusive

Nomini Casino

100% up to $580 and 200 extra spins

FIRSTBONUS
8.1

Legal Framework: The Tension Between GlüStV 2021 and GDPR

The Interstate Treaty on Gambling 2021 and the GDPR pursue different goals: while the GlüStV demands maximum transparency for addiction prevention, the GDPR limits data processing to what is necessary. These diverging requirements present operators with complex compliance challenges, as they must adhere to both legal frameworks in parallel.

Conflict Between Reporting Obligations and Data Minimization

The Interstate Treaty on Gambling 2021 obliges providers to report player data to central registers like OASIS in order to combat gambling addiction and fraud. This extensive data collection conflicts directly with the principle of data minimization from the General Data Protection Regulation, which requires processing to be limited to what is necessary. Critics argue that the groundless retention of data from all players, even those without addiction symptoms, is questionable under data protection law. The Federal Data Protection Act complements the European regulation as a national special rule, but must submit to the primacy of the GDPR when it comes to fundamental processing principles. The challenge lies in reconciling the statutory reporting obligations of the GlüStV 2021 with the high protection standards of the GDPR without disproportionately restricting users' privacy.

Role of the Joint Gambling Authority of the Federal States

The Joint Gambling Authority of the Federal States (GGL) acts as the central supervisory body for the legal gambling market in Germany. It monitors compliance with the requirements of the Interstate Treaty on Gambling 2021, including the technical connection to the blocking systems. Although the GGL primarily checks compliance with gambling law, its supervisory function has direct implications for data protection, as it controls the correct transmission of data to the limit file and the blocking file. A failure of the Joint Gambling Authority of the Federal States to enforce these standards could lead to unlawful data flows. In parallel, the decision of the Maltese Data Protection Commissioner of July 2024 shows that foreign authorities also penalize violations of the General Data Protection Regulation, which strengthens the position of German players.

Privacy by Design and Technical Compliance

Technical systems must be designed according to the "Privacy by Design" principle to ensure GDPR compliance from the very beginning. This means that data is only collected if it is required for a specific, legitimate purpose. The Federal Data Protection Act requires strict purpose limitation here, which must be implemented through technical precautions in the casino software. Providers should use data automation to minimize manual errors and technically enforce data minimization. This is the only way to ensure that the requirements of the General Data Protection Regulation and the Interstate Treaty on Gambling 2021 are met in parallel without unnecessarily exposing player data.

A central aspect here is the record of processing activities in accordance with Art. 30 GDPR. Every online casino must maintain this record to document seamlessly which data is processed for what purpose, who has access, and how long the storage lasts. If this record is missing or incomplete, this is already considered a serious violation of transparency obligations. In addition, a clear deletion concept must exist, which defines when data is automatically and securely deleted after the statutory retention periods have expired or after consent has been withdrawn. Without such a concept, providers risk storing data longer than legally permitted, which increases the risk of data leaks.

Central Registers: OASIS, Limit File, and Blocking File

GDPR and data transfer in online casinos are subject to strict requirements of the Interstate Treaty on Gambling 2021. Providers must transmit player data in real time to the central registers of the Joint Gambling Authority of the Federal States (GGL). This includes the limit file for checking deposit limits, the activity file for preventing parallel play, and the blocking file in the OASIS player blocking system. This data processing is not a voluntary measure, but a legal obligation to fulfill legal obligations in accordance with Art. 6 (1) (c) GDPR.

Functionality of the Limit File and Activity File

Before each deposit, online gambling providers are obliged to send identification data and the planned deposit amount to the limit file. The personal data processed includes first and last name, date of birth, address, as well as the cross-provider deposit limit and the history of transactions made. This transmission serves to enforce the legal upper limits and constitutes data processing that requires justification.

In parallel, the Hessian Gambling Authority maintains the activity file to prevent parallel play on the Internet. Name, birth data, and current activity status are stored here. In accordance with the principle of data minimization, this data must be deleted as soon as the comparison is completed. Groundless data retention is impermissible. Players have a clear right to information about the processing of their data, which must not be restricted by mere assumptions about the use of the data in legal disputes.

Blocking File and OASIS Integration

The OASIS player blocking system is the nationwide instrument for addiction prevention and contains the blocking file with all blocked players. The Interstate Treaty on Gambling 2021 mandates the creation of this system to exclude participants from public gambling. Providers must carry out a real-time query against the blocking file before game participation.

The integration of OASIS ensures that a block is effective across all forms of play and providers. The transfer of data to this system is mandatory in order to fulfill the legal obligation under Art. 6c Paragraph 4 GlüStV 2021. Anyone listed in the blocking file cannot play at any licensed provider in Germany, which requires the technical coupling of OASIS and the individual platforms.

Legal Basis for Identity Verification

The extensive identity verification (KYC) apparently conflicts with the GDPR, but is absolutely necessary for entry in OASIS and the limit file. Without exact identification data such as place of birth and address, a reliable comparison with the blocking file or the limit file is technically impossible.

The Hessian Gambling Authority uses this data to preserve the integrity of the registers. The processing is covered by Art. 6 (1) (c) GDPR, as it serves to fulfill a legal obligation. Players should note that refusing to provide this data will lead to account suspension, as providers would otherwise violate the Interstate Treaty on Gambling 2021. Data sovereignty remains with the German authorities, not with the operators.

Player Rights: Access, Deletion, and Enforcement

Enforcing GDPR and data transfer in online casinos requires a strategic approach, as many providers delay access requests. Players have a legal right of access under Art. 15 GDPR, which must not be restricted by blanket references to ongoing legal disputes. These data subject rights form the basis for forcing transparency regarding stored data and uncovering potential violations of the Interstate Treaty on Gambling 2021.

Enforcement of the Right of Access Under Art. 15

The right of access is a key tool among data subject rights, allowing players to gain insight into the processing of their personal data. Pursuant to Art. 15 GDPR, providers must disclose in detail which data is stored and for what purpose it is used. Providers often refuse access by referring to ongoing civil proceedings, which the Maltese Data Protection Commissioner, however, classified as inadmissible. This argument is legally untenable, as the GDPR does not provide for a general suspension of the duty to provide access simply because a player might sue for repayments. The correct application of Art. 15 GDPR ensures that transparency is not undermined by strategic delay tactics.

Decision of the Maltese Data Protection Commissioner

A groundbreaking clarification was provided by the Maltese Data Protection Commissioner, who, in a specific decision, prohibited a Malta-based provider from refusing access. Since numerous online casinos are based in Malta, the Maltese Data Protection Commissioner's decision has a significant precedent effect for German players. The authority clarified that the provider's fear that the player could use the data for lawsuits is not a legitimate basis for a restriction under Art. 23 GDPR. This decision by the Maltese Data Protection Commissioner signals that licensees based abroad must also comply with the EU General Data Protection Regulation and cannot arbitrarily refuse access.

Connection Between GDPR Violations and Repayments

Attorneys like István Cocron from CLLB Rechtsanwälte use systematic GDPR violations to enforce repayment claims. István Cocron emphasizes that the refusal to provide access is often part of a strategy to make filing a lawsuit more difficult. CLLB Rechtsanwälte assists data subjects in overcoming these hurdles by insisting on the binding legal situation. When providers violate Art. 15 GDPR, this significantly weakens their position in civil proceedings. István Cocron sees the consistent prosecution of these data protection violations as leverage to obtain not only transparency but also financial compensation for illegally offered games.

Financial Transactions and Third-Party Providers: Financial Blocking

The processing of payment data in online casinos is subject to strict guidelines. GDPR and data transfer in online casinos is a critical review point for the legality of operation. While payment service providers such as PayPal, Klarna, or Trustly process transactions, they must collect personal data, which often conflicts with the principle of data minimization. In particular, financial blocking to block illegal providers conflicts with data protection principles, as it requires extensive monitoring of financial flows. Players should always check whether their data is being securely transmitted to third parties and whether rights of access are preserved.

Financial Blocking and Data Protection Conflicts

Financial blocking is a measure that obliges credit institutions and payment service providers to stop transactions to illegal gambling providers. To implement these blocks, however, financial service providers must process personal data intensively to identify suspicious payment flows. This is in direct conflict with the GDPR, as the data processing required for this often lacks a sufficient legal basis. The collection of additional data to implement financial blocking represents a change of purpose that must satisfy the strict requirements of Art. 6 (4) GDPR, which frequently fails in practice.

Legal experts argue that a data protection-compliant implementation of financial blocking is hardly possible, as the fundamental rights of the data subjects outweigh this given the depth of the intervention. Credit institutions thus face a dilemma: on the one hand, they must comply with legal blocking requirements, but on the other hand, they must not process data without authorization. This incompatibility leads to many banks hesitating to block accounts globally without concrete individual suspicion that would justify processing.

Data Transfer to PayPal, Klarna, and Trustly

When using e-wallets and instant transfers like PayPal, Klarna, or Trustly, player data is inevitably transmitted to these third-party providers. PayPal, a global payment service provider, as well as Klarna and Trustly, which often serve as an interface to the bank account, require name, address, and transaction details for processing. This transfer is necessary for the fulfillment of the contract, but must be transparent. According to Art. 15 GDPR, players have the right to know exactly which data is flowing to these payment service providers.

Players' data sovereignty is further fragmented by the integration of external service providers. It is crucial that casinos disclose these data flows, as an untransparent transfer to credit agencies or other third parties can represent a violation of transparency obligations.

International Data Transfer and Schrems II

Data transfer to providers outside the EU, especially to countries like Curacao, carries significant risks under the Schrems II ruling. In the absence of adequacy decisions, the transfer of personal data is legally insecure. In contrast, Malta, as an EU member state, offers a clearer framework, where the Maltese Data Protection Commissioner recently strengthened players' rights in a landmark decision. A casino had rejected an access request, which the Commissioner classified as inadmissible.

This decision of the Maltese Data Protection Commissioner is an important precedent, as many providers are located in Malta. It shows that access requests must not be refused with reference to ongoing legal disputes. Law firms like CLLB Rechtsanwälte increasingly use such violations to support players in enforcing their rights. For German players, this means: with providers without an EU headquarters, the risk of data misuse is higher, since GDPR complaints are hardly enforceable there.

Learn how to protect your privacy from OASIS and which providers really keep your personal info to themselves.

FAQ

Is the transfer of player data to third parties by online casinos GDPR-compliant?
Data transfer is only permitted if there is a legal basis, such as the Interstate Treaty on Gambling 2021, or if the player has given explicit consent. Without this basis, for example, when transferring to unlicensed partners, the provider acts unlawfully and risks high fines under the GDPR. The transmission to payment service providers without transparent information is particularly critical, as this often violates the principles of data minimization.
What data are online casinos allowed to transmit to payment service providers under the GDPR?
Providers may only pass on the data strictly necessary for the transaction, such as name and account details, to payment service providers. Comprehensive profiling or transferring gaming behavior to third parties for marketing purposes is inadmissible under data protection law without separate consent. This often conflicts with measures such as financial blocking, which requires more intensive data processing by banks and must therefore be carefully examined.
Does an online casino have to obtain my consent for data transfer?
No additional consent is required for the fulfillment of the contract (e.g., payouts), but it is for marketing or transfer to advertising partners. Many providers based in Malta try to refuse access requests in order to make legal steps by players more difficult, which, however, was classified as inadmissible by the Maltese Data Protection Commissioner. Consent must be voluntary, informed, and revocable at any time to meet the standards of the General Data Protection Regulation.
How can I object to the data transfer of my online casino?
You can object to the processing of your data for direct marketing or profiling at any time by contacting customer support or changing the settings in your customer account. This objection does not apply to basic contract fulfillment, but you can delete your account, which must stop further use of your data. If the provider ignores your objection or access request, you can contact the responsible supervisory authority, such as the Joint Gambling Authority of the Federal States.
Are online casinos with an EU license safer regarding GDPR than those without?
Providers with a license from Malta or other EU states are subject to the GDPR, but enforcement is more complex abroad than in Germany. However, the Maltese Data Protection Commissioner has clarified that providers located there cannot reject access requests under Art. 15 GDPR blanketly with reference to ongoing legal disputes. Nevertheless, licensed providers under the Interstate Treaty on Gambling 2021 often offer higher transparency due to the connection to OASIS and local supervision.
What happens to my data when I delete my account in an online casino?
After account deletion, the provider must delete your personal data, unless statutory retention periods (e.g., for tax purposes) prevent this. However, data transmitted to the limit file or the OASIS player blocking system to comply with the Interstate Treaty on Gambling 2021 remains there for addiction prevention. This transfer is legally mandated and serves to protect players, regardless of the deletion of the customer account with the operator.
Are online casinos allowed to pass on my data to gambling authorities?
Yes, licensed providers are legally obliged to transmit certain data to authorities such as the Joint Gambling Authority of the Federal States. This includes reports to the central blocking system OASIS and the limit file to ensure compliance with deposit limits and player blocks. This data transfer is based on the Interstate Treaty on Gambling 2021 and represents permissible processing in the public interest, which does not require consent.
What rights do I have under the GDPR against an online casino?
Among other things, you have the right to access (Art. 15 GDPR), rectification, deletion, and restriction of the processing of your data. The right of access is a key instrument for understanding what data the casino stores and passes on to third parties, such as payment service providers. If these rights are violated, data subjects can file a complaint with the responsible supervisory authority and claim damages in the event of harm.

About This Article - Editorial & Responsibility

Author: Sarah Weber - Casino Tester & Bonus Analyst

Expertly reviewed by: Dr. Markus Hoffmann - Senior iGaming Compliance Analyst

Last Update: 2026-07-29.

This article on "GDPR and Data Transfer in Online Casinos" was written by Sarah Weber and expertly reviewed by Dr. Markus Hoffmann. Both regularly update the content regarding regulatory changes, license availability, and bonus terms. All statements regarding licenses, authorities, and legal frameworks refer to publicly accessible sources (GGL (Joint Gambling Authority of the Federal States), Interstate Treaty on Gambling 2021 (GlüStV 2021)).

About the Author

8+ years of casino reviews, 200+ personally tested platforms in the EU and internationally. Former member of the eCOGRA Player Advocacy Program (2018-2022). Specialization: wagering requirements, withdrawal workflows, customer support evaluation.

About the Reviewer

12+ years in the iGaming industry, including 5 years as a compliance consultant for licensed operators under the Interstate Treaty on Gambling 2021. PhD in Financial Mathematics. Research focus: bonus mathematics, wager analysis, player protection systems (OASIS).

Responsible Gambling

Gambling can be addictive. If you feel like you are losing control of your gaming behavior, please contact the BzgA gambling addiction help, Check-dein-Spiel.de, or use the central blocking system (OASIS (central player blocking system)). Set personal deposit and loss limits before playing with real money. Breaks and cooldown functions from providers are not a sign of weakness - they are a tool for sustainable fun in gaming.

Legal Disclaimer

The information in this article is for editorial and comparison purposes only. It does not constitute legal advice. The legal assessment of online gambling without a German license is a gray area and is subject to ongoing adjustments by the GGL (Joint Gambling Authority of the Federal States). Players themselves are responsible for compliance with local regulations.