GDPR and Data Transfer in Online Casinos: Rights, Risks, and OASIS
GDPR and data transfer in online casinos are subject to strict rules, as providers may only process personal data with a legal basis. Players have a right to information regarding stored data under Art. 15 GDPR. Transfer to OASIS or payment service providers is legally required, while marketing data transfers without consent are inadmissible. Violations can result in fines and repayment claims.
Thor Casino
150% up to $340
BoaBoa Casino
100% up to $570 and 200 extra spins
Cactus Casino
150% up to $230 and 125 extra spins
Gamblezen Casino
220% up to $1,700 and 200 extra spins
N1 Bet Casino
100% up to $1,100 and 150 extra spins
LETSGOFrumzi Casino
100% up to $570 and 200 extra spins
LevelUp Casino
100% up to $2,300 and 100 extra spins
DundeeSlots Casino
100% up to $230 and 100 extra spins
MyStake Casino
150% up to $850
Legal Frameworks: The Tension Between GlüStV 2021 and GDPR
The State Treaty on Gambling 2021 and the GDPR pursue different objectives: while the GlüStV demands maximum transparency for addiction prevention, the GDPR limits data processing to the necessary extent. These divergent requirements present operators with complex compliance challenges, as they must adhere to both legal frameworks in parallel.
Conflict Between Reporting Obligations and Data Minimization
The State Treaty on Gambling 2021 obliges providers to report player data to central registers such as OASIS to combat gambling addiction and fraud. This extensive data collection directly collides with the principle of data minimization from the General Data Protection Regulation, which requires limiting processing to the necessary extent. Critics argue that the indiscriminate stockpiling of data from all players, including those without addiction characteristics, is questionable from a data protection perspective. The Federal Data Protection Act supplements the European regulation as a national special provision, but must subordinate itself to the primacy of the GDPR when it comes to fundamental processing principles. The challenge lies in reconciling the statutory reporting obligations of the GlüStV 2021 with the high protection standards of the GDPR without disproportionately restricting user privacy.
Role of the Joint State Gambling Authority
The Joint State Gambling Authority (GGL) functions as the central supervisory body for the legal gambling market in Germany. It monitors compliance with the requirements of the State Treaty on Gambling 2021, including technical connection to the blocking systems. Although the GGL primarily checks gambling law compliance, its supervisory function has direct impacts on data protection, as it controls the correct data transmission to the limit file and block file. A failure of the Joint State Gambling Authority to enforce these standards could lead to unlawful data flows. In parallel, the decision by the Maltese Data Protection Authority from July 2024 shows that foreign authorities also penalize violations of the General Data Protection Regulation, strengthening the position of German players.
Privacy by Design and Technical Compliance
Technical systems must be designed according to the "Privacy by Design" principle to ensure GDPR compliance from the outset. This means that data is only collected when it is required for a specific, legitimate purpose. The Federal Data Protection Act demands strict purpose limitation here, which must be implemented through technical precautions in the casino software. Providers should use data automation to minimize manual errors and enforce data minimization technically. Only in this way can it be ensured that the requirements of the General Data Protection Regulation and the State Treaty on Gambling 2021 are met in parallel, without unnecessarily exposing player data.
A central aspect here is the record of processing activities under Art. 30 GDPR. Every online casino must maintain this record to document comprehensively which data is processed for which purpose, who has access, and how long storage lasts. If this record is missing or incomplete, this already constitutes a serious violation of transparency obligations. Furthermore, a clear deletion concept must exist, defining when data is automatically and securely deleted after the expiration of statutory retention periods or after withdrawal of consent. Without such a concept, providers risk that data is stored longer than legally permissible, increasing the risk of data leaks.
Central Registers: OASIS, Limit File, and Block File
GDPR and data transfer in online casinos are subject to strict requirements of the State Treaty on Gambling 2021. Providers must transmit player data in real time to the central registers of the Joint State Gambling Authority (GGL). This includes the limit file for controlling deposit limits, the activity file for preventing parallel play, and the block file in the player block system OASIS. This data processing is not a voluntary measure, but a statutory obligation to fulfill legal obligations under Art. 6(1)(c) GDPR.
How the Limit File and Activity File Work
Before each deposit, online gambling operators are required to send identification data and the planned deposit amount to the limit file. The processed personal data includes first and last name, date of birth, address, as well as the cross-provider deposit limit and the history of transactions made. This transmission serves to enforce the statutory upper limits and constitutes a data processing operation that requires justification.
In parallel, the Hessian Gambling Authority maintains the activity file to prevent simultaneous online play. Here, name, date of birth, and current activity status are stored. In accordance with the principle of data minimization, this data must be deleted as soon as the reconciliation is complete. Storage without a specific occasion is inadmissible. Players have a clear right to information regarding the processing of their data, which may not be restricted by mere assumptions about the use of data in legal disputes.
Block File and OASIS Integration
The player block system OASIS is the nationwide instrument for addiction prevention and contains the block file with all blocked players. The Interstate Treaty on Gambling 2021 mandates the creation of this system to exclude participants from public games. Operators must perform a real-time query against the block file before game participation.
The integration of OASIS ensures that a block applies across game types and providers. Data transfer to this system is mandatory to fulfill the legal obligation under Art. 6c (4) GlüStV 2021. Anyone listed in the block file cannot play with any licensed provider in Germany, which requires the technical coupling of OASIS and the individual platforms.
Legal Basis for Identity Verification
The extensive identity verification (KYC) apparently conflicts with the GDPR, but is mandatory for registration in OASIS and the limit file. Without exact identification data such as place of birth and address, reliable reconciliation with the block file or the limit file is technically impossible.
The Hessian Gambling Authority uses this data to maintain the integrity of the registers. The processing is covered by Art. 6 (1) (c) GDPR, as it serves to fulfill a legal obligation. Players should note that refusal to provide this data leads to account suspension, as operators would otherwise violate the Interstate Treaty on Gambling 2021. Data sovereignty remains with the German authorities, not with the operators.
Player Rights: Information, Deletion, and Enforcement
Enforcing the GDPR and data transfer in online casinos requires strategic action, as many providers delay information requests. Players have a statutory right to information under Art. 15 GDPR, which may not be restricted by general references to ongoing legal proceedings. These data subject rights form the basis for demanding transparency regarding stored data and uncovering potential violations of the Interstate Treaty on Gambling 2021.
Enforcing the Right to Information under Art. 15
The right to information is a central instrument of data subject rights, allowing players to gain insight into the processing of their personal data. Under Art. 15 GDPR, providers must disclose in detail which data is stored and for what purpose it is used. Providers often refuse to provide information by citing ongoing civil proceedings, which the Maltese Data Protection Authority, however, classified as inadmissible. This argumentation is legally untenable, as the GDPR does not provide for a general suspension of the obligation to provide information simply because a player may sue for refunds. The correct application of Art. 15 GDPR ensures that transparency is not undermined by strategic delay tactics.
Decision of the Maltese Data Protection Authority
A landmark clarification was provided by the Maltese Data Protection Authority, which in a specific decision prohibited the refusal of information by a Malta-based provider. Since numerous online casinos are based in Malta, the Maltese Data Protection Authority has a significant precedential effect for German players. The authority clarified that the provider's fear that the player might use the data for lawsuits does not constitute a legitimate basis for a restriction under Art. 23 GDPR. This decision by the Maltese Data Protection Authority signals that licensees based abroad must also comply with the EU General Data Protection Regulation and may not arbitrarily refuse to provide information.
Connection Between GDPR Violations and Refunds
Lawyers such as István Cocron of CLLB Rechtsanwälte use systematic GDPR violations to enforce refund claims. István Cocron emphasizes that the refusal to provide information is often part of a strategy to make filing a lawsuit more difficult. CLLB Rechtsanwälte helps affected individuals overcome these hurdles by insisting on the binding legal situation. When providers violate Art. 15 GDPR, this significantly weakens their position in civil proceedings. István Cocron sees the consistent pursuit of these data protection violations as a lever to achieve not only transparency but also financial compensation for illegally offered games.
Financial Transactions and Third Parties: Financial Blocking
The processing of payment data in online casinos is subject to strict requirements. GDPR and data transfer in online casinos is a critical checkpoint for the legality of operations. While payment service providers such as PayPal, Klarna, or Trustly process transactions, they must collect personal data, which often conflicts with the principle of data minimization. In particular, financial blocking to block illegal providers is in tension with data protection principles, as it requires extensive monitoring of financial flows. Players should always check whether their data is securely transmitted to third parties and whether rights to information are preserved.
Financial Blocking and Data Protection Conflicts
Financial blocking is a measure that obliges credit institutions and payment service providers to prevent transactions with illegal gambling providers. To implement these blocks, however, financial service providers must intensively process personal data to identify suspicious payment flows. This is in direct conflict with the GDPR, as the data processing required for this often lacks a sufficient legal basis. The collection of additional data to implement financial blocking constitutes a change of purpose that must meet the strict requirements of Art. 6(4) GDPR, which often fails in practice.
Legal experts argue that a data protection-compliant implementation of financial blocking is hardly possible, as the fundamental rights of those affected outweigh the depth of intervention. Credit institutions thus find themselves in a dilemma: on the one hand, they must comply with statutory blocking requirements, but on the other hand, they may not process data without authorization. This incompatibility leads many banks to hesitate to block accounts en bloc without concrete individual grounds of suspicion that would justify processing.
Data Transfer to PayPal, Klarna, and Trustly
When using e-wallets and instant transfers such as PayPal, Klarna, or Trustly, player data is inevitably transmitted to these third-party providers. PayPal, a global payment service provider, as well as Klarna and Trustly, which often serve as an interface to the bank account, require name, address, and transaction details for processing. This transfer is necessary for contract fulfillment, but must be transparent. Players have the right under Art. 15 GDPR to find out exactly which data flows to these payment service providers.
The players' data sovereignty is further fragmented by the integration of external service providers. It is crucial that casinos disclose these data flows, as non-transparent transfer to credit agencies or other third parties can constitute a violation of transparency obligations.
International Data Transfer and Schrems II
The transfer of data to providers outside the EU, particularly to countries such as Curacao, entails considerable risks under the Schrems II ruling. In the absence of adequacy decisions, the transfer of personal data is legally uncertain. In contrast, Malta as an EU member state offers a clearer framework, with the Maltese Data Protection Commissioner recently strengthening players' rights in a landmark decision. A casino had rejected a request for information, which the Commissioner classified as inadmissible.
This decision by the Maltese Data Protection Commissioner is an important precedent, as many providers are based in Malta. It shows that requests for information may not be refused with reference to ongoing legal disputes. Law firms such as CLLB Rechtsanwälte increasingly use such violations to support players in enforcing their rights. For German players, this means: with providers without an EU seat, the risk of data misuse is higher, as GDPR complaints are hardly enforceable there.
About This Article - Editorial & Responsibility
Author: Sarah Weber - Casino Tester & Bonus Analyst Professionally reviewed by: Dr. Markus Hoffmann - Senior iGaming Compliance Analyst Last updated: 2026-07-26.
This contribution on "GDPR and Data Transfer in Online Casinos" was written by Sarah Weber and professionally reviewed by Dr. Markus Hoffmann. Both regularly update the content with regard to regulatory changes, license availability, and bonus conditions. All statements on licenses, authorities, and legal frameworks refer to publicly accessible sources (GGL (Joint Gambling Authority of the States), Interstate Treaty on Gambling 2021 (GlüStV 2021)).
About the Author
8+ years of casino reviews, 200+ personally tested platforms in the EU and internationally. Former member of the eCOGRA Player Advocacy Program (2018-2022). Specialization: wagering requirements, payout workflows, customer support evaluation.
About the Reviewer
12+ years in the iGaming industry, including 5 years as a compliance consultant for licensed operators under the Interstate Treaty on Gambling 2021. PhD in Economic Mathematics. Research focus: bonus mathematics, wager analysis, player protection systems (OASIS).
Responsible Gaming
Gambling can be addictive. If you feel you are losing control of your gaming behavior, please contact BzgA Spielsuchthilfe, Check-dein-Spiel.de, or use the central exclusion system (OASIS (central player exclusion system)). Set personal deposit and loss limits before playing with real money. Provider pause and cooldown functions are not a sign of weakness - they are a tool for sustainable gaming enjoyment.
Legal Notice
The information in this article is for editorial and comparison purposes only. It does not constitute legal advice. The legal assessment of online gambling without a German license is a gray area and is subject to ongoing adjustments by the GGL (Joint Gambling Authority of the States). Players are responsible for complying with local regulations.