Data is exploding in usage and availability in new ways unforeseen due to the developments of emerging technologies, such as AI.
Operators within the gambling sector are now more prone than ever to falling foul of data laws and regulations as they move market-to-market. However, there are also other technologies, such as open banking, enabling greater insight into consumer data to how they can both tailor their offerings while also mitigating money laundering.
Speaking to Payment Expert ahead of his appearance at the Payment Expert Summit at SBC Summit in Lisbon, James Myles, Head Of Compliance at Dragonbet, explains why operators should be wary of the new data that is available and how it can both be a help and a hindrance.
Could you outline some of the varying global privacy laws operators should be aware of?
Operators should know where their customers and data are, to ensure they are observing each relevant territory’s laws.
In the UK and the European Union (EU) where privacy laws are at their most developed, it’s primarily GDPR (and UK GDPR), as well as each state’s local data protection act.
On top of that you have electronic communication laws such as Privacy and Electronic Communications Regulations (PECR) in the UK. California’s California Consumer Privacy Act (CCPA) is the most established and well known in the USA, with other states gradually introducing their own laws.

What are some of the common pitfalls operators experience from regulators pertaining to data and privacy laws when scaling operations?
Operators need to keep track of their data flows and the parties they are sharing data with. It’s an unpleasant task unpicking it. Operators are expected to be able to demonstrate to the data regulators that they have comprehensive records of processing. The gambling regulators generally expect operators to carry out due diligence on their suppliers, and the outsourcing policies and procedures should incorporate data considerations.
Also, as operations scale, it’s important to carry out risk assessments on projects where personal data may be processed. These assessments need to cover obligations under all applicable data regulations (such as carrying out Data Protection Impact Assessments), marketing obligations (such as consent management) and the regulations of the relevant gambling licence jurisdictions (such as customer protection codes).
How has Open Banking enabled operators to gain greater customer insight to ensure they are fully compliant with the regulator’s guidelines?
Depending on the product employed, and the configuration selected, open banking can provide an extraordinary amount of information on the customer.
The visibility afforded allows operators to implement very effective money laundering controls, as well as to detect possible risks of gambling-related harm with their customers.
In the same vein, how can open banking data be used to ensure a seamless customer onboarding process while removing as much friction as possible?
The information from open banking provides for effective verification of the customer’s identity and source of funds. This has to be set up carefully though, as there are obligations on operators when they seek to rely on third parties for customer due diligence.
What are some of the emerging threats you have identified that can be a risk to consumer data in the modern day?
With technologies such as open banking, consumer data is more widely exposed. In the UK the Online Safety Act further requires businesses to collect and verify personal data of consumers in more circumstances than before.
The risks are that the parties collecting the data for legitimate purposes may fall foul of data breaches, and that some such parties may abuse the data by using it for purposes additional to those for which it was collected. This is prejudicial to consumer trust.
In the same vein, which emerging technologies are bolstering the proliferation of customer data so operators can tailor offers to them while remaining within the regulatory boundaries?
With all the opportunities presenting themselves for access to data the real challenge is an internal one for operators to make sure they don’t overstep. While being able to take advantage of additional visibility of customer information and behaviour, systems need to be in place to ensure the additional processing is lawful.
You are speaking on a panel at SBC Summit titled: “How much is too much data”, and with the acceleration of AI, has the explosion of newfound data created fragmentation?
Personal data, particularly in Europe, needs to be processed transparently and proportionately. A lot of very aggressive data processing goes on in ways that aren’t clear to the customer or proportionate.
We see this in adtech and consumer tracking. We see it where AI is modeling customer behaviour. Some operators don’t want the additional visibility of customer financial data, for example, because then they have to put efforts into taking account of it to fulfil their regulatory obligations.
Operators ought to consider why they want the data as well as what that can lead to.
Lastly James, what are some of the key themes and topics you are looking forward to speaking about with attendees at SBC Summit in Lisbon?
I’m looking forward to visiting Lisbon for its own sake, as I attend very few conferences. The panel discussions will be enlightening, and I’m looking forward to learning more about attendees’ views on customer data and security.
Held in Lisbon from 29 September to 1 October 2026, SBC Summit is one of the world’s largest gatherings of betting and gaming professionals.
The event will bring together 40,000 attendees from across the industry for three days of learning, networking, and discussion, alongside a major exhibition featuring leading brands from around the globe.
For more information and tickets, visit: sbcevents.com/sbc-summit
Source: Payment Expert