Why Player Data Is a Central Risk for Operators
A gambling operator begins nearly every relationship with data: player registration, identification and verification, the history of deposits and withdrawals, the behavioural profile of play, checks against self-exclusion and prohibited-person lists — all of this is the processing of personal data. Article 2 of the Law of Georgia on Personal Data Protection defines the scope of the law: it applies to the processing of data by automatic and semi-automatic means, to the non-automatic processing of data that forms part of a filing system or is intended to be included in one, and to the processing, by a controller registered outside Georgia, carried out using technical means located in Georgia — except where such means are used only for the transit of data.
This means that even an operator operating through a foreign structure, but using Georgian servers or other technical means, falls within the effective zone of Georgian law. At the same time, the law does not apply to processing for personal or family purposes, for state security, defence and intelligence purposes, to court proceedings, or to the activities of mass media — but commercial gambling activity does not fit within those exceptions.
Principles of Processing
Article 4 establishes the principles that must be observed in every operation. Data must be processed lawfully, fairly and transparently in relation to the data subject, and without violating their dignity; collected only for specific, clearly defined and legitimate purposes, with further processing for a purpose incompatible with the original one prohibited; and processed only to the extent necessary to achieve the relevant legitimate purpose — the data must be proportionate to that purpose.
Data must be accurate and, where necessary, kept up to date, and inaccurate data must be corrected, erased or destroyed without unjustified delay. Storage is permitted only for as long as necessary to achieve the purpose — once the purpose is achieved, the data must be erased, destroyed or depersonalised. And finally, security: technical and organisational measures must be taken that adequately protect the data from unauthorised or unlawful processing, accidental loss, destruction or damage. When assessing further processing, the law weighs the connection between the original and the new purpose, the subject’s reasonable expectations and the possible consequences — and the controller is obliged to be able to demonstrate compliance with these principles.
Grounds for Processing
Article 5 sets the rule: processing is admissible only where one of the listed grounds exists. In the player context, the most frequently used are: the data subject’s consent to processing for one or more specific purposes; the performance of an obligation under a contract with the subject, or the conclusion of a contract at the subject’s request; processing provided for by law — particularly relevant in gambling, since identification requirements flow precisely from here; processing necessary to consider an application; and legitimate interests, where no overriding interest of the data subject’s rights exists.
What matters is this: the obligation to substantiate the legal ground for processing lies with the controller — a mistake in choosing the ground places the entire processing on a doubtful foundation. That is why each data flow — marketing, bonuses, analytics, compliance — must have its own defined ground and purpose.
Special Categories of Data
Article 6 imposes a strict regime on special categories of data: their processing is admissible only where the controller ensures the guarantees for the protection of the subject’s rights and interests provided for by the law, and one of the grounds established by the law exists. The first and most demanding route is written consent — ordinary consent does not suffice for special categories of data. Among the other grounds are processing directly regulated by law, vital interests, and social security.
In the gambling business lens this is critical: a behavioural profile of play and assessments related to dependence concern a person’s health and behaviour, so their processing must be structured with special caution precisely through the prism of this article. The obligation to substantiate the legal ground for processing special categories of data likewise rests with the controller.
The Compliance Architecture for an Operator
In practice, player data protection consists of three layers: a map of purposes, where each flow has a fixed purpose, ground and storage period; a consent management mechanism that records the giving, modification and withdrawal of consent; and security measures — technical and organisational — that protect the data from unauthorised access.
Special attention belongs to the flows that come from the law — identification, list checks, financial monitoring information: there the ground is the law, not consent, and this difference must be clearly visible in the documentation so that, upon request, the operator can justify every single step.
Frequently Asked Questions
Does the law apply to a foreign operator?
Yes, where a controller registered outside Georgia processes data using technical means located in Georgia — except where those means are used only for transit.
What is the difference between consent and a statutory obligation?
Consent is the subject’s free decision on a specific purpose, while processing provided for by law has the law as its ground — for example, identification requirements. In both cases justification is the operator’s duty.
Which principle is violated most often?
Purpose limitation and minimisation: collecting data in the “everything that might come in handy” mode. The law requires only specific, clearly defined and legitimate purposes and the volume necessary for the purpose.
How does written consent work for special data?
Special categories may be processed on the basis of written consent or on grounds directly provided for by law, with guarantees for the protection of the subject’s rights ensured.
How We Help on Legal.ge
We will build the complete framework for player data protection: a map of purposes and grounds, consent forms, rules for processing special categories of data, and a description of security measures. Contact us on Legal.ge — compliance built today will receive tomorrow’s request without a problem.
