Skip to content
Cybersecurity & Tech Innovation

New AI Laws Reshape Data Protection Obligations for Gambling Sector

The Update:
A wave of legislative developments across jurisdictions is redefining how companies must manage data when deploying artificial intelligence (AI). The EU’s Artificial Intelligence Act, provisionally adopted in March 2024 and due to be enforced in phases from 2025, categorises AI systems by risk level and mandates stricter compliance obligations for high-risk applications. This includes systems used in customer profiling, fraud prevention, and responsible gambling, core areas for operators and suppliers in the gambling sector.

Simultaneously, the UK government is pursuing a principles-based framework through its “pro-innovation” AI regulation strategy. While the UK avoids blanket legislation like the EU, sector regulators including the Gambling Commission are expected to enforce tailored guidance under existing data protection and consumer laws. Globally, jurisdictions including Canada, Brazil, and several US states are advancing their own AI-specific privacy and algorithmic transparency laws, many overlapping with existing GDPR-style obligations.

Why It Matters:
AI is increasingly embedded in gambling operations, from behavioural analytics and automated customer service to dynamic odds modelling and anti-money laundering systems. These use cases typically rely on sensitive personal data and automated decision-making, now directly targeted by emerging legal frameworks. Under the EU AI Act, for example, gambling-related AI systems that influence user behaviour or risk assessment could be classified as “high-risk”, triggering new duties such as human oversight, risk management documentation, and post-market monitoring.

Even in non-EU markets, AI deployments intersect with core data protection principles: transparency, fairness, accuracy, and minimisation. Where AI tools process special category data (such as inferred mental health or addiction indicators), obligations under GDPR, the UK Data Protection Act, or equivalent laws are significantly heightened. Failing to address these intersections could expose operators to regulatory enforcement, reputational damage, and litigation.

Of particular concern is the legal scrutiny around automated decisions that produce significant effects, such as limiting customer access or triggering affordability checks. These actions may require explicit consent or human intervention under GDPR and similar rules. Operators using AI to streamline compliance functions must now balance efficiency with growing legal expectations for explainability, non-discrimination, and data subject rights.

Executive Takeaways:

  1. Do your AI systems qualify as “high-risk” under the EU AI Act? Mapping your AI use cases now can help determine if you fall under stricter obligations across EU operations or partnerships.
  2. Are your AI-driven decisions transparent and explainable to consumers and regulators? Ensure your models include documentation, oversight, and appeal mechanisms for decisions affecting users’ rights or access.
  3. Have your data protection impact assessments been updated for AI use? Existing GDPR and UK DPA obligations may already require you to reassess AI-related risks, particularly where profiling or special category data is involved.

Sources for Reference:

  • EU Artificial Intelligence Act (2024)
  • UK Department for Science, Innovation and Technology – AI Regulation White Paper (2023)
  • UK Information Commissioner’s Office (ICO) guidance on AI and data protection
  • European Data Protection Board (EDPB) guidelines on automated decision-making
  • Gambling Commission statements on data and digital tools in gambling regulation (2023–2024)