This Thought Experiment is a scenario-based exercise designed to provoke discussion. It is not a prediction or statement of fact.
Brazil has given the gambling industry an unusually detailed set of wind-down rules, and almost all of them are about money. Medida Provisória nº 1.394, signed on 25 September 2026, stopped deposits on publication, took the licensed sites offline on 6 October, and puts every bettor balance back through the banks by taxpayer number this week. One clause then asks operators to hold five years of bettor records after the business that collected them has stopped existing in any useful sense. Nothing in the measure says who looks after those records, where they sit, who still has access, or who signs to confirm they were destroyed at the end. This piece asks what happens if the answer turns out to be nobody.
Key Takeaways
- Medida Provisória nº 1.394 of 25 September 2026 bans fixed-odds betting across Brazil. Deposits stopped on publication, the licensed sites were disabled on 6 October under Article 7, and Article 4 extinguishes the 85 authorisations around 25 October.
- Article 10 then requires operators to keep complete and accessible records of bettors, bets, financial operations and prize payments for at least five years after they stop trading. It names no custodian, sets no security standard for the retained store, restricts no sale or reuse, and says nothing about who certifies deletion.
- Great Britain has the same gap. The Gambling Commission’s guidance for licensees closing a business is detailed on returning customer funds and silent on customer data, and the five-year retention duty sits in anti-money laundering law instead. Australia runs the equivalent duty for seven years.
- The scenario is an orphaned data estate: an identity-grade database that a public authority requires a company to keep for five years, inside an entity with no licence, no revenue and soon no staff who know where it is.
1. What does Brazil’s ban actually require operators to keep?
The measure requires five years of complete and accessible records on every bettor, every bet, every financial operation and every prize payment. Medida Provisória nº 1.394 took effect on publication on 25 September 2026, which stopped new money entering operators’ transactional accounts that day. Article 7 gave them 10 days to disable their websites and applications, so the licensed Brazilian sites went dark on 6 October. Article 8 then gave them two days to fund the refunds and to send each institution holding their transactional accounts a list of bettors with CPF numbers and amounts, copied to the Secretariat of Prizes and Bets, with a fine of R$200,000 a day for missing it. Article 9 gave the banks seven days to pay.
Article 10 outlives all of that. The end of an authorisation does not end the obligations of the period the authorisation covered, and the fourth item on its list is the five-year retention duty. Article 11 keeps operators reporting into Sigap until activity stops, and Article 5 requires a current legal representative and contact details to stay registered with the Secretariat for as long as any duty survives. The money has a deadline, the retention has a duration, and the custody of what is retained has neither.
2. What would an orphaned bettor database look like?
It would look like a database that outlives every commercial reason anyone had to defend it. Take an operator holding a few hundred thousand Brazilian accounts. After the regime it has just lived through, that record set is an identity file rather than a marketing list: name, CPF, address, bank account, deposit, withdrawal and bet-level history, and often facial images from onboarding alongside income estimates bought from credit bureaux.
Instituto SIGILO, a Brazilian digital rights body that opened its own civil inquiry on 27 September, sampled five licensed platforms and reported retention periods of five to 10 years and in part indefinite, facial biometrics and data about compulsive play handled as ordinary personal data, income and vulnerability estimated from credit bureau and social programme records, and international transfers with no publicly identified mechanism. Those are an advocacy body’s findings rather than a regulator’s, and they describe the estate that the retention duty has now frozen in place.
Now take the revenue away. The sector supported more than 15,000 jobs according to a 2025 study commissioned by the National Association of Games and Lotteries, operators have already warned about cuts, and a platform contract is an obvious thing to terminate. The engineers who knew which storage bucket the biometric images sit in will take other jobs, as people do. Five years is long enough for the access list to stop matching the payroll twice over, and nobody in the structure is paid to notice.
3. Does any market name a custodian for the data after an exit?
Not on the published evidence, and Great Britain is the useful comparison because its exit rules are otherwise the most detailed anywhere. The Gambling Commission’s guidance for a licensee closing a licensed gambling business is specific about money: agree a closure plan with the Licensing Team, give customers two to four weeks’ notice, return funds including to inactive customers, keep a refund route open for about four weeks after the site closes, and report customer numbers, funds held and ante-post liabilities. On customer data it says nothing.
The British retention duty sits in anti-money laundering law rather than in the exit process. Regulation 40(3) of the Money Laundering Regulations 2017 requires customer identification records to be kept for five years after the business relationship ends, and regulation 40(5) then requires the personal data to be deleted unless a law, court proceedings or the customer’s own agreement keeps it. The Commission’s data protection guidance adds that it expects regulatory data to be available for a minimum of five years, and that what to keep is the licensee’s decision. Australia runs the same duty for seven years under sections 107, 108, 111 and 116 of the AML/CTF Act 2006, so the clock there can still be running long after a business has stopped offering anything.
| Market | What the exit rules say about customer money | How long customer data must be kept after trading stops | Custody and deletion named? |
| Brazil | MP nº 1.394 Articles 7 to 9: deposits stopped on publication, sites disabled within 10 days, bettor lists to the banks and the Secretariat within two days, bank refunds within seven days, R$200,000 a day for failure, Caixa Econômica Federal as the backstop | At least five years of bettor, betting, financial and prize records (Article 10) | No. No custodian, no security standard, no deletion step, and no restriction on sale or reuse |
| Great Britain | Closure plan agreed with the Licensing Team, two to four weeks’ notice to customers, funds returned including to inactive customers, refund route open about four weeks after closure, customer funds and ante-post liabilities reported | Five years from the end of the customer relationship (regulation 40(3), Money Laundering Regulations 2017), and the Commission expects the same five years for regulatory data | Deletion is required once the period ends (regulation 40(5)), but no custodian is named and the licensee decides what to keep |
| Australia | Not addressed as a single exit process in the same way | Seven years, counted from the end of the relationship or the creation of the record (AML/CTF Act 2006, sections 107, 108, 111 and 116) | No. The duty attaches to the reporting entity, with nothing on what happens once it stops operating |
4. What happens to a bettor database that nobody owns?
It acquires a market. Offshore brands’ share of Brazilian iGaming demand went from 3.4% on 24 September to 9.9% on 29 September on Blask figures reported in the trade press, and affiliate coverage of the 20 most promoted brands fell 41.5% in a week, from 715 sites to 418. Brazilian players did not stop existing when the licensed sites closed, so a verified list of people with a known deposit history is about the most valuable acquisition asset in that market. Nothing in MP nº 1.394 forbids selling one, which is why Instituto SIGILO has asked the ANPD and SENACON to prohibit it, including in insolvency and inside the same corporate group.
Insolvency is where this gets tested first, and the nearest precedent is not from gambling. When 23andMe went through Chapter 11 in 2025 the asset that mattered was the genetic database, state attorneys general intervened over how customer data would be treated in the sale, and the business was bought for $305m by a non-profit with privacy undertakings attached. A bettor file is less intimate than a genome and very much larger. The quieter version of this needs no bad actor at all: if a retained store is breached in 2029, Article 48 of the LGPD still requires the controller to tell the ANPD and the people affected, and that controller is a company with no licence and possibly no employees.
5. What should an operator do before the lights go out?
Give the retained data an owner before the entity holding it stops functioning. Six steps, and they work the same way in any market exit rather than only this one.
- Name the custodian in writing: the surviving legal entity that holds the records, the individual accountable for them by name, the budget line paying for storage and monitoring, and the review date. Leaving it with a dormant local subsidiary is a decision too, so take it deliberately rather than by default.
- Cut the retained set down to what the duty actually names, field by field. Article 10 asks for records of bettors, bets, financial operations and prize payments. It does not ask for facial images, marketing profiles, affordability inferences or call recordings, so decide which of those the duty genuinely covers and delete the rest while somebody still knows where it is.
- Revoke access against a named list rather than against the payroll. Export every account with read access to the retained stores, third-party platform, warehouse, analytics and customer service vendors included, then close them one at a time with a record of who approved each closure.
- Decide where the data physically sits, and whether moving it to a group entity in another country creates an international transfer that needs its own mechanism now that no local controller is left behind it.
- Fix the deletion date and name who certifies it. Five years from which event, calculated how, evidenced by whom, and reported to whom.
- Write the incident route for an entity with no licence, naming the person who notifies the ANPD under Article 48 of the LGPD, the person who notifies the bettors, and the legal representative registered with the Secretariat who answers the phone.
Boardroom Questions
- Which entity in our group holds retained customer records for every market we have exited, and who is the named individual accountable for each one?
- What sits inside those retained stores beyond what the retention duty names, and what would deleting the rest cost us this quarter?
- If a retained Brazilian store were breached three years from now, who notifies the ANPD and the bettors, and is that person still employed by us?
- What is our written policy on selling, transferring or reusing a bettor database from a closed market, including inside our own group?
- When a market exit plan next comes to this board, will it carry a data custody section beside the customer funds section?
Sources
1. Medida Provisória nº 1.394, de 25 de setembro de 2026, Presidência da República, Casa Civil, planalto.gov.br. Articles 4, 5, 7, 8, 9, 10 and 11, and Article 29 on the revocation of provisions of Law nº 14,790/2023.
2. Lei nº 13.709/2018 (Lei Geral de Proteção de Dados Pessoais), Articles 15, 16 and 48, on termination of processing, the grounds for retaining data afterwards, and communication of a security incident to the ANPD and to the people affected.
3. Instituto SIGILO, “O que acontece com os seus dados quando as bets fecham as portas”, published 28 September 2026, and Inquérito Civil ICI-SIGILO nº 004/2026 opened 27 September 2026. The findings on retention periods, biometrics and international transfers are the Institute’s own, drawn from a sample of five licensed platforms, and the companies are not named.
4. Gambling Commission, “Closing a Gambling Commission licensed gambling business”, guidance for licensees and businesses, gamblingcommission.gov.uk.
5. The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, SI 2017/692, regulation 40(3) and regulation 40(5), as set out in the Gambling Commission’s money laundering manual, part 7.8, retention period.
6. Gambling Commission, “Gambling regulation and the General Data Protection Regulation (GDPR)”, guidance for licensees, on the five-year expectation and on licensee responsibility for retention decisions.
7. AUSTRAC, “Record keeping overview”, citing the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), sections 107(1), 108(2), 111(2) and 116(3).
8. CasinoBeats, “Brazil’s betting ban puts operators and jobs under pressure”, 7 October 2026, reporting Blask data via Yogonet on offshore demand share and affiliate coverage, and a 2025 study commissioned by the National Association of Games and Lotteries and the Brazilian Institute for Responsible Gaming on employment supported by the sector.
9. In re 23andMe Holding Co., Chapter 11 proceedings, United States, 2025. The sale to the TTAM Research Institute for $305m was approved by the bankruptcy court after interventions by state attorneys general over the treatment of customer genetic data.