Connect with us
SIS

Affiliate Industry

Gambling Affiliates’ Guide to GDPR

George Miller

Published

on

Gambling Affiliates’ Guide to GDPR
Reading Time: 6 minutes

As of the 25th May 2018, the GDPR comes into effect, and its influence will be felt across virtually every industry imaginable where data is being collected and used on individuals located in the EU. Its overall aim is to ensure better protection of consumers’ information, both online and offline, by enforcing regulations on how data is collected, processed and secured.

What is GDPR?

GDPR stands for General Data Protection Regulation. It’s the result of over 6 years of preparation and consultation over data privacy concerns for EU consumers. The way in which data is collected and used today is profoundly different to how it was a decade ago. According to a report published in 2016 by IBM, “90 percent of the world’s data had been created in the last 12 months” and “many data analysts are suggesting the digital

universe will be 40 times bigger by 2020”.

 

Prior to GDPR, the ‘Data Protection Directive 95/46/EC’ attempted to harmonise the practices of EU member states in terms of their approach to data privacy. Directive 95/46/EC built on the ‘Guidelines on the Protection of Privacy and Transborder Flows of Personal Data’ first published in 1980, which was acknowledged by both the European Union and the United States, as a way to protect personal data and individuals’ privacy.

 

These guidelines still form the basis for the GDPR, but as they and Directive 95/46/EC were merely guidelines and directives, a more stringent and consistent approach was required to “protect the fundamental rights of individuals throughout future waves of innovation”.

 

The GDPR not only unifies the approach to data privacy across the EU, it also regulates it, meaning it is enforceable by law, and in turn carries penalties of up to 4% of annual turnover, or €20 million, whichever is the greater.

 

Pinch yourself all you like, this is happening affiliates, and failure to act now is nothing short of corporate suicide..!

Consent

The main way in which the GDPR aims to protect data subjects (individuals), is through consent. Data subjects must be made aware of the data being collected on them, why it is being collected, what will be done with it, and how long it will be retained for.

Personal Data

The most important thing for affiliates to realise is what Personal Data includes. It doesn’t stop at names, email addresses and phone numbers; it extends to social media posts, IP addresses, and even information stored in tracking cookies.

The GDPR defines it as..

any information relating to an identified or identifiable natural person

 

And importantly..

an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person”.

 

The use of the words ‘directly or indirectly’ is important here. Just because a person’s name and address isn’t stored in a cookie, it doesn’t mean that the information in that cookie can’t be used to identify them. Cookies used by ad networks are able to track an individual from one site to the next, extremely well. In fact, they can potentially track a user across millions of websites.

 

Not only must you pay attention to any data you are collecting directly from individuals, such as name, phone number, email address; you must also think about what tracking codes and analytics software you have installed on your websites, which are used to build a ‘profile’ of someone, usually for advertising purposes.

 

Standard analytics code doesn’t track users across websites, so providing you don’t have any advertising features enabled in your Google Analytics (or other) code, then you won’t necessarily need to obtain consent before setting those cookies. Anything more will require clear and concise consent from your visitors though, ensuring the request for consent includes what, why, and how that data is being collected and used.

Informed Choice

The ‘Cookie Law’ introduced in 2011 (yes, it’s been 7 years!) targeted the usage of non-essential cookies i.e. those not entirely necessary for the basic functionality of a website. However, it didn’t offer users much control or choice.

 

The GDPR aims to change this in that users should be given a choice as to whether or not they agree to non-essential cookies being stored on their computer/browser. Now, accepting that cookies used by standard analytics software aren’t essential, and that they don’t contain ‘personal data’, then where does that leave us? Well, the answer lies in transparency. So long as you are clear in your ‘request for consent’ that the cookies used in your analytics software don’t collect identifiable data, nor are they shared across websites, then you should be fine. Otherwise, if they do (i.e. you have advertising features enabled), you must obtain consent from each and every visitor before setting those cookies.

Newsletter Subscriptions & Accounts

Similarly, if you have a newsletter subscription or account creation feature on your website, then you must obtain consent from users before you can collect their data. Common practice has usually been to present a “Send me occasional news by email” or “I agree to the website T&Cs” checkbox to users. This practice is now imperative, and furthermore, the declaration should be a request for consent, and should point to your Privacy Policy (it can’t be hidden in your T&Cs) which contains the full ‘request for consent’ in a clear and intelligible form, remembering to detail the what, why’s and how’s.

 

And whatever you do, don’t pre-tick the checkbox, or have any kind of “opt-out” option. Consent must be definitive, and unambiguous, and a timestamp of when that consent was obtained, and what the user was consenting to, must be recorded for audit purposes.

 

If your current privacy policy doesn’t satisfy the conditions of the GDPR, then you will need to obtain additional consent from your existing users or subscriber base.

 

In addition, “it must be as easy to withdraw consent as it is to give it”. Users must be offered an option to unsubscribe in all communications, or delete their account on your platform.

 

Think about what data you’re collecting, and whether you really need to. Obtaining consent to collect that data may present more risks than what it’s worth. Additionally, if you later decide to start collecting more data than is detailed in your original privacy policy (or the terms of your privacy policy change), then you will need to obtain additional consent to the updated privacy policy.

Affiliate Tracking Codes

Affiliate tracking cookies are fundamental to online gambling affiliates. Most affiliates are unlikely to want to offer users the ability to disable their tracking codes, and strictly speaking, as the cookies do not (shouldn’t) contain identifiable data that is shared between websites, then it might not be necessary.

 

However, affiliates should still be crystal clear about what cookies may be set as a result of clicking links on their site, why they’re being set, and how they’re being used.  It would also be prudent to offer advice about how users can block these kinds of cookies, for those who choose not to have them set.

Data Subject Rights

The GDPR also empowers individuals with control over their data, as well as outlines a number of responsibilities organisations must adhere to in order to fulfil individuals’ rights to access and control the data held on them.

 

Affiliates must be aware of their responsibilities, and put plans in place to be able to handle those responsibilities:-

Right to Access

Data subjects have the right to know what data is held on them, and how it is being used. They also have the right to request access to that data, which must be delivered to them with 1 month of the the request, in a standard electronic format, free of charge, such that they can transmit that data to another data controller (organisation) should they wish to (Data Portability).

Right To Be Forgotten

Data subjects will also have the right to be forgotten and have any data held on them deleted. Such data will include their personal information, as well as any data which could lead to them being identified, directly or indirectly. If you have implemented any tracking solutions which create a link between the data you hold, and data stored in third party software, then that link will also need to be deleted, and potentially the data stored in the third party software.

Privacy by Design & Security

The GDPR will enforce strict penalties on organisations that have failed to invest appropriate resources into securing their systems, and preventing access of data to unauthorised persons, both online and offline…

 

“The controller shall..implement appropriate technical and organisational measures..in an effective way..in order to meet the requirements of this Regulation and protect the rights of data subjects”.

 

Affiliates should ensure that any data they collect and process has been secured from the outset. If freelancers, designers or content writers have access to data unnecessarily, then it should be restricted. Similarly, any physical data should be locked safely away to prevent unauthorised access, and any new systems or website features should be designed with data privacy in mind.

 

Thought should also be given to data that can be encrypted – it may no longer be acceptable to only encrypt passwords.

Breach Notification

Organisations will be required to notify their appropriate Data Protection Authority within 72 hours of a data breach, where that breach is likely to “result in a risk for the rights and freedoms of individuals”. The gambling industry carries many negative connotations – most individuals probably wouldn’t want their identity associated with a gambling-related website, and so any data breach in this industry is likely to fall into the above category.

Data Protection Officers

Organisations who deal with large scale data processing or ‘special’ categories of data will be required to appoint a Data Protection Officer. Whilst this might not apply to most affiliates, they must understand their responsibilities as data controllers (and/or processors) to ensure the safety and security of data they hold, and ensure it isn’t shared or otherwise fall into the wrong hands. They should keep appropriate internal records, and ensure that their records are auditable.

 

This article contains general information for affiliates to make their own informed decisions about the upcoming GDPR. You must not rely on the information in this article as an alternative to professional legal advice.  The article has been contributed by Pavlos Sideris of Cashbacker – the leading gambling cashback community.

George Miller started his career in content marketing and has started working as an Editor/Content Manager for our company in 2016. George has acquired many experiences when it comes to interviews and newsworthy content becoming Head of Content in 2017. He is responsible for the news being shared on multiple websites that are part of the European Gaming Media Network.

Continue Reading
Advertisement
Comments

Affiliate Industry

Multilotto continue to increase their focus on Affiliates

Zoltan Tundik

Published

on

In this photo: Multilotto’s Chief Growth Officer, Alex Sakota
Reading Time: 1 minute

 

As Multilotto’s Chief Growth Officer, Alex Sakota, joins the panel at the London Affiliate Conference, Multilotto launches its Affiliate site.

There is no doubt that the affiliate market is an integral part of the iGaming industry and at a time where both operators and affiliates are navigating the several changes to regulations from a different jurisdiction, there is an even greater need of better communication and collaboration between the two.

Seeing these changes, Multilotto has decided to up the ante and launch their new website focused solely on Affiliates. The site includes information about their revenue share model, why Affiliates should choose Multilotto, testimonials and a comprehensive blog.

Alex Sakota, Multilotto’s Chief Growth Officer, will also be speaking at the London Affiliates Conference about the recent Swedish Legislation in the “Stockholm Syndrome or: How I Learned to Stop Worrying and Love the Swedish Regulator” panel.

Mr Sakota has a very strong reputation within the industry and has led acquisitions efforts at a number of leading organizations in Malta including EPC Masters, Dating Factory, Traffic Mansion and GFI Software. He organized the island’s first-ever internet marketing seminars and has aced as a lead spokesperson at a number of major events, including eProfitMalta and RE/MAX Europe where he managed in excess of 90M visitors a month, setting new records in the process.

 

About Multilotto

Multilotto is an established online lottery betting service with licenses in the UK, Ireland, Malta and Sweden. It is the online destination for customers who want to access a wide range of international lottery jackpots, offering accessibility, simplicity and ease of use.

Our two biggest jackpots are Powerball and Mega Millions from the United States. We also offer Europe’s largest transnational lotteries, EuroJackpot and EuroMillions, and more lotteries from across the globe.

Continue Reading

Affiliate Industry

CasinoGuide goes German!

Zoltan Tundik

Published

on

CasinoGuide_screenshot
Reading Time: 2 minutes

 

The online casino comparison site launches on a new domain catering for German-speaking players.

A new domain

Following the successful relaunch of CasinoGuide.com back in October, the CasinoGuide team have wasted no time in adding another site to their growing portfolio – CasinoGuide.de. The brand-new site will cater exclusively for the German-speaking community and offer an equally comprehensive range of casino content as the already-established CasinoGuide.com and CasinoGuide.co.uk.

CasinoGuide.de will also benefit from the same technical advantages of its sister sites, by being fully mobile responsive, quick to load, and complemented by a concise selection of the most popular casino games. Slots fans will find the Spieleautomaten page well-equipped with free-play versions of the hottest titles, and players of other casino classics like Roulette and Blackjack won’t be disappointed either.

Why German?

The trend data shows that as with most countries, the popularity of online casinos has been growing steadily in Germany over the past five years, and with an estimated population of over 82 million people it’s no surprise to see more sites appearing in this market. And while the majority of the site’s visitors will be based in Germany, CasinoGuide.de will also cater for German-speaking online casino players based in Austria, Switzerland, and the rest of the world.

Launched in record time

Project Manager Alex Tester stated: “bringing the CasinoGuide experience to German speakers is something we’ve been wanting to do for some time now, and I’m very much looking forward to working within this challenging market. This is just the first step in what we hope will be a highly successful year of expansion and growth for CasinoGuide.

“A huge amount of praise must be given to content and development teams, who have collaborated brilliantly; delivering this project to a very high standard, in record time.”

The CasinoGuide.de team will be hoping to emulate the success of its sister sites as quickly as possible – but of course it remains to be seen whether it will meet the standard.

Contact information: info@casinoguide.com

Continue Reading

Affiliate Industry

GamblersPick awards first “Select” seals to leading brands

George Miller

Published

on

GamblersPick awards first “Select” seals to leading brands
Reading Time: 1 minute

 

House Tech Ads’ community-driven casino portal grants seals of approval

 

GamblersPick.com, the community-driven online casino portal managed by leading affiliate network House Tech Ads, has awarded top-tier online casinos its first “Select” seals of approval.

The first brands to be recognised are Bet365, PlayOJO, Twin Casino, 888, Royal Vegas and Jackpot City, chosen for their commitment to the highest standards of credibility, customer experience and player safety while maintaining a diverse selection of the best cross-platform games.

GamblersPick Select was launched to provide a stamp of approval guiding players to find the highest-rated online casinos.

Oren Arzony, Director at House Tech Ads, said: “One of the defining features of GamblersPick.com is the Select seal, and we are delighted to have enhanced its offering in granting our first seals of approval to leading gaming brands that meet the highest standards of technical and commercial excellence.

“GamblersPick is a community-driven affiliate site that encourages players to share their views and experiences to create a fairer, fulfilling and more enjoyable online casino experience. The establishment of GamblersPick Select makes it the perfect site for finding the ideal place to play.”

The leading affiliate network also operates highly regarded affiliate marketing brands Jackpots Finder and Online Casino Reports, partnering with many leading operators worldwide including 888 Holdings, EGamingOnline, L&L Europe, Buffalo Partners, Affiliate Club and more.

Continue Reading
Advertisement
NSoft

Global Gaming Industry Newsletter – Weekly Digest (sent every Wednesday)

Please select all the ways you would like to hear from European Gaming Media and Events:

You can unsubscribe at any time by clicking the link in the footer of our emails. For information about our privacy practices, please visit our website.

We use Mailchimp as our marketing platform. By clicking below to subscribe, you acknowledge that your information will be transferred to Mailchimp for processing. Learn more about Mailchimp's privacy practices here. Read more about European Gaming Media and Event's Privacy Policy and Terms of Service.

Subscribe to our News via Email

Enter your email address to subscribe to our news and receive notifications of new posts by email.

Latest by author

Trending

Notice for AdBlock users

We are constantly showing banners about important news regarding events and product launches. Please turn AdBlock off in order to see these areas.