- Home
- Practice areas
- iGaming and Sports Betting
- Data Protection and LGPD
LGPD for betting operators: player data under control
Registration, biometrics, payments and betting behavior form one of the most sensitive databases in the market. Two regulators look at it at the same time.

LGPD for betting operators means aligning the operator with Law 13,709/2018, Brazil's General Data Protection Law, together with the data rules issued by the SPA/MF. It covers a legal basis for each processing activity, care with biometrics, secure storage, player rights and incident response. Engage counsel when building the platform, switching technology suppliers or facing an incident.
LGPD for betting operators is not a side chapter of compliance: it is part of the license. Operators process ID documents, CPF (the Brazilian taxpayer number), bank details, geolocation, facial biometrics and each customer's betting history, and answer for it under Law 13,709/2018 (LGPD, Brazil's General Data Protection Law) and before the Secretariat of Prizes and Betting of the Ministry of Finance (SPA/MF).
Sector rules overlap with the LGPD. SPA/MF Ordinance 722/2024 sets technical and security requirements and requires systems and data to be hosted in data centers located in Brazil, with an exception for countries that have an international legal cooperation agreement with Brazil. SPA/MF Ordinance 1,231/2024 requires facial recognition in defined situations and protects self-excluded players, and SPA/MF Ordinance 1,857/2024 governs data transfers between companies of the same group.
We see the topic as legal engineering: every data point needs a purpose, a legal basis, a retention period and an owner. Once that is designed, the operator answers data subjects, the regulator and the press with the same version of the facts.
When to call a lawyer
Platform or KYC provider changing
Switching platform, identity verification or cloud providers changes where data sits and who can access it. Without a contract and an assessment, the operator inherits the supplier's risk.
Data processed outside Brazil
Foreign groups often centralize data abroad. Ordinance 722/2024 limits that choice and the LGPD requires a valid mechanism for international transfers.
Use of biometrics and behavioral profiling
Biometric data is sensitive data under the LGPD. Monitoring behavior for responsible gambling also requires a well-defined legal basis and transparency.
Data subject request, complaint or breach
An access or deletion request, a consumer protection complaint or a suspected incident shows whether the process really exists.
What happens when it is left for later
- Sanctions by the ANPD (Brazil's National Data Protection Authority) under the LGPD, including warnings, fines, public disclosure of the violation and blocking or deletion of the data involved.
- Proceedings before the SPA/MF when a data failure also breaches a technical or security requirement of the authorization.
- Lawsuits by players and consumer claims after an incident, with defense and response costs added to any fine.
- Immediate reputational damage: a leak of players' financial data reaches the press, payment partners and the authorization renewal.
How we work
Data mapping
We inventory data processed in registration, KYC, payments, responsible gambling, marketing and customer service, with source, purpose, storage location and suppliers involved.
Legal basis and sector rules
We define the legal basis for each activity, including the sensitive data grounds of Article 11 of the LGPD for biometrics, and cross-check the result against SPA/MF ordinances.
Documents and contracts
We draft the privacy policy, cookie notices, a data protection impact assessment where appropriate and data protection clauses with platform, KYC, payment, affiliate and cloud providers.
Governance and data subject rights
We structure the data protection officer role, the player service channel, retention periods and the flow for international or intra-group transfers.
Incident response plan
We build the protocol for containment, assessment and notification to the ANPD and data subjects, run simulations and act if the incident becomes an administrative or court case.
What you receive
- Personal data inventory with purpose, legal basis and retention period.
- Privacy policy and player notices in plain language.
- Data protection impact assessment for the highest-risk activities.
- Data protection addenda and clauses for key suppliers.
- Incident response plan with a decision matrix and communication templates.

Why the firm
LGPD read through the betting regulator's lens
We do not apply a generic privacy template. The work considers, at the same time, the LGPD and the SPA/MF ordinances the operator must comply with.
Responsible gambling without privacy conflict
Monitoring signs of addiction and honoring self-exclusion requires data. We design that use with a clear purpose and transparency toward players.
From prevention to defense
The same team that builds the program handles incident response, dealings with authorities and litigation.
Illustrative scenario
Hypothetical scenario, for illustration only. A foreign group obtains authorization to operate in Brazil and plans to keep its platform and database in the data center it already uses abroad, with its facial verification provider in a third country. In a situation like this, the work starts by checking what Ordinance 722/2024 allows regarding data location, continues with an analysis of the international transfer mechanism required by the LGPD and a review of each supplier contract. The aim is a data architecture the operator can explain to the regulator, with known risks and documented decisions.
A hypothetical scenario, shown only to illustrate our method. Every case depends on its own facts.Frequently asked questions
Does LGPD for betting operators have specific rules?
There is no separate data protection law for betting, but operators must comply with Law 13,709/2018 plus the SPA/MF data rules. These include Ordinance 722/2024 on technical requirements and data location, Ordinance 1,231/2024 on authentication and responsible gambling, and Ordinance 1,857/2024 on intra-group data transfers. Compliance must address both layers at once.
Can player data be stored outside Brazil?
As a rule, no. SPA/MF Ordinance 722/2024 requires systems and data to be kept in data centers in Brazil and allows an exception for countries with an international legal cooperation agreement with Brazil in civil and criminal matters. Even under the exception, the transfer must follow the LGPD rules on international transfers.
Is a player's facial biometric data sensitive data?
Yes. The LGPD classifies biometric data linked to a person as sensitive personal data, which narrows the available legal bases and calls for stronger security. In practice, the authentication purpose required by the regulation and the retention period must be documented.
What should an operator do after a player data breach?
Contain the incident, preserve evidence and assess the risk to data subjects immediately. If there is relevant risk or harm, the LGPD requires notice to the ANPD and to affected players, within the deadline and format set by the authority. Having the protocol ready before an incident is what prevents improvised decisions.
Does a betting operator need a data protection officer?
Yes, the LGPD requires the controller to appoint a data protection officer, who handles data subjects and deals with the ANPD. In a betting operator, this role needs direct access to governance and close interaction with compliance, information security and customer service.
Can an operator send advertising to a self-excluded player?
No. SPA/MF Ordinance 1,231/2024 prohibits sending advertising to players who requested self-exclusion or were excluded by court order. Marketing databases, including those of affiliates, must therefore be kept updated with the list of barred players.
Related matters
Is your players' data protected and documented?
Talk to our iGaming team. We start by mapping your data and deliver a compliance plan with clear priorities.