Self-exclusion mechanism and GDPR principles
Session Title
Session 2-2-C: Consumer Protection
Presentation Type
Event
Location
Caesars Palace, Las Vegas, Nevada
Start Date
29-5-2019 11:00 AM
End Date
29-5-2019 12:25 PM
Disciplines
Gaming Law | Internet Law | Privacy Law | Science and Technology Law
Abstract
The core of the research is about the interaction between one of the most common measures of responsible gambling, self-exclusion mechanism, and principles of General Data Protection Regulation (GDPR). The principles enshrined by GDPR reflect the contemporary legislative state in the European Data Protection Law with tendencies to become international standards for personal data protection. Thus, the research tends to present how the application of GDPR principles affects the functioning of different types of self-exclusion mechanism.
Self-exclusion mechanisms might be organized in several different ways. Regulatory arrangements on self-exclusion mechanisms may vary from self-regulation to regulations at the international and supranational level. Regulations may limit data processing mechanisms in a manner that affects the accessibility and availability of self-exclusion databases. Thus, for the purposes of this research, the presentation of several different organizations which offer self-exclusion mechanisms are distinguished according to two dimensions – horizontal and vertical. Even though these dimensions are intertwined, the horizontal dimension concerns the connectivity between self-exclusion databases, whereas the vertical aspect concerns the existence of (or lack of) regulations aimed at organizing self-exclusion mechanisms. Taking into consideration both dimensions and their practical variations, a self-exclusion mechanism could be understood as being constructed in the following ways:
- Horizontally disconnected; vertically unregulated
- Horizontally connected; vertically unregulated
- Horizontally connected; vertically regulated
- Horizontally disconnected, vertically regulated
The research demonstrates the relation between the implementation of general principles of GDPR on the one part, and the effectiveness of a self-exclusion mechanism on the other. The research presents how the application of GDPR principles affect each of the four above presented forms of self-exclusion mechanisms with regard to their organizational and regulatory aspects. Thus, it reveals whether confronting interests exist between the effectiveness of a self-exclusion mechanism on the one part and the pro-privacy-oriented approach concerning processing personal data of self-excluded online gamblers on the other. For this purpose, the research answers the following general research question:
- How does the application of GDPR principles affect the effectiveness of a self-exclusion mechanism?
To answer the main research question, the following sub-questions need to be answered:
- What is a self-exclusion mechanism and how it could be organized/regulated?
- What are the features (advantages and disadvantages) of different self-exclusion mechanisms taking into consideration their organizational and regulatory aspects?
- What are the postulates of the effectiveness for self-exclusion mechanisms?
- What are the data protection principles set out by GDPR?
- How does each of the GDPR principles affect the functioning/effectiveness of each of the proposed forms of self-exclusion mechanisms?
The ultimate impact of the research should be found in its contribution to the regulation of technologies, and in reconsideration of the current legislative approach over the online gambling-related activities.
Keywords
Online Gambling, Self-exclusion mechanisms, GDPR, EU Data Protection Law
Funding Sources
The overall research is funded by UNLV’s International Center for Gaming Regulation (ICGR)
Competing Interests
The research presents the continuity of the previously conducted research that the author completed during his Ph.D. fellowship carried out at several European universities (University of Bologna, Italy, University of Turin, Italy, Autonomous University Barcelona, Spain and Tilburg University, Netherlands). His Ph.D. fellowship was funded by the European Commission through the Erasmus Mundus project.
Self-exclusion mechanism and GDPR principles
Caesars Palace, Las Vegas, Nevada
The core of the research is about the interaction between one of the most common measures of responsible gambling, self-exclusion mechanism, and principles of General Data Protection Regulation (GDPR). The principles enshrined by GDPR reflect the contemporary legislative state in the European Data Protection Law with tendencies to become international standards for personal data protection. Thus, the research tends to present how the application of GDPR principles affects the functioning of different types of self-exclusion mechanism.
Self-exclusion mechanisms might be organized in several different ways. Regulatory arrangements on self-exclusion mechanisms may vary from self-regulation to regulations at the international and supranational level. Regulations may limit data processing mechanisms in a manner that affects the accessibility and availability of self-exclusion databases. Thus, for the purposes of this research, the presentation of several different organizations which offer self-exclusion mechanisms are distinguished according to two dimensions – horizontal and vertical. Even though these dimensions are intertwined, the horizontal dimension concerns the connectivity between self-exclusion databases, whereas the vertical aspect concerns the existence of (or lack of) regulations aimed at organizing self-exclusion mechanisms. Taking into consideration both dimensions and their practical variations, a self-exclusion mechanism could be understood as being constructed in the following ways:
- Horizontally disconnected; vertically unregulated
- Horizontally connected; vertically unregulated
- Horizontally connected; vertically regulated
- Horizontally disconnected, vertically regulated
The research demonstrates the relation between the implementation of general principles of GDPR on the one part, and the effectiveness of a self-exclusion mechanism on the other. The research presents how the application of GDPR principles affect each of the four above presented forms of self-exclusion mechanisms with regard to their organizational and regulatory aspects. Thus, it reveals whether confronting interests exist between the effectiveness of a self-exclusion mechanism on the one part and the pro-privacy-oriented approach concerning processing personal data of self-excluded online gamblers on the other. For this purpose, the research answers the following general research question:
- How does the application of GDPR principles affect the effectiveness of a self-exclusion mechanism?
To answer the main research question, the following sub-questions need to be answered:
- What is a self-exclusion mechanism and how it could be organized/regulated?
- What are the features (advantages and disadvantages) of different self-exclusion mechanisms taking into consideration their organizational and regulatory aspects?
- What are the postulates of the effectiveness for self-exclusion mechanisms?
- What are the data protection principles set out by GDPR?
- How does each of the GDPR principles affect the functioning/effectiveness of each of the proposed forms of self-exclusion mechanisms?
The ultimate impact of the research should be found in its contribution to the regulation of technologies, and in reconsideration of the current legislative approach over the online gambling-related activities.