Competing gambling firms already exchange health-related data about their most vulnerable customers through a shared scheme. Nothing equivalent exists for payment fraud, even though the financial sector has run exactly such a system, lawfully, for decades…
Britain’s largest online gambling operators pass details of their most vulnerable customers directly to their competitors.
Someone who tells one firm that they have a gambling addiction, are seeking treatment, or should not be gambling because of a medical condition can be identified across every rival brand where they hold an account, and have those accounts closed as well.
The scheme which carries this information, GamProtect, states in its own privacy notice the data it moves is ‘special category data’, which is a health-related category UK data protection law guards most closely.

GamProtect transfers a defined set of fields once an operator closes a customer’s account on health grounds: full name, date of birth, postcode, email address, telephone number, a unique customer identifier and a flag marking the closure.
Operators participating in GamProtect can check their live customer databases against the system and close the accounts of anyone who matches.
GamProtect’s privacy notice rests the general processing on the operators’ legitimate interests in protecting customers from harm. The health data, which the law protects more tightly, falls under a separate ground – the Data Protection Act 2018‘s substantial-public-interest condition for safeguarding individuals at risk.
A person added to the system stays subject to matching for an initial five years, a window that can run on for as long as 35 years, before a further seven-year archive.
The scheme exists because the Gambling Commission challenged the industry in 2020 to build a “single customer view” that could identify at-risk customers across operators, and the work ran alongside the Information Commissioner’s Office (ICO), whose regulatory sandbox tested whether the sharing could be lawful.
The Commission’s 2023-24 annual report records that GamProtect was trialled and implemented across four of its largest operators; the industry has identified these founding firms as Flutter, Entain, bet365 and William Hill, with Broadway Gaming and Betway joining afterwards.
By the Commission’s own account, given by Executive Director Tim Miller at the scheme’s September 2024 showcase, 5,527 customers had been flagged to GamProtect since the 2023 pilot, with 88% of them matched by at least one other operator.
Health data – legally, the harder case – now moves between direct competitors as routine practice.
Data protection in gambling is not the barrier
No comparable facility exists for payment fraud across gambling operators, and the objection usually raised against one is data protection.
The ICO has found it necessary to publish guidance rejecting this objection; its advice on sharing personal information to prevent scams and fraud states UK data protection law does not stand in the way of sharing personal information to prevent harm.
For private-sector firms sharing fraud data, the guidance lists legitimate interests, consent and performance of a contract as available lawful bases, and it points out that Recital 47 of the UK GDPR expressly recognises fraud prevention as a legitimate purpose.
The Data (Use and Access) Act 2025 employs a “recognised legitimate interest” basis, in force since February 2026, which names the prevention, detection and investigation of crime – fraud included – as a pre-approved purpose for processing, sparing firms even the balancing exercise the ordinary legitimate-interests test requires.
The financial sector already runs one
The financial sector addressed the fraud data sharing issue some time ago in the shape of Cifas.
The United Kingdom’s fraud-prevention service runs the National Fraud Database, into which banks, insurers, lenders and other members file confirmed fraud cases and against which they check applications and existing accounts.

The database holds roughly two million records, takes a new case around every 90 seconds and records more than 350,000 cases a year. Cifas states in its published legitimate-interests assessment members using the database prevent more than £1bn in fraud losses annually, and it put the figure at an estimated £1.8bn for 2023.
The arrangement runs under the same UK GDPR and Data Protection Act, on the legitimate-interests basis, supported by an evidential standard for every entry, a set of eight operating principles and a redress route for anyone recorded who disputes it.
Cifas describes fraud in that assessment as “a non-competitive issue”, operating as a not-for-profit body specified under section 68 of the Serious Crime Act 2007. Members must file their own cases to draw on everyone else’s.
The scale of the problem gambling operators face alone appears in UK Finance’s figures. Its members reported £1.28bn stolen through payment fraud in 2025, a 4% rise on the year before. Unauthorised fraud – transactions the customer never sanctioned, including stolen-card purchases – accounted for £703.4m across 3.81 million cases.
Remote purchase card fraud, in which criminals use stolen card details to buy online, reached £423.5m on its own, with case numbers up 13% to 3.2 million. Authorised push payment fraud, the bank-transfer scams behind much of the rest, added a further £576.4m.

UK Finance compiles this data from members which includes the card-payment acquirers sitting behind gambling checkouts.
Ruth Ray, UK Finance’s Managing Director of Economic Crime, said the financial sector “cannot be the only line of defence”. Jonathan Frost, a global advisory director at the behavioural-intelligence firm BioCatch, argued in the same report that no institution can defeat this fraud on its own, and that a connected industry denies criminals a scale a fragmented one cannot.
Gambling operators hold plenty of fraud signals of their own, and a duty to act on them.
Licence Condition 12.1.1 of the Commission’s rulebook requires them to guard against money laundering and terrorist financing; Licence Condition 17.1.1 requires them to verify a customer’s identity before that customer may gamble, and to keep that information accurate.
The Commission’s money-laundering guidance instructs operators to consider whether identity documents are sufficient to catch false, stolen or “mule” third-party identities, which are among the signals payment fraud turns on.
Operators already run enhanced due diligence, source-of-funds and source-of-wealth checks. They collect, verify and act on precisely the customer and financial data a shared fraud utility would draw on, under legal obligation, without treating data protection as an obstacle.
Why no shared system exists for fraud
What each operator lacks is the view across the market: the same stolen card, the same mule account or the same fraud ring surfacing at six competing brands at once.
The cross-operator picture does not gather inside any single firm, but accumulates instead inside the payment service providers, acquirers and orchestration platforms whose fraud-scoring engines operators buy as a product.
So why don’t they build it? No operator or payments firm has publicly set out a rationale. The reasons that fit best are commercial, because fraud prevention has become a competitive function, and a firm which publishes its loss figures or surrenders its pattern library gives rivals an advantage; reluctance on that ground is understandable.
Ownership of data is another pressure, as the businesses best placed to build a shared fraud utility – the acquirers and orchestration platforms holding the cross-market data – already sell fraud scoring based on the data, so a shared, industry-wide database would compete with the product they market. The commercial incentive runs against building the thing which could help operators the most.
Both GamProtect and Cifas needed a convenor. One followed a regulator’s explicit challenge, an industry delivery body and several years of sandbox work with the ICO. The other has spent decades as a trusted, not-for-profit intermediary which competitors were willing to feed.
A fraud-sharing equivalent for gambling would need the same components – a lawful-basis assessment, an evidential standard, a neutral operator – together with the agreement of the payments firms currently holding the data. Blocking this from becoming a reality, at present, is a party willing to assemble them, and a regulator applying the pressure that produced GamProtect.