On Tuesday night, your sportsbook meets the rules in three countries. By Wednesday morning, two ad rules shift, a card rail shuts a gate, and a data memo lands. This is normal now. Cross-border betting is not just a license game. It is a dance between ads, payments, player checks, and data across many borders.
In this report, we keep the words simple and the points sharp. You will see what changed, why it matters, and what to do next. We cover the UK and EU hubs, North America, APAC, and LatAm. We add one table you can keep open in a second tab. Then a short checklist you can act on today.
The UK still sets the tone in Europe for safer play and ads. The UK Gambling Commission consultations keep the focus on risk checks, bonus clarity, and data use. The big theme is “affordability” checks that match risk, not one flat rule for all. Expect more trials, and more talk with banks and data vendors.
Policy moves track the government’s white paper on reform. Read the latest note here: UK gambling white paper update. For cross-border teams, watch ad rules, VIP controls, and game design reviews. They shape how you build one code base for many markets.
There is no EU‑wide “passport” for betting. Each state has its own license path. Still, Malta stays a key base for B2B and many B2C brands. The Malta Gaming Authority guidance is clear on AML, change control, and tech rules. It also supports test beds for new tools, but wants tight logs and faster incident reports.
For cross-border teams, the EU risk feels most in data and ads. You must align with GDPR, local ad codes, and match KYC triggers to each state. Do not assume one size fits all. Keep a country matrix and update it monthly.
Germany is strict, with a central body across states. The Gemeinsame Glücksspielbehörde der Länder (GGL) runs more site blocks and pushes payment blocks too. Ads face time and content limits. Slots have stake and speed caps. These rules shape UX, ad copy, and even your bonus plan.
The Dutch market is open but firm. The CRUKS self‑exclusion check is part of KYC, and ad rules are tight, with extra care for young adults. The watchdog is active: see Kansspelautoriteit enforcement. If you run cross-border ads, map Dutch limits apart from your EU set. It is not a copy‑paste job.
In the US, two mature hubs stand out. New Jersey keeps a strong, stable set under the NJ Division of Gaming Enforcement. Nevada stays a special model with retail at the core; check the Nevada Gaming Control Board for updates. Market data and harm tools improve slowly but steadily; see also the American Gaming Association research for trends.
In Canada, Ontario is the key open market with a tough eye on ads and suppliers. Rules sit under AGCO’s iGaming framework. Expect strict copy checks, no “risk‑free” claims, and close watch on affiliates.
Singapore holds a tight, central model. The Gambling Regulatory Authority uses a mix of DNS, IP, and payment blocks. Ads and promos are narrow. Cross-border supply to people in Singapore without the right set‑up is blocked and can draw firm action.
Australia uses both state and federal tools. The ACMA illegal online gambling enforcement page shows ongoing site blocks. Ad timing and content are also set at the federal level. Plan for split ad calendars and creative by region.
Brazil is the big new story. The move from law to rules is in play, with a focus on tax, safer play, ad claims, and vendor checks. For context, see: Brazil regulates sports betting (Reuters). Timelines and fine print still evolve, so do not hard‑code one model yet.
This table gives you one view of core duties by market. It is not legal advice. Use it to plan, then check the primary source before you push code or launch a campaign.
| United Kingdom | Debate on affordability checks; bonus clarity | Open | Partial (payment, counter‑ad) | Strict ad codes; extra care for vulnerable groups | Enhanced due diligence at risk triggers | Point‑of‑consumption | UKGC |
| Malta | Guidance refresh on innovation/sandbox | Open (B2C/B2B) | Limited (focus on licensees) | Clear marketing disclosures | Risk‑based AML | Corporate tax/levies | MGA |
| Germany | GGL boosts site and payment blocks | Open, tightly regulated | Yes (DNS/IP/payment) | Time caps; slots stake/speed limits | Strong KYC with logs | GGR‑based (by state) | GGL |
| Netherlands | Ad limits hold; CRUKS central to onboarding | Open | Yes (blocking/payment) | No inducements to young adults | KYC + CRUKS check each play | Channel‑specific | KSA |
| Ontario (Canada) | Open model maturing; strict ad copy review | Open (per brand) | Partial (service/payment) | No “risk‑free” claims; firm ad rules | AML under federal law | Tax/fees via iGO | AGCO/iGO |
| Singapore | Central model; ongoing blocking | Controlled | Yes (DNS/IP/payment) | Tight ad space | Robust AML controls | N/A | GRA |
| Australia | ACMA expands site blocking | Mixed state/federal | Yes (DNS/IP) | Federal time/content limits | AML/CTF Act scope | Point‑of‑consumption | ACMA |
| Brazil | Law in force; rules in build‑out | Hybrid (evolving) | To be set | Ad claims under review | AML per federal rules | GGR‑based (proposed) | Context |
Payment rails are often the first pain point. In the EU, SCA and PSD2 rules shape how you take cards and e‑money. PSPs also run blocks for some markets on request from a regulator. Keep a live list of methods by country. Test fallback flows. If a card rail shuts, do you have a local e‑wallet ready? Set flags in your risk engine to route payments by geo and product.
Data is the next hard edge. Cross‑border data flows must match lawful bases and transfer rules. For EU data, start with the law text on transfers: GDPR cross‑border transfers (EU law). If you move data to vendors outside the EU, use SCCs, run a DPIA when risk is high, and keep your RoPA updated. If a state needs local storage, set that at the start. Do not bolt it on late.
AML and KYC duties align with global norms, but each state has its own detail. See the baseline: FATF Recommendations. Build a core KYC flow, then add state rules like CRUKS checks or affordability flags. Keep your triggers, docs, and note fields clear and short so agents can act fast.
Ads can bring fast wins but also fast risk. Ban words like “risk‑free” in markets that bar them. Age‑gate all creatives. Log every promo with country tags and dates. Train affiliates. Use pre‑approved copy where needed. Watch whistle‑to‑whistle bans and live odds hooks around sport events.
Before you expand, or sign a deal, verify license status, tools for safer play, and how teams handle disputes. Start with the public register for each market. Then add a second look from an independent hub. One example is 1xBet applications, which tracks apps, features, and user notes across regions. Use sites like this to cross‑check claims on payout speed, KYC friction, and bonus rules. Do not treat any one site as gospel. Triangulate with the regulator’s register and your own test accounts.
No. There is no simple passport for betting across the EU. Some states allow cross‑border supply in parts, but most need a local license or nod. Always check the law in the player’s country.
Yes. Many states use DNS or IP blocks. Some ask PSPs to block payments. Germany, Singapore, and Australia use these tools a lot. See their public notes for proof of action.
It varies. Some use a point‑of‑consumption model. Others tax GGR at the state level. Fees can stack on top. Build tax as a separate module so you can change fast.
Sometimes. In some markets, affiliates must register or hold a license if they do certain ad acts. If you are an affiliate, keep proof of compliance, and use approved copy where required.
Use a lawful base. If you move EU data out of the EU, use SCCs and run a DPIA if risk is high. Keep your vendor map up to date. Cut data you do not need. Less data, less risk.
This article is for information only and is not legal advice. Always read the primary source and speak to counsel before launch. We draw on public guidance and laws from regulators and global bodies. Key sources include the UKGC, MGA, GGL, KSA, NJ DGE, Nevada GCB, AGCO, GRA, ACMA, the GDPR, and the FATF Recommendations.
Update cadence: we review this page each quarter or after any major rule change. Version: 1.0. Date updated: 2026‑07‑28. If you spot a change we missed, please send a note with the source link.