In Spain, online player identity verification is mandatory by law, with multi-million-euro fines serving as a warning. We look at what Law 10/2010 requires, what the DGOJ’s Safe Gambling Programme adds, and what the European AML Regulation (AMLR) will bring in 2027.
In 2026, two regulatory frameworks coexist in Spain which, although they stem from different objectives, converge on the same point: player identity. On the one hand, the Directorate General for the Regulation of Gambling (DGOJ) has published its 2026–2030 Safe Gambling Programme, successor to the 2019–2022 Responsible Gambling Programme, focused on protecting participants and preventing gambling addiction. On the other, Law 10/2010 on the prevention of money laundering and terrorist financing, in force for more than a decade, requires gambling operators to identify and continuously verify their customers.
Both regulations address, each within its own area of competence, the same underlying issue: knowing with certainty who is behind each gambling account and maintaining that certainty over time. They are not isolated pieces of legislation. Behind both lies institutional cooperation between the DGOJ, the Ministry of Economy, the Treasury and the Executive Service of the Commission for the Prevention of Money Laundering (SEPBLAC), placing player identification among the sector’s most closely supervised areas at present.
What the DGOJ’s 2026–2030 Safe Gambling Programme says
The new programme is structured around three priorities: analysis and diagnosis, prevention, and the promotion of safe gambling, developed through six general objectives and twenty-four specific measures. Above all, it is a programme focused on research, guidance and awareness-raising that does not introduce new technical measures for online player identity verification in Spain. It does, however, make clear in several areas that player identity is a key foundation underpinning many of its objectives.
Some of the measures
Measure 1.1.e) addresses the introduction of an online risk gambling detection mechanism, enabled by Royal Decree 176/2023. The aim is for all operators to apply the same parameters for identifying risky behaviour. However, this mechanism only makes sense if the operator can guarantee that the person gambling today is the same person who gambled yesterday. Ultimately, detecting risk patterns depends on consistent and reliable identification.
Measure 1.1.f), which focuses on gender analysis in gambling behaviour, includes an assessment of identity theft “tangentially”, noting that it primarily affects women. This appears to be a relevant finding confirming that the problem is not anecdotal, but rather a recognised pattern that has already been documented by the authorities.
Phishing Alert and the Protocol for Action for Impersonated Taxpayers (PACS)
Both existing initiatives are referenced in the programme’s background and in Measure 1.1.d), which proposes studying the sociodemographic profile of the people using these services. Their inclusion is an explicit acknowledgement by the DGOJ itself that identity theft remains an issue in the online gambling sector. That said, the response provided by both tools is reactive: they help people who have already been impersonated, rather than preventing identity theft at registration or access.
General Register of Gambling Access Bans (RGIAJ)
Something similar applies to the RGIAJ, whose automated interconnection with regional registers has been strengthened in recent years. Self-exclusion and self-banning only genuinely protect the person who requests them if the operator can verify, without room for error, that the person attempting to access the account is that same individual. Once again, this requires reliable identification at source, carried out in advance and independently of the RGIAJ check itself.
This is compounded by a contextual finding included in the programme itself. According to the 2022–2023 Gambling Prevalence Study, 6.29% of people aged between 18 and 25 have participated in gambling activities, with online gambling being the predominant channel. It is precisely this young, digitally active and social media-oriented demographic that the programme repeatedly identifies as vulnerable, and it is also the group most exposed to phenomena such as identity theft or the use of third-party accounts to circumvent self-exclusion.

What Law 10/2010 already requires today
While the Safe Gambling Programme operates in the area of access control (minors and self-excluded players), Law 10/2010 and its implementing regulation, Royal Decree 304/2014, have for years governed a different and more demanding area: online player identity verification in Spain for the purposes of preventing money laundering, together with ongoing monitoring throughout the business relationship.
Article 7.6 of Law 10/2010 is particularly specific to the industry. It establishes that gambling operators operating through electronic, computer, telematic and interactive means must identify and verify the identity of all persons seeking to participate in such games or bets, under the terms established by regulation. This obligation applies specifically to the online channel and is different from the requirements applicable to land-based gambling. It does not depend on reaching any financial threshold. It applies from the moment someone seeks to participate, not only when they move a certain amount of money. From there, the law establishes additional obligations.
Other relevant obligations
- Formal identification and identification of the beneficial owner before establishing the business relationship.
- Ongoing monitoring of the relationship (Article 6): verification at registration is not enough. Operators must keep documents up to date and continuously monitor the customer’s behaviour.
- Special examination (Article 17) of unusual or complex transactions with no apparent economic or lawful justification.
- Enhanced identification when a customer withdraws winnings or places bets with a value equal to or above €2,000 (Article 7.6), whether in a single transaction or across several transactions that appear to be related.
SEPBLAC, which supervises compliance with this legislation, has significantly increased its focus on the sector in recent years.
In February 2025, the first sector-specific conference on the prevention of money laundering and terrorist financing aimed specifically at online gambling operators was held. It was jointly organised by the DGOJ, the Treasury and SEPBLAC, with the participation of licensed operators.
Shortly afterwards, SEPBLAC added a dedicated online gambling section to its FAQ page, addressing issues such as the applicable rules on customer identification and the number of current accounts and payment methods used by the same player as a potential money laundering risk indicator. This last point is particularly relevant because it shows that the law does not need to change for the supervisor to make clear that reliably linking a player’s identity to their payment methods is already a supervisory priority.
The real cost of non-compliance
These obligations are not merely theoretical, and the Spanish online gambling sector is already seeing the consequences on two different enforcement fronts, which should not be confused.
Breaches of Law 13/2011 regulating gambling
On the one hand, the DGOJ itself sanctions breaches of Law 13/2011 regulating gambling. The legislation governing licences and gambling activities. In a single batch of decisions, the DGOJ imposed sanctions for serious and very serious breaches on more than thirty operators in the betting and online gambling sector, with fines totalling more than €33 million. These included several very serious breaches involving foreign operators operating without a licence in Spain.
Infractions of Law 10/2010 on the prevention of money laundering
Separately, the Ministry of Economy, Trade and Enterprise sanctions breaches of Law 10/2010 on the prevention of money laundering, following proposals from SEPBLAC. In 2026, the Spanish Official State Gazette published a final sanction against a licensed online gambling operator in Spain for two serious breaches of the law: failure to comply with Article 6 (ongoing monitoring of the business relationship) and Article 17 (the obligation to conduct a special examination). The result was two fines of €275,976 each, together with a public reprimand in both cases. More than €550,000 in sanctions, without taking into account the reputational cost of having the company’s name published in the Official State Gazette alongside the words “serious breach”.
It is worth noting that neither of these decisions is a court judgment or creates case law. They are administrative sanctioning decisions that are final at the administrative level. They do not establish an interpretative doctrine on what constitutes sufficient ongoing monitoring or exactly when a special examination is triggered. The published texts do not provide details of the facts in each case, but they do confirm that the Spanish online gambling sector is being inspected and sanctioned by two different authorities under two different laws, with player identification and ongoing monitoring being the common thread in both cases.
So, what does compliance actually mean in practice?
Beyond the wording of the law, complying with these two requirements usually translates into specific operational processes.
Ongoing monitoring (Article 6):
- Continuous transaction monitoring of deposits, withdrawals and gambling patterns, not just at registration.
- Regular updates to customer data and risk profile information.
- Detection of inconsistencies between the profile declared by the customer and their actual behaviour.
- Monitoring the number of current accounts or payment methods associated with the same player. SEPBLAC itself identifies this as a potential risk indicator, which requires operators to be able to link each payment method with certainty to a single verified identity.
- Documentary traceability of this monitoring and the ability to demonstrate it during an inspection.
The special examination (Article 17):
- Rules for detecting unusual transactions (deposits followed by rapid withdrawals with little or no gambling activity in between, the use of multiple third-party payment methods, splitting deposits to avoid thresholds, and geographical inconsistencies).
- A documented examination of each alert, including a written record of what was reviewed and what was concluded.
- An internal control body responsible for receiving and resolving these examinations, with a representative appointed before SEPBLAC.
- Reporting to SEPBLAC within the established timeframes when the examination reveals indications of money laundering.
In other words, the operator must be able to guarantee that the person gambling today is the same person whose identity was verified when they registered. Also, that this identification remains reliable over time. If the initial verification is not robust or is not updated when necessary, both ongoing monitoring and the analysis of risk situations are built on an unreliable foundation.
The challenge of protecting what has already been verified
Everything above assumes that online player identity verification works correctly. But there is a question that falls outside both Law 10/2010 and the Safe Gambling Programme, and which a recent incident in Spain’s online gambling sector has brought back into focus: what happens to identity data once it has been captured and verified?
In 2026, a Spanish lottery and betting platform suffered unauthorised access to a service used to verify its users’ identities. What was stolen was not passwords or banking data, but images of users’ identity documents (both sides) and their verification selfies. The company notified the Spanish Data Protection Agency, as required by law, as well as the National Police.
Security risks in online player identity verification in Spain
This access creates a security risk because anyone in possession of an identity card image together with its holder’s verification selfie effectively has the same combination required by many online services to open an account, from neobanks to cryptocurrency exchanges. This creates opportunities for identity theft on third-party services, not just on the original platform.
The incident is not a failure of customer due diligence under Law 10/2010. It is not about incorrectly identifying a player or failing to monitor their behaviour, but rather a different and complementary issue concerning the security and minimisation of biometric and documentary data once captured. Complying with the obligation to verify does not remove the obligation to protect the verified data, nor the need for encryption, access controls or minimising how long images are retained. There is little value in correctly identifying a customer if those same data are subsequently exposed to third parties.

Beyond document verification
The law requires customers to be identified and verified, but it does not impose a single method for doing so. This gives operators room to decide how the process should be carried out. Document verification, which consists of checking the validity of an identity document and matching it to its holder, remains the foundation. Nevertheless, the incident described above highlights a fundamental limitation: if the process relies solely on static images of an identity document and a selfie, those same images, once stolen, may be enough to attempt to impersonate the individual on another service.
This is where facial biometrics with liveness detection comes in. Unlike a simple photo comparison, these solutions verify in real time that a real person is in front of the camera rather than a photograph, a recorded video or a generated image. This means that a stolen identity document and selfie from a previous data breach cannot, on their own, be used to pass verification with another operator or service. The law does not specifically require this method for online player identity verification in Spain, but it does require operators to identify individuals with certainty, and an increasing number of operators are choosing this additional layer precisely because of the type of risk that has already materialised in the sector.
Screening lists
It is complemented, within the customer due diligence process, by another layer offered by Mobbeel: screening against sanctions lists and politically exposed persons (PEPs).
This type of screening matchs naturally with the requirements of Article 6. It can move from a one-off check at registration to a control that can be repeated periodically, helping to detect changes in a customer’s risk profile that a one-time verification performed only at the beginning could never capture. It also aligns with SEPBLAC’s warning regarding payment methods. If the same player is linked to several accounts or payment instruments, only robust identification can establish whether this is the same person operating normally or an attempt to circumvent limits, self-exclusion measures or source-of-funds controls.
What is coming with the European AMLR
The EU Regulation 2024/1624, known as the AMLR, is the cornerstone of the European anti-money laundering package adopted by the European Parliament and the Council on 31 May 2024. Unlike a directive, an EU regulation does not require transposition into national law. It will apply directly and uniformly across all 27 Member States from 10 July 2027.
For the gambling sector, the AMLR brings reassuring news in terms of continuity. Article 19(5) establishes that providers of gambling services must apply customer due diligence measures when a customer withdraws winnings, places bets with a monetary value, or both, from a minimum value of €2,000, whether in a single transaction or across several related transactions. This is exactly the same threshold that currently applies under Article 7.6 of Law 10/2010. In terms of online player identity verification in Spain, this specific requirement already meets the standard that will apply across the European Union.
How does the overall overall framework change more boradly?
The general due diligence threshold for occasional transactions rises to €10,000, compared with the €1,000 threshold currently required by Spanish legislation for other sectors. A new European supervisory authority is also being established. The AMLA (European Anti-Money Laundering Authority), which will coordinate approaches across countries and work alongside national supervisors. In Spain, this does not mean that SEPBLAC will cease to operate as the Financial Intelligence Unit. It will remain the direct point of contact for gambling operators, now under the technical coordination of AMLA.
The obligation to continuously monitor the business relationship, currently set out in Article 6 of Law 10/2010, is similarly reflected in Article 26 of the AMLR, once again providing continuity of substance within a more harmonised framework that will apply directly across the EU.
What should an operator expect from its identity verification provider?
With all of the above in mind, the practical question for any online gambling operator in Spain is what, specifically, it should require from the provider delivering its online player identity verification. Some criteria emerge from everything discussed above:
| Criterion | What the provider should offer | Risk mitigated |
|---|---|---|
| Document verification | Detection of manipulated or forged documents, not just data extraction | Impersonation using fraudulent documents |
| Facial biometrics | Liveness detection against photos, videos or generated images | Reuse of images stolen in previous data breaches |
| Screening | Checks against sanctions and PEP lists | Business relationships with high-risk individuals |
| Data protection | Encryption and an agreed retention policy with clear timeframes | Data exposure in the event of a breach |
| Support | Support during inspections and regulatory requests | Inability to demonstrate compliance to the supervisor |
None of these points replaces the others. Verifying correctly at registration, monitoring continuously and protecting the data captured are three different layers, and all three are necessary to protect players.
Looking to strengthen identity verification on your gambling platform? We help online gambling operators meet their identification and anti-money laundering obligations.

I am a curious mind with knowledge of laws, marketing, and business. A words alchemist, deeply in love with neuromarketing and copywriting, who helps Mobbeel to keep growing.
INDUSTRY PAGE
Discover everything we can do for the online gaming sector
Online gaming is vital in the gambling industry, where biometric verification not only verifies players’ ages and enhances the gaming experience but also fights compulsive and pathological behaviours, keeping its recreational nature.



