Online casinos collect government IDs, selfies, source-of-funds documents, device fingerprints, and betting histories. That is personal and often sensitive personal information under the Data Privacy Act of 2012 (Republic Act No. 10173) and National Privacy Commission issuances. A PAGCOR license does not exempt the operator from NPC registration, privacy notices, or breach notification. It adds a second regulator who will ask overlapping questions after an incident.
Register the system that actually exists
NPC registration and the accompanying descriptions of data processing systems should match the live architecture: website, apps, KYC vendor, CRM, affiliate postbacks, call-center tools, and cloud regions. Registering “a customer database in Makati” while IDs sit in an EU KYC vendor is a mismatch waiting for a compliance visit. Appoint a Data Protection Officer who can explain the diagram, not a nominee who only signs forms.
Lawful basis and purpose limitation
KYC and AML are legal obligations of a covered person. Marketing cookies and affiliate profiling are not. Privacy notices and consent banners should not pretend that accepting terms is consent for every future SMS blast. Separate the AML file from the marketing list. Regulators and plaintiffs notice when a “verification” email is actually a bonus campaign.
Cross-border processors
Most iGaming stacks use offshore KYC, fraud, and hosting vendors. Cross-border transfers need a lawful basis, contractual clauses, and a record of which countries receive which data. A processor agreement that is silent on sub-processors is incomplete. If a live-dealer studio in another country records player video, that stream is in scope.
Breach notification is a dual-track problem
NPC rules require notification of certain breaches to the Commission and to data subjects within tight timelines (commonly discussed as 72 hours from knowledge, subject to the current circular). PAGCOR license conditions may separately require incident reports for cyber events that affect player funds or game integrity. One incident, two clocks. Build a single incident playbook with both notice templates, a fact log, and a named decision-maker.
Privacy impact assessments should be done before launching a new verification vendor or a facial-recognition step—not after a journalist writes about a leak.
Abanto Law Firm aligns DPA documentation with gaming-license exhibits so the AML manual, the privacy notice, and the NPC registration describe the same operation.
This article is general information about Philippine online casino licensing. It is not legal advice, does not create a lawyer-client relationship, and does not guarantee that a regulator will approve any application. License grants remain solely within the discretion of PAGCOR, CEZA, APECO, or any other competent authority. Contact Abanto Law Firm for advice on a specific transaction.


