There is no regulatory finding or court record showing a licensed gambling operator selling verification selfies to third parties for profit. What the evidence does show is messier: a verification selfie routinely passes through a chain of external vendors, biometric images carry a stricter legal status than a driver’s license number, at least one major identity-verification processor has already leaked document images tied to gambling-adjacent platforms, and regulators openly permit certain forms of KYC data sharing for anti-money-laundering purposes. The risk isn’t a black-market sale — it’s diffusion across an under-audited supply chain.
Key takeaways
- The GDPR classifies biometric data as a type of special category of personal data, meaning facial images used for identity matching cannot be processed without a qualifying legal basis such as explicit consent.
- The UK’s Information Commissioner’s Office has confirmed that data protection law does not stop gambling companies from conducting financial risk checks on customers, and that lenders can share personal information for this purpose provided it is done transparently and proportionately.
- A 2024 breach at AU10TIX, an identity verification service used by major platforms, exposed personal data of individuals who had uploaded identity documents, including names, birthdates, nationalities, identification numbers, and images of their IDs.
- US biometric-privacy litigation under Illinois’ BIPA has produced settlements running into the hundreds of millions of dollars, underlining how commercially significant mishandled facial-recognition data has become.
- Anti-money laundering data retention requirements mandate keeping customer verification documents and transaction records for five years post-account closure, extending the window in which a selfie remains exposed.
Table of contents
How a verification selfie moves through the KYC pipeline
Most players assume a verification selfie stays on the operator’s own servers, reviewed once by a compliance team and then archived. In practice, the vast majority of licensed operators outsource the actual matching work to a specialist identity-verification (IDV) vendor rather than building facial-comparison technology in-house. That vendor receives the selfie and the ID photo, runs liveness detection and facial-similarity scoring, and returns a pass/fail decision plus a confidence score to the operator.
One of the most prominent uses of biometric data by private entities is identity verification, and the need to verify individuals’ identities becomes heightened in regulated spaces such as online gaming and sports betting, where confirming legal age and passing anti-money-laundering and know-your-customer requirements is a licensing condition, not an option.
The identity-verification industry that sits behind this process is now a substantial commercial sector in its own right.
The global identity verification market size was valued at USD 13.75 billion in 2025, and is projected to grow to USD 15.84 billion in 2026 and USD 50.58 billion by 2034.
That scale matters for privacy purposes: a handful of IDV vendors now process biometric and document data for a very large share of the world’s online casinos, sportsbooks, banks, ride-share apps and social platforms simultaneously, which concentrates risk rather than distributing it.
Biometric data is a special legal category
Unlike a name or an email address, a facial image used to uniquely identify someone is treated differently under most modern privacy frameworks.
The GDPR classifies biometric data as a type of special category of personal data, meaning it may not be processed unless the processing falls within one of the lawful reasons for processing, such as the explicit consent of the data subject or substantial public interest.
That higher bar is why a well-run KYC vendor should ask for a specific, standalone consent for facial matching rather than folding it into a general terms-of-service checkbox.
As of March 2025, the European Data Protection Board has consistently confirmed that consent to the processing of biometric data must be freely given, specific, informed, and unambiguous, and a pre-ticked box does not qualify.
Regulators have already fined identity-verification-style services over exactly this issue.
The Spanish Data Protection Authority imposed a €950,000 fine on a company offering digital identity and age verification services that rely on facial analysis technology.
Separately,
in 2022 the French data protection authority fined Clearview AI 20 million euros and ordered it to stop collecting and using data on individuals in France without a legal basis, additionally ordering the company to delete the data already collected.
Neither case involved a gambling operator, but both concern the same underlying technology — facial matching against a stored biometric template — that sits behind every casino “liveness check.”
Gambling-specific enforcement exists too, though on a smaller scale so far.
One documented case involved an online gambling platform that collected an individual’s phone number when a third party registered an account, without verifying the accuracy of the data supplied, and when the affected individual later tried to trace the source of their contact details, the company unlawfully and excessively collected and retained sensitive personal documentation — including a copy of their national identification card and a selfie photograph — to process the request.
That case illustrates a subtler risk than outright sale: operators sometimes over-collect biometric material even during unrelated customer-service interactions.
What data sharing actually looks like in regulated markets
Regulators do explicitly permit some forms of KYC-adjacent data sharing, which is worth distinguishing from the “sold to third parties” framing. In the UK, credit reference agencies (CRAs) are allowed to pass information to operators for affordability and financial-risk checks.
Following a request from UK Finance, the ICO confirmed that data protection law does not stop gambling companies from conducting financial risk checks on customers, and that lenders can share people’s personal information — but this must be done transparently and proportionately.
The ICO expects CRAs to conduct a Data Protection Impact Assessment before processing personal information for financial risk checks because of the nature of the processing and the outcomes it generates, including denial of service.
A related, more ambitious proposal has been the “Single Customer View” concept explored in the UK.
In February 2020, the Gambling Commission challenged the industry to develop a cross-operator view of a customer’s gambling behaviour to enable timely interventions, and worked with the ICO’s regulatory sandbox to establish which lawful bases could be relied upon by operators to process this shared personal data.
Separately, on the harm-prevention side,
data protection law does not prevent gambling operators from sharing the personal data of vulnerable gamblers, and because one gambler may have multiple accounts with different operators, the desire to increase this kind of sharing is understandable.
These are sanctioned, purpose-limited exchanges built around safeguarding rather than commercial resale — but they confirm that “your data never leaves the operator” is not how the regulated ecosystem is actually designed to work.
On the licensing side, the UK Gambling Commission’s own guidance is explicit that identity checks are a hard requirement, not a courtesy.
There are three main reasons gambling companies ask for ID: to check a player is old enough to gamble, to check whether they have self-excluded, and to confirm their identity — and all online gambling businesses must ask a player to prove their age and identity before they gamble.
For readers weighing why smaller operators sometimes struggle with these obligations, our related analysis on the cost of compliance and why small casinos are being forced out of regulated markets looks at the financial burden of running KYC/AML programs to this standard.
When the vendor becomes the leak
The clearest documented privacy failure involving verification selfies to date is not a sale — it’s a security lapse at a vendor serving the exact category of platforms now required to age-verify users, including gambling sites.
In 2024, a data breach struck AU10TIX, an identity verification service used by major platforms including TikTok, Uber, and X, underscoring the inherent privacy and security risks of such services.
The breach, discovered by a cybersecurity researcher, exposed credentials that provided access to a logging platform containing links to the personal data of individuals who had uploaded identity documents, including names, birthdates, nationalities, identification numbers, and images of their IDs.
What made the incident particularly concerning was its duration and the company’s own account of it.
The exposed credentials had reportedly been harvested by malware in December 2022 and posted to a Telegram channel in March 2023, and despite AU10TIX’s claims of rescinded access, the credentials remained active until shortly before the breach was discovered.
The company only became aware of the breach in 2024 and in 2025 released a statement claiming that an internal review found no evidence of data exposure or customer impact.
Reporting on the incident specifically flagged its relevance to age-restricted sectors:
as more legislation emerges requiring platforms like gambling services, social networks, and porn sites to verify their users’ age, the requirement for authentication companies offering that service rises.
The vendor at the centre of this incident is not a marginal player in gambling-industry identity checks either.
Its own Q1 2024 fraud report found that the online gaming industry’s share of identity-fraud attempts increased by more than 250% over the previous quarter
, meaning the same infrastructure that failed to secure admin credentials for over a year is a vendor actively marketing itself to the sector this article is examining. This is the core structural problem: consolidation of KYC processing into a small number of vendors means a single infrastructure failure can expose document images tied to dozens of unrelated platforms at once, gambling operators among them.
What biometric litigation reveals about the stakes
US litigation under Illinois’ Biometric Information Privacy Act (BIPA) is instructive even though most reported cases involve facial-recognition surveillance on the casino floor rather than the online KYC selfie specifically. The pattern shows how seriously courts and regulators now treat unauthorized biometric collection, and why operators and vendors have strong legal incentive to handle facial data carefully.
A federal lawsuit alleged an Illinois casino used surveillance cameras equipped with facial recognition technology to scan and collect the facial geometry of patrons who visited its riverfront gaming operation without their knowledge or permission.
A second, related suit made similar allegations against a nearby casino.
Plaintiffs claimed state law was broken when their facial biometric geometry was recorded without consent, in violation of the Illinois Biometric Information Privacy Act of 2008, which requires written authorization and posted notices before biometric identifiers are recorded.
The financial exposure from mishandled facial data at scale has been enormous in adjacent industries, which is why compliance teams treat the selfie step so cautiously.
In 2021, the parent company of TikTok agreed to a $92 million settlement over alleged unlawful collection of face and voice data, and in 2022 Google settled an Illinois class action for $100 million over a Google Photos tool that used face-recognition to group similar faces without required consent.
An even larger case involved a facial-recognition company:
in a landmark 2020 settlement, Facebook paid $650 million to resolve a BIPA class action alleging its facial-recognition photo-tagging feature scanned Illinois users’ faces without consent.
| Matter | Jurisdiction | Approx. year | Outcome |
|---|---|---|---|
| Facebook photo-tagging facial recognition | Illinois (BIPA) | 2020 | $650 million class settlement |
| TikTok face and voice data collection | Illinois (BIPA) | 2021 | $92 million settlement |
| Google Photos face-grouping feature | Illinois (BIPA) | 2022 | $100 million settlement |
| Clearview AI facial-recognition database | France (GDPR) | 2022 | €20 million fine, ordered to delete French data |
| Facial-analysis age/identity verification vendor | Spain (GDPR) | Recent | €950,000 fine |
| AU10TIX identity-document exposure | Global vendor incident | 2024 | Admin credentials exposed identity documents for over a year |
None of these are gambling-operator cases directly, and none prove a casino sold a selfie to a third party. What they establish is that facial images are treated in law as materially more sensitive than a name or address, and that mishandling them — through unauthorized collection, weak consent, or poor vendor security — carries nine- and ten-figure financial consequences. That is the regulatory backdrop against which every gambling KYC vendor now operates.
Retention: selfies do not vanish after approval
A common misconception is that a verification selfie is deleted once an account is approved. Regulatory retention rules generally require the opposite.
Anti-money laundering data retention requirements mandate keeping customer verification documents and transaction records for five years post-account closure, providing a clear legal obligation for operators to retain this data.
Online gambling operators face increased GDPR scrutiny because they process special category data related to gambling addiction, handle large volumes of financial transactions, and employ automated decision-making systems for fraud detection and responsible gambling interventions.
This retention obligation is not itself evidence of wrongdoing — it exists to let regulators trace historical AML failures — but it does mean a selfie submitted years ago at a now-closed account can still sit in an operator’s or vendor’s systems, and remains a target for exactly the kind of infrastructure breach described above. Readers researching how operators are scored on data-handling transparency more broadly may find our overview of security, fraud detection and fair play useful context, as retention and breach exposure feed directly into that category of our scoring.
What players can actually check before uploading a selfie
Because outright biometric “sale” is not what the evidence supports, the more useful player question is which operators minimize downstream exposure. Before submitting a selfie, it is worth checking three things in an operator’s privacy notice: whether a named third-party IDV vendor is disclosed, what the stated retention period is beyond the regulatory minimum, and whether the policy commits to deleting biometric templates (as distinct from the raw photo) after verification. Few privacy policies volunteer all three, which is itself a useful signal —
the ICO expects organizations to update their privacy notices and other relevant accountability information to reflect the actual scope of data sharing taking place
, and an operator that hasn’t done so for its KYC vendor relationships is a weaker bet on transparency generally.
Players who want to understand how these signals get weighted algorithmically rather than editorially can review our scoring system and algorithmic weights methodology, which explains how disclosure gaps translate into score deductions across the operators we track.
Frequently answered questions
Can an online casino legally sell my verification selfie to advertisers?
No public regulator finding or court case establishes that a licensed operator has sold verification selfies for advertising purposes, and doing so would conflict with GDPR’s purpose-limitation principle and the special-category status of biometric data. The documented risks are different: vendor breaches, over-retention, and permitted (not sold) sharing with credit agencies for AML and affordability checks.
Does my selfie get deleted after my account is verified?
Usually not immediately. Anti-money laundering rules generally require operators to retain verification documents, including selfies, for a set period after account closure — commonly cited as five years in EU/UK compliance guidance — so the image can remain in operator or vendor systems well after onboarding.
Is my selfie processed by the casino directly or by a separate company?
Most licensed operators outsource facial-comparison and liveness checks to specialist identity-verification vendors rather than building the technology in-house. This means your biometric data typically passes through at least one external processor, and the operator’s privacy policy should — but does not always — name that vendor.
Have identity-verification vendors used by gambling-adjacent platforms actually been breached?
Yes. A 2024 incident at AU10TIX, an identity-verification vendor used by major consumer platforms, exposed identity documents and personal data after administrative credentials were left accessible online for over a year, illustrating the concentration risk created by relying on a small number of shared vendors.
Why do US biometric lawsuits matter if they weren’t filed against gambling sites?
Illinois’ BIPA litigation against casinos and tech platforms has produced settlements from tens of millions to $650 million, which shapes how seriously every company handling facial data — including gambling KYC vendors — now treats consent and storage limitation, even outside Illinois.
Methodology
For KYC-related coverage, GamblScout.com’s algorithm scrapes operator privacy policies and terms of service for disclosed identity-verification subprocessors, stated retention periods, and biometric-specific consent language, then cross-references those disclosures against public breach-notification records and regulatory enforcement trackers such as data-protection authority decisions. This scoring feeds into our broader KYC and AML hub and complements the fraud- and security-focused signals described in our data scraping and technical engine methodology. We do not rely on operator self-disclosure alone or on paid reviewer testimony, consistent with our core principles on algorithmic review.
Gambling involves risk. Only play with money you can afford to lose and use the deposit limits and self-exclusion tools available in your jurisdiction.
