SlideShare a Scribd company logo
1 of 47
Download to read offline
DICTAO
152, avenue Malakoff
75116 PARIS, France
+33 1 73 00 26 00
www.dictao.com
Regulators’ Traceability Requirements
and Solutions for iGambling operators
on New Regulated Markets in Europe
Denmark, Spain, France & Schleswig-Holstein cases.
2013
Copyright Dictao 2012
1
Executive Summary
Dictao, leading supplier of iGambling IT Requirement-compliant solutions
Fact: Traceability is a key regulatory requirement in each new regulated market
Problem: Data traceability is complex, and increases costs & time
Solution: Dictao simplifies operators’ life, hides complexity, and reduces TCO
Operator benefits
 Compliance, flexibility and cost-effectiveness
Market Cases of traceability requirements and gaming system architectures
 Denmark, Spain, France and Schleswig-Holstein cases
Regulators’ Frequently Asked Questions
Next step : Dictao iGambling data traceability model
Copyright Dictao 2012 2
Agenda
3
Dictao
Regulators’ Frequently Asked Questions
Market cases
Copyright Dictao 2013
Facts, Problem and Solution
Operators’ Benefits
Dictao
Specialized in 3 areas:
 Data traceability
 Strong authentication
 Electronic signatures
Dictao products power mission-critical applications across multiple sectors
 Gaming, banking, industry, defense, government, …
Dictao products are certified EAL3+ by the French Network and Information Security
Agency (ANSSI), SigG and SigV by the Bundesnetzagentur in Germany, and 3-D
Secure by Visa and MasterCard.
4Copyright Dictao 2012
Dictao in the iGaming industry
Main traceability offer built to answer compliance requirements:
 E-vault product
 Hosted services
 Consulting services
But also player authentication and registration where eID can be used
Dictao is the industry’s leading technical compliance solution provider:
 The only offer covering Spain, Denmark, France and Schleswig-Holstein
 40+ operators are clients
 9 out of the top 10 operators from eGaming Review’s Power50 list
 45% of the first licensed operators in France
 45% of the first licensed operators in Denmark
 28 operators chose Dictao in Spain
 First supplier in Schleswig Holstein
5Copyright Dictao 2012
Agenda
6
Dictao
Regulators’ Frequently Asked Questions
Market cases
Copyright Dictao 2013
Fact, Problems and Solution
Operators’ Benefits
Fact: Traceability is a key regulatory requirement
Regulators see traceability as mean to achieve :
 Consumer protection
 Anti money laundering
 Fight against fraud
 Tax control
Traceability : Pervasive in all regulated markets
 Italy AAMS* and SOGEI’s centralized system (2009)
 France ARJEL* ‘Frontal’ (2010)
 Denmark DGA* ‘SAFE’ (2011)
 Spain CNJ* ‘Almacen’ (2011)
 Schleswig-Holstein ‘Kontrollsystem’ (2012)
 Greece GSCC* ‘Supervision and Control IT System’
(2012 – est.)
Next EU markets
 “E15” Germany, the Netherlands, Poland, Bulgaria…
(I) AAMS: Amministrazione autonoma dei monopoli di Stato
(II) ARJEL: Autorité de Régulation des Jeux en Ligne
(III) DGA: Danish Gaming Authority
(IV) CNJ: Comisión Nacional del Juego
(V) GSCC: Games of Chance Supervision and Control
Commission
Copyright Dictao 2012
Problem: Traceability is complex, and increases costs & time
8
Especially when each jurisdiction
requires distinct and specific:
 Data formats
 Server location
 Backup location
 Certifications
 Secure storage
 Data retention policies
 Language
 …
This wide heterogeneity
 Creates additional complexity
 Delays go-to-market
 Increases running costs
Capteur
.FR
Core Gaming Platforms
.DE.DK
.ES
Capturador
Copyright Dictao 2012
Solution: Dictao simplifies operators’ life
A single partner for every regulation
 For all jurisdictions that do not impose a
central system
 For all games
Dictao focuses on traceability only
 We are regulation and traceability
experts
 We only extract operator’s data
 We manage traceability data storage
and download by the local regulator
9
Operator platform
Dictao
DGAARJEL S-HCNJ
Casino Sports
book
Poker
Copyright Dictao 2012
…
Agenda
10
Dictao
Regulators’ Frequently Asked Questions
Market cases
Copyright Dictao 2013
Facts, Problem and Solution
Operators’ Benefits
Operators’ benefits (1/3): Guaranteed compliance
We nurture close relationships with local regulators
Compliance with current regulations
 First ARJEL-compliant ‘frontal’ in France
 DGA-compliant SAFE in Denmark
 DGOJ-compliant Internal Control System (ICS) in Spain
 First Schleswig Holstein-compliant SAFE
Strategic commitment to comply with future regulatory requirements
 100% compliant with next generation European (DE, NL, UK, …) requirements
 Dictao guarantees compliance with future regulation modifications
11Copyright Dictao 2012
Operators’ benefits (2/3): Flexibility
Business model flexibility
 Software license: operator integrates and operates the service
 Software as a Service (SaaS): Dictao hosts and operates the service on behalf of the
operator
 Managed service: Dictao operates the service hosted in operator’s premises
Integration flexibility
 Standard Webservices API
 Managed test environment
 Connection link
 over the internet
 over dedicated leased line
Technical flexibility
 Scalable : from a few to several thousands of events per second
 Reliable: high availability (>99.99%) and multiple sites
12Copyright Dictao 2012
Operators’ benefits (3/3): Cost-effectiveness
Low investment costs
 The solution is based on existing in-house products
 The development costs are spread across multiple customers
 The SaaS platform shares infrastructure
Low recurring costs
 One dedicated compliance team operates the vaults of several customers
 Evolutions in regulation included
13Copyright Dictao 2012
Agenda
14
Dictao
Regulators’ Frequently Asked Questions
Market cases
Copyright Dictao 2013
Facts, Problem and Solution
Operators’ Benefits
Copyright Dictao 2012
Spain
France
Denmark
Schleswig-Holstein
Examples of Control Systems
16
Spain
France
Denmark
Schleswig-Holstein
Copyright Dictao 2013
Spain – Technical architecture
17Copyright Dictao 2013
Spain – Authentication
Spain is introducing electronic IDs for its citizens ("DNIe" – Documento
Nacional the Identidad). One of the authorized player registration
mechanisms is the digital certificate from the electronic ID.
The Spanish regulator has set up an online service to check personal
details and verify player’s age using a national citizen database.
The Spanish regulator has set up an online service to check the banned
player register. The register is updated hourly.
18Copyright Dictao 2013
Spain – Traceability
Operators must implement a control and supervision system (internal
control system)
Operators are responsible to run their internal control system
Transactions must be stored in near real-time in a Safe on Spanish soil
The regulator (CNJ) has real-time access to the Safe
Game software and hardware and the organization of the operator must be
audited by an officially approved test lab
19Copyright Dictao 2013
Spain – Traceability
Data is securely stored in a digital Safe:
 Standardized XML-format to allow uniform processing by regulator
 Main storage site located on Spanish soil
 Digital signature to seal records (XAdES BES 1.3.2)
 Timestamps from an approved TSA (RFC3161)
 Encryption of records (AES-256)
 Guarantee that regulator has real-time access via a secure channel to the data
 Data archived one year online
 Data archived six years offline
Internal control system must be certified
20Copyright Dictao 2013
Examples of Control Systems
21
Spain
France
Denmark
Schleswig-Holstein
Copyright Dictao 2013
France – Technical Architecture
22Copyright Dictao 2013
France – Technical architecture
Front-End
 In standard web architecture, this is the presentation layer. This module implements the gambling site
interface in French, including all the moderators required by the authority (e.g. pop-ups, warnings).
Data extraction („Capteur”)
 This module retrieves the information relevant for control and oversight by the regulator. The regulator
defines the nature and format of the data (XML).
Back-end relay
 This module transfers the transactions initiated by gamblers to the operator's back-end gambling
engines. Back-end servers may be located outside of France.
Digital Safe
 The vault module collects the records produced by the capteur to preserve them in a secure manner. If
required, the future authority must be able to access the electronic vault either on site or remotely. The
Safe must be certified (CSPN) by the French IT-security government agency (ANSSI).
23Copyright Dictao 2013
France – Authentication
Player registration is a complex paper-based process. One step of the
process is a letter sent by physical mail to the player‘s address with an
activation code.
The regulator manages a national banned player register. Each operator
must check his entire player base against that register at least once a
month.
24Copyright Dictao 2013
France – Traceability
Gaming activity is stored in real-time in a digital Safe. Data reflects the
player‘s perspective.
 Standardized XML-format to allow uniform processing by regulator
 “Frontal” (Safe and capture device) located on French soil
 Digital signature to seal records (XAdES)
 Data protected with strong authentication mechanisms
 Data encrypted with regulator public key (RSA). Only the regulator can decrypt records.
 Operators are responsible for running the “Frontal”
 Synchronous real-time processing
 Data archived one year online
 Data archived five years offline
 Safe must be certified (CSPN) by the French IT-security government agency (ANSSI)
25Copyright Dictao 2013
Examples of Control Systems
26
Spain
France
Denmark
Schleswig-Holstein
Copyright Dictao 2013
Denmark – Architecture
27Copyright Dictao 2013
Denmark – Authentication
Regulator provides a central online service to check players against banned
player register (ROFUS/LUR)
The regulator manages this central register. Each operator is required to
check through the online service whether a player is banned or not.
Authentication at each login with NemID and an OCES digital signature.
This is the same mechanism used for banks and online services of the
public administration. The Danish service provider “DanID” runs this service
for the government.
28Copyright Dictao 2013
Denmark – Traceability
Standardized XML-format to allow uniform processing by regulator
Near real-time: Data must be stored within five minutes of an event happening
Safe location can be anywhere as long as the regulator has sufficient guarantees to get access
Digital seals using the regulator‘s central tamper proof system
Encrypted communication between digital Safe and regulator
Operators are responsible for running the “Frontal”
Data archived one year online
Data archived five years offline
End-of-day records
29Copyright Dictao 2013
Examples of Control Systems
Copyright Dictao 2013 30
Spain
France
Denmark
Schleswig-Holstein (Germany)
Schleswig-Holstein – Technical architecture
Copyright Dictao 2013 31
Schleswig-Holstein – SAFE-server features
Copyright Dictao 2013 32
Location in Schleswig-Holstein
Near-real time data capture
Certification by accredited 3rd parties
Data encryption
Digital seals/signatures
Standards-based
36 months data storage
Standardized Data (XML)
 Gameplay
 Financial
 Personal information
Agenda
33
Dictao
Regulators’ Frequently Asked Questions
Market cases
Copyright Dictao 2013
Facts, Problem and Solution
Operators’ Benefits
FAQ about…
Preventing fraud/ AML
Real Time versus Near-Real Time data traceability
Control of data
Tax control
Minor and problem gambler protection
Dependency on the Authority
Service Providers’ Standard Compliancy
Technology suppliers & technology neutrality
Copyright Dictao 2012 34
Preventing fraud/ AML (1/2)
Q: How is the traceability of money flows regulated?
 Each financial transaction is sealed and stored in a safe
 Regular analysis is performed by the Authority
 Operator cash account is separated from the player money account (escrow)
 Money may not be transferred between players except through gaming
 Money may only be withdrawn to the named bank account associated with the relevant
player account
 In kind winnings are traced as well (prize description and estimated value)
Dictao recommends all of the above
35Copyright Dictao 2013
Preventing fraud/ AML (2/2)
Q: How can the security and continuity best be secured?
 Security principles (best practices, not specific to iGaming)
 Integrity: data is sealed through digital signature and chaining
 Confidentiality: data is encrypted so that only the regulator may access it
 Authentication: use strong credentials like digital certificates
 Non repudiability: data is signed
 Availability: SLA requirements from operators and suppliers
 Continuity and recovery
 Require a “Business Continuity Plan” and a “Data Recovery Plan” from operators and suppliers
 Require all data to be backed up on a secondary site and maximum delay of recovery
Dictao recommends all of the above
36Copyright Dictao 2013
Control of data (1/3)
Q: option #1: All data flows through the server of the Gambling authority
(vault). What are the pros and cons?
MARKET CASE: Centralized solution only implemented in Italy
- COST: Very expensive for the regulator (platform to design and set up, maintain technical
operation team, ensure backup of the data, maintenance, several people to support
operators) SOGEI employs 500 persons to perform data control
- RESPONSABILITY: The regulator is responsible for tracing the data
- TIME: 6 to 12 months to setup the infrastructure
Dictao recommends not using this solution
37Copyright Dictao 2013
Control of data (2/3)
Q: option #2 : the Gambling Authority provides access to a special server
that securely stores a copy of the data. What are the pros and cons?
+ BEST PRACTICE: Decentralized solution used in FR, DK, SP, DE (E15 + SH)
+ COST: very low cost for the regulator.
For example, ARJEL employs 6 persons to perform data control
+ TIMING: gaming operation may start, even if the regulator platform is not ready
+ SLA: gaming operation may carry on, even if regulator platform is down
- TCO / OPERATOR : standard TCO is < 1 to 0,5% of GGR
Dictao recommends the solution of a “distributed safe” placed under the
responsibility of the operator
38Copyright Dictao 2013
Control of data (3/3)
Q: option#3 : the data and its back up data is located / hosted within the
national borders of the regulator. What are the pros and cons?
+ ENFORCEMENT: Location of safe in the regulated territory enables regulator to seize it
+ EU COMPLIANCE: Host of a safe in a national territory complies with EU jurisprudence,
whereas requirements to locate the whole gaming server(s) does not comply
Also avoids potentially complex and lengthy cross-border collaboration
+ CONVENIENCE: Country-hosted data facilitates the control of data completeness and data
compliance with the Authority (or delegated third party) requirements
- Back-up data is not supposed to be seized, but data recovery from back-up shall be quick
Dictao recommends main data repository in the Authority’s territory, a back-
up located in the EU, and a recovery delay of 48 hours
39Copyright Dictao 2013
Tax control
Q: As lots of operators are located abroad, for tax control it is necessary for
the Authority to access actual information. What are the best practices from
other countries?
 Require traceability of all money transactions (including bonus money, gaming network
transactions)
 Require agregated financial reports from the operator and reconcile those reports with the
information available in the safe
Q: Do you have any insight on how tax control is maintained in case of poker
liquidity, where players from different jurisdictions participate in a game?
 The only cross-country liquidity we are familiar with is Denmark
 Only data regarding local players is traced in the safe, tax control is based on these data
Dictao recommends all of the above
40Copyright Dictao 2013
Minor and problem gambler protection
Q: Do you have any insight on how problem gambling is monitored in
different countries?
 Availability of a centralized authorization service maintained by the Authority
 Problem gambler list shared with landbased casinos
 Operators required to check the authorization service during player registration and
regularly during player logon
 Technical aspects
 Preserve player confidentiality (operators shall not discover information about players they do
not “know”)
 Use open standards like webservice or DNS to allow all operator technologies to connect
 High availability and performance
Dictao recommends all of the above
41Copyright Dictao 2013
Dependency on the Authority
Q: How to prevent that a dependency on the authority for the purpose of
authenticity or communication will form a single point of failure for the
industry?
 Require a decentralized safe under the operator’s responsibility
 The only dependency on the Authority regards the authorization (blacklist) service
 For confidentiality, it should stay centralized
 For availability reasons, it should be rendundant
 When the service is down
 Gaming operation is still allowed (thus downtime is not disruptive)
 Account registration is temporary until the service is back up
Dictao recommends all of the above
42Copyright Dictao 2013
Service Providers’ Standard Compliancy
Q: Dictao’s strategy is to rely on standards. Could you elaborate on the
standards?
 The internet technology stack relies on standards at all levels, from hardware to
application level.
 Standards developed for e-commerce, e-government or e-banking applications are all
applicable in the online gambling environment:
 XSD/XML to define reporting formats
 RFC3161 to define time stamps
 XMLDSig for digital seals
 X509 for digital certificates
 ISO27001 for IT security management
Dictao recommends using internationally recognized standards
43Copyright Dictao 2013
Technology suppliers & technology neutrality (1/2)
Q: How can we prevent that requirements on the availability of data favor
certain suppliers?
 Authority should require the usage of open standards instead of proprietary formats,
technologies and solutions
 Require application of best practices recognized by everyone
 Have the Authority’s technical experts assess the neutrality of the requirements
Dictao recommends all of the above
44Copyright Dictao 2013
Technology suppliers & technology neutrality (2/2)
Q: According to EU law, requirements may not be directed towards a
certain technology of certain suppliers
 Dictao does not recommend any technology, only standards
 All standards Dictao recommends are open, patent-free and may be freely implemented
by anyone
 Dictao lobbies for European-wide standards
Dictao competes on the market with technology-neutral differentiators
 Turnkey SaaS infrastructure accelerates projects
 Spreading investments over multiple clients lowers costs
 Professional services to assist operators
Dictao recommends using these internationally recognized standards
45Copyright Dictao 2013
Next step
Based on strong experience and proximity with regulators and operators,
Dictao has built a template model of an ideal traceability system that:
 Covers the needs of tax and fraud control, AML, player protection
 Facilitates integration by the operator
 Is 100% technology-neutral
We would like to introduce this model to you at your earliest convenience
46Copyright Dictao 2013
For more information, please contact:
Frédéric Engel
fengel@dictao.com
+33 1 73 00 26 34
+33 6 13 42 38 98 (mobile)
www.dictao.com
http://www.dictao.com/en/solutions/online-gambling

More Related Content

Similar to Regulators' traceability requirements and solutions for i gambling operators on new regulated markets 2013

CAR BLACK BOX SYSTEM
CAR BLACK BOX SYSTEMCAR BLACK BOX SYSTEM
CAR BLACK BOX SYSTEMIRJET Journal
 
Building the Next Generation IoT & Telematics Platform
Building the Next Generation IoT & Telematics PlatformBuilding the Next Generation IoT & Telematics Platform
Building the Next Generation IoT & Telematics PlatformCloudera, Inc.
 
Airport security 2013 slawomir szlufik
Airport security 2013   slawomir szlufikAirport security 2013   slawomir szlufik
Airport security 2013 slawomir szlufikRussell Publishing
 
Presentation On Advance Monitoring of Cold chain truck
Presentation On Advance Monitoring of Cold chain truckPresentation On Advance Monitoring of Cold chain truck
Presentation On Advance Monitoring of Cold chain truckPUSHP RAJ BHARTI
 
Webinar - Transforming Manufacturing with IoT
Webinar - Transforming Manufacturing with IoTWebinar - Transforming Manufacturing with IoT
Webinar - Transforming Manufacturing with IoTHARMAN Services
 
Fin fest 2014 - Internet of Things and APIs
Fin fest 2014 - Internet of Things and APIsFin fest 2014 - Internet of Things and APIs
Fin fest 2014 - Internet of Things and APIsRobert Greiner
 
Introduction to new technologies
Introduction to new technologiesIntroduction to new technologies
Introduction to new technologiesTracey Roberts
 
RCA OCORA: Safe Computing Platform using open standards
RCA OCORA: Safe Computing Platform using open standardsRCA OCORA: Safe Computing Platform using open standards
RCA OCORA: Safe Computing Platform using open standardsAdaCore
 
Truzzt pitchdeck white
Truzzt pitchdeck whiteTruzzt pitchdeck white
Truzzt pitchdeck whiteh-bauer2014
 
SplunkLive! Utrecht 2018 - Customer presentation: Irdeto
SplunkLive! Utrecht 2018 - Customer presentation: Irdeto SplunkLive! Utrecht 2018 - Customer presentation: Irdeto
SplunkLive! Utrecht 2018 - Customer presentation: Irdeto Splunk
 
The UK's Code of Practice for Security in Consumer IoT Products and Services ...
The UK's Code of Practice for Security in Consumer IoT Products and Services ...The UK's Code of Practice for Security in Consumer IoT Products and Services ...
The UK's Code of Practice for Security in Consumer IoT Products and Services ...44CON
 
Smart Cards & Devices Forum 2013 - Protecting enterprise sensitive informatio...
Smart Cards & Devices Forum 2013 - Protecting enterprise sensitive informatio...Smart Cards & Devices Forum 2013 - Protecting enterprise sensitive informatio...
Smart Cards & Devices Forum 2013 - Protecting enterprise sensitive informatio...OKsystem
 
Hand to Hand RFID baggage tracking system
Hand to Hand RFID baggage tracking system Hand to Hand RFID baggage tracking system
Hand to Hand RFID baggage tracking system Sergey Tsybouk
 

Similar to Regulators' traceability requirements and solutions for i gambling operators on new regulated markets 2013 (20)

Deimos airport suite eng
Deimos airport suite engDeimos airport suite eng
Deimos airport suite eng
 
CAR BLACK BOX SYSTEM
CAR BLACK BOX SYSTEMCAR BLACK BOX SYSTEM
CAR BLACK BOX SYSTEM
 
Building the Next Generation IoT & Telematics Platform
Building the Next Generation IoT & Telematics PlatformBuilding the Next Generation IoT & Telematics Platform
Building the Next Generation IoT & Telematics Platform
 
Airport security 2013 slawomir szlufik
Airport security 2013   slawomir szlufikAirport security 2013   slawomir szlufik
Airport security 2013 slawomir szlufik
 
Presentation On Advance Monitoring of Cold chain truck
Presentation On Advance Monitoring of Cold chain truckPresentation On Advance Monitoring of Cold chain truck
Presentation On Advance Monitoring of Cold chain truck
 
Webinar - Transforming Manufacturing with IoT
Webinar - Transforming Manufacturing with IoTWebinar - Transforming Manufacturing with IoT
Webinar - Transforming Manufacturing with IoT
 
Fin fest 2014 - Internet of Things and APIs
Fin fest 2014 - Internet of Things and APIsFin fest 2014 - Internet of Things and APIs
Fin fest 2014 - Internet of Things and APIs
 
Introduction to new technologies
Introduction to new technologiesIntroduction to new technologies
Introduction to new technologies
 
MASSIVE SCALE SECURITY FOR THE IoT
MASSIVE SCALE SECURITY FOR THE IoTMASSIVE SCALE SECURITY FOR THE IoT
MASSIVE SCALE SECURITY FOR THE IoT
 
Smart condition monitoring
Smart condition monitoringSmart condition monitoring
Smart condition monitoring
 
Deimos building control suite eng
Deimos building control suite engDeimos building control suite eng
Deimos building control suite eng
 
Deimos security suite eng
Deimos security suite engDeimos security suite eng
Deimos security suite eng
 
RCA OCORA: Safe Computing Platform using open standards
RCA OCORA: Safe Computing Platform using open standardsRCA OCORA: Safe Computing Platform using open standards
RCA OCORA: Safe Computing Platform using open standards
 
Truzzt pitchdeck white
Truzzt pitchdeck whiteTruzzt pitchdeck white
Truzzt pitchdeck white
 
SplunkLive! Utrecht 2018 - Customer presentation: Irdeto
SplunkLive! Utrecht 2018 - Customer presentation: Irdeto SplunkLive! Utrecht 2018 - Customer presentation: Irdeto
SplunkLive! Utrecht 2018 - Customer presentation: Irdeto
 
The UK's Code of Practice for Security in Consumer IoT Products and Services ...
The UK's Code of Practice for Security in Consumer IoT Products and Services ...The UK's Code of Practice for Security in Consumer IoT Products and Services ...
The UK's Code of Practice for Security in Consumer IoT Products and Services ...
 
Smart Cards & Devices Forum 2013 - Protecting enterprise sensitive informatio...
Smart Cards & Devices Forum 2013 - Protecting enterprise sensitive informatio...Smart Cards & Devices Forum 2013 - Protecting enterprise sensitive informatio...
Smart Cards & Devices Forum 2013 - Protecting enterprise sensitive informatio...
 
GoSecure
GoSecureGoSecure
GoSecure
 
Hand to Hand RFID baggage tracking system
Hand to Hand RFID baggage tracking system Hand to Hand RFID baggage tracking system
Hand to Hand RFID baggage tracking system
 
ACTAtek 3 Introduction
ACTAtek 3 IntroductionACTAtek 3 Introduction
ACTAtek 3 Introduction
 

More from Market Engel SAS

MODI Vision Health Station
MODI Vision Health StationMODI Vision Health Station
MODI Vision Health StationMarket Engel SAS
 
About aevatar french version
About aevatar french versionAbout aevatar french version
About aevatar french versionMarket Engel SAS
 
1er Baromètre de la_transformation_digitale_CSC_2015_Les secrets des super he...
1er Baromètre de la_transformation_digitale_CSC_2015_Les secrets des super he...1er Baromètre de la_transformation_digitale_CSC_2015_Les secrets des super he...
1er Baromètre de la_transformation_digitale_CSC_2015_Les secrets des super he...Market Engel SAS
 
Iot report federal trade commission_150127iotrpt
Iot report federal trade commission_150127iotrptIot report federal trade commission_150127iotrpt
Iot report federal trade commission_150127iotrptMarket Engel SAS
 
Internet of-things-world-preview-program
Internet of-things-world-preview-programInternet of-things-world-preview-program
Internet of-things-world-preview-programMarket Engel SAS
 
GSMA_mobile-economy-report_2014
GSMA_mobile-economy-report_2014GSMA_mobile-economy-report_2014
GSMA_mobile-economy-report_2014Market Engel SAS
 
Le baromètre de la dématerialisation en 2014_YOOZ
Le baromètre de la dématerialisation en 2014_YOOZLe baromètre de la dématerialisation en 2014_YOOZ
Le baromètre de la dématerialisation en 2014_YOOZMarket Engel SAS
 
Today's employees most wanted tools_Ricoh's survey
Today's employees most wanted tools_Ricoh's surveyToday's employees most wanted tools_Ricoh's survey
Today's employees most wanted tools_Ricoh's surveyMarket Engel SAS
 
Electronic Signature markets and vendors_Forrester Wave_Q2_2013
Electronic Signature markets and vendors_Forrester Wave_Q2_2013Electronic Signature markets and vendors_Forrester Wave_Q2_2013
Electronic Signature markets and vendors_Forrester Wave_Q2_2013Market Engel SAS
 
Digital signatures, paving the way to a digital Europe_Arthur D Little_2014
Digital signatures, paving the way to a digital Europe_Arthur D Little_2014Digital signatures, paving the way to a digital Europe_Arthur D Little_2014
Digital signatures, paving the way to a digital Europe_Arthur D Little_2014Market Engel SAS
 
KPMG cree un pole dedie a l’activite Franchise et Reseaux
KPMG cree un pole dedie a l’activite Franchise et Reseaux KPMG cree un pole dedie a l’activite Franchise et Reseaux
KPMG cree un pole dedie a l’activite Franchise et Reseaux Market Engel SAS
 

More from Market Engel SAS (20)

MODI Vision Health Station
MODI Vision Health StationMODI Vision Health Station
MODI Vision Health Station
 
About aevatar french version
About aevatar french versionAbout aevatar french version
About aevatar french version
 
About Aevatar
About Aevatar About Aevatar
About Aevatar
 
_ 公司_ Aevatar_Chinese
_ 公司_ Aevatar_Chinese_ 公司_ Aevatar_Chinese
_ 公司_ Aevatar_Chinese
 
Happy new year mmxvi
Happy new year mmxviHappy new year mmxvi
Happy new year mmxvi
 
1er Baromètre de la_transformation_digitale_CSC_2015_Les secrets des super he...
1er Baromètre de la_transformation_digitale_CSC_2015_Les secrets des super he...1er Baromètre de la_transformation_digitale_CSC_2015_Les secrets des super he...
1er Baromètre de la_transformation_digitale_CSC_2015_Les secrets des super he...
 
Iot report federal trade commission_150127iotrpt
Iot report federal trade commission_150127iotrptIot report federal trade commission_150127iotrpt
Iot report federal trade commission_150127iotrpt
 
Internet of-things-world-preview-program
Internet of-things-world-preview-programInternet of-things-world-preview-program
Internet of-things-world-preview-program
 
Happy new year 2015 !
Happy new year 2015 !Happy new year 2015 !
Happy new year 2015 !
 
Sigfox whitepaper
Sigfox whitepaperSigfox whitepaper
Sigfox whitepaper
 
AuditMyApps_English
AuditMyApps_EnglishAuditMyApps_English
AuditMyApps_English
 
GSMA_mobile-economy-report_2014
GSMA_mobile-economy-report_2014GSMA_mobile-economy-report_2014
GSMA_mobile-economy-report_2014
 
Le baromètre de la dématerialisation en 2014_YOOZ
Le baromètre de la dématerialisation en 2014_YOOZLe baromètre de la dématerialisation en 2014_YOOZ
Le baromètre de la dématerialisation en 2014_YOOZ
 
Today's employees most wanted tools_Ricoh's survey
Today's employees most wanted tools_Ricoh's surveyToday's employees most wanted tools_Ricoh's survey
Today's employees most wanted tools_Ricoh's survey
 
Electronic Signature markets and vendors_Forrester Wave_Q2_2013
Electronic Signature markets and vendors_Forrester Wave_Q2_2013Electronic Signature markets and vendors_Forrester Wave_Q2_2013
Electronic Signature markets and vendors_Forrester Wave_Q2_2013
 
Digital signatures, paving the way to a digital Europe_Arthur D Little_2014
Digital signatures, paving the way to a digital Europe_Arthur D Little_2014Digital signatures, paving the way to a digital Europe_Arthur D Little_2014
Digital signatures, paving the way to a digital Europe_Arthur D Little_2014
 
KPMG cree un pole dedie a l’activite Franchise et Reseaux
KPMG cree un pole dedie a l’activite Franchise et Reseaux KPMG cree un pole dedie a l’activite Franchise et Reseaux
KPMG cree un pole dedie a l’activite Franchise et Reseaux
 
Gamers in the UK
Gamers in the UKGamers in the UK
Gamers in the UK
 
Gamers in holland
Gamers in hollandGamers in holland
Gamers in holland
 
Gamers in france
Gamers in franceGamers in france
Gamers in france
 

Recently uploaded

A Spotlight on Darla Leigh Pittman Rodgers: Aaron Rodgers' Mother
A Spotlight on Darla Leigh Pittman Rodgers: Aaron Rodgers' MotherA Spotlight on Darla Leigh Pittman Rodgers: Aaron Rodgers' Mother
A Spotlight on Darla Leigh Pittman Rodgers: Aaron Rodgers' Motherget joys
 
Aesthetic Design Inspiration by Slidesgo.pptx
Aesthetic Design Inspiration by Slidesgo.pptxAesthetic Design Inspiration by Slidesgo.pptx
Aesthetic Design Inspiration by Slidesgo.pptxsayemalkadripial4
 
办理滑铁卢大学毕业证成绩单|购买加拿大文凭证书
办理滑铁卢大学毕业证成绩单|购买加拿大文凭证书办理滑铁卢大学毕业证成绩单|购买加拿大文凭证书
办理滑铁卢大学毕业证成绩单|购买加拿大文凭证书zdzoqco
 
ECOLUXE pre-ESPYS Ultimate Sports Lounge 2024
ECOLUXE pre-ESPYS Ultimate Sports Lounge 2024ECOLUXE pre-ESPYS Ultimate Sports Lounge 2024
ECOLUXE pre-ESPYS Ultimate Sports Lounge 2024Durkin Entertainment LLC
 
Statement Of Intent - - Copy.documentfile
Statement Of Intent - - Copy.documentfileStatement Of Intent - - Copy.documentfile
Statement Of Intent - - Copy.documentfilef4ssvxpz62
 
Princess Jahan's Tuition Classes, a story for entertainment
Princess Jahan's Tuition Classes, a story for entertainmentPrincess Jahan's Tuition Classes, a story for entertainment
Princess Jahan's Tuition Classes, a story for entertainmentazuremorn
 
Zoom In Game for ice breaking in a training
Zoom In Game for ice breaking in a trainingZoom In Game for ice breaking in a training
Zoom In Game for ice breaking in a trainingRafik ABDI
 
Flying Avocado Cat Cryptocurrency Created, Coded, Generated and Named by Grok...
Flying Avocado Cat Cryptocurrency Created, Coded, Generated and Named by Grok...Flying Avocado Cat Cryptocurrency Created, Coded, Generated and Named by Grok...
Flying Avocado Cat Cryptocurrency Created, Coded, Generated and Named by Grok...TeslaStakeHolder
 
Biswanath Byam Samiti Open Quiz 2022 by Qui9 Grand Finale
Biswanath Byam Samiti Open Quiz 2022 by Qui9 Grand FinaleBiswanath Byam Samiti Open Quiz 2022 by Qui9 Grand Finale
Biswanath Byam Samiti Open Quiz 2022 by Qui9 Grand FinaleQui9 (Ultimate Quizzing)
 
NO1 Certified Black magic specialist,Expert in Pakistan Amil Baba kala ilam E...
NO1 Certified Black magic specialist,Expert in Pakistan Amil Baba kala ilam E...NO1 Certified Black magic specialist,Expert in Pakistan Amil Baba kala ilam E...
NO1 Certified Black magic specialist,Expert in Pakistan Amil Baba kala ilam E...Amil Baba Dawood bangali
 
Fight Scene Storyboard (Action/Adventure Animation)
Fight Scene Storyboard (Action/Adventure Animation)Fight Scene Storyboard (Action/Adventure Animation)
Fight Scene Storyboard (Action/Adventure Animation)finlaygoodall2
 
What Life Would Be Like From A Different Perspective (saltyvixenstories.com)
What Life Would Be Like From A Different Perspective (saltyvixenstories.com)What Life Would Be Like From A Different Perspective (saltyvixenstories.com)
What Life Would Be Like From A Different Perspective (saltyvixenstories.com)Salty Vixen Stories & More
 
Taken Pilot Episode Story pitch Document
Taken Pilot Episode Story pitch DocumentTaken Pilot Episode Story pitch Document
Taken Pilot Episode Story pitch Documentf4ssvxpz62
 
Uk-NO1 Amil In Karachi Best Amil In Karachi Bangali Baba In Karachi Aamil In ...
Uk-NO1 Amil In Karachi Best Amil In Karachi Bangali Baba In Karachi Aamil In ...Uk-NO1 Amil In Karachi Best Amil In Karachi Bangali Baba In Karachi Aamil In ...
Uk-NO1 Amil In Karachi Best Amil In Karachi Bangali Baba In Karachi Aamil In ...Amil baba
 
THE MEDIC, A STORY for entertainment.docx
THE MEDIC, A STORY for entertainment.docxTHE MEDIC, A STORY for entertainment.docx
THE MEDIC, A STORY for entertainment.docxazuremorn
 
NO1 Certified kala ilam Expert In Peshwar Kala Jadu Specialist In Peshwar Kal...
NO1 Certified kala ilam Expert In Peshwar Kala Jadu Specialist In Peshwar Kal...NO1 Certified kala ilam Expert In Peshwar Kala Jadu Specialist In Peshwar Kal...
NO1 Certified kala ilam Expert In Peshwar Kala Jadu Specialist In Peshwar Kal...Amil Baba Dawood bangali
 

Recently uploaded (20)

A Spotlight on Darla Leigh Pittman Rodgers: Aaron Rodgers' Mother
A Spotlight on Darla Leigh Pittman Rodgers: Aaron Rodgers' MotherA Spotlight on Darla Leigh Pittman Rodgers: Aaron Rodgers' Mother
A Spotlight on Darla Leigh Pittman Rodgers: Aaron Rodgers' Mother
 
Aesthetic Design Inspiration by Slidesgo.pptx
Aesthetic Design Inspiration by Slidesgo.pptxAesthetic Design Inspiration by Slidesgo.pptx
Aesthetic Design Inspiration by Slidesgo.pptx
 
S10_E02_How to Pimp Social Media 101.pptx
S10_E02_How to Pimp Social Media 101.pptxS10_E02_How to Pimp Social Media 101.pptx
S10_E02_How to Pimp Social Media 101.pptx
 
办理滑铁卢大学毕业证成绩单|购买加拿大文凭证书
办理滑铁卢大学毕业证成绩单|购买加拿大文凭证书办理滑铁卢大学毕业证成绩单|购买加拿大文凭证书
办理滑铁卢大学毕业证成绩单|购买加拿大文凭证书
 
S10_E06-Sincerely,The Friday Club- Prelims Farewell Quiz.pptx
S10_E06-Sincerely,The Friday Club- Prelims Farewell Quiz.pptxS10_E06-Sincerely,The Friday Club- Prelims Farewell Quiz.pptx
S10_E06-Sincerely,The Friday Club- Prelims Farewell Quiz.pptx
 
ECOLUXE pre-ESPYS Ultimate Sports Lounge 2024
ECOLUXE pre-ESPYS Ultimate Sports Lounge 2024ECOLUXE pre-ESPYS Ultimate Sports Lounge 2024
ECOLUXE pre-ESPYS Ultimate Sports Lounge 2024
 
Statement Of Intent - - Copy.documentfile
Statement Of Intent - - Copy.documentfileStatement Of Intent - - Copy.documentfile
Statement Of Intent - - Copy.documentfile
 
Princess Jahan's Tuition Classes, a story for entertainment
Princess Jahan's Tuition Classes, a story for entertainmentPrincess Jahan's Tuition Classes, a story for entertainment
Princess Jahan's Tuition Classes, a story for entertainment
 
Zoom In Game for ice breaking in a training
Zoom In Game for ice breaking in a trainingZoom In Game for ice breaking in a training
Zoom In Game for ice breaking in a training
 
Flying Avocado Cat Cryptocurrency Created, Coded, Generated and Named by Grok...
Flying Avocado Cat Cryptocurrency Created, Coded, Generated and Named by Grok...Flying Avocado Cat Cryptocurrency Created, Coded, Generated and Named by Grok...
Flying Avocado Cat Cryptocurrency Created, Coded, Generated and Named by Grok...
 
Biswanath Byam Samiti Open Quiz 2022 by Qui9 Grand Finale
Biswanath Byam Samiti Open Quiz 2022 by Qui9 Grand FinaleBiswanath Byam Samiti Open Quiz 2022 by Qui9 Grand Finale
Biswanath Byam Samiti Open Quiz 2022 by Qui9 Grand Finale
 
NO1 Certified Black magic specialist,Expert in Pakistan Amil Baba kala ilam E...
NO1 Certified Black magic specialist,Expert in Pakistan Amil Baba kala ilam E...NO1 Certified Black magic specialist,Expert in Pakistan Amil Baba kala ilam E...
NO1 Certified Black magic specialist,Expert in Pakistan Amil Baba kala ilam E...
 
Sincerely, The Friday Club - Farewell Quiz-Finals.pptx
Sincerely, The Friday Club - Farewell Quiz-Finals.pptxSincerely, The Friday Club - Farewell Quiz-Finals.pptx
Sincerely, The Friday Club - Farewell Quiz-Finals.pptx
 
Moveable Feast_Travel-Lifestyle-Culture Quiz.pptx
Moveable Feast_Travel-Lifestyle-Culture Quiz.pptxMoveable Feast_Travel-Lifestyle-Culture Quiz.pptx
Moveable Feast_Travel-Lifestyle-Culture Quiz.pptx
 
Fight Scene Storyboard (Action/Adventure Animation)
Fight Scene Storyboard (Action/Adventure Animation)Fight Scene Storyboard (Action/Adventure Animation)
Fight Scene Storyboard (Action/Adventure Animation)
 
What Life Would Be Like From A Different Perspective (saltyvixenstories.com)
What Life Would Be Like From A Different Perspective (saltyvixenstories.com)What Life Would Be Like From A Different Perspective (saltyvixenstories.com)
What Life Would Be Like From A Different Perspective (saltyvixenstories.com)
 
Taken Pilot Episode Story pitch Document
Taken Pilot Episode Story pitch DocumentTaken Pilot Episode Story pitch Document
Taken Pilot Episode Story pitch Document
 
Uk-NO1 Amil In Karachi Best Amil In Karachi Bangali Baba In Karachi Aamil In ...
Uk-NO1 Amil In Karachi Best Amil In Karachi Bangali Baba In Karachi Aamil In ...Uk-NO1 Amil In Karachi Best Amil In Karachi Bangali Baba In Karachi Aamil In ...
Uk-NO1 Amil In Karachi Best Amil In Karachi Bangali Baba In Karachi Aamil In ...
 
THE MEDIC, A STORY for entertainment.docx
THE MEDIC, A STORY for entertainment.docxTHE MEDIC, A STORY for entertainment.docx
THE MEDIC, A STORY for entertainment.docx
 
NO1 Certified kala ilam Expert In Peshwar Kala Jadu Specialist In Peshwar Kal...
NO1 Certified kala ilam Expert In Peshwar Kala Jadu Specialist In Peshwar Kal...NO1 Certified kala ilam Expert In Peshwar Kala Jadu Specialist In Peshwar Kal...
NO1 Certified kala ilam Expert In Peshwar Kala Jadu Specialist In Peshwar Kal...
 

Regulators' traceability requirements and solutions for i gambling operators on new regulated markets 2013

  • 1. DICTAO 152, avenue Malakoff 75116 PARIS, France +33 1 73 00 26 00 www.dictao.com Regulators’ Traceability Requirements and Solutions for iGambling operators on New Regulated Markets in Europe Denmark, Spain, France & Schleswig-Holstein cases. 2013 Copyright Dictao 2012 1
  • 2. Executive Summary Dictao, leading supplier of iGambling IT Requirement-compliant solutions Fact: Traceability is a key regulatory requirement in each new regulated market Problem: Data traceability is complex, and increases costs & time Solution: Dictao simplifies operators’ life, hides complexity, and reduces TCO Operator benefits  Compliance, flexibility and cost-effectiveness Market Cases of traceability requirements and gaming system architectures  Denmark, Spain, France and Schleswig-Holstein cases Regulators’ Frequently Asked Questions Next step : Dictao iGambling data traceability model Copyright Dictao 2012 2
  • 3. Agenda 3 Dictao Regulators’ Frequently Asked Questions Market cases Copyright Dictao 2013 Facts, Problem and Solution Operators’ Benefits
  • 4. Dictao Specialized in 3 areas:  Data traceability  Strong authentication  Electronic signatures Dictao products power mission-critical applications across multiple sectors  Gaming, banking, industry, defense, government, … Dictao products are certified EAL3+ by the French Network and Information Security Agency (ANSSI), SigG and SigV by the Bundesnetzagentur in Germany, and 3-D Secure by Visa and MasterCard. 4Copyright Dictao 2012
  • 5. Dictao in the iGaming industry Main traceability offer built to answer compliance requirements:  E-vault product  Hosted services  Consulting services But also player authentication and registration where eID can be used Dictao is the industry’s leading technical compliance solution provider:  The only offer covering Spain, Denmark, France and Schleswig-Holstein  40+ operators are clients  9 out of the top 10 operators from eGaming Review’s Power50 list  45% of the first licensed operators in France  45% of the first licensed operators in Denmark  28 operators chose Dictao in Spain  First supplier in Schleswig Holstein 5Copyright Dictao 2012
  • 6. Agenda 6 Dictao Regulators’ Frequently Asked Questions Market cases Copyright Dictao 2013 Fact, Problems and Solution Operators’ Benefits
  • 7. Fact: Traceability is a key regulatory requirement Regulators see traceability as mean to achieve :  Consumer protection  Anti money laundering  Fight against fraud  Tax control Traceability : Pervasive in all regulated markets  Italy AAMS* and SOGEI’s centralized system (2009)  France ARJEL* ‘Frontal’ (2010)  Denmark DGA* ‘SAFE’ (2011)  Spain CNJ* ‘Almacen’ (2011)  Schleswig-Holstein ‘Kontrollsystem’ (2012)  Greece GSCC* ‘Supervision and Control IT System’ (2012 – est.) Next EU markets  “E15” Germany, the Netherlands, Poland, Bulgaria… (I) AAMS: Amministrazione autonoma dei monopoli di Stato (II) ARJEL: Autorité de Régulation des Jeux en Ligne (III) DGA: Danish Gaming Authority (IV) CNJ: Comisión Nacional del Juego (V) GSCC: Games of Chance Supervision and Control Commission Copyright Dictao 2012
  • 8. Problem: Traceability is complex, and increases costs & time 8 Especially when each jurisdiction requires distinct and specific:  Data formats  Server location  Backup location  Certifications  Secure storage  Data retention policies  Language  … This wide heterogeneity  Creates additional complexity  Delays go-to-market  Increases running costs Capteur .FR Core Gaming Platforms .DE.DK .ES Capturador Copyright Dictao 2012
  • 9. Solution: Dictao simplifies operators’ life A single partner for every regulation  For all jurisdictions that do not impose a central system  For all games Dictao focuses on traceability only  We are regulation and traceability experts  We only extract operator’s data  We manage traceability data storage and download by the local regulator 9 Operator platform Dictao DGAARJEL S-HCNJ Casino Sports book Poker Copyright Dictao 2012 …
  • 10. Agenda 10 Dictao Regulators’ Frequently Asked Questions Market cases Copyright Dictao 2013 Facts, Problem and Solution Operators’ Benefits
  • 11. Operators’ benefits (1/3): Guaranteed compliance We nurture close relationships with local regulators Compliance with current regulations  First ARJEL-compliant ‘frontal’ in France  DGA-compliant SAFE in Denmark  DGOJ-compliant Internal Control System (ICS) in Spain  First Schleswig Holstein-compliant SAFE Strategic commitment to comply with future regulatory requirements  100% compliant with next generation European (DE, NL, UK, …) requirements  Dictao guarantees compliance with future regulation modifications 11Copyright Dictao 2012
  • 12. Operators’ benefits (2/3): Flexibility Business model flexibility  Software license: operator integrates and operates the service  Software as a Service (SaaS): Dictao hosts and operates the service on behalf of the operator  Managed service: Dictao operates the service hosted in operator’s premises Integration flexibility  Standard Webservices API  Managed test environment  Connection link  over the internet  over dedicated leased line Technical flexibility  Scalable : from a few to several thousands of events per second  Reliable: high availability (>99.99%) and multiple sites 12Copyright Dictao 2012
  • 13. Operators’ benefits (3/3): Cost-effectiveness Low investment costs  The solution is based on existing in-house products  The development costs are spread across multiple customers  The SaaS platform shares infrastructure Low recurring costs  One dedicated compliance team operates the vaults of several customers  Evolutions in regulation included 13Copyright Dictao 2012
  • 14. Agenda 14 Dictao Regulators’ Frequently Asked Questions Market cases Copyright Dictao 2013 Facts, Problem and Solution Operators’ Benefits
  • 16. Examples of Control Systems 16 Spain France Denmark Schleswig-Holstein Copyright Dictao 2013
  • 17. Spain – Technical architecture 17Copyright Dictao 2013
  • 18. Spain – Authentication Spain is introducing electronic IDs for its citizens ("DNIe" – Documento Nacional the Identidad). One of the authorized player registration mechanisms is the digital certificate from the electronic ID. The Spanish regulator has set up an online service to check personal details and verify player’s age using a national citizen database. The Spanish regulator has set up an online service to check the banned player register. The register is updated hourly. 18Copyright Dictao 2013
  • 19. Spain – Traceability Operators must implement a control and supervision system (internal control system) Operators are responsible to run their internal control system Transactions must be stored in near real-time in a Safe on Spanish soil The regulator (CNJ) has real-time access to the Safe Game software and hardware and the organization of the operator must be audited by an officially approved test lab 19Copyright Dictao 2013
  • 20. Spain – Traceability Data is securely stored in a digital Safe:  Standardized XML-format to allow uniform processing by regulator  Main storage site located on Spanish soil  Digital signature to seal records (XAdES BES 1.3.2)  Timestamps from an approved TSA (RFC3161)  Encryption of records (AES-256)  Guarantee that regulator has real-time access via a secure channel to the data  Data archived one year online  Data archived six years offline Internal control system must be certified 20Copyright Dictao 2013
  • 21. Examples of Control Systems 21 Spain France Denmark Schleswig-Holstein Copyright Dictao 2013
  • 22. France – Technical Architecture 22Copyright Dictao 2013
  • 23. France – Technical architecture Front-End  In standard web architecture, this is the presentation layer. This module implements the gambling site interface in French, including all the moderators required by the authority (e.g. pop-ups, warnings). Data extraction („Capteur”)  This module retrieves the information relevant for control and oversight by the regulator. The regulator defines the nature and format of the data (XML). Back-end relay  This module transfers the transactions initiated by gamblers to the operator's back-end gambling engines. Back-end servers may be located outside of France. Digital Safe  The vault module collects the records produced by the capteur to preserve them in a secure manner. If required, the future authority must be able to access the electronic vault either on site or remotely. The Safe must be certified (CSPN) by the French IT-security government agency (ANSSI). 23Copyright Dictao 2013
  • 24. France – Authentication Player registration is a complex paper-based process. One step of the process is a letter sent by physical mail to the player‘s address with an activation code. The regulator manages a national banned player register. Each operator must check his entire player base against that register at least once a month. 24Copyright Dictao 2013
  • 25. France – Traceability Gaming activity is stored in real-time in a digital Safe. Data reflects the player‘s perspective.  Standardized XML-format to allow uniform processing by regulator  “Frontal” (Safe and capture device) located on French soil  Digital signature to seal records (XAdES)  Data protected with strong authentication mechanisms  Data encrypted with regulator public key (RSA). Only the regulator can decrypt records.  Operators are responsible for running the “Frontal”  Synchronous real-time processing  Data archived one year online  Data archived five years offline  Safe must be certified (CSPN) by the French IT-security government agency (ANSSI) 25Copyright Dictao 2013
  • 26. Examples of Control Systems 26 Spain France Denmark Schleswig-Holstein Copyright Dictao 2013
  • 28. Denmark – Authentication Regulator provides a central online service to check players against banned player register (ROFUS/LUR) The regulator manages this central register. Each operator is required to check through the online service whether a player is banned or not. Authentication at each login with NemID and an OCES digital signature. This is the same mechanism used for banks and online services of the public administration. The Danish service provider “DanID” runs this service for the government. 28Copyright Dictao 2013
  • 29. Denmark – Traceability Standardized XML-format to allow uniform processing by regulator Near real-time: Data must be stored within five minutes of an event happening Safe location can be anywhere as long as the regulator has sufficient guarantees to get access Digital seals using the regulator‘s central tamper proof system Encrypted communication between digital Safe and regulator Operators are responsible for running the “Frontal” Data archived one year online Data archived five years offline End-of-day records 29Copyright Dictao 2013
  • 30. Examples of Control Systems Copyright Dictao 2013 30 Spain France Denmark Schleswig-Holstein (Germany)
  • 31. Schleswig-Holstein – Technical architecture Copyright Dictao 2013 31
  • 32. Schleswig-Holstein – SAFE-server features Copyright Dictao 2013 32 Location in Schleswig-Holstein Near-real time data capture Certification by accredited 3rd parties Data encryption Digital seals/signatures Standards-based 36 months data storage Standardized Data (XML)  Gameplay  Financial  Personal information
  • 33. Agenda 33 Dictao Regulators’ Frequently Asked Questions Market cases Copyright Dictao 2013 Facts, Problem and Solution Operators’ Benefits
  • 34. FAQ about… Preventing fraud/ AML Real Time versus Near-Real Time data traceability Control of data Tax control Minor and problem gambler protection Dependency on the Authority Service Providers’ Standard Compliancy Technology suppliers & technology neutrality Copyright Dictao 2012 34
  • 35. Preventing fraud/ AML (1/2) Q: How is the traceability of money flows regulated?  Each financial transaction is sealed and stored in a safe  Regular analysis is performed by the Authority  Operator cash account is separated from the player money account (escrow)  Money may not be transferred between players except through gaming  Money may only be withdrawn to the named bank account associated with the relevant player account  In kind winnings are traced as well (prize description and estimated value) Dictao recommends all of the above 35Copyright Dictao 2013
  • 36. Preventing fraud/ AML (2/2) Q: How can the security and continuity best be secured?  Security principles (best practices, not specific to iGaming)  Integrity: data is sealed through digital signature and chaining  Confidentiality: data is encrypted so that only the regulator may access it  Authentication: use strong credentials like digital certificates  Non repudiability: data is signed  Availability: SLA requirements from operators and suppliers  Continuity and recovery  Require a “Business Continuity Plan” and a “Data Recovery Plan” from operators and suppliers  Require all data to be backed up on a secondary site and maximum delay of recovery Dictao recommends all of the above 36Copyright Dictao 2013
  • 37. Control of data (1/3) Q: option #1: All data flows through the server of the Gambling authority (vault). What are the pros and cons? MARKET CASE: Centralized solution only implemented in Italy - COST: Very expensive for the regulator (platform to design and set up, maintain technical operation team, ensure backup of the data, maintenance, several people to support operators) SOGEI employs 500 persons to perform data control - RESPONSABILITY: The regulator is responsible for tracing the data - TIME: 6 to 12 months to setup the infrastructure Dictao recommends not using this solution 37Copyright Dictao 2013
  • 38. Control of data (2/3) Q: option #2 : the Gambling Authority provides access to a special server that securely stores a copy of the data. What are the pros and cons? + BEST PRACTICE: Decentralized solution used in FR, DK, SP, DE (E15 + SH) + COST: very low cost for the regulator. For example, ARJEL employs 6 persons to perform data control + TIMING: gaming operation may start, even if the regulator platform is not ready + SLA: gaming operation may carry on, even if regulator platform is down - TCO / OPERATOR : standard TCO is < 1 to 0,5% of GGR Dictao recommends the solution of a “distributed safe” placed under the responsibility of the operator 38Copyright Dictao 2013
  • 39. Control of data (3/3) Q: option#3 : the data and its back up data is located / hosted within the national borders of the regulator. What are the pros and cons? + ENFORCEMENT: Location of safe in the regulated territory enables regulator to seize it + EU COMPLIANCE: Host of a safe in a national territory complies with EU jurisprudence, whereas requirements to locate the whole gaming server(s) does not comply Also avoids potentially complex and lengthy cross-border collaboration + CONVENIENCE: Country-hosted data facilitates the control of data completeness and data compliance with the Authority (or delegated third party) requirements - Back-up data is not supposed to be seized, but data recovery from back-up shall be quick Dictao recommends main data repository in the Authority’s territory, a back- up located in the EU, and a recovery delay of 48 hours 39Copyright Dictao 2013
  • 40. Tax control Q: As lots of operators are located abroad, for tax control it is necessary for the Authority to access actual information. What are the best practices from other countries?  Require traceability of all money transactions (including bonus money, gaming network transactions)  Require agregated financial reports from the operator and reconcile those reports with the information available in the safe Q: Do you have any insight on how tax control is maintained in case of poker liquidity, where players from different jurisdictions participate in a game?  The only cross-country liquidity we are familiar with is Denmark  Only data regarding local players is traced in the safe, tax control is based on these data Dictao recommends all of the above 40Copyright Dictao 2013
  • 41. Minor and problem gambler protection Q: Do you have any insight on how problem gambling is monitored in different countries?  Availability of a centralized authorization service maintained by the Authority  Problem gambler list shared with landbased casinos  Operators required to check the authorization service during player registration and regularly during player logon  Technical aspects  Preserve player confidentiality (operators shall not discover information about players they do not “know”)  Use open standards like webservice or DNS to allow all operator technologies to connect  High availability and performance Dictao recommends all of the above 41Copyright Dictao 2013
  • 42. Dependency on the Authority Q: How to prevent that a dependency on the authority for the purpose of authenticity or communication will form a single point of failure for the industry?  Require a decentralized safe under the operator’s responsibility  The only dependency on the Authority regards the authorization (blacklist) service  For confidentiality, it should stay centralized  For availability reasons, it should be rendundant  When the service is down  Gaming operation is still allowed (thus downtime is not disruptive)  Account registration is temporary until the service is back up Dictao recommends all of the above 42Copyright Dictao 2013
  • 43. Service Providers’ Standard Compliancy Q: Dictao’s strategy is to rely on standards. Could you elaborate on the standards?  The internet technology stack relies on standards at all levels, from hardware to application level.  Standards developed for e-commerce, e-government or e-banking applications are all applicable in the online gambling environment:  XSD/XML to define reporting formats  RFC3161 to define time stamps  XMLDSig for digital seals  X509 for digital certificates  ISO27001 for IT security management Dictao recommends using internationally recognized standards 43Copyright Dictao 2013
  • 44. Technology suppliers & technology neutrality (1/2) Q: How can we prevent that requirements on the availability of data favor certain suppliers?  Authority should require the usage of open standards instead of proprietary formats, technologies and solutions  Require application of best practices recognized by everyone  Have the Authority’s technical experts assess the neutrality of the requirements Dictao recommends all of the above 44Copyright Dictao 2013
  • 45. Technology suppliers & technology neutrality (2/2) Q: According to EU law, requirements may not be directed towards a certain technology of certain suppliers  Dictao does not recommend any technology, only standards  All standards Dictao recommends are open, patent-free and may be freely implemented by anyone  Dictao lobbies for European-wide standards Dictao competes on the market with technology-neutral differentiators  Turnkey SaaS infrastructure accelerates projects  Spreading investments over multiple clients lowers costs  Professional services to assist operators Dictao recommends using these internationally recognized standards 45Copyright Dictao 2013
  • 46. Next step Based on strong experience and proximity with regulators and operators, Dictao has built a template model of an ideal traceability system that:  Covers the needs of tax and fraud control, AML, player protection  Facilitates integration by the operator  Is 100% technology-neutral We would like to introduce this model to you at your earliest convenience 46Copyright Dictao 2013
  • 47. For more information, please contact: Frédéric Engel fengel@dictao.com +33 1 73 00 26 34 +33 6 13 42 38 98 (mobile) www.dictao.com http://www.dictao.com/en/solutions/online-gambling