Skip to main content
All Watch files
ConfirmedPlayer protection·Watch Explained·Malta·Cross-brand self-exclusion and player protection

Malta tested self-exclusion across 20 licensees and found gaps between brands

A mystery-shopping review of 58 gambling URLs found delays, cooling-off failures and difficulty matching duplicate identities across brands.

Published 26 August 2026 · Updated 26 August 20267 minute read
By iGaming Atlas Editorial Team1 primary sourcesNext review 9 September 2026
Jump to a section

Evidence behind the story

What we checked

Primary documents

1 checked

Response record

Response included

Last source check

26 August 2026

Next scheduled review

9 September 2026

Why this matters

A player can experience one operator group as several brands while compliance systems see separate accounts. Malta's review exposes the technical and governance work needed to make a self-exclusion decision follow the person across that structure.

Procedural status

Thematic review completed; remediation requested

The MGA communicated findings to relevant licensees and requested rectification plans. Follow-up supervisory engagement may continue, but the summary announces no named sanction.

The current picture

  • The MGA reviewed self-exclusion controls across 20 B2C licensees and 58 active URLs using mystery shopping.
  • It found broadly positive compliance alongside delays, missed cooling-off periods and weak duplicate-identity detection across brands.
  • Relevant licensees were asked to submit rectification plans, with follow-up supervision where needed.

Confirmed by the record

  • The review was carried out in 2025 after reports that some excluded players could access multiple brands.
  • The authority tested cross-brand controls and how responsible-gambling information appeared at key points of play.
  • Other findings included missing registration limit prompts and incomplete Reality Check pop-ups.
  • The February 2026 publication is thematic and does not publicly name the 20 licensees.

Not established

  • The review does not say that all 20 licensees failed every control.
  • Fifty-eight URLs are not 58 separate corporate operators.
  • The public summary does not identify individual affected players or quantify financial harm.
  • A requested rectification plan is not the same as a public fine or licence sanction.

Sources for each key claim

Evidence map

Each core claim is paired with the document used to substantiate it. Open the record and check our reading.

1

The MGA examined 20 B2C licensees and 58 active URLs through a 2025 mystery-shopping review.

2

The review found delays, cooling-off failures, cross-brand identity-matching challenges and incomplete player-protection prompts.

3

The authority asked relevant licensees for rectification plans and reserved follow-up supervisory engagement.

What changed, and when

  1. 1 January 2025

    Review carried out

    The MGA says the thematic work occurred during 2025; no exact opening date is published.

  2. 17 February 2026

    Findings published

    The authority releases the sample, themes and remediation expectation.

  3. 24 August 2026

    Follow-up source check

    The public summary still presents rectification and future supervision rather than a named sanction list.

The difficult test starts after the first exclusion

Self-exclusion works visibly when one account closes. The harder question is whether the same person can open or use another account under a sister brand, a slightly different identity record or a separate front end. Malta's regulator built its 2025 thematic review around that real-world problem.

The MGA mystery-shopped 58 active URLs operated by 20 B2C licensees. It tested exclusion activation, cross-brand account controls and the presentation of safer-gambling tools. The sample is broad enough to reveal patterns, but it is not a list of 58 independent companies.

What the regulator found

The authority says most assessed licensees were broadly aligned with expectations. It also identified delays before exclusions became active, cases where exclusions were lifted without the mandatory cooling-off period, and difficulty detecting duplicate or closely matching identity information across brands.

The same exercise found absent prompts to set limits during registration and incomplete information in Reality Check pop-ups. Those are different control failures. One concerns who can play; another concerns what a player is asked or shown while playing.

Why identity matching is not a simple name search

People enter names, addresses and dates in inconsistent ways. Brands may use separate account systems, and a group can acquire platforms built on different technology. A literal exact match can miss the same person; an aggressive fuzzy match can block someone else.

That trade-off requires rules, human review and evidence. The goal is not to collect more personal data without limit. It is to use permitted identity data consistently enough that a self-exclusion choice is not defeated by spelling, formatting or brand architecture.

Cooling-off is part of exclusion integrity

A control can activate promptly and still fail later if the account is reopened too easily. The MGA's cooling-off finding matters because a momentary request to return may occur during the risk period the exclusion was meant to create.

The public summary does not quantify how often this happened or identify the brands involved. It supports a thematic concern, not a claim that every tested operator restored excluded accounts improperly.

Rectification is not a public penalty

The authority sent findings to relevant licensees and asked for rectification plans. It says follow-up supervision will continue where necessary. No named fine, warning or licence suspension appears in the thematic announcement.

That status should survive into coverage. A remediation request can produce material operational change without becoming an enforcement sanction. If named decisions follow, they need their own documents and response records.

What a credible fix looks like

A strong programme needs near-real-time activation, group-level identity resolution, locked cooling-off logic and tests that prove every connected brand receives the status. Mystery shopping should be repeated after remediation rather than treating a policy update as evidence of effect.

Operators also need exception handling. When matching confidence is uncertain, staff need a route to investigate without allowing play to continue by default or retaining unnecessary data.

Testing should include ordinary variations: accents, compound surnames, changed addresses and account details entered in a different order. The purpose is not to create traps for staff. It is to find the predictable points where a group-level promise fails when real customer data is less tidy than a test record.

The follow-up measure that matters

The next useful disclosure would report how many remediation actions were completed and whether retesting found the same gaps. Aggregate results could improve accountability without exposing individual players.

Until then, the measured conclusion is strong enough: Malta found generally positive practice and repeatable weaknesses across a multi-brand sample. Both halves belong in the headline file.

Response record

The MGA's positive overall compliance assessment and the unnamed-licensee scope are included alongside the weaknesses.

Status: included

Sources checked