Malta tested self-exclusion across 20 licensees and found gaps between brands
A mystery-shopping review of 58 gambling URLs found delays, cooling-off failures and difficulty matching duplicate identities across brands.
Jump to a section
20 licensees · 58 URLs
Cross-brand protection fails where identity and systems split
Malta · self-exclusion
Evidence behind the story
What we checked
Primary documents
1 checked
Response record
Response included
Last source check
26 August 2026
Next scheduled review
9 September 2026
Why this matters
A player can experience one operator group as several brands while compliance systems see separate accounts. Malta's review exposes the technical and governance work needed to make a self-exclusion decision follow the person across that structure.
Procedural status
Thematic review completed; remediation requested
The MGA communicated findings to relevant licensees and requested rectification plans. Follow-up supervisory engagement may continue, but the summary announces no named sanction.
The current picture
- The MGA reviewed self-exclusion controls across 20 B2C licensees and 58 active URLs using mystery shopping.
- It found broadly positive compliance alongside delays, missed cooling-off periods and weak duplicate-identity detection across brands.
- Relevant licensees were asked to submit rectification plans, with follow-up supervision where needed.
Confirmed by the record
- The review was carried out in 2025 after reports that some excluded players could access multiple brands.
- The authority tested cross-brand controls and how responsible-gambling information appeared at key points of play.
- Other findings included missing registration limit prompts and incomplete Reality Check pop-ups.
- The February 2026 publication is thematic and does not publicly name the 20 licensees.
Not established
- The review does not say that all 20 licensees failed every control.
- Fifty-eight URLs are not 58 separate corporate operators.
- The public summary does not identify individual affected players or quantify financial harm.
- A requested rectification plan is not the same as a public fine or licence sanction.
Sources for each key claim
Evidence map
Each core claim is paired with the document used to substantiate it. Open the record and check our reading.
The MGA examined 20 B2C licensees and 58 active URLs through a 2025 mystery-shopping review.
The review found delays, cooling-off failures, cross-brand identity-matching challenges and incomplete player-protection prompts.
The authority asked relevant licensees for rectification plans and reserved follow-up supervisory engagement.
What changed, and when
1 January 2025
Review carried out
The MGA says the thematic work occurred during 2025; no exact opening date is published.
17 February 2026
Findings published
The authority releases the sample, themes and remediation expectation.
24 August 2026
Follow-up source check
The public summary still presents rectification and future supervision rather than a named sanction list.
The difficult test starts after the first exclusion
Self-exclusion works visibly when one account closes. The harder question is whether the same person can open or use another account under a sister brand, a slightly different identity record or a separate front end. Malta's regulator built its 2025 thematic review around that real-world problem.
The MGA mystery-shopped 58 active URLs operated by 20 B2C licensees. It tested exclusion activation, cross-brand account controls and the presentation of safer-gambling tools. The sample is broad enough to reveal patterns, but it is not a list of 58 independent companies.
What the regulator found
The authority says most assessed licensees were broadly aligned with expectations. It also identified delays before exclusions became active, cases where exclusions were lifted without the mandatory cooling-off period, and difficulty detecting duplicate or closely matching identity information across brands.
The same exercise found absent prompts to set limits during registration and incomplete information in Reality Check pop-ups. Those are different control failures. One concerns who can play; another concerns what a player is asked or shown while playing.
Why identity matching is not a simple name search
People enter names, addresses and dates in inconsistent ways. Brands may use separate account systems, and a group can acquire platforms built on different technology. A literal exact match can miss the same person; an aggressive fuzzy match can block someone else.
That trade-off requires rules, human review and evidence. The goal is not to collect more personal data without limit. It is to use permitted identity data consistently enough that a self-exclusion choice is not defeated by spelling, formatting or brand architecture.
Cooling-off is part of exclusion integrity
A control can activate promptly and still fail later if the account is reopened too easily. The MGA's cooling-off finding matters because a momentary request to return may occur during the risk period the exclusion was meant to create.
The public summary does not quantify how often this happened or identify the brands involved. It supports a thematic concern, not a claim that every tested operator restored excluded accounts improperly.
Rectification is not a public penalty
The authority sent findings to relevant licensees and asked for rectification plans. It says follow-up supervision will continue where necessary. No named fine, warning or licence suspension appears in the thematic announcement.
That status should survive into coverage. A remediation request can produce material operational change without becoming an enforcement sanction. If named decisions follow, they need their own documents and response records.
What a credible fix looks like
A strong programme needs near-real-time activation, group-level identity resolution, locked cooling-off logic and tests that prove every connected brand receives the status. Mystery shopping should be repeated after remediation rather than treating a policy update as evidence of effect.
Operators also need exception handling. When matching confidence is uncertain, staff need a route to investigate without allowing play to continue by default or retaining unnecessary data.
Testing should include ordinary variations: accents, compound surnames, changed addresses and account details entered in a different order. The purpose is not to create traps for staff. It is to find the predictable points where a group-level promise fails when real customer data is less tidy than a test record.
The follow-up measure that matters
The next useful disclosure would report how many remediation actions were completed and whether retesting found the same gaps. Aggregate results could improve accountability without exposing individual players.
Until then, the measured conclusion is strong enough: Malta found generally positive practice and repeatable weaknesses across a multi-brand sample. Both halves belong in the headline file.
Response record
The MGA's positive overall compliance assessment and the unnamed-licensee scope are included alongside the weaknesses.
Status: included