Skip to main content
All Watch files
DevelopingPlayer protection·Watch Brief·Netherlands·Cruks identity checks and land-based venue access

Ksa acts after Cruks registrants used other people's ID to enter Dutch gambling venues

The regulator says Cruks returned the correct result for the identity presented, but venue staff failed to stop identity misuse at the door.

Published 8 September 2026 · Updated 8 September 20265 minute read
By iGaming Atlas Editorial Team2 primary sourcesNext review 15 September 2026
Jump to a section

Evidence behind the story

What we checked

Primary documents

2 checked

Response record

Last source check

8 September 2026

Next scheduled review

15 September 2026

Why this matters

A self-exclusion register protects the person whose identity is checked. If the document belongs to somebody else, the database can answer correctly while the real visitor is excluded. The case places the control boundary at the physical identity check, not only inside Cruks.

Procedural status

Regulator action announced; venue outcomes pending

The Ksa says it is acting towards the gambling halls and casinos named in the broadcast. It has not published venue-level findings or sanctions.

The current picture

  • The Dutch gambling regulator says people registered in Cruks entered gambling halls and casinos through identity fraud shown in a television investigation.
  • The Ksa says the register worked for the identity presented; the failure occurred when staff did not establish that the visitor matched the document.
  • The regulator is taking action towards the venues named in the broadcast, but has not yet published a breach decision or sanction.

Confirmed by the record

  • The Ksa published its response on 3 September 2026.
  • The regulator says a Cruks registrant used another person's identity document to enter a gambling hall.
  • Ksa guidance requires an identity and Cruks check every time a player enters a gambling hall.
  • The guidance says access must be refused when staff doubt that the visitor is the person shown on the identity document.

Not established

  • The regulator's statement does not name the venues or publish the number of successful entries.
  • No administrative fine, warning, licence condition or closure order has been announced in the cited sources.
  • The statement does not show that the Cruks database returned an incorrect result for the identity submitted.
  • A television demonstration does not establish the same control failure at every Dutch gambling venue.

Sources for each key claim

Evidence map

Each core claim is paired with the document used to substantiate it. Open the record and check our reading.

1

The Ksa says Cruks registrants gained access to Dutch gambling venues through identity fraud shown in the PowNews investigation.

2

The regulator says Cruks worked when a person's own identity was presented and that the reported weakness concerned human access control.

3

Ksa guidance requires venues to establish identity, check Cruks and refuse access when the visitor does not reliably match the document.

4

The Ksa announced action towards the venues named in the programme but did not announce a sanction.

The register answered the identity it was given

The Kansspelautoriteit says people registered in the Netherlands' Cruks self-exclusion system were able to enter gambling halls and casinos by using identity fraud. Its 3 September response followed a PowNews investigation and says at least one excluded person entered a venue with somebody else's identity document.

The regulator draws a precise technical boundary. Cruks worked when a visitor identified with their own document. If staff accept a document belonging to another person, the register checks the identity on that document rather than discovering the real visitor's exclusion. A correct database result cannot repair a false identity match at the entrance.

The control is both human and digital

Ksa guidance requires a venue to establish the player's identity and check Cruks every time the person enters. On a first visit, staff must see an original valid document. If the photo, age or other details create doubt, the guidance says the visitor must not be admitted.

The same principle applies to membership or loyalty cards used on repeat visits. A unique identifier must belong to one player, and venues need technical and organisational measures that stop another person using it. The guidance specifically lists borrowed cards, forged documents and another person's ID among known failure patterns.

Ksa action is not yet a venue-level verdict

The regulator says it is taking action towards the gambling halls and casinos named in the programme. The public response does not name them, count the entries or identify a formal enforcement measure. No fine, warning, licence condition or closure order appears in the two official sources reviewed for this file.

That means the event is developing. The Ksa has acknowledged a serious signal and a control failure that should not have happened, but the next document must establish which venue did what, whether the regulator confirms a breach and how the operator responds.

Why this is different from a Cruks outage

A system outage prevents or disrupts the register query. The reported route here is different: the query can complete against the wrong person's identity. Describing the event as Cruks failing would therefore place the defect in the wrong part of the process.

For venue operators, the practical lesson is that access control cannot be reduced to receiving a green answer from software. Staff training, photo comparison, escalation when details do not match and controls around repeat-visit identifiers are part of the same protective chain.

The next publication should name the outcome

The Ksa has enough information to approach the venues shown in the investigation. A later inspection result or sanction should identify the legal entity, site, failed control, evidence period and required remediation. A venue response would add the operator's explanation and any corrective action.

Until then, the supported conclusion is narrow but important: excluded people reportedly bypassed entry controls through identity misuse, the regulator says the Cruks check itself worked for the identity presented, and venue-level enforcement outcomes remain pending.

Response record

The Ksa statement does not name the venues, so no entity-specific response can be attributed. The article does not infer admissions or repeat failures.

Status: not available

Sources checked