Image by Ilse Vantuyne
A phone held flat over a kitchen table at eleven at night. A driver’s license under a lamp, photographed twice because the first shot caught a glare, then pushed into a registration form.
The account opens, and the person who took the photo stops thinking about it. In a data center somewhere, that image is now a record with a retention schedule attached.
American online gambling splits into two populations, and both end at that upload. Real-money online casinos are licensed in seven states, each through its own gaming authority, and each setting the minimum age at 21.
The second population runs on promotional sweepstakes law rather than gambling law, and tends to ask for the document later, when a prize is redeemed.
That second group looks like the smaller problem. It is not, because redemption pulls the same class of document into the same kind of store.
Legal Sports Report’s reporting on top sweepstakes casino sites records identity verification as a step that happens before a redemption is paid, operator entry after operator entry.
The Fields Are Named In Federal Law, Not In A Product Spec
A casino with gross annual gaming revenue above $1,000,000 is a financial institution under the Bank Secrecy Act, and the recordkeeping rule that follows is specific about what it wants.
Section 1021.410(a) of title 31 tells a casino to secure and maintain the name, permanent address and Social Security number of anyone who opens an account, and to verify the name and address by examining a document.
The same paragraph says the specific identifying information has to be recorded, which means the license number itself, not a note that a license was seen.
For a nonresident alien it wants the passport number, or a description of whatever other government document was used.
New Jersey’s internet gaming rules go further into the schema. N.J.A.C. 13:69O-1.3(b) sets out the electronic patron file: legal name, date of birth, the whole Social Security number or its last four digits where the patron volunteered it, account number, address, email and telephone number.
The list then closes with any other information used to verify identity, the method used, the date of verification, and the document number of the government issued credential examined.
So the answer to why an operator needs all this names a rule rather than a growth team. The collection is compelled, and there is little discretion to collect less.
Ninety Days, Five Years, Ten Years
Deletion is the cheapest security control ever invented, and gambling regulation takes most of it off the table.
The Bank Secrecy Act sets the federal floor at five years for every record the chapter requires, and adds that those records have to stay accessible within a reasonable period of time.
Nevada’s cybersecurity regulation sets its own five-year minimum for the compliance documentation it demands.
New Jersey stretches it much further. Under 13:69O-1.8(d), a gaming system has to hold everything needed to recreate a patron’s play and account activity for each session, including any identity or location verifications, for no less than ten years.
Set that against the same rule’s treatment of authentication logs, which have to stay accessible for 90 days. The record of who was verified outlives the record of who logged in by roughly nine and a half years.
A quieter obligation sits underneath. Where those federal records live on machine-readable media they must stay there, and the indexes, record layouts, file descriptions and manuals that let someone read them back must be kept as long as the records.
Schema documentation is a retained artifact, not an internal convenience.
What The Rules Actually Order You To Encrypt
The New Jersey encryption mandate is shorter than most engineers expect. Paragraph (b)(2) of that patron file rule names three things: a Social Security number or its foreign equivalent; any password or PIN; and credit card numbers, bank account numbers or other personal financial information.
The credential document number that the very next paragraph tells the operator to record is not on the list.
Nevada arrives from the other direction. Regulation 5.260 asks a covered entity, a class that includes interactive gaming licensees, to run a risk assessment and develop the cybersecurity best practices it deems appropriate.
It names CIS Version 8, COBIT 5, ISO/IEC 27001 and NIST SP 800-53 as examples rather than requirements.
Group I licensees carry governance on top: a named individual responsible for the practices, an annual internal audit verifying the organization follows them, and an annual independent review attesting in writing that they comply.
That is a real audit trail. It is not a control catalogue, which leaves the scanned image protected by whatever the operator’s own assessment concluded.
PCI DSS Draws Its Boundary Around The Card
Card data is the one category with a prescriptive standard behind it, and that standard says the opposite of what the gaming rules say.
Requirement 3.2.1 of PCI DSS v4.0.1 wants a retention and disposal policy that keeps stored account data to a minimum, and Requirement 3.3 bars sensitive authentication data after authorization.
The standard also asks an organization to verify quarterly that data past its retention period has been deleted or rendered unrecoverable.
Nevada put the whole thing into statute: NRS 603A.215 requires a data collector doing business in the state that accepts a payment card to comply with the current version of PCI DSS.
None of Requirement 3 reaches a passport scan. MGM Resorts showed the shape of that boundary in its Form 8-K of October 5, 2023, which concerned its US resort systems rather than an online patron file.
The company said criminal actors obtained names, contact details, gender, dates of birth and driver’s license numbers for some customers who had transacted before March 2019, plus Social Security and passport numbers for a limited number of them.
It did not believe passwords, bank account numbers or payment card information had been taken. The card scope held. The identity scope did not. That is the asymmetry the whole problem sits on.
The Redemption Desk Builds The Same Store From Tax Law
On the sweepstakes side the document arrives through a different door, and the tax code is holding it open.
The IRS instructions for Forms 1099-MISC and 1099-NEC put prizes and awards that are not payment for services into box 3, and add one sentence that decides the question: “Also, include amounts paid to a winner of a sweepstakes not involving a wager.”
Where a wager is made, the winnings go on Form W-2G instead.
For tax years beginning after 2025 that reporting threshold sits at $2,000. Filing the return requires a taxpayer identification number, which is what Form W-9 collects, and a missing number triggers backup withholding.
Follow that through and the redemption desk holds a name, an address and a taxpayer identification number for every redeemer above the threshold, assembled for a tax filing rather than for a gaming regulator.
The control standards quoted earlier attach to a state gaming licence. An operator without one answers to general state data statutes and the tax rules instead.
The category’s own legal position is contested and still moving. Connecticut and New Jersey issued cease and desist notices by the middle of 2025, New York passed restricting legislation that year, and Tennessee followed with orders in December.
However that resolves, the store already exists.
The Vendor Holds A Copy Too
New Jersey draws the perimeter in two unusual ways. Employees doing patron identification, anti-money laundering detection or fraud prevention, where the work needs access to confidential patron account information, have to be physically present in the state.
Operators and their vendors are separately barred from keeping patron account information without the permit holder’s express written consent.
Nevada writes the contract term rather than the geography: an agreement that discloses personal information must oblige the recipient to implement and maintain reasonable security measures.
Both rules exist because the copy outside the building is the harder one to see. Caesars Entertainment’s Form 8-K of September 14, 2023 traced its incident to a social engineering attack on an outsourced IT support vendor.
The filing said the actor acquired a copy of its loyalty program database, which includes driver’s license numbers and social security numbers for a significant number of members.
It also notes that customer-facing operations, including the online and mobile gaming applications, ran without disruption, and that the company found no evidence that member passwords, PINs or payment card data had been acquired.
Three Clocks, Three Different Starting Guns
The Nevada Gaming Commission adopted amendments to Regulation 5.260 on January 29, 2026, effective on adoption, and both the deadline and its trigger changed. The old rule gave a licensee 72 hours from becoming aware of a cyber attack.
The new one gives 24 hours from the moment the licensee activates the response procedures in its own incident response plan.
An initial incident response report follows within five calendar days, and written status updates run every 30 days until the matter is resolved and documented. The second clock is slower and vaguer.
NRS 603A.220 requires disclosure to any Nevada resident whose unencrypted personal information was acquired, in the most expedient time possible and without unreasonable delay. No hour count appears anywhere in it.
That word unencrypted carries weight. The state defines personal information as a name combined with one of a listed set of elements when those elements are not encrypted, and it excludes the last four digits of a Social Security number or a license number, the same minimized field the New Jersey patron file permits.
The third clock belongs to investors. A listed company files Item 1.05 of Form 8-K within four business days of deciding an incident is material, in force since December 2023. Both 2023 casino filings predate it.
Who The Operator Answers To When It Fails
Nevada’s regulation closes with the sentence that matters most commercially: failing to exercise proper due diligence in complying with it is an unsuitable method of operation and may bring disciplinary action.
That reaches the licence itself. The consumer statute adds its own teeth. A violation of the state’s data chapter counts as a deceptive trade practice, and the Attorney General or a district attorney can seek an injunction.
NRS 603A.215 offers a narrow shelter for a data collector that complied with that section where the breach did not involve gross negligence or intentional misconduct.
Read closely, the shelter is anchored to the payment card standard, and everything else falls back on the general duty to keep reasonable security measures.
The regulator, not the operator, now sets the tempo. When the Gaming Control Board workshopped the shorter deadline on December 4, 2025, the Nevada Resort Association argued that many operators depend on third-party vendors whose contracts allow up to 48 hours to notify the licensee.
The 24-hour rule was adopted regardless, which tells a vendor manager what the next contract renewal has to fix.
Security teams on the US side can follow the same regulators through Legal Sports Report, at @LSPReport.
Caesars wrote the honest ending itself. The company said it had taken steps to ensure the stolen data was deleted by the unauthorized actor, “although we cannot guarantee this result.” A copied license cannot be recalled.
Everything that works happens before the upload: collect the narrowest field the rule allows, encrypt what the rule names, and keep a defensible written answer for the records nobody is allowed to delete.





