Guide · Betting, Gambling & Prediction MarketsUpdated August 17, 2026

How should a betting or gambling operator handle a law enforcement request?

The law treats a betting operator as a financial institution. Most request-response functions are not built to that standard. This page covers what arrives, how strong programs verify and produce, and what regulators check.

Get the handbookThe LE Request Response Handbook for Betting, Gambling & Prediction Markets.

Why do betting operators get so many law enforcement requests?

A sportsbook, an online casino, and a prediction market hold the same data a bank holds: verified identity, payment instruments, transaction history, and a geolocation record for every customer. US law treats a betting operator as a financial institution under the Bank Secrecy Act. UK, EU, and Australian law treats it as an obliged entity. Banks built their response functions over decades. Betting operators have had about five years.

No betting operator publishes its request numbers. Comparable account-based money businesses do. Kraken reported 4,923 government requests in 2023 and 6,826 in 2024, a 38.6 percent increase. Coinbase has received more than ten thousand requests a year since 2022. Casinos and card clubs filed about 77,000 suspicious activity reports in fiscal 2025.

The growth follows the market. Legal US sports betting expanded from a handful of states to 39 plus DC, and licensed operations in the UK, Europe, and Australia grew over the same period.

At many operators, one person handles all of this volume. The intake address is often that person's own inbox, because the first subpoena arrived there. The function sits in legal at some companies, and in compliance or financial crime at others. A single-person function has no coverage for vacation, sickness, or departure. The deadlines continue through all three.

Is your volume compulsory process, or is it something else?

Request volume in this vertical divides into two different jobs. Which job you have determines how to build the function.

Most volume at a US-licensed operator is compulsory process: subpoenas, search warrants, and grand jury demands. Each carries a deadline set by a court or an agency. The job is to process every request before its deadline.

At an internationally licensed group, a large share of volume arrives with no legal compulsion: a foreign police force asking without citing an authority, a financial intelligence unit requesting broadly, an agency asking for data it has no power to demand. The job is to decide, case by case, whether to disclose. A voluntary disclosure to the wrong requester creates liability to your own customer.

Identify your mix before you design intake, staffing, or policy. A due-date policy written for subpoenas does not help an MLRO decide whether to answer a request with no legal force.

How do you verify a law enforcement request is real?

Forged legal process is cheap, good, and documented at the federal level. In November 2024 the FBI warned that criminals were using compromised US and foreign government email accounts to send fraudulent emergency data requests to US companies. Betting operators are a specific target because they house so much data: verified identity, Social Security number, bank accounts, home address, device data, and a complete financial-behavioral history sit in a single production. One fake subpoena returns a full doxxing kit. The threat comes in two forms:

The forged document

FORGERY

AI can draft a convincing subpoena in minutes from public court formats and an operator's own published submission instructions.

Review catches some of these

The compromised real account

TAKEOVER

A real account on a real government or police domain, sold by country and agency. The document and the domain both pass review. The sender is not the account owner.

Passes every manual check

Manual verification fails against the second form. The phone number printed on a forged subpoena connects to the forger. A compromised .gov account passes domain checks, document checks, and callback checks.

The alternative is to verify requesters through a network, before first contact. Kodex verifies 15,000+ government agencies and 150,000+ verified investigators across 180+ countries. A requester's identity is established once and monitored across every company on the network.

For the verification procedure, see how to verify a law enforcement request. For the forged-EDR threat, see fraudulent emergency data requests.

What kinds of requests show up beyond the subpoena?

Subpoenas, warrants, and court orders are not the full list. Operators also receive these request types:

  1. Emergency disclosure requests. In this vertical they are often geolocation-driven: a missing person or a fugitive placed a bet from a known location. Emergencies are also the request type forgers imitate most.
  2. Keep-open requests. Law enforcement asks you to keep an account active and not tell the customer during an investigation. This requires a written policy, a review schedule, and a record.
  3. Preservation demands. Hold the data, produce nothing yet. The standard term is 90 days, renewable.
  4. FinCEN 314(a) and 314(b) inquiries. Financial institutions are on these distribution lists automatically, whether or not a team was set up to receive them.
  5. Canadian production orders. These begin when an operator serves Ontario, and they have their own formal requirements.

This is an AML vertical first, and the request types reflect that.

FinCEN publishes sports-betting-specific laundering typologies. The crimes behind most requests are the ones an AML program already monitors: laundering, fraud, identity theft, account takeover, and proceeds of crime.

What should you actually produce, and to whom?

Verification establishes that the requester is real. Production is a separate question: does this document compel this data from this entity? Five rules cover most cases:

  1. Define standard production packages before requests arrive. Requests track what the business holds: identity and KYC records, payment and transaction data, wagering and session activity, and customer communications. With packages defined, most production decisions reduce to a package and a date range.
  2. Push back on overbroad requests. "Everything on this customer" is not a valid scope. Return it and ask for a proportionate request. Agencies rarely contest a stated scope policy.
  3. Match production to the entity that was actually served. A request served on the Spanish entity gets the Spanish entity's data only. Groups built by acquisition can run dozens of brands, and requests often name the public parent when a subsidiary holds the license. Map your entities in advance and route by entity at intake.
  4. Give voluntary requests their own default. For requests with no legal compulsion, the safe default is no production unless a written policy states otherwise. Liability for a wrongful voluntary disclosure falls on the operator, not the requesting agency.
  5. Set your own response deadline and hold it. Subpoena return dates are set by whoever drafted the subpoena. Set an internal deadline you can meet on a day when several subpoenas arrive at once, state it to requesting agencies, and do not miss it. Agencies accept a consistent deadline. They lose confidence when response times vary.

What do regulators actually check?

State gaming commission AML examinations now test whether the program works. Examiners sample case files and check for a complete, timestamped record from intake to resolution. A program that keeps this record as part of normal work answers the examiner in an afternoon.

The same shift is visible in every jurisdiction:

FinCEN

The effectiveness framework requires operators to show the program works, and FinCEN has published sports-betting-specific laundering typologies.

UK Gambling Commission

Enforcement actions continue to accumulate, and obliged-entity duties make request handling part of the AML program.

AUSTRAC

Multiple major operators are in or exiting enforcement simultaneously, with AML program failures at the center of each action.

Nevada Reg 5

Recent amendments assign AML responsibility to a named, personally licensed individual. Vendors in this workflow may also need state gaming-vendor licenses, in particular in New Jersey and Pennsylvania.

The EU e-Evidence Regulation, with its 8-hour emergency deadlines, is also cited to this industry. A US-only operator with no EU offering is out of scope. For EU-facing operators, the regulation's financial-services carve-out does not clearly cover gambling, and adjacent services such as chat and community features are the most likely route into scope. Confirm scope with counsel.

Frequently asked questions

Is a sportsbook or online casino legally required to respond to law enforcement requests?

Yes. The legal basis differs by geography. In the US, licensed operators are casinos and money services businesses under the Bank Secrecy Act, with SAR filing obligations and standing distribution lists such as FinCEN 314(a). In the UK, EU, and Australia, licensed operators are obliged entities under their AML frameworks. Compulsory legal process, such as a subpoena or warrant, carries its own response deadline set by the issuing court or agency.

What's the difference between a compulsory request and a voluntary one?

A compulsory request, such as a subpoena, warrant, or grand jury demand, has legal force and a deadline. A voluntary request does not. The agency is asking, not compelling. At internationally licensed groups, a meaningful share of volume is voluntary. Producing data against an unauthorized voluntary request creates liability to the customer whose data was disclosed.

Does EU e-Evidence apply to gambling operators?

For a US-only operator with no EU offering, no. For EU-facing operators, possibly. The regulation's financial-services carve-out does not clearly cover gambling, and adjacent services such as chat and community features are the most likely route into scope. Confirm with counsel.

How do you verify that a law enforcement request is genuine?

Document inspection and phone callbacks do not catch a compromised government email account, because the domain and the document both pass review. The reliable method is to verify requester identity against a network where agencies and investigators are known before first contact and monitored across every company on the network.

How fast should a betting operator respond to a subpoena?

Set a deadline the team can meet on a day when several subpoenas arrive at once, state it consistently to requesting agencies, and do not miss it. A deliberate, consistent deadline matters more than a short one.

Where does your program stand?

Programs in this vertical sit along a common line. At the early end, the intake address is one person, the tracker is a spreadsheet, and verification is a web search. In the middle, there is a shared alias, written procedures, and a fixed default deadline. This handles routine volume and little fraud. The strongest programs combine verified intake, network-based requester verification, self-set deadlines that hold for months, entity-aware production, and coverage that does not depend on one person. Most operators sit earlier on this line than they estimate, and moving up does not require a rebuild. The full handbook maps the line, with the regulatory reference behind every claim on this page.

Kodex is the network for handling legal requests: requesters are verified before a human reads the request, requests are structured and routed to the correct entity, and responses are delivered with a complete audit trail. To see it against your own volume, request a demo and bring your last quarter's numbers.

New to this area? Start with the complete guide to law enforcement data request management.