Skip to content
RiverCore
Dutch Regulator Renews Eight iGaming Licenses to 2031
Dutch iGaming licensesKSA renewalHolland CasinoDutch online gambling license renewal 2031KSA iGaming regulatory framework Netherlands

Dutch Regulator Renews Eight iGaming Licenses to 2031

19 Sep 20267 min readJames O'Brien

Renewing a Dutch gambling license in 2026 is a bit like getting your car through the NCT after five years of hard driving: the inspector doesn't just glance at the paintwork, they run a torch under the chassis and ask why the exhaust smells funny. The Kansspelautoriteit has just waved the first eight operators through the bay doors. But the smell of a self-exclusion scandal is still hanging in the air, and that inspection metaphor is going to matter all the way to 2031.

This is the first real stress test of the framework the Netherlands stood up in 2021, and the results tell you a lot about how European regulators are thinking about the second wave of licensed iGaming.

What Happened

The Dutch Gaming Authority has issued its first batch of follow-up licenses under the Kansspel op afstand regime, as Gambling News reported on 18 September. Eight operators are through. The original permits, handed out when the regulated market opened in 2021, expire at the end of September 2026, so the timing is not accidental. The renewed licenses run from October 2026 to September 2031, another five-year cycle.

The list reads like a who's who of the Dutch market: TOTO Online B.V. (running TOTO and Winnitt), Holland Casino N.V. (Holland Casino Online), Play North Limited (Kansino), FPO Nederland B.V. (FairPlay Casino), Bingoal Nederland B.V. (Bingoal), Hillside (New Media Malta) Plc (Bet365), NSUS Malta Limited (GG Poker), and Betent B.V. (Betcity).

The KSA was clear about the criteria. It went back through five years of compliance history for each licensee and asked each applicant to explain, in writing, what technical and operational controls they'd put in place so the same breaches don't happen again. That's not a box-tick exercise. It's a documented remediation trail that will sit on file and be referenced the next time something goes wrong.

The context is uncomfortable. In parallel, Holland Casino, one of the eight renewed, allowed a self-excluded reporter to gamble at its Eindhoven land-based venue using a colleague's driver's license. The same reporter also got play at Jack's Casino in Utrecht and Casino Be One in Rotterdam. Staff at all three checked ID and still missed it. The KSA has said it will take appropriate action. The regulator also recently published a study on how early exposure to gambling shapes young people's perception of the industry, so the political mood music is not exactly permissive.

Technical Anatomy

The interesting bit for engineers is not the paperwork, it's what the renewal process actually inspects. A KSA follow-up license is a rolling audit of your control plane. The regulator is looking at KYC pipelines, self-exclusion registers (CRUKS integration in the Dutch case), deposit limit enforcement, marketing controls, source-of-funds workflows, and the incident logs that show how each of those systems failed and got fixed over five years.

The Holland Casino Eindhoven incident is a beautiful illustration of where the guts of it fall apart. A CRUKS check at the door only works if the identity presented at the door actually belongs to the person standing there. A driver's license swipe validates the document, not the human. Without biometric matching (facial recognition against the ID photo, or a live liveness check), a borrowed license defeats the entire self-exclusion architecture. This is the part where it all falls over, and it falls over in exactly the same way whether you're a land-based venue or an online operator relying on document upload without a live selfie.

For online operators, the technical stack under scrutiny is deeper. The KSA wants to see how CRUKS lookups are cached (or not), how limit changes propagate across product silos (sportsbook, casino, poker often live on different platforms), how affiliate traffic is filtered before a registration form is even served, and how ad targeting excludes vulnerable cohorts. Anyone who has debugged a cross-product limit-enforcement bug knows the pain: a player hits a daily deposit cap on sportsbook, jumps to casino under the same wallet, and the check silently passes because the cap counter lives in the wrong microservice.

The renewal framework effectively says: show us your architecture, show us your incidents, show us your fixes. That's a maturity model closer to what the UK Gambling Commission has been pushing on operators for years, and it's a world away from the light-touch "did you fill out the form" style of early European licensing.

Who Gets Burned

The eight operators on the list have breathing room until 2031, but that's a false sense of comfort. Holland Casino is renewed and simultaneously facing KSA action over the self-exclusion breach. A follow-up license is not a shield. It's a contract with performance clauses, and the regulator has already signalled that the next five years are going to be judged on the same non-compliance ledger that the last five were.

Operators that weren't in this first batch are in a more awkward spot. The KSA has just publicly demonstrated what "good enough" looks like, and by extension what isn't. Anyone still waiting on a renewal decision, or anyone contemplating a fresh Dutch application through an MGA-licensed entity like the ones Malta Gaming Authority supervises, now knows the bar. Documented remediation for every past breach, or you don't get through.

Platform vendors and B2B suppliers are quietly on the hook too. When an operator has to explain "measures taken to prevent future breaches," a chunk of that answer is usually "we upgraded our platform provider's fraud module" or "we switched KYC vendors." If your product sits inside a Dutch licensee, your roadmap for the next 90 days just got dictated by their renewal file. Expect RFPs for identity verification with liveness detection, cross-product limit orchestration, and unified self-exclusion middleware.

The land-based side is the ugliest. Three venues, three failures, one reporter. The KSA now has a public-interest reason to demand biometric checks at physical entry points, and that's a capex conversation nobody in the Dutch retail casino sector was planning to have this quarter. Expect procurement cycles to compress.

Playbook for iGaming Operators

If you hold a Dutch license, or want one, three things belong at the top of the engineering backlog this week.

First, build the compliance evidence pipeline before you need it. Every self-exclusion check, every KYC decision, every limit enforcement event should be logged with immutable timestamps and queryable by regulator request. The operators who cruised through this renewal are the ones who could produce that evidence on demand. The ones who scramble in 2030 will be scrambling because they treated logging as an afterthought in 2026.

Second, close the identity loop. Document verification without biometric matching is theatre. If your onboarding flow accepts a driver's license photo without a matched selfie and liveness check, you have the same failure mode that Holland Casino's Eindhoven staff had. It's cheaper to fix in the app than at a physical turnstile.

Third, unify the limit engine. If your sportsbook, casino, and poker verticals each maintain their own deposit and loss caps, you have a latent breach waiting to be found. Consolidate to a single wallet-level enforcement service with strong consistency guarantees. Yes, it's a hard migration. It's harder to explain to a regulator why a self-excluded player kept playing because the microservices disagreed about who they were.

For technical standards guidance across those workstreams, groups like the Gaming Technology Association publish useful baseline material, but the real reference is the incident log of the operator across the road from you.

Key Takeaways

  • Eight Dutch operators including Bet365, Holland Casino Online, Betcity, and GG Poker have five more years, running October 2026 to September 2031.
  • The KSA renewal process is a five-year compliance audit, not a form-filling exercise: past breaches and documented fixes are the currency.
  • Holland Casino was renewed while simultaneously under KSA scrutiny for a land-based self-exclusion failure across three venues, proving a license is not absolution.
  • Biometric identity matching (liveness plus photo match) is now the practical minimum for both online onboarding and physical entry.
  • Cross-product limit enforcement and immutable compliance logging should be on every Dutch-facing operator's roadmap before 2027.

Back to the NCT bay. The inspector waved eight cars through this month. The next inspection is in 2031, and the torch will be brighter.

Frequently Asked Questions

Q: Which operators had their Dutch iGaming licenses renewed?

The KSA renewed eight operators: TOTO Online B.V., Holland Casino N.V., Play North Limited (Kansino), FPO Nederland B.V. (FairPlay Casino), Bingoal Nederland B.V., Hillside (New Media Malta) Plc (Bet365), NSUS Malta Limited (GG Poker), and Betent B.V. (Betcity). The renewed licenses run from October 2026 to September 2031.

Q: What did the KSA check before granting renewal?

The regulator reviewed each licensee's non-compliance history over the past five years and required operators to explain the specific measures they've taken to prevent the same breaches from recurring. It's a documented remediation trail rather than a simple form-based reapplication.

Q: Does the Holland Casino self-exclusion incident affect its renewed license?

The license was renewed, but the KSA has said it will take appropriate action following the incident where a self-excluded reporter accessed Holland Casino Eindhoven, Jack's Casino Utrecht, and Casino Be One Rotterdam using a colleague's driver's license. A renewal doesn't immunise an operator against enforcement for fresh breaches.

JO
James O'Brien
RiverCore Analyst · Dublin, Ireland
SHARE
// RELATED ARTICLES
HomeSolutionsWorkAboutContact
News06
Dublin, Ireland · EUGMT+1
LinkedIn
🇬🇧EN