
Originally Posted by
SlotMonster
When we were "building" our security system, we had to decide how should we store players' data and their documents. We tried to discuss every possible problem or data breach
I'm sure your system is secure, like mine, I wasn't implying this. I can't imagine someone getting hold of a players documents either and this is why I've been discouraging the process of online casino's requesting personal information via unencrypted email , fax and mail. You're obviously on the right track.
I was pointing out the fact that IOM regulations requires you to save this information in your server for a min. of six years, I wouldn't want that no matter how secure the system. Example: If a player opens an account, uploads their doc's to your casino, closes the account you'll still be holding their information for at least six years. UK DSA states - (Where sensitive personal data is concerned, it is particularly important to make sure you collect or retain only the minimum amount of information you need.)
It's the IMO regulation requirement which you can't avoid. So even though you've taken steps to help your staff and player security, I can't support it being done through the casino server.
Under the UK Data Security Act, if a UK player for example asks for an (SAR) subject access request, players can ask to see information being held on computer and some paper forms and I'm assuming servers too. This might cause a problem for you too if people should start asking for information on them being held in your system five or six years down the road.
“The safe way to double your money is to fold it over once and put it in your pocket.”
Bookmarks