betting bet sport phone gamble laptop conceptMobile sports wagering may be new to New York state, but privacy and security threats are not. After the law in New York changed in 2021 to permit mobile sports betting, New York sportsbook apps launched early this year and have set records for total sports betting volume. When gambling occurs online, it creates a perfect storm for privacy and security risks. Online betting companies store an immense amount of personal data, some of it very sensitive. Huge amounts of money are transacted. Hackers are drawn by the data, but also by the opportunity to impact the integrity of the betting to rig wagers in their favor or increase their own notoriety in the dark web community. As mobile betting platforms and operators enjoy the influx of New York state bettors, they must be aware of the unique privacy and security challenges they face and of the federal and state regulations that apply to the various categories of data that they process.

|

Intrastate Transactions

The state constitution does not permit gambling except in licensed casinos located in New York state. Accordingly, the law passed in 2021 to allow mobile sports betting (S.B. S2509, 2021 Leg., 2021-2022 Sess., Part Y, §2 (N.Y. 2021)) provides that it is legal so long as the bettor is physically present in New York state at the time of the transaction and all servers of the sports betting platform are physically located in a licensed casino in New York. So, the law limits mobile sports wagering to intrastate transactions. Given the nature of the online ecosystem and the mobility of data, privacy and security laws typically cross state lines. But, somewhat unique to mobile sports betting, the privacy and security laws of New York are the primary compliance focus for operators and platform providers and for the New York state regulators scrutinizing them.

|

Who Is Regulated?

New York has created a complex regulatory framework for mobile sports wagering which regulates "platform providers" and "operators," each of which must satisfy compliance requirements as conditions of licensure. The platform itself is the combination of hardware, software, and data networks used to administer sports wagering and any associated wagers accessible by electronic means. The "platform provider" is the entity responsible for managing the platform that the operators then use to facilitate thousands of wagers per day. An "operator" is the mobile sports wagering skin which has been licensed by the Commission to operate a sports pool through a mobile sports wagering platform.