The organisation should perform risk assessments that to identify which player PII and sensitive account information must be treated as confidential and protected from unauthorised disclosure.
The procedures should cover information such as player account balances, credited or debited funds, amounts wagered, account numbers, authentication credentials, names, addresses, and other information that could identify the player.
Confidential player information should only be accessed or disclosed where permitted by the privacy policy, required by law, or required by the regulatory body.