“The Site does not present itself as a gambling platform.”Read the operator’s wording ↗
The cost of
proving yourself.
How a skin-gambling service can demand identity and financial records before releasing access to the user’s balance.
CSGORoll asks for identity papers, financial histories and, in some cases, a relative’s documents. Its policy places those records in the hands of its own trained team — and ties refusal to withdrawal delays and account suspension. We follow that claim through the company records, security promises and privacy notices.
The user must expose their identity and finances. The operator offers assurances while retaining the power to withhold access. Its authority, recipients, safeguards and retention rules must withstand the same scrutiny it demands of the user. The policies examined here do not earn that trust.
The “not gambling” claim
and the demand for a financial dossier
The loss of control extends beyond the skin. Once value has entered an outside service, that operator can impose conditions on its release. CSGOFast distances itself from gambling and real-world monetary value; CSGORoll uses internal units with different redemption rules. Their verification policies nevertheless examine the user’s real identity, payment accounts and sources of wealth.
Paid funding, AML demands and a gambling-enforcement history
Fast’s own FAQ describes skin deposits, gift codes and cryptocurrency funding. Its AML policy requests identity and financial evidence. In April 2025, the Dutch regulator ordered Gamusoft LP to stop unlawful gambling offered through csgofast.com; its published record states that the order became final and violations continued.
The monetary-value disclaimer does not describe the whole transaction. The customer pays for a code, transfers cryptocurrency or supplies a skin; the service records a balance and controls its use. Roll’s current terms distinguish ordinary Coins from eligible Roll Chips that can be redeemed in cryptocurrency. These are restrictions on particular units and claims, rather than an absence of payment or economic value. Payment routes and redemption terms ↗
Roll’s AML policy shows how far the operator’s authority over that balance can reach. It allows requests for identity documents and selfies, bank and exchange records, property-sale contracts, wills and a relative’s identity and source of funds. The same policy links missing documents to delayed withdrawals or account suspension. The user is being asked to surrender a personal file whose documented scope runs to fourteen request groups — including a deceased person’s will and a relative’s identity and source of funds — while the operator controls access to the value already inside its system. CSGORoll’s document demands and withdrawal conditions ↗
The operator records credit on its own ledger.
The request can extend to relatives and counterparties.
The operator can delay or suspend access during verification.
The published explanation fails the scrutiny demanded of the user
Roll assigns handling to its own trained team and promises high security standards, but its AML notice supplies no named standard or clear account of who can copy or export the original files. Its separate privacy notice allows sharing with vendors and affiliates without mapping those routes to the KYC records. That notice, revised in August 2026, still names the EU–US Privacy Shield, whose adequacy decision was invalidated in 2020. These are identifiable defects in the assurance offered to the person uploading a passport. Read the policies beside the legal record ↗
Fast’s disclosures create a different set of problems. Its AML and privacy pages display a 2024 update date while naming an Estonian company registered in September 2026. The AML wording pairs that company with UK law and includes unusual attention to the AML policy among suspicion indicators. The operator demands an explanation of the user’s finances while leaving its own identity, version history and asserted legal basis inadequately explained. Named companies and registry records ↗ The legal-basis discrepancy ↗
This is the same dependence revealed by the ownership comparison, extended to another service. The consumer cannot complete the promised exchange solely by owning or sending the skin. They must satisfy a platform that controls the ledger, interprets the rules and can demand further evidence before releasing access.
All fourteen document groups, the entities and the policy defects
Read the source records, withdrawal conditions, data-handling claims and applicable legal tests.
They price the entry.
They police the exit.
A purchased balance, a gambling stake and the asset delivered on withdrawal are different things. The question is concrete: what did the customer surrender, what did the service credit, and what can the customer actually recover?
| Operator / unit | Value entering | What leaves | Identity gate |
|---|---|---|---|
| CSGORollCoins / eligible Roll Chips | Paid Coin top-ups; skin, card, bank, crypto and gift-card routes are documented. [K11] | The FAQ links Coins to CS2 skins and Chips to crypto, and rules out converting Coins into Chips. The terms restrict ordinary Coins’ cash redemption. [K10] [K02] | The FAQ describes a KYC lock after 2,000 Coins in top-ups, plus restrictions on rewards and games. This is broader than a final cash-out check. [K10] |
| CSGOFastCredits / Fast Coins | Skins, partner gift codes, crypto and card-mediated routes. The gift-code purchase happens on a partner’s site. [K43] | The reviewed withdrawal guide describes a skin delivered by another Steam user. Its policy nevertheless denies real-world monetary value to Credits and digital items. [K44] [K07] | The AML notice makes requested data mandatory and connects refusal to delays or ineligibility. It does not supply one universal numerical withdrawal threshold. [K05] |
| CSGOEmpireEmpire Coins | Its terms cover skins, supported crypto and fiat. Its own deposit page directs gift-card buyers to Kinguin. [K36] [K41] | Published routes include skins and crypto. Its help distinguishes skin deposits, which need no wagering for crypto withdrawal, from cash/crypto deposits, where full-deposit wagering is required; skins remain an alternative. [K50] | Current terms and older help describe different 4,500-Coin triggers. Both allow earlier checks. [K36] [K37] Compare the documents ↓ |
A “no monetary value” clause does not erase the payment that bought access. The accountability problem is paid entry, restricted redemption and the operator’s power to demand more evidence while value remains inside the service. The withdrawal asset and contractual promise must be named precisely.
Coins, Credits and Chips are operator-controlled balance units. The Steam WebAPI token examined in the trade-tracking audit is an access credential. Empire explicitly describes gambling; the “not gambling” disclaimers examined here belong to Fast and Roll.
One balance.
Conflicting instructions.
Empire’s rules connect a Steam inventory, an internal balance, cryptocurrency withdrawals and a third-party identity file. The public instructions leave important differences in when verification starts and what happens if the user cannot complete it.
Moonrail
Limited B.V.
Curaçao · company 148182
JHOLT Ltd
Cyprus · HE393291
Named as acting on Moonrail’s behalf. [K41]
Checkin.com
Named in the privacy notice dated 12 February 2025. [K40]
DIFFERENT ACTIVITY COUNTED
Cumulative crypto withdrawals
The help article describes this as the usual trigger, with possible earlier checks. It requests live identity evidence and recent address evidence and names Checkin. [K37]
Cumulative deposits and withdrawals
The terms require verification no later than this combined threshold, allow earlier checks and permit withholding or delaying the affected transaction. [K36]
The scope of the trigger has changed, but both explanations remain public. A customer reading the older help cannot determine the current trigger from that page. Empire should reconcile the guidance, identify the version accepted by the customer and show the transaction calculation behind a hold.
Refuse verification: withdraw, or remain blocked?
The main FAQ says a person who fails or refuses KYC must withdraw the remaining balance and stop using the service. The newer terms permit a hold until verification is complete. These instructions conflict: the FAQ promises a user who fails or refuses KYC withdrawal of the remaining balance and an exit from the service; the newer terms authorise holding that balance until verification is complete. Empire must state which rule governs a refused user’s funds and publish the calculation behind any hold. [K39] [K36]
“Automated verification” still leaves a human and a backup.
The main FAQ names Checkin or Shuftipro, says documents also enter Empire’s own backups, and describes employee review when automated reading fails. The dedicated help names Checkin; the privacy notice names Checkin.com. The record therefore reaches beyond a yes/no verification badge. Who has the original, who can retrieve the backup, and what retention rule applies to each copy? [K39] [K37] [K40]
Empire’s 2025 privacy notice also still cites the invalidated EU–US Privacy Shield among transfer safeguards. That is the same identifiable disclosure defect examined below for Roll. An operator collecting passports must identify the safeguard actually covering the transfer. [K40] [K20]
The payment buys a code.
The operator controls what follows.
This is a documented distribution route. Empire’s redemption page directs buyers to Kinguin. Fast’s help describes payment on a partner’s website followed by code redemption on Fast. [K41] [K43]
These listings identify the seller by the operator’s brand and describe official supply. Kinguin lists PayPal among its methods, with availability dependent on country, currency and cart contents. No checkout was executed here. Empire’s listing excludes activation by US residents, among other territories. [K42] [K45]
The seller, payment recipient and casino operator occupy different roles in the same purchase.
Kinguin’s September 2026 terms identify Kinguin Digital Limited in Hong Kong as the marketplace operator. Payment normally goes to that entity; an alternative recipient, Anton Capitals Limited in Malta, must be disclosed before authorisation and in the payment record. Kinguin generally separates its marketplace role from the seller’s contract. The seller answers for a usable key; complaints about the external service are directed to that service, subject to mandatory consumer rights. [K46]
The receipt should name the legal seller and payment recipient. Connect those identities to the marketplace order, supplied code and credited gambling balance. This is the intermediary structure the investigation asks the participating businesses and payment providers to disclose.
Select where the failure occurs.
Identify who was paid and what was sold.
The record is the product description, legal seller, order, receipt and delivery evidence. PayPal eligibility must be checked separately; a functioning checkout does not itself provide Purchase Protection.
Connect: order ID · legal seller · payment recipient · funding method · delivery status
Match the delivered code to the ledger entry.
Delivery of a valid code and crediting the intended account are separate events. The receiving operator should be able to explain whether redemption occurred, which account received value, and whether the promised amount appeared.
Connect: redemption timestamp · receiving account · credited unit and amount · error or rejection
The code may work while access to value remains blocked.
A later KYC hold concerns the operator’s release decision. Proof that a code was delivered does not establish that this decision was justified. Obtain the accepted policy version, trigger calculation, requested evidence, review deadline and appeal route.
Connect: balance history · payout asset · KYC request · hold decision · final recipient
Analytical map of the separate events and evidence required; no individual payment or dispute outcome is reconstructed here. [K46] [K14] [K38]
PayPal never settles with the casino: the gift code severs direct settlement with the operator’s legal entity.
Under US Purchase Protection, both gift/prepaid value and gambling or entry-fee-and-prize activities are excluded. The code route therefore sits outside those protections; the same policy also excludes the direct gambling transaction. Card-issuer chargeback rights may be broader — but any chargeback also runs against the marketplace’s payment recipient — Kinguin Digital Limited or Anton Capitals Limited — not against the operator, so it cannot restore the severed settlement. [K14] Unauthorised transactions have a separate regime; an authorised purchase followed by a payout dispute does not automatically fall into it. [K47]
PayPal’s US acceptable-use rules require prior approval for relevant stored-value services, gambling facilitation and marketplaces. A voucher does not disclose the approval, merchant classification or settlement agreement. The enforcement question is whether the actual recipient and business activity were correctly disclosed and approved. A payment logo cannot answer it. [K48]
The customer’s payment claim and the operator’s withdrawal decision become separated. The PayPal payment settles with Kinguin Digital Limited — or its disclosed alternative — and never with the casino’s legal entity: direct settlement is severed by design. The merchant and settlement records should show who received the money, who imposed the hold and who can return it.
A deposit address
does not identify its custodian.
There are three separate control questions: who credits the gambling balance, who can sign the blockchain transfer, and who holds the customer’s eventual payout. Calling all three a “wallet” conceals the distinctions that matter.
The operator
controls the release.
Empire’s manual-review help ties crypto withdrawal to verification and account restrictions. This demonstrates platform-level control over release. [K38]
PUBLISHED CONTROLCustody remains
to be attributed.
Fast describes an account-linked USDT deposit address. The investigation’s working attribution — likely not an exchange — stands until Fast and its payment partners name the private-key holder; Fast must disclose who controls the address. [K43]
ATTRIBUTION TASK · LIKELY NOT AN EXCHANGEThe user may hold
an exchange account.
Empire’s July 2023 help explicitly describes withdrawal to the user’s exchange deposit address. Current terms require destination checks. An address associated with a user is not necessarily self-custodied. [K49] [K36]
PUBLISHED DESTINATION OPTIONThe custody map starts with the deposit instruction and address, network, transaction identifier and credited ledger entry. It follows the processor or custodian to the payout and final recipient. Empire, Fast and their payment partners should identify which entity holds signing authority and customer funds at each step, and release the records that connect those responsibilities.
Empire’s current terms permit a payment provider to receive, hold and manage funds. Its default crypto withdrawal rule refers to the original wallet and asset, with verified alternatives. Neither clause names the custodian of a particular deposit address. [K36]
A Steam account restriction answers only part of this chain. It does not, by itself, identify the voucher seller, payment collector, crypto custodian or recipient of the passport. An enforcement account must explain which of those relationships it reaches and what happens to the user’s deposited value. The skin owner, the gambling ledger and the payment business must be traced separately.
“Our specially trained team.”
The AML notice speaks in the operator’s own voice. It gives the document-handling role to its team. It does not identify Sumsub, Onfido or another external verification company as the party performing that role. [K01]
“only handled by our specially trained team, ensuring your privacy and safety at all times”
Highest standards.
Exclusive handling.
Safety at all times.
These are expansive claims about the treatment of intensely personal records. The same section supplies no named security standard, certification scope, independent audit reference or document-retention schedule.
The promise has
no measurable specification.
The AML notice does not explain who can view, copy or export the files, or identify a specific security standard. The privacy notice separately allows sharing with vendors and affiliates without mapping those routes to the KYC documents.
Together, the notices promise safe handling without giving the user a clear account of who holds the originals and who can receive copies.
A payment processor is a different part of the chain.
The privacy notice says a payment processor stores payment data. That sentence does not identify the custodian of passports, selfies, wills or source-of-funds evidence requested under the AML policy. The two data flows need their own explanation. [K03]
A friendly phrase.
A restriction on access.
CSGORoll’s policy softens the consequences with the language of reassurance and a temporary pause. The stated operational consequences are withdrawal delay and possible account suspension. [K01]
or pending withdrawal
The operator decides whether verification is complete.
Verification proceeds
The user has disclosed identity and financial evidence. Release remains subject to the platform’s checks.
Withdrawal delayed
The policy also allows the account to be paused until the issue is resolved.
This reconstructs the published policy’s mechanism. Checks may be requested at different stages; it is not a claim that every user first encounters verification at withdrawal.
The platform controls both the evidence demand and access to the balance. The user’s decision takes place inside that dependency. Calling a hold a pause does not explain the legal basis, the deadline for review, or the route for challenging an excessive request.
Consent cannot be reduced to a forced choice.
Where consent is claimed, the ability to refuse without adverse pressure matters. Where a statutory duty is claimed, identify the law and the processing it requires. The EDPB treats these as different legal bases with different conditions. [K18]
From a passport
to a family’s financial history.
The following inventory covers every document category in the CSGORoll policy supplied for this investigation and checked against the live page. Requests vary by activity; the policy says the list is open-ended and documents may need renewing. [K01]
Passport, selfie, home, payment account
Salary, trading, crypto, property
Donor identity, wills, contracts
01IdentityIdentity and face+
Passport photo pages; driver’s licence front and back; identity card front and back; a selfie with an identity document.
EXPOSURE TO EXAMINEA legal identity and face can be connected to the platform account.
02Residential addressHome and banking+
A bank statement issued within the previous three months, with a card number covered if shown; or a recent utility bill, including gas, electricity, water or council tax. Birth certificates, payslips and mobile-phone bills are not accepted for this purpose.
EXPOSURE TO EXAMINEThe home address can be linked to bank and household-service records.
03Payment-method ownershipCards and accounts+
For bank transfers: a statement showing the transaction. For Visa or Mastercard: photographs of the card’s front and back. For e-wallets: the account overview with personal and account details, plus evidence of at least one transaction with the site; the website URL must be visible.
EXPOSURE TO EXAMINEThe account holder, payment instrument and transaction become part of the same verification file.
04SalaryIncome+
A recent bank statement showing salary received, together with the original payslip.
EXPOSURE TO EXAMINEEmployer, pay and potentially unrelated transactions may be visible.
05Gambling winningsOther gambling activity+
A receipt or bank record for the winnings and a certificate confirming the win.
EXPOSURE TO EXAMINEActivity with another gambling provider can be connected to the person.
06Crypto trading profitExchanges and brokers+
Screenshots of profitable transactions, withdrawal history, or the exchange / broker account showing the user’s details.
EXPOSURE TO EXAMINEAn identified exchange account and its trading or withdrawal history.
07ICO and token salesContracts and wallets+
A contract or agreement confirming crypto payment; the ICO’s full name and project website; purchase and withdrawal histories with wallet addresses and transaction IDs; a bank statement if fiat funded the investment; and purchase-confirmation emails.
EXPOSURE TO EXAMINEThe investment, payment trail, addresses and contractual counterparties.
08MiningEquipment and operations+
Equipment receipts with the buyer’s and seller’s addresses; operating expenses such as electricity bills in the user’s name; mining income or reward screenshots; or wallet transaction histories with addresses and transaction IDs. Self-compiled Excel lists are not accepted.
EXPOSURE TO EXAMINEBusiness equipment, operational location, expenditure and wallet activity.
09AirdropsWallet activity+
Transaction-history screenshots identifying the relevant transfers, wallet addresses and transaction IDs.
EXPOSURE TO EXAMINEA link between the identified person and public transaction history.
10Lending and liquidity poolsCollateral and DeFi+
Transaction-history screenshots with addresses and transaction IDs, plus an explanation of where assets were pledged, the amount and the origin of the collateral.
EXPOSURE TO EXAMINECollateral positions, protocols, amounts and the provenance of the assets.
11Sale of investmentsInvestment holdings+
A bank statement clearly showing the proceeds and a statement from the investment company.
EXPOSURE TO EXAMINEPrior holdings, an investment-provider relationship and sale proceeds.
12Sale of propertyProperty and contracts+
A copy of the sale contract and a bank statement showing receipt of the proceeds.
EXPOSURE TO EXAMINEProperty details, the transaction value and information about other parties.
13InheritanceFamily and estate+
A copy of the deceased person’s will and a bank statement showing receipt of the inheritance.
EXPOSURE TO EXAMINEEstate arrangements and information about relatives or other beneficiaries.
14Gift from a relativeAnother person’s identity+
A donor’s letter explaining the reason, date and amount of the gift and the source of the donor’s funds; documents confirming the donor’s identity; and supporting evidence for the donor’s funding source.
EXPOSURE TO EXAMINEThe request reaches beyond the player to another person’s identity and finances.
An identity record becomes a financial dossier.
Identity images, proof of address, account ownership and transaction histories can be linked to one person. A will or family-gift file extends that exposure to people who may never have used the site. Bank and exchange records can reveal counterparties and activity unrelated to the deposit being checked.
Copies of identity and financial documents create a risk of impersonation and attempted reuse elsewhere. The operator should disclose access logs, export restrictions, recipients and deletion controls. Its broad document demands put the customer’s identity at risk; its public assurances should account for the protection actually applied to those copies.
The policy explicitly asks for photographs of both sides of a payment card. It tells users to hide a card number appearing on a bank statement, but supplies no equivalent masking instruction alongside the card-photo request. That omission matters because the requested image can expose security details unnecessary to demonstrate ownership of the payment method.
A selfie raises an additional question about processing.
A document photograph is personal data. If a face is technically processed for unique identification, the biometric-data conditions become relevant as well. The operator should disclose whether it creates a face template, runs liveness or matching, and retains the result or the original image. [K26]
The brand is not
the legal identity.
These are the entities identified by the reviewed public documents. Operator, payment handler and data controller must be mapped to the particular transaction and document request.
Max Stacks Limited
- Published registration
- C 64304
- Published address
- Unit 207, Heritage Plaza II, Main Street, Charlestown, Nevis
- Payment entity
- Feral Entertainment (Cyprus) Limited · HE388908
- Document role
- AML page: the operator’s specially trained team.
Privacy introduction: CSGORoll / Max Stacks Limited.
The terms identify the contracting company and say some payments may be handled by the Cyprus entity. The KYC file needs a corresponding, explicit responsibility map. [K02] [K03]
Lumigrid OÜ
PAYPLAYSOFT LIMITED
- Estonian entity
- Lumigrid OÜ · 17589540
Vesivärava tn 50-201, Tallinn, 10152 - Cyprus entity
- PAYPLAYSOFT LIMITED · HE454356
Boumpoulinas 1–3, Office 42, Nicosia, 1060 - Document role
- The privacy notice says either company may be the service provider and/or controller, depending on the service, payment flow, region or operation.
That conditional wording leaves the person uploading a passport without a definite controller for their particular flow. A list of possible companies does not identify who is accountable for that file. [K05] [K06]
Company registration
does not establish a gambling licence.
The reviewed EMTA gambling-operator list contains no match for Lumigrid, CSGOFast, PAYPLAYSOFT or Gamusoft. Separately, Lumigrid’s company registry card records incorporation on 2 September 2026 and advertising as its principal activity. Its zero MTR entries are company-register detail, rather than the gambling-permit test. [K08] [K09]
The official EMTA list of legal gambling operators contains no entry for Lumigrid, CSGOFast, PAYPLAYSOFT or Gamusoft: no Estonian gambling permit is on record for the named service. A company registration is no substitute for a permit identifying the entity, domain, authorised activity and current validity.
Specific discrepancies.
Identifiable sources.
The findings below concern published wording, dates and official records. They do not depend on accepting the operators’ security assurances.
invalidated by the CJEU
still names Privacy Shield
privacy revision year
company those pages name
- 01
CSGOROLL / HANDLING CLAIM
Exclusive team handling; broader sharing elsewhere.
The AML page assigns handling to its trained team. Its privacy notice permits multiple categories of recipients, including vendors and affiliates. The reassuring AML promise leaves the reader without a clear account of which sharing routes apply to the passport and financial file. [K01] [K03]
- 02
CSGOROLL / TRANSFER SAFEGUARDS
A 2026 notice still lists Privacy Shield.
The privacy page is marked revised 1 August 2026 and still lists the EU–US Privacy Shield as an example of an approved transfer safeguard. The CJEU invalidated that adequacy decision on 16 July 2020. The later EU–US Data Privacy Framework is a different mechanism. Naming an invalidated framework in a 2026 notice is a concrete failure of the published assurance. The operator still owes users the valid safeguard covering their transfer. [K03] [K20] [K21]
- 03
CSGOROLL / ACCESS TO THE NOTICE
The terms’ privacy link resolved to the FAQ.
On this review, the privacy URL incorporated by the terms,
/en/info/privacy-statement, redirected to/info/faq/. The separate/info/privacy-policy/page was accessible and is the notice analysed here. The redirect and response hashes are recorded. [K02] [K04] - 04
CSGOFAST / VERSION HISTORY
A 2024 revision date names a company formed in 2026.
The AML and privacy pages name Lumigrid OÜ while displaying 10.11.2024 as their last-update date. The official registry dates the company’s registration to 2 September 2026. A 2024 revision label cannot account for the introduction of a company formed in 2026. The displayed history fails to tell users when their purported controller changed. [K05] [K06] [K08]
- 05
CSGOFAST / LEGAL BASIS
The Estonian company is paired with UK law.
Section 2.1 of the AML policy assigns Cyprus law to PAYPLAYSOFT and United Kingdom law to Lumigrid. The introduction identifies Lumigrid as Estonian. The policy also invokes an EU AML directive and public-interest processing. It does not explain the UK connection or identify the national provision imposing the relevant duty on this Estonian operator. [K05]
- 06
CSGOFAST / SCRUTINY OF THE POLICY
Attention to the AML policy is itself a suspicion indicator.
Section 4 includes unusual attention to the companies’ AML policy among examples of suspicious activity. The policy turns scrutiny of its own authority into a suspicion indicator. A user challenging a passport demand is entitled to a reasoned explanation; the operator’s wording creates pressure in the opposite direction. [K05]
- 07
BOTH OPERATORS / LIFE OF THE FILE
The notices do not explain the life of the KYC file.
Both notices give general retention criteria without clearly applying them to the identity images, financial evidence and family documents requested in these checks. The reader cannot identify which event starts retention for this file, which duty determines its duration, or when the originals and backups will be deleted. [K03] [K06]
CSGOFast’s notice claims encrypted transmission and storage and agreements with processors. Those statements do not name the actual custodians, access arrangements or retention implementation — CSGOFast must disclose them. [K06]
Who imposes the duty?
Who supervises its use?
There are three distinct issues: the company’s existence, permission to offer the relevant service, and the lawful basis for each data-processing activity. A registration number or an AML heading cannot settle all three.
Name the law. Show the connection.
The EDPB requires a legal obligation to be imposed on the controller by applicable EU or national law, with a defined processing purpose. Public-interest processing also needs a basis in law. A private notice cannot create that authority simply by declaring the activity to be in the public interest. [K18]
Estonia’s AML Act identifies categories of obliged entities, including gambling operators, and provides rules for diligence, record keeping and supervision. The missing link in CSGOFast’s notice is a precise explanation of which category, national provision and supervisor applies to each named company and service. [K27]
A separate assessment is required for collection based on fraud prevention or another claimed interest: purpose, necessity, proportionality and the person’s rights. Requesting a document and retaining its full original are separate decisions that each need justification.
The party deciding why
the file is collected is accountable.
A controller determines the purposes and means; a processor acts on its instructions. For the promise under review, the immediate question concerns CSGORoll’s own team. If a third party also participates, its role and access must be explained. Outsourcing does not remove the controller’s responsibility. [K19]
Readers should be able to establish the purposes and legal basis, relevant recipients, retention period or meaningful criteria, rights and transfer safeguards. These are substantive transparency requirements. [K22] [K23]
There are named regulators.
There are recorded actions.
CSGORoll / Feral Holdings Limited
ACMA announced a formal warning for prohibited interactive gambling services and said the site had withdrawn from Australia. Its reasoning expressly addressed skins and their conversion through third-party markets. [K16]
CSGOFast / Gamusoft LP
ACMA’s quarterly record lists a formal warning to Gamusoft LP for providing CSGOFast as a prohibited interactive gambling service. [K17]
CSGOFast / Gamusoft LP
Ksa ordered the unlawful offer to Dutch players to stop, backed by €280,000 per week up to €840,000. Its page records that the decision became final and that follow-up checks found continued violations with penalties incurred. [K24]
These gambling-enforcement records are dated, public and final where recorded. No regulator has yet adjudicated the AML document-handling examined here — the operators’ own notices are the record of it, and they are the parties who must disclose the handling, access and retention logs.
Protection follows the processing.
GDPR scope covers processing in the context of an EEA establishment and can reach non-EEA operators targeting people in the EU or monitoring their behaviour there. Relevant establishment and targeting facts matter. Where GDPR applies, disclosure to another organisation outside the EEA also engages the international-transfer rules. The applicable safeguard must be explained alongside the basis for collecting the data. [K28] [K23]
Data-protection oversight is distinct from gambling licensing. Estonia’s Data Protection Inspectorate and Cyprus’s Commissioner for Personal Data Protection are listed by the EDPB; individuals can identify the authority relevant to their circumstances through that directory. [K29]
Identify the applicable protection.
State, residency and business-scope rules need to be checked. For example, California’s CCPA grants rights to California residents against covered businesses, including notice and access rights. US citizenship alone does not identify one universal KYC-storage regime. [K30]
The operator should specify the protections applicable to the person’s records, the responsible entity and the complaint route. An offshore address does not answer those questions.
Make the handling
of identity inspectable.
The investigation asks for concrete records about authority and control. The user’s willingness to upload a passport cannot substitute for those records.
- Identify the controller for each flow.Which legal entity receives the identity file, payment-ownership evidence and source-of-funds material? Explain any joint responsibility.
- Identify the actual legal duty.Give the national law, relevant provision, obliged-entity category, regulated service and competent supervisor. Explain the UK-law references for Lumigrid.
- Justify each requested field and original.Explain why age confirmation, a redacted statement or a verified result is insufficient in that case. Address donor information and unrelated counterparties.
- Explain who handles the files.Name service providers and their roles; identify which staff groups can view, download, export or forward originals and how access is reviewed.
- Describe storage and transfers.Give hosting and support-access countries, encryption and key-management responsibilities, current transfer mechanisms and onward recipients.
- Set out retention and deletion.Provide periods or meaningful criteria for originals, extracted fields, biometric outputs, logs and backups; explain legal holds and deletion verification.
- Explain the withdrawal hold.State the trigger, scope, review deadline, proportionality assessment, appeal route and treatment of unused value when a document request is contested.
- Make the security promise testable.Identify the standard, certification scope and independent assurance available to users; explain incident response and protection against document reuse.
- Account for earlier operators and policy versions.Provide revision dates, notices of controller changes, transfers of historical KYC files and the duties retained by each entity.
- Map the payment counterparty.For direct payments, crypto and vouchers, identify the legal seller, recipient, processor and applicable refund or dispute route.
The internal currency is the operator’s label. The exposure belongs to the user. Real assets enter the service; real passports, bank records and family documents can be demanded. The operator can hold access while its own published account of authority and handling remains defective. That imbalance is the central finding, and a security promise does not resolve it.
What was checked.
Public operator policies, company and regulator records, product listings and payment rules were reviewed on 10 October 2026. No identity documents were uploaded, no user account was verified and no payment or withdrawal was attempted. Internal storage, staff access, vendor contracts and production data transfers were not inspected.
Findings about omissions are scoped to the reviewed documents. Potential identity reuse is examined as a risk and a demand for controls, rather than an attributed incident. The linked evidence record contains source URLs, retrieval times, response hashes and the registry-name search result. Hashes identify the downloaded responses, including changing page content; they are not security certifications.
11 October 2026 addition: Empire’s published rules, balance units, gift-code counterparties, PayPal US terms and wallet-custody questions were checked separately. Direct public responses were retained where accessible; Empire policies were also read through indexed primary-source pages where direct requests returned 403. The retained record covers the published arrangements, policy versions, named counterparties and available wallet-custody statements. Read the added source record ↗
Read the underlying record.
Operator statements establish what the operator publishes. Registry and enforcement records establish their own dated findings. Legal guidance explains the standards used to assess the disclosure.
- K01User Verification and Security / AML policy ↗PRIMARY SOURCE · CSGORoll
Operator policy; document categories also supplied by the investigator.
- K02Terms of Service — effective 12 August 2026 ↗PRIMARY SOURCE · CSGORoll
Published entities, balances, verification powers and incorporated policy URL.
- K03Privacy policy — revised 1 August 2026 ↗PRIMARY SOURCE · CSGORoll
Recipient categories, payment-data wording, retention criteria and transfer safeguards.
- K04Privacy URL incorporated by the terms ↗PRIMARY SOURCE · CSGORoll
Resolved to the FAQ during the recorded HTTP retrieval.
- K05AML-CFT policy — displayed date 10.11.2024 ↗PRIMARY SOURCE · CSGOFast
Reviewed sections 1, 2.1, 4, 6, 7 and Annex 1.
- K06Privacy policy — displayed date 10.11.2024 ↗PRIMARY SOURCE · CSGOFast
Conditional controller identity, claimed safeguards and retention criteria.
- K08Lumigrid OÜ — registry code 17589540 ↗PRIMARY SOURCE · Estonian e-Business Register
Official registration date, principal activity and MTR counts, reviewed 10 October 2026.
- K09List of legal gambling operators ↗PRIMARY SOURCE · Estonian Tax and Customs Board
Official list and explanation of operating permits; name search recorded.
- K16Action against CS:GO Roll / Feral Holdings — 17 May 2023 ↗PRIMARY SOURCE · ACMA
Australian enforcement announcement, including the role of skins and youth-market concern.
- K17Interactive gambling enforcement — April to June 2025 ↗PRIMARY SOURCE · ACMA
Quarterly record lists CSGOFast / Gamusoft LP.
- K18Process personal data lawfully ↗PRIMARY SOURCE · European Data Protection Board
Official explanation of legal obligation, public interest, consent and necessity.
- K19Data controller or data processor ↗PRIMARY SOURCE · European Data Protection Board
Roles, contracts, responsibilities and continuing controller accountability.
- K20Schrems II — judgment announcement, 16 July 2020 ↗PRIMARY SOURCE · Court of Justice of the European Union
Invalidation of the EU–US Privacy Shield adequacy decision.
- K21EU–US data transfers ↗PRIMARY SOURCE · European Commission
The later Data Privacy Framework and current transfer arrangements.
- K22Respect individuals’ rights ↗PRIMARY SOURCE · European Data Protection Board
Transparency, access, recipients and retention information.
- K23International data transfers ↗PRIMARY SOURCE · European Data Protection Board
Transfer mechanisms and safeguards for data leaving the EEA.
- K24Gamusoft LP — order dated 16 April 2025 ↗PRIMARY SOURCE · Kansspelautoriteit
Official Dutch order page, finality and enforcement follow-up.
- K26Biometric-data definition — paragraphs 312–313 ↗PRIMARY SOURCE · Supervisory-authority decision, hosted by EDPB
Distinction between ordinary photographs and specific technical processing for identification.
- K27Money Laundering and Terrorist Financing Prevention Act ↗PRIMARY SOURCE · Riigi Teataja / Riigikogu
Official English text; obliged entities, preservation of data (§47) and supervision.
- K28Guidelines 3/2018 on territorial scope ↗PRIMARY SOURCE · European Data Protection Board
Establishment, targeting and location criteria under Article 3.
- K29Members — national supervisory authorities ↗PRIMARY SOURCE · European Data Protection Board
Official directory including Estonia and Cyprus.
- K30Frequently Asked Questions ↗PRIMARY SOURCE · California Privacy Protection Agency
California residents, covered businesses and applicable privacy rights.
- K07Responsible Play Policy ↗PRIMARY SOURCE · CSGOFast
Operator identity and the stated treatment of Credits and digital items.
- K10FAQ — balances, KYC and P2P settlement ↗PRIMARY SOURCE · CSGORoll
Coins / Chips distinction and published platform trading rules.
- K11What Payment Methods do we Accept? ↗PRIMARY SOURCE · CSGORoll Help Center
Payment-method list, dated 21 July 2026.
- K12CSGORoll 1 Coin Gift Card ↗PRIMARY SOURCE · Kinguin
Marketplace listing and displayed seller name; no test purchase.
- K13CSGOFAST 10 Fast Coins Gift Card ↗PRIMARY SOURCE · Kinguin
Marketplace listing and displayed seller name; no test purchase.
- K14Purchase Protection Program ↗PRIMARY SOURCE · PayPal US
Gift-card / gaming exclusions and separate card-issuer dispute provisions; US terms.
- K36Terms of Service — 6 October 2026 ↗PRIMARY SOURCE · CSGOEmpire
Deposits & Withdrawals §§11–12; KYC; trading; payment-provider authority. Published rules, not verification of implementation.
- K37KYC checks — 13 February 2025 ↗PRIMARY SOURCE · CSGOEmpire Help Centre
Older crypto-withdrawal threshold, identity/address evidence and Checkin processing.
- K38Account under manual review — 13 February 2025 ↗PRIMARY SOURCE · CSGOEmpire Help Centre
Withdrawal restrictions for verification and unwagered cash/crypto funding, including gift codes.
- K39Main FAQ / About ↗PRIMARY SOURCE · CSGOEmpire
KYC-refusal exit wording, named providers, operator backups and manual document review. Undated live page.
- K40Privacy policy — 12 February 2025 ↗PRIMARY SOURCE · CSGOEmpire
Checkin.com recipient, retention and transfer wording including Privacy Shield.
- K41Kinguin gift-card purchase and redemption page ↗PRIMARY SOURCE · CSGOEmpire
Operator-endorsed purchase route and footer entity disclosures. No code entered or checkout attempted.
- K42CSGOEmpire 100 Coin Gift Card — listing 90693 ↗PRIMARY SOURCE · Kinguin
Seller label, official-publisher claim and territory restrictions; listing excludes US residents. No transaction.
- K43FAQ — balance funding ↗PRIMARY SOURCE · CSGOFast
Partner vouchers, skin deposits, crypto/card routes and account-linked USDT deposit addresses; does not identify key custody.
- K44How to make a withdrawal? ↗PRIMARY SOURCE · CSGOFast
Operator description of user-to-user skin delivery. Its older trade-ban wording is not relied on here.
- K45Which payment methods does Kinguin accept? ↗PRIMARY SOURCE · Kinguin Support
PayPal listed; availability depends on billing country, currency and cart contents.
- K46Terms and Conditions v1.3 — September 2026 ↗PRIMARY SOURCE · Kinguin
§§1.10, 2.2–2.3.3 and 5.2.1–5.2.4: operator, seller, external service and payment collection; mandatory consumer rights retained.
- K47User Agreement — 14 September 2026 ↗PRIMARY SOURCE · PayPal US
US account terms; Liability for Unauthorized Transactions and Other Errors. Separate from Purchase Protection.
- K48Acceptable Use Policy ↗PRIMARY SOURCE · PayPal US
Activities Requiring Approval: stored-value services, gambling facilitation and marketplaces. No merchant-specific approval was obtained.
- K49How do I sell my crypto? — 20 July 2023 ↗PRIMARY SOURCE · CSGOEmpire Help Centre
Published example of payout to a customer’s exchange deposit address.
- K50Do I need to wager to withdraw? (Crypto) — 27 November 2023 ↗PRIMARY SOURCE · CSGOEmpire Help Centre
Different payout conditions for skin-funded and cash/crypto-funded balances; compared with current Trading terms.
Funding routes, account restrictions and what the public totals leave out.