Palmerbet’s BetStop breaches led to 18-month ACMA undertaking after 535 account-closure failures
Palmer Bookmaking Pty Ltd, trading as Palmerbet, has entered an 18-month court-enforceable undertaking with the Australian Communications and Media Authority (ACMA) after an investigation found hundreds of breaches of Australia’s national self-exclusion rules. For high-risk operators, the message is simple: if your account data is wrong, your exclusion controls are wrong too.
- The ACMA’s inquiry focused on a customer who registered with BetStop, the National Self-Exclusion Register (NSER), on 2 September 2023. Once a consumer is registered, wagering operators must close existing accounts “as soon as practicable”. Palmerbet did not close the account until 22 February 2025, nearly 18 months later.
- During that period, Palmerbet accepted bets from the same customer on 18 separate occasions between December 2024 and February 2025. The ACMA identified 18 contraventions of section 61KA(3) of the Interactive Gambling Act 2001 (IGA) for providing licensed interactive wagering services to a self-excluded individual, one for each day of service.
- The regulator also counted 535 contraventions of section 61MB(5) for failing to close the customer’s account “as soon as practicable” after NSER registration. In the ACMA’s reading, the breach continued day by day until the account was finally shut.
- The mechanism failure was basic and expensive: the NSER relies on operators submitting accurate personal details, including full legal name, date of birth (DOB) and postcode, so that customer records can be matched against the register. Palmerbet repeatedly submitted checks using incorrect data, including a shortened first name and an erroneous DOB, which produced negative matches and kept wagering open.
- Records showed Palmerbet first flagged the individual to the database on 6 September 2023 using flawed information. Once the register returned a positive match on 22 February 2025, Palmerbet closed the account. The ACMA said the company failed to take “reasonable precautions and exercise due diligence” in verifying and handling the customer’s identity data.
There is a procedural point here that matters to PSPs, acquirers and partner banks: Palmerbet updated its onboarding procedures in mid-2023 to verify DOB and other details, but those controls were not applied consistently to legacy accounts. The regulator had already issued technical specifications before NSER launched, and repeated the guidance in March 2024.
Weekly high-risk digest
Regulation, sanctions and payment news across your verticals — once a week, free.
Please check your inbox and click the link to confirm your subscription.
Please enter a valid email address!