GGL collected player data for years. Why wait until 2027?

Germany’s gambling authority has built a system capable of following the regulated online activity of millions of registered players. It has required licensed operators to connect their systems, transmit information and maintain Safe Servers so that supervisors can inspect the market electronically. Now the GGL says the decisive analytical step is still ahead.
In a 21 July announcement about the further development of LUGAS, the authority stated that evaluations will be based more extensively on Safe Server data from 2027. The same announcement says LUGAS processed data connected to more than 60 permitted gambling providers and approximately five million registered players during 2025.
Those two statements do not sit comfortably together. The GGL has administered the Safe Server evaluation systems and central databases since 1 January 2023, while Dataport has operated them. If Safe Server data will only become a stronger basis for evaluation in 2027, Germany deserves a precise account of what has been collected, what has been analysed and what supervisory decisions those data have produced during the intervening years.
The announcement does not say that Safe Server information has never been used. It says its use for evaluations will increase, which is an important distinction. It is still a remarkably late milestone for an infrastructure presented as the central data foundation of German online gambling supervision.
The law promised control at any time
The Safe Server was not designed as a future research project. Germany’s official explanation of the Glücksspielstaatsvertrag 2021 says operators of sports betting, online casino games, online poker and virtual slot games must operate a technical system recording all data required for gambling supervision. The stated purpose is to enable electronic control by the responsible authority at any time.
That language is much stronger than the cautious timetable now being described. “At any time” suggests an operational supervisory instrument, not a reservoir of information whose more extensive analytical value will emerge six years after the treaty entered into force and four years after the GGL took full control of the system.
LUGAS combines two different functions. Its central limit and activity files enforce cross-provider deposit limits and prevent parallel play across participating platforms. The Safe Servers sit on the operators’ side and are intended to preserve the detailed information required for regulatory inspection and analysis.
The distinction matters because a central file can block an action in real time without proving that the authority is using the wider Safe Server record to recognise patterns, compare operators or test whether player-protection duties are working. Germany can therefore operate a technically intrusive control mechanism while still falling short of genuinely data-led supervision.
Five million registrations deserve more than a press release
The GGL’s new figure is substantial. LUGAS handled information relating to around five million registered players in 2025 alone. The authority does not explain in the announcement whether that means five million unique individuals, five million pseudonymous records or another measure affected by multiple registrations across operators.
That missing definition is not a minor statistical detail. A system designed around cross-provider activity must be exceptionally clear about how identities, pseudonyms and multiple accounts are counted. Otherwise, the headline figure sounds impressive without telling the public how many people were actually represented or how completely their activity could be assessed.
The GGL tells players that the LUGAS limit and activity files determine whether cross-provider limits have been reached and whether a person is already active elsewhere. Operators and players therefore experience the system as an immediate regulatory reality. The analytical results generated from the broader dataset are far less visible.
The public record does not identify how many supervisory investigations in 2023, 2024 or 2025 began with a Safe Server alert or analytical comparison. It does not disclose how many operators supplied defective data, how long corrections took, how many material anomalies were found or how often Safe Server evidence led to sanctions, licence conditions or formal interventions.
A regulator can reasonably withhold details that would reveal investigative methods or personal information. Aggregate reporting would not create that problem. Numbers showing data-quality failures, completed analyses and regulatory actions could be published without identifying a single player or compromising an active case.
The GGL has been promising better use for two years
The 2027 timetable becomes more difficult to defend when compared with the authority’s earlier statements. In its June 2025 presentation of the 2024 activity report, the GGL said the use of Safe Servers would be developed further during 2025 to improve supervision and enable more precise monitoring.
One year later, the GGL’s report on its 2025 activities described the enforcement of mandatory and correct Safe Server use as an arduous process. It said better data quality was necessary to create a reliable and comparable basis for supervision, analysis and future regulatory decisions.
The sequence is revealing. In 2025, the authority planned to develop more precise supervision through Safe Server use. In its review of that year, it acknowledged continuing difficulties with correct use and data quality. In July 2026, it announced that evaluations would rely more strongly on the data from 2027.
This does not prove that the system failed or that the GGL neglected its duties. It establishes that a central pillar of the regulatory model has taken years to reach the level of data quality and analytical use the authority itself considers necessary. That should be stated plainly rather than dressed up as routine digital progress.
Licensed operators carried the burden immediately
The long implementation period has not been neutral for the regulated market. Licensed operators had to build interfaces, adapt account processes, transmit data and maintain the required infrastructure while continuing to comply with the central limit and activity controls. The GGL’s technical access page for LUGAS makes clear that connection is embedded in the licensing and testing process.
The authority also publishes a dedicated LUGAS download area containing connection documents, access declarations, central-file pricing and data-protection information. This is not a theoretical regulatory aspiration. It is an operational and financial requirement imposed on every participating legal business.
That creates an accountability imbalance. Operators must supply the infrastructure and information according to technical requirements that are not fully public, yet the authority provides very little public evidence showing how effectively the resulting information is converted into supervision. The market is measured continuously while the performance of the measuring authority remains largely unmeasured.
The GGL may have legitimate security reasons for restricting publication of technical specifications. It may also be conducting analyses that are not described individually because they form part of confidential supervisory work. Neither explanation prevents the publication of aggregated performance data, implementation milestones and independent audit findings.
Dataport’s role also needs measurable accountability
Dataport is the central public-sector IT provider operating the Safe Server evaluation systems and LUGAS central databases for the GGL. The authority describes LUGAS as one of the most demanding digital projects in the regulatory environment and calls it security-critical. Those descriptions increase the need for measurable assurance rather than reducing it.
The July announcement contains no information about system availability, processing delays, security audits, incidents, recovery testing or service targets. It does not state the cost of operating or expanding LUGAS, the duration of the arrangement with Dataport or the standards against which performance is assessed.
There is no basis in the published material to conclude that Dataport has performed poorly. The problem is that the public is offered praise from both organisations without the figures needed to evaluate the relationship. A system handling market-wide regulatory information should not be judged through mutual statements of confidence alone.
Germany would never accept an operator saying its compliance technology is reliable simply because its own supplier agrees. Regulators expect documentation, testing and evidence. The same standard should apply when the infrastructure belongs to the regulator and the supplier belongs to the public sector.
The 2026 treaty evaluation cannot wait for 2027 data
The timing creates a second problem. Germany is already evaluating the Glücksspielstaatsvertrag 2021, including the effectiveness and practicality of its player-protection measures. The GGL says the results will inform the treaty evaluation and the next licensing cycle beginning in 2027.
A serious evaluation should be based on evidence generated during the existing regulatory period. If the Safe Server data become a materially stronger analytical source only from 2027, they arrive too late to provide a mature longitudinal basis for decisions that must be prepared before or during that same year.
The GGL’s 2025 activity report says it wants a reliable and comparable dataset for future regulatory decisions. That wording exposes the difficulty. Germany has already made consequential decisions on licensing, limits, product design and supervision while the authority was still working towards the data quality it now says those decisions require.
This does not invalidate every earlier decision. It does mean the government and the 16 states should separate rules supported by observed outcomes from rules defended mainly through regulatory assumptions. LUGAS was supposed to give Germany an evidential advantage. That advantage is diminished if the data reach full analytical usefulness only as the first regulatory cycle is ending.
What the GGL should publish before 2027
The GGL does not need to expose personal records or reveal confidential enforcement techniques. It should publish a clear annual LUGAS performance statement explaining the scale, quality and regulatory use of the information under its control.
That statement should define the five million figure and distinguish unique individuals from registrations, accounts and pseudonymous records. It should identify how many permitted providers transmitted complete Safe Server datasets, how many required correction and how long remediation took.
The authority should also report how many aggregate analyses were completed, which regulatory questions they addressed and how many supervisory procedures were initiated or materially supported by the results. Availability, incident and recovery figures should be published for the central systems operated by Dataport, together with the cost of operation and development.
None of this would weaken player protection. It would show whether the machinery built in its name is doing more than processing transactions and enforcing limits. Germany has required the licensed market to prove its compliance continuously. The authority should be able to prove the effectiveness of its own central instrument at least once a year.
Our final thoughts and conclusion
The evidence establishes that LUGAS is large, mandatory and central to Germany’s regulatory model. It processed information connected to approximately five million registered players and more than 60 permitted providers in 2025. The Safe Server evaluation systems and central databases have been under GGL administration and Dataport operation since January 2023.
The evidence does not establish that the GGL ignored Safe Server data or failed to conduct meaningful supervision. Its latest wording is nevertheless damaging because it confirms that stronger reliance on those data for evaluation remains a future milestone. Earlier reports also show that correct operator use and sufficient data quality were still unresolved implementation problems years after the system became mandatory.
Germany did not build LUGAS merely to collect data. It built the system to control a national online gambling market, test compliance and support decisions with evidence. A regulator cannot celebrate the scale of the database while remaining vague about the regulatory results extracted from it.
The GGL should publish what Safe Server analysis has achieved since 2023 before presenting 2027 as the beginning of a more data-driven phase. If the answer is that data quality delayed the programme, that should be explained. If extensive analysis has already taken place, the aggregate outcomes should be visible.
Until then, the public is left with an uncomfortable picture. Licensed operators and millions of players entered Germany’s central surveillance architecture years ago, while the regulator is still describing fuller analytical use as the next stage. The data arrived on time. Public accountability has not.
Principal sources
The principal sources are the GGL’s 21 July 2026 LUGAS and Dataport announcement, its explanations of the Glücksspielstaatsvertrag and mandatory IT systems and its LUGAS technical-access and download pages. The analysis also uses the GGL’s published summaries of its 2024 and 2025 activity reports.
All principal online sources are embedded as clickable hyperlinks in the article text. No private correspondence, interested-party submission or unverified operator allegation has been used as evidence.
Evidence notes for editorial review for future articles
Established facts
The GGL says LUGAS processed data from more than 60 permitted providers and approximately five million registered players during 2025. It also says the Safe Server evaluation systems and central files have been administered by the GGL and operated by Dataport since 1 January 2023.
The authority stated on 21 July 2026 that evaluations will be based more extensively on Safe Server data from 2027. Its 2025 activity report separately acknowledged that enforcing mandatory and correct Safe Server use remained demanding and that better data quality was necessary.
Disputed or qualified claims
The available material does not establish that Safe Server data were unused before 2027. The phrase “more extensively” indicates an increase in reliance rather than a completely new start.
The public material does not establish technical failure, unlawful data handling or poor performance by Dataport. It establishes a lack of published metrics sufficient for an external assessment of performance and regulatory impact.
Reasonable inferences
The GGL’s sequence of statements indicates that the Safe Server component has taken longer to become a reliable and comparable analytical instrument than the original promise of anytime electronic supervision might suggest. The absence of aggregate outcome data prevents the public from measuring how much supervisory value has already been delivered.
The 2027 timetable risks limiting the usefulness of mature Safe Server analysis for the current evaluation of the Glücksspielstaatsvertrag and preparation of the next licensing cycle. That consequence depends on how much analysis has already occurred but not been publicly described.
Unanswered questions
The GGL has not publicly defined whether the five million figure represents unique people, player registrations, accounts or pseudonymous records. It has not published the number of incomplete datasets, corrections, Safe Server-led investigations or regulatory interventions arising from the system.
The July announcement does not disclose LUGAS costs, availability, incident statistics, independent audit results or service targets for Dataport. It also does not explain which additional evaluations will begin in 2027 and which analyses are already performed today.
FAQs
What is GGL?
The GGL (Gemeinsame Glücksspielbehörde der Länder) is Germany's national gambling regulator responsible for supervising licensed online gambling operators and enforcing gambling regulations.
What is LUGAS?
LUGAS is Germany's central gambling monitoring system that manages deposit limits, player activity checks and regulatory oversight across licensed online gambling operators.
Why is GGL's 2027 announcement attracting attention?
The announcement states that Safe Server data will be used more extensively for evaluations from 2027, despite the system collecting data since 2023.
How many players were covered by LUGAS in 2025?
According to GGL, LUGAS processed information relating to approximately five million registered players and more than 60 licensed gambling providers during 2025.
What are Safe Servers?
Safe Servers are operator-managed systems that store detailed gambling data required for regulatory inspections and market analysis by the GGL.
What concerns does the article raise?
The article questions why broader analytical use of Safe Server data is only planned for 2027 when the infrastructure has existed and collected information for several years.
Does the article claim that GGL failed to supervise the market?
No. The article explicitly states that there is no evidence showing GGL ignored Safe Server data or failed to perform meaningful supervision.
What role does Dataport play?
Dataport operates the Safe Server evaluation systems and LUGAS central databases on behalf of the GGL.
Why is data transparency important?
The article argues that publishing aggregated performance metrics would improve public accountability without compromising investigations or player privacy.
What does the article recommend before 2027?
It recommends that the GGL publish annual reports covering data quality, completed analyses, regulatory outcomes, system performance and operational transparency before expanding evaluations in 2027.
Related Posts

Lotto BW used the World Cup to promote online slots
July 24, 2026












































