Dutch licence renewals 2026: the affordability questions operators are asking

The first five-year online gambling licences issued in the Netherlands are expiring. Holland Casino, Bingoal, and TOTO Online have already secured renewals. For the remaining operators – including BetCity, bet365, Kansino, and Fair Play – licences begin lapsing on a rolling basis from 1 October 2026, depending on when they were originally granted.

Dutch regulator, the Kansspelautoriteit (KSA), designed the five-year term so it could use its supervisory experience to inform renewal decisions. This intention has been proved out, as the compliance landscape has changed considerably since licences were first issued in 2021.

The questions operators are actually asking

The renewal process itself is well documented – the KSA’s own guidance and several Dutch law firms cover the procedural steps in detail. What we find is that operators preparing for renewal tend to have a different set of questions: not “what do I need to submit?” but “can my compliance stack actually meet the standard the KSA is now setting?” – and specifically, can it do so without adding friction that drives players to the grey market.

That’s the problem Yaspa’s Intelligent Payments platform is designed to solve. It combines instant Pay by Bank deposits with AI-powered financial intelligence. When a player deposits via Yaspa, they connect their bank through open banking – and with the player’s consent, Yaspa analyses live transaction data to verify income, classify spending, calculate affordability, and surface gambling activity, all in real time and embedded in the payment flow. No separate compliance tool, no document uploads, no interruption to the player journey.

Below, we answer the questions Dutch operators ask us most often about how this works in practice.

What’s happening with gambling regulation in the Netherlands?

The KSA opened its renewal application procedure on 1 December 2025. Not all operators entered the market at the same time, so expiry dates vary – Jacks.nl has until 20 November 2026, 711 until 16 March 2027, and Unibet (FDJ United) until 8 June 2027.

Renewal is not automatic. Operators must submit a new application under the Remote Gambling Policy Rules 2026 (Beleidsregels vergunningverlening kansspelen op afstand 2026 [Remote Gambling Licensing Policy Rules 2026]), which introduced several new requirements from 1 January 2026: a mandatory exit plan, a change notification document, and a risk analysis on AML/CTF compliance under the Wwft (Wet ter voorkoming van witwassen en financieren van terrorisme [Anti-Money Laundering and Anti-Terrorist Financing Act]). The application fee rose to €61,300 from 1 April 2026.

For renewal applicants specifically, the KSA reassesses duty of care policies, advertising compliance, and CDB (control database) integration – including a fresh technical test. Any breaches or shortcomings over the past five years must be disclosed and explained. Operators must show how they’ve learned from mistakes. At a closed-door session in October 2025, the KSA told operators it would strive to make the process smooth – but acknowledged that the raised bar on responsible gambling and operational transparency adds real complexity.

The wider market context matters too. The gambling tax has risen from 30.5% to 37.8%, advertising restrictions have tightened year on year, and the KSA’s own data puts the legal market’s share of GGR at approximately 49%. LiveScore and Tombola both exited in 2024. Operators seeking renewal are being assessed against a materially higher standard than the one they were originally licensed under.

Does open banking data meet the KSA’s evidence standard for affordability checks?

The KSA’s Financial Capacity Assessments: Duty of Care guidance requires that financial capacity assessments be based on “sufficient, accurate, and verifiable supporting documents.” Pay stubs and income tax returns are named as examples that meet this standard. Self-declarations, plausibility checks, and questionnaires explicitly do not.

Open banking data – specifically, transaction data accessed via a regulated Account Information Service (AIS) connection with explicit player consent – is bank-sourced, timestamped, and reproducible for audit. It provides a verifiable, real-time view of a player’s income and spending that is arguably stronger than a static payslip, which can be outdated or fabricated. The underlying bank data is retained and can be produced on request.

The KSA has not published a definitive list of approved evidence formats, and operators should form their own legal view. But the characteristics the KSA requires – sufficiency, accuracy, and verifiability – are inherent properties of regulated open banking data. We break down exactly how this works in practice, including how Intelligent Payments generates evidence at the point of deposit without adding extra steps or friction, in our post on evidence-based income verification under the KSA’s new standard.

We already use a transaction categoriser – what makes Yaspa’s different?

Many Dutch operators already run some form of transaction categorisation, often through third-party providers. But they keep telling us the results are patchy – especially on Dutch-specific patterns and merchants that a generic model wasn’t trained on. There’s a friction problem too: these checks typically run as standalone AIS connections outside the payment flow, which means an additional step for the player and a measurable hit to conversion.

The issue is that open banking provides the raw transaction data from a player’s bank account – but raw data alone doesn’t tell you whether a €2,400 credit is salary, a dividend, a PGB payment, or a savings transfer. That classification is where accuracy matters, and it’s where the quality gap between providers shows.

Yaspa’s AI transaction categoriser uses machine learning models trained specifically on financial patterns relevant to iGaming. It classifies income, gambling spend, and excluded income types with 96%+ accuracy and precision – meaning the operator can trust the output without manually reviewing each transaction. The categoriser is continuously updated as new merchants and transaction patterns emerge.

For context, the KSA has specifically flagged operators who made errors interpreting tax returns and miscounted gross income for self-employed players. The categoriser eliminates that class of error entirely: it measures net inflows as received, post-tax, so the risk of miscounting gross as net doesn’t arise.

This accuracy matters because the KSA mandates a long list of income exclusions – and miscounting any of them inflates the net deposit limit beyond what the player can actually afford. Borrowed money, earmarked income (kinderalimentatie [child maintenance], kinderbijslag [child benefit], PGB [personal care budget], huurtoeslag [rent allowance], verzekeringsuitkeringen [insurance payouts], belastingtoeslagen [tax office allowances]), partner income, and non-liquid assets must all be excluded. Yaspa’s categoriser handles these automatically – we cover the full exclusion framework and how each type is treated in our post on income calculation and exclusions.

How does Intelligent Payments handle self-employed income?

Self-employed income is one of the trickiest areas under the KSA’s rules. The regulator has observed operators counting gross dividend payments from a player’s own business as net income, and counting business balance sheet assets as personal income. Both are wrong, and the KSA considers these errors a compliance breach.

Yaspa handles this by measuring personal account inflows only – what actually reaches the player’s personal bank account after business expenses and tax. Dividends from a company bearing the player’s name are identified and treated as business income, measured net.

Can the affordability check be automated when a player requests a limit increase?

In short, yes. Under KSA rules, the standard net deposit limit is €700 per month (€300 for players aged 18–24). A player who wants to deposit more must request an increase, and the operator must conduct a financial capacity assessment before granting it. Importantly, the KSA does not allow operators to prompt players to raise their limits – the request must come from the player.

With Intelligent Payments, the data to assess that request is often already on file. If the player has previously deposited via Yaspa and their open banking consent is still active, verified income, exclusions, and the gambling-to-income ratio are already current. When the player initiates a limit increase, the assessment can resolve against the operator’s own criteria in seconds – no documents to request, no waiting period, and no manual review unless the operator’s rules require it above a certain threshold.

The result is a process that’s both faster for the player and more defensible for the operator. The player gets a decision quickly; the operator gets an evidence-based, timestamped record of why the increase was granted (or declined) that’s ready for the KSA if they ask.

This is particularly relevant in the Netherlands, where it’s common for players to hold one account that receives their salary and a separate account they use for day-to-day spending – including gambling. Dutch operators tell us this happens in a significant share of cases: the account a player deposits from is not the account their income goes into.

Yaspa has built-in capability to identify bank account type – salary account vs spending account – based on the transaction patterns it sees, and assigns a completeness score to the affordability picture. If no income data is present, Yaspa flags the account type to the operator, who can then prompt the player to connect their primary account – the one that receives their salary. The player gets a clear reason (“we need to see your income account to assess your deposit limit”) rather than a generic document request.

This matters because the KSA requires income verification based on verifiable evidence. An account with no salary data can’t support an affordability assessment, and proceeding on incomplete data creates compliance risk. The account type detection means operators catch this at the point of deposit rather than discovering the gap during an audit.

How does continuous monitoring work under GDPR?

Operators sometimes ask whether maintaining an ongoing open banking connection raises data protection concerns. The short answer: it’s designed for this.

Under PSD2, open banking consent is explicit, time-bound, and fully within the player’s control. In the EU, the player has to re-authenticate every 180 days to maintain the connection. The player can revoke consent at any time. Data access is read-only – no one can move money or modify the account.

From a GDPR perspective, the operator has a clear lawful basis for processing: the data is necessary for compliance with the KSA’s duty of care obligations (regulatory compliance as a legal basis) and is processed with the player’s explicit consent. Yaspa handles the data connection and processing as a regulated payment provider; the operator receives the categorised output – income classification, affordability metrics, gambling-to-income ratios – not raw transaction data for every line item.

For operators used to point-in-time document checks, the shift to continuous monitoring can feel like a bigger data footprint. In practice, it’s a more proportionate approach: the data is structured, purpose-limited, and retained only for as long as it’s needed to support the affordability assessment on file.

What does the audit trail actually look like?

The KSA requires that every net deposit limit calculation be “properly documented using supporting documentation and retained until the limit is adjusted.” With the control database giving the KSA 24/7 read access to operator data, and licence renewals requiring disclosure of past breaches, the quality of your documentation trail is directly tied to your renewal prospects.

Yaspa generates the audit trail automatically as part of the deposit flow. Each assessment produces a timestamped record covering the open banking consent event, the transaction data accessed, how income was classified, which exclusions were applied, the resulting gambling-to-income ratio, and the affordability output. A player’s bank statement with categorised transactions can also be downloaded as a standalone supporting document.

None of this requires manual assembly. The documentation builds itself with every deposit, creating a continuous, regulator-ready record for each player. We go deeper on how this works – including how it maps to the KSA’s specific enforcement requirements around immediate deposit blocks and 30-day bonus blocks – in our post on enforcement and audit trails.

Preparing for what comes next

The operators that have already renewed went into the process with the advantage of strong compliance track records. For operators still preparing, the KSA’s message is clear: they want evidence of consistent, effective player protection, properly documented and demonstrable over the five-year licence period.

Yaspa’s Intelligent Payments platform addresses the three core duty of care requirements the KSA assesses – evidence-based income verification, accurate income calculation with automatic exclusions, and auto-generated audit trails – within a single integration, embedded in the deposit flow. No separate compliance tool, no additional friction for the player, and no gaps in the documentation trail.

To see how it works for the Dutch market, talk to one of our experts.


This post is part of Yaspa’s coverage of the Dutch regulated market. For deeper detail on the KSA’s duty of care requirements, read our three-part series: Evidence-based income verification | Income calculation and exclusions | Enforcement and audit trails

Yaspa is an FCA-authorised open banking payment provider, operating across Europe. Our Intelligent Payments platform combines instant Pay by Bank deposits with AI-powered financial intelligence for iGaming operators. Learn more about Intelligent Payments.

Where Yaspa provides the underlying data and signal, the operator applies it within their own platform and policy – deposit limits, blocks, and thresholds remain enforcement decisions the operator makes.

Yaspa becomes founding member of UNLV’s AI Research Hub to advance responsible AI adoption in the gambling industry
Read more
Yaspa US new joiners
Yaspa boosts US team with two senior appointments to support its North American expansion
Read more
Monthly policy update – February 2026
Read more
A smarter approach to open banking payment outcomes
Read more

Subscribe

Stay in the know

Discover the latest payments news and events from Yaspa and the fintech world in our monthly newsletter.

"*" indicates required fields

This field is for validation purposes and should be left unchanged.