Regulation

Sweden Turns Spelpaus Self-Exclusion Into a Real-Time API Duty

Spelinspektionen's SIFS 2026:3 took effect 1 August, forcing every Swedish licensee to run live API checks against Spelpaus before marketing, signup and login.

Sweden Turns Spelpaus Self-Exclusion Into a Real-Time API Duty

Image credit: Source: Spelinspektionen public statement. Never imply stock depicts the actual event.

Spelinspektionen's SIFS 2026:3 took effect on 1 August 2026, requiring every Swedish gambling licensee to run a live API check against the Spelpaus self-exclusion register before sending direct marketing, registering a new player, or letting an existing player log in. The Swedish Gambling Authority decided the standard on 23 April and published it on 29 April, giving operators just over three months to build the integration before it became mandatory.

The rule replaces a self-exclusion system that leaned on operators checking Spelpaus periodically with one that treats each of three moments, marketing, signup and login, as its own mandatory query. Each licence holder gets a unique Actor ID and API Key from the regulator, and the marketing check runs through a separate API from the one covering registration and login. A player who self-excludes through Spelpaus should now be invisible to a licensee's marketing systems and locked out of new accounts and existing sessions within the same real-time check, rather than catching up on the next scheduled sync.

The compliance duty does not move with the outsourcing

Spelinspektionen's standard makes explicit what many licensees would rather leave ambiguous: responsibility for the checks stays with the licence holder even when the technical work runs through a third-party platform or affiliate integration. An operator that hands its Spelpaus queries to a vendor is still the party the regulator holds accountable if a self-excluded player gets a marketing email or logs back in. That is a heavier compliance posture than the credit and financial-risk checks regulators elsewhere have leaned on. The UK's financial risk checks still work through deposit thresholds an operator monitors on its own schedule, not a query it must run against a national register at three specific trigger points before it can act.

The regulation itself does not yet spell out the API's exact specifications, response formats or service performance standards, details that matter for integration timelines and that operators are still waiting on. What it does confirm is the direction: Sweden is moving self-exclusion from a passive consumer safeguard, where a player opts in and hopes operators catch up, to an active duty the operator has to prove it discharged at the moment it mattered.

Part of a broader Nordic and European tightening

The August rule follows Sweden's ban on gambling funded by credit, overdrafts, loans or buy-now-pay-later services, which took effect 1 May 2026 as the first such ban in the EU. Together the two rules put Sweden ahead of the Netherlands' own 2026 enforcement priorities, which have focused more on channelisation and payment-rail pressure against unlicensed operators than on real-time self-exclusion infrastructure. For a market where channelisation is the number regulators use to judge whether enforcement is working, Spelinspektionen is betting that a harder technical duty on licensed operators, not just tougher enforcement against unlicensed ones, is what keeps players inside the regulated system once they have asked to leave it.

Licensees that have not finished integrating the marketing and login APIs are already out of compliance as of 1 August. Spelinspektionen has not published a grace period or stated penalties for the gap between the rule's effective date and an operator's actual integration, which leaves enforcement timing as the open question for any licensee still finishing the build.

i
iGamingNews Editorial Desk

We are here to create the best source of trends and news for the iGaming world