34.2 Internet Gambling Controls, Child Privacy and Email Rules
Key Takeaways
Regulation GG controls depend on the payment system, participant role and applicable exclusions.
COPPA duties depend on covered child-directed services or actual knowledge and regulator jurisdiction.
CAN-SPAM requirements are separate from rules for lawful processing of gambling payments.
Designated Payment Systems
Regulation GG identifies five covered payment systems through which unlawful gambling transactions could pass:
- Automated Clearing House (ACH) systems;
- Card systems (credit card, debit card, and prepaid card networks);
- Check collection systems;
- Wire transfer systems (Fedwire and CHIPS); and
- Money transmitting businesses.
Bank Compliance Obligations: Written Policies and Due Diligence
Regulation GG requires every participant depository institution to establish and maintain written policies and procedures reasonably designed to identify and block or prevent restricted transactions:
Commercial Customer Due Diligence (CDD) at Account Opening
Depository institutions are not required to monitor individual consumer transactions or screen everyday checking accounts for gambling activity. Instead, compliance is achieved primarily through risk-based commercial customer due diligence:
- Commercial Account Screening: At the time a commercial account is opened, the bank must conduct due diligence to determine whether the commercial enterprise presents a risk of engaging in Internet gambling.
- Entities Presenting No Gambling Risk: For standard commercial businesses (e.g., manufacturing, professional services, retail stores), standard customer identification and due diligence satisfy Regulation GG.
- Gambling-risk customers: Under the applicable payment-system role, obtain the required certification and evidence, such as a license or a reasoned legal opinion, and review appropriate policies and controls. Licensing and a legal opinion are not universally cumulative requirements.
For card systems, policies can use coding and authorizations to identify and block restricted transactions. A gambling merchant category code alone does not establish unlawfulness. ACH, check and wire obligations depend on the participant’s role and exemptions; commercial-customer diligence and procedures for actual knowledge are central. Do not claim the rule universally requires blocking all MCC 7995 transactions.
As depository institutions expand digital onboarding, youth banking applications, and electronic communications, compliance officers must integrate federal online privacy statutes into institutional CMS frameworks.
Children's Online Privacy Protection Act (COPPA, 16 CFR Part 312)
Enacted under 15 U.S.C. § 6501 et seq. and enforced by the Federal Trade Commission (FTC) and prudential banking regulators, COPPA applies to operators of commercial websites and mobile applications directed to children under 13 years of age, or general audience platforms that have actual knowledge that they are collecting personal information from children under 13.
- Application to Depository Institutions: Banks offering dedicated youth checking accounts, child savings mobile apps, or gamified financial literacy portals directed to children under 13 must comply with COPPA.
- Verifiable Parental Consent (VPC): The financial institution must obtain verifiable parental consent prior to collecting, using, or disclosing any personal information (such as child name, physical address, Social Security Number, phone number, persistent online identifiers, or biometric data) from a child under 13.
- Permissible VPC verification methods include: signed consent forms returned via mail or electronic scan, verification using a parent's credit card or debit card in connection with a monetary transaction, videoconferencing with trained staff, or checking government-issued photo identification.
- Parental Review and Revocation Rights: Parents must be granted the legal right to review the specific personal information collected from their child, revoke consent, and request deletion of collected personal information and refuse further collection or use under the applicable COPPA provisions.
- Data Minimization and Security: The institution cannot condition a child's participation in an online game or financial activity on the disclosure of more personal information than is reasonably necessary, and must maintain reasonable administrative, physical, and technical data security controls.
The CAN-SPAM Act of 2003 (16 CFR Part 316)
The Controlling the Assault of Non-Solicited Pornography and Marketing Act (CAN-SPAM) establishes federal standards for transmitting commercial electronic mail messages (e.g., email marketing for credit cards, auto loans, or deposit promotions):
- Commercial vs. Transactional Messages: Commercial emails promote a commercial product or service. Transactional or relationship messages (such as account balance alerts, periodic statement notifications, or fraud warnings) are exempt from CAN-SPAM marketing rules.
- Core Requirements for Commercial Emails:
- Truthful header information (accurate 'From' and 'To' routing data);
- Non-deceptive subject lines reflecting the actual content of the message;
- Clear and conspicuous identification that the message is an advertisement or solicitation;
- A valid physical postal address of the financial institution;
- A clear, conspicuous, and functional opt-out mechanism allowing recipients to unsubscribe, which the institution must honor within 10 business days.
Comparison: Regulation D vs. Regulation II vs. Regulation GG
| Compliance Dimension | Regulation D (12 CFR Part 204) | Regulation II (12 CFR Part 235) | Regulation GG (12 CFR Part 233) |
|---|---|---|---|
| Primary Regulatory Focus | Deposit liability classifications and reserve requirements | Debit card interchange fee limits and network routing rules | Unlawful Internet gambling transaction prevention and screening |
| Statutory Authority | Federal Reserve Act Section 19 | Electronic Fund Transfer Act Section 920 (Durbin Amendment) | Unlawful Internet Gambling Enforcement Act of 2006 (UIGEA) |
| Covered Institution Scope | ALL depository institutions accepting transaction or savings deposits | Interchange cap: Assets $10 billion or more; Routing rules: ALL issuers | ALL depository institutions participating in designated payment systems |
| Core Operational Rule | 0% reserve ratio; transfer limits left to bank contract discretion | Cap: 21¢ + 5 bps + 1¢ fraud adjustment; Multi-network routing | Commercial customer due diligence (CDD) at account opening |
| Transaction-Level Filtering | No mandatory federal monitoring of 6-transfer savings limits | Network-level transaction routing over unaffiliated networks | Role-specific controls; coding is not a universal finding of unlawful gambling |
| Consumer Exemption | N/A (Applies to consumer and commercial deposit classification) | Excludes government-administered prepaid cards and reloadable cards | Determine payment-system role, exemptions and actual-knowledge procedures |
Network, gambling and children’s-data boundaries
Regulation II’s small-issuer exemption aggregates the issuer with its affiliates; a stand-alone bank balance sheet below ten billion dollars is insufficient if the combined group exceeds the threshold. The two-unaffiliated-network rule extends to card-not-present transactions. Regulation GG duties depend on the participant’s role in a designated payment system; do not treat all participants as if they were the commercial customer’s account-holding bank. A gambling merchant code is not itself proof of unlawful Internet gambling. Risk-based commercial-customer diligence and applicable certifications, licensing or legal-opinion evidence support compliance.
COPPA generally covers operators of child-directed online services and operators with actual knowledge of collecting personal information from children under thirteen. Parental-consent rules have specified exceptions, including limited support for internal operations. The FTC’s 2025 amendment generally required compliance by April 22, 2026; distinguish current implementation from ABA’s exam-law cutoff. A bank should assess its services and regulator jurisdiction rather than assume every bank website is child-directed.
Under Regulation GG (12 CFR Part 233 / 31 CFR Part 132), which of the following operational controls represents the primary method by which a depository institution satisfies its statutory obligation to prevent unlawful Internet gambling transactions across ACH, wire, and check systems?
Requiring all consumer checking account applicants to sign a notarized affidavit pledging not to gamble online.
Monitoring outgoing consumer check clearing lines and blocking any draft made payable to an entity licensed outside the United States.
Reviewing every incoming ACH credit and wire transfer in real time to inspect payee descriptions for casino-related keywords.
Establishing and maintaining written policies and procedures to conduct commercial customer due diligence at account opening to screen commercial entities for gambling risk.
Sections you finish are checked off in the contents.