Guide on monthly reporting introduced by Law 141/2025, AML and GDPR obligations for B2B providers, and sanctions effectively applied by ONJN.
In brief
- Monthly reporting: blocked access situation, by the 10th of each month, for software, platform and payment providers
- Continuous screening: clients must hold a Class I license and not appear on the ONJN blacklist
- Annual payments: license fee at least 10 days before each year's anniversary, plus responsible gambling contribution
- Key sanction: license revocation, effectively applied in practice
Reporting to ONJN
The most important monthly obligation, introduced by Law 141/2025 for licensees holding a license for software, platform or payment processing: submitting to ONJN, no later than the 10th of each month, a consolidated report with the number of players whose access was blocked and their identification data, for the entire previous month.
The same categories must maintain at all times an up-to-date report, available upon ONJN's request at any time, with the countries from which the IT system is accessed and the entities that allow Romanian players' access.
Player Geolocation
Software, platform and payment providers are required to implement technical measures that allow identification of players' actual location, regardless of information shared through integration with the Class I operator's platform.
Notifications and Records
Class II license holders must inform ONJN of any significant change to the data on which the license was issued, within 48 hours for online submission, or within 5 business days for submission by post or at ONJN's registry. Under Order no. 33/2025, the main changes covered are those regarding the beneficial owner, directors/representatives/shareholders, registered office, company name, criminal record and share capital.
Monthly screening of the ONJN blacklist for the client portfolio is effectively an operational necessity: providing services to entities that allow Romanian players' access without a license is prohibited.
AML: What Obligations Does a B2B Provider Have
Under Law no. 129/2019, the obliged entity in the sector is the Class I operator. Class II licensees do not automatically become obliged entities, but may become so on other grounds — payment processors authorized as payment institutions have a full AML program: KYC, transaction monitoring, reporting to ONPCSB, compliance officer.
GDPR: Typical Role as Data Processor
The Class I operator is the data controller for player data; the platform or hosting provider that accesses or stores this data is a data processor, with a mandatory processing agreement under Art. 28 GDPR. Critical points: data retention aligned with gambling/AML requirements, prompt notification of incidents to the controller, international transfers and data segregation by operator.
Frequently Asked Questions
Do all Class II categories report monthly?
No. Monthly reporting of blocked access and the on-demand report apply to software, platform and payment processing providers. Affiliates, certifiers and auditors do not have these obligations but remain subject to notification requirements and client restrictions.
Is there a monthly percentage-based fee?
No. The Class II regime does not include a monthly percentage-based fee. Specific payment obligations are annual; only general tax obligations remain monthly — VAT, salary taxes, as applicable.
Is a Class II provider an AML obliged entity?
Not automatically. It becomes an obliged entity only if its activity qualifies separately — the typical case being a processor authorized as a payment institution. Other providers respond through the due diligence chain required by operators.
What risks does a provider face when working with an unlicensed site?
Providing services to entities that allow Romanian players' access without a license is prohibited, and the ONJN blacklist now also includes persons conducting ancillary activities without a license — with license revocation and market exclusion as consequences.











