Virginia Regulatory Town Hall
Agency
Virginia Lottery
 
Board
Virginia Lottery Board
 
Previous Comment     Next Comment     Back to List of Comments
9/9/20  7:48 pm
Commenter: Gaming Laboratories International (GLI)

GLI: 11 VAC 5-70-270 Sports Betting Platform Requirements
 

Key:   Recommended Modifications and Additional Rule Text    Removals  Movement  

 

Original Section(s)

11 VAC 5-70-270 Sports Betting Platform Requirements.

GLI Recommendations

 

11 VAC 5-70-270.B

Before a permit holder is issued its permit Prior to operating sports betting, all equipment and software used in conjunction with its operation shall be submitted to, reviewed, tested and approved by an independent testing laboratory approved by the Director, to the requirements of Article 2 of Chapter 40 of the Code of Virginia (§ 58.1-4030 et seq.), 11 VAC 5-70, 11 VAC 5-80, the standards set forth in the latest version of the GLI-33 Standards for Event Wagering Systems, and any additional system specifications specified by the Director through the issuance of technical bulletins.

GLI recommends modification to add specificity on what requirements will need to be tested, including the GLI-33 Standard for Event Wagering Systems, as initially specified in 11 VAC 5-70-300.A. The majority of sports wagering markets in the US have already incorporated GLI-33 adoption into their rules and regulations which have ensured security of the sports wagering systems and provided guidance for sports wagering operations.

GLI also recommends merging in text of 11 VAC 5-70-270.S.

 

 

The permit holder or its sports betting platform supplier shall pay all costs of testing, certification, and approval under this chapter including, but not limited to, all costs associated with:

    1. Equipment and technical services required by an independent testing laboratory to conduct the testing and certification process;
    2. Operational audits;
    3. System Integrity and Security Assessments; and
    4. Implementation testing.

GLI recommends adding after 11 VAC 5-70-270.C the section based on what has been seen for other markets.

 

 

The Director shall approve the location of the sports betting platform’s servers used by permit holder to conduct sports betting in the Commonwealth of Virginia.

  1. The primary server used to resolve domain name service (DNS) inquiries must be physically located in a secure hosting facility, located within the United States. At least one secondary server must be able to resolve DNS queries.
  2. Redundancy, secondary and emergency servers must be physically located in a secure hosting facility at a separate location than the primary server. The separate location may be outside of the United States provided that its operation does not require the communication or storage of personally identifiable information outside of the United States, or unless authorized by the Director.           

 

 

A sports betting platform shall be designed to ensure the integrity and confidentiality of all communications and ensure the proper identification of the sender and receiver of all communications. If communications are performed across a public or third-party network, the system shall either encrypt the data packets or utilize a secure communications protocol to ensure the integrity and confidentiality of the transmission.

 

11 VAC 5-70-270.M

If a player has a pending wager and the player subsequently self-excludes,

  1. The permit holder’s internal controls shall govern the handling of the pending wager; shall be cancelled and
  2. The funds and account balance on settled wagers shall be returned to the player in accordance with the permit holder’s internal controls.

GLI recommends updates based on what has been seen in other markets. Allowing self-exclusion to automatically cancel pending wagers can be something a player can potentially exploit.

 

11 VAC 5-70-270.D

11 VAC 5-70-270.Q

11 VAC 5-70-270.R

A permit holder and a supplier providing a permit holder’s sports betting platform shall grant the Director with remote, read only, real time access to all wagers, including canceled, voided, pending, and redeemed wagers, wagering systems, transactions, and related data as deemed necessary and in the manner required by the Director.

A sports betting platform shall provide a mechanism for the Director to query or sort and export, in the format required by the Director, all sports betting platform data.

GLI recommends merging clauses with similar intent: 11 VAC 5-70-270.D, 11 VAC 5-70-270.Q, 11 VAC 5-70-270.R

 

11 VAC 5-70-160.G

All requested data shall be made available in the report formats and database formats required by the Director.

GLI recommends moving 11 VAC 5-70-160.G and 11 VAC 5-70-160.E into 11 VAC 5-70-270 as the last items of the section.

 

11 VAC 5-70-160.E

A permit holder shall deliver all data requested by the Director either by report or data file in the form and frequency required by the Director while achieving compliance with the standards of integrity, security, and control.

 

CommentID: 84627