Operational standard, not legal advice. Exclusion durations, register obligations and re-entry rules are set per market; hold them as configuration rows with sources and owners, and confirm with counsel per regime.

The request path: two taps, zero negotiation

The player who has decided to exclude is doing something difficult; the product's job is to make it easy. The standard: reachable from account settings and from every RG surface in at most a couple of steps, clear duration options per the market's menu, and effect that lands in the same transaction — sessions killed, login blocked, promotions suppressed, the confirmation stating exactly what has happened. Retention offers, surveys and 'are you sure' loops inserted into this path are the pattern regulators cite by name.

Enforcement: a state, not a flag

SurfaceEnforcementThe leak it closes
IdentityExclusion binds the group-level player key; duplicate detection screens new registrationsThe fresh account on the sister brand
AccessLogin blocked across brands; sessions terminated at effect timeThe still-open tab that keeps playing
MarketingSuppression at the single send/export gate — the one-gate architectureThe uploaded audience refreshed on a cycle
PartnersAffiliate postbacks and audience seeds exclude excluded players — the affiliate railThe side-channel nobody mapped
MoneyDeposit paths closed; balance returned per the market's rulesThe payment flow that quietly recreates a wallet
RegisterNational register checked at registration and login where one exists; fail-closed on outageThe latency window an excluded person walks through

The unifying principle: exclusion is enforced where flows converge — the gates — not by every consuming system remembering to check. Systems forget; gates do not.

The two hardest engineering cases

Migration. Exclusion state migrates first, is verified independently of the balance reconciliation, and is re-checked as the final gate before any login path opens — the standard set in player data migration, restated here because the lapse-during-replatform is the failure regulators remember longest.

Re-registration. The determined excluded person with a new email is a solved-in-principle, hard-in-practice problem: the duplicate-identity machinery (documents, instruments, device and address signals) that fraud teams already run must serve exclusion enforcement with at least the same diligence — same mechanism, higher stakes, per the identity discipline.

Expiry without a sales funnel

The period ending is not a reactivation event. No outreach at expiry; return on the player's initiative through a deliberate re-entry step per market rules; protective defaults on the returned account (conservative limits, closer monitoring windows); and the history retained so the function's institutional memory outlives the exclusion itself. The audit page covers the records; the operating culture point is simpler — the exclusion was a protective decision, and everything about re-entry should honour it.

Continue reading: The interventions playbook — the steps before exclusion becomes necessary. Reporting and audit — proving all of this to a regulator.