Skip to the departures board

18+ · Independent information desk, not a licensed operator

The momentum desk
Industry Trends

How CRUKS and the Koa Act Turned Self-Exclusion Into a Platform Feature

Isometric illustration of a compliance shield protecting a player at a digital screen

Route recap

PM-01 FromThe Regulatory Shift That Changed Platform Design Dutch online gambling platforms no longer treat self-exclusion as a courtesy feature buried in account settings. Since… ToHow CRUKS and the Koa Act Turned Self-Exclusion Into a Platform Feature

The Regulatory Shift That Changed Platform Design

Dutch online gambling platforms no longer treat self-exclusion as a courtesy feature buried in account settings. Since 1 October 2021, the Koa Act (Wet kansspelen op afstand) opened the regulated online market in the Netherlands, and with it came CRUKS, the national self-exclusion register managed by the Kansspelautoriteit (KSA). A CRUKS check is now a legal precondition for play under the Koa Act framework.

When a requirement sits at the legal threshold of market access, it moves from the settings menu to the onboarding flow. The user experience changes because the compliance obligation changes. The design logic follows from enforcement. The legal requirement leaves no room for a lax implementation, so the check cannot live in a rarely visited part of the account dashboard. It must sit where the platform can prove it happens every time. That proof requirement reshapes the entire front-end architecture.

The compliance team and the product team now share a single roadmap. A feature that once belonged to a responsible-gambling silo becomes part of the core registration pipeline. Player-protection tooling now gets the same engineering attention as payment rails or identity verification.

Pre-Koa Act vs Post-Koa Act: Default Player-Protection Posture

AspectPre-Koa Act (before Oct 2021)Post-Koa Act (current)
Self-exclusion registerNo national mandatory registerCRUKS, managed by the KSA, checked before play
Identity verification for exclusionNo standardised requirementBSN check required against the national register
Deposit-limit defaultsNo dated mandatory-default rule in the evidence aboveMandatory default limits since October 2024
Affordability check-inNo mandatory triggerTriggered at net-deposit thresholds, mandatory contact
Third-party registrationNo formal route named in the evidence aboveFormal family-member route since the recent KSA update

Each row’s post-Koa column states a dated legal requirement from the evidence above. The pre-Koa column simply reflects the absence of that same requirement before its stated start date. Read together, the table shows five mechanisms moving from optional to obligatory between 2021 and 2024.

Timeline of CRUKS launch, deposit-limit mandate, and third-party exclusion update
Three dates mark the shift: the 2021 CRUKS launch, the 2024 deposit-limit mandate, and the 2026 third-party registration update.

What CRUKS Actually Does

The BSN Check Mechanism

Licensed operators must verify every player against CRUKS using their BSN, the Dutch citizen service number, before allowing any play. A registered self-excluded player gets refused, with no exceptions and no operator discretion.

The check happens at the point of entry, the moment a player attempts to register or log in to play, when the platform queries the register. There is no opt-out for the operator and no override for the player. The BSN requirement is the technical anchor of the system. Without a unique national identifier, an operator could not reliably match a player against the register. The BSN removes ambiguity about identity, which is why the check returns one definite answer for every player.

This design choice also explains why the system operates as one shared national register. A player excluded from one platform could simply move to another if registers were siloed. The shared register closes that loophole by making the exclusion portable across the entire licensed market.

Isometric illustration of an identity checkpoint gateway before platform entry
The BSN check sits at the gateway itself, not somewhere a player can skip past on the way in.

Immediate Effect and Minimum Term

Self-exclusion through CRUKS takes effect immediately. The minimum term is six months, and the player chooses the maximum, which can extend to 99 years, effectively permanent.

There is no cooling-off period before the exclusion activates, no processing window, no business-day delay. The registration is live the moment it is confirmed.

The six-month minimum serves a specific function. It prevents a player from registering for exclusion during a moment of regret and then reversing the decision the next day when the urge returns. The floor creates a genuine pause. The 99-year maximum reflects a regulatory acknowledgment that some players need a permanent off-ramp. For those individuals, the option to make exclusion effectively irreversible removes the mental burden of periodically renewing a decision they have already made.

Deposit Limits as a Designed Checkpoint

Since 1 October 2024, mandatory deposit limits have become a hard operational requirement for Dutch-licensed operators. The mechanism works through default limits combined with net-deposit contact thresholds that trigger a check-in with the player.

A checkpoint intervenes at the moment of the threshold crossing, prompting contact from the platform. That intervention is a designed moment in the user journey, with the same operational weight as payment processing or identity verification.

This changes how platforms think about player flows. The deposit limit is built into the architecture of play as a checkpoint, sitting alongside payment processing and identity verification in the core transaction path.

Gross deposits would penalise a player who deposits and withdraws frequently without net losses. Net deposits measure actual money at risk, isolating the figure from raw transaction volume. The mandatory contact requirement forces a conversation that might otherwise never happen. Many players would not voluntarily discuss their spending with a platform. The regulatory design removes that choice and makes the dialogue a condition of continued play beyond the threshold.

Deposit limits interact with CRUKS in a layered fashion. A player who has not registered for exclusion still encounters a spending ceiling and a mandatory conversation when crossing it. The system catches players at different stages of risk through different mechanisms, and each mechanism operates independently while sharing the same underlying infrastructure of identity verification and account-level tracking.

The Recent KSA Update: Third-Party Self-Exclusion Requests

The KSA has moved to make it easier for third parties to register someone for CRUKS self-exclusion. Family members, through a formal process, can now initiate registration on behalf of someone else.

Before this update, initiating a CRUKS registration fell to the player alone. The recent KSA update recognises that the person most likely to spot a gambling problem is not always the person living it.

There is a defined procedure, which balances the protective intent against the risk of misuse. The KSA extended who can initiate a request through that formal structure alone. The design tension sits between accessibility and abuse prevention, and the defined steps are the KSA’s answer to it.

For platforms, this update adds a new operational layer. The CRUKS check must now handle registrations that originate from third parties as well as from the player. That changes the data flow and the edge cases an operator must handle in the onboarding pipeline.

What This Means for Players Evaluating a Platform

For someone assessing a Dutch-licensed platform, the presence of CRUKS integration and deposit-limit checkpoints is now a baseline compliance signal. Every licensed operator must have these features. Their absence constitutes a legal violation under the Koa Act framework.

A CRUKS check that happens early in onboarding, with clear language about what it means, suggests compliance treated as a design principle. A check that feels bolted on, with dense legal text and no explanation, suggests the opposite. Players should also understand the asymmetry of the system. The platform must check CRUKS before allowing play. Registering for exclusion in the first place is initiated by the player, or, since the recent KSA update, by a family member on the player’s behalf. The check protects the registered player while leaving the unregistered player free to continue. That is the regulatory design, and the third-party route is the one exception to player-only initiation.

The deposit-limit mechanism works similarly. A default limit applies to the account, and the affordability check-in triggers at the net-deposit threshold, a moment where the player’s situation gets reviewed.

For the broader market, the Dutch approach shows what happens when player-protection tools become legal infrastructure. They stop being features that platforms compete on and start being a shared baseline. The competitive differentiation shifts to execution quality. How smoothly the check integrates, how clearly the platform communicates the limits, and how respectfully the affordability conversation is handled all become the new points of comparison.

Regulation sets the legal floor a platform’s design must clear, which is now the baseline players and competitors both measure against. See also: Key Features of Trusted Online Casino Platforms.

The evaluation heuristic for a player is therefore about how the friction is built, since every licensed platform carries some. Every licensed platform has friction at onboarding. The question is whether that friction is informative, respectful, and brief, or whether it is bureaucratic, opaque, and obstructive. A platform that explains why the CRUKS check exists, what the deposit limit protects, and what the affordability conversation involves is treating the player as a participant in a shared system. A platform that runs the checks silently, with minimal context, treats the player as a compliance object.

The third-party registration route adds another evaluation dimension. A player concerned about their own behaviour can now ask a family member to act. That option is only useful if the platform’s systems handle such registrations cleanly, without forcing the third party through an opaque process.

Where to Get Help

National Support Services

Loket Kansspel is the Netherlands’ free, anonymous national point of contact for gambling-related help, reachable via a national helpline.

The KSA, as the Dutch gambling regulator, oversees both licensed operators and the national player-protection tooling including CRUKS. For questions about how the register works or how to file a request, the regulator’s own channels are where those questions get answered. See the Dutch government’s gambling-help FAQ.

Loket Kansspel offers support; the KSA, as the Dutch gambling regulator, oversees licensed operators and tooling including CRUKS. One is a support line. The other is a regulator.

Official Dutch government page listing help resources for gambling problems
The Dutch government’s own help page lists the same contact routes described here, independent of any platform.

Responsible Gambling Framing

Self-exclusion and deposit limits exist because gambling carries real risk. The Dutch regulatory framework treats that risk as a design problem to be engineered into the platform’s architecture. Every account carries a deposit limit by default, CRUKS registration is open to any player, and help is available to anyone who asks. Gambling should remain an entertainment choice made by adults who understand the stakes. The tools described in this article exist to keep it that way. If gambling stops being entertainment, the help infrastructure is there. Loket Kansspel offers direct support, the KSA handles regulatory questions, and CRUKS remains open to those who decide that stepping away is the right call.

This content is intended for readers aged 18 and over. Anyone struggling with gambling, or concerned about someone who is, can treat reaching out to a support service as a constructive first step.

FAQ

Can a CRUKS registration be shortened or cancelled early?

The minimum term is six months once registration is confirmed, and that six-month floor is the shortest term the CRUKS scheme allows. A player who wants a shorter break has to look outside CRUKS for it.

Is third-party CRUKS registration the same process as registering yourself?

Self-registration and third-party requests both end in the same CRUKS entry. The recent KSA update created a separate formal channel specifically for family members, standing apart from the player’s own account flow.

Do deposit limits apply to every player on Dutch-licensed platforms?

Default deposit limits apply to all players as a baseline requirement since that regulatory deadline. For a player who never approaches the net-deposit threshold, the practical effect is invisible. The limit sits in the background, and the mandatory affordability conversation never triggers.

Is the CRUKS check a one-time event or a recurring verification?

The CRUKS register is checked at the point of entry before play is allowed. Because the register is national and shared across all licensed operators, a registration made on one platform blocks play on all of them.