Skip to content
2,151 standards indexed across 19 jurisdictions View the Atlas
3 hubs live · 3 more in the pipeline See all compliance topics
Daily news + multi-week series Browse all insights
3 tools live · 4 interactive tools in development Roadmap
Technical Standards · Location 15 min read Aug 3, 2026

Geofencing vs IP Blocking vs Device Fingerprinting: Which Technical Controls Satisfy Regulators

Which location controls pass GLI certification and which survive UKGC, MGA, DGE, and AGCO enforcement? This guide maps the exact regulatory requirements for each approach.

Matt Denney

By

Founder, gamingcompliance.io · 15 yrs in iGaming compliance

Published Aug 3, 2026 15 min read Filed Technical Standards

Every licensed iGaming operator must prevent players in prohibited territories from accessing real-money games. Three technical approaches dominate the implementation landscape: geofencing using multi-source location detection, IP blocking, and device fingerprinting. They are not interchangeable. Regulators across the UKGC, MGA, New Jersey Division of Gaming Enforcement, and AGCO Ontario each articulate different technical requirements, and the enforcement record shows that an approach that passes initial certification can still produce a settlement when real-world implementation is inadequate. This article maps what each regulator requires, where IP blocking falls short as a standalone control, and how device fingerprinting fits into a defensible compliance architecture.

What Do Regulators Actually Require From Location Controls?

No major licensed jurisdiction accepts passive territorial restriction. The regulatory minimum is active, dynamic, real-time location detection before a wager is accepted and at defined intervals throughout a session. The relevant technical standards literature draws a clear distinction between three mechanisms: detecting where a player physically is (geolocation), blocking network paths associated with prohibited regions (IP blocking), and verifying the integrity of the device being used to connect (device fingerprinting). Regulators require the first. They treat the second as a supplementary signal. They increasingly mandate the third as a fraud-prevention layer rather than a location-verification tool in its own right.

GLI-19 Standards for Interactive Gaming Systems v3.0, section 2.7, sets the baseline that most North American and a number of European regulators use as their technical floor. The standard is explicit: where interactive gaming occurs over a public network, the interactive gaming system shall incorporate a location detection service or application to reasonably detect and dynamically monitor the location of a player attempting to play a game, and to monitor and enable the blocking of unauthorised attempts to play a game. The word “dynamically” carries significant operational weight. A one-time login check does not satisfy this requirement. Location must be re-verified on an ongoing basis during a session.

Certification vs. Enforcement: GLI certification of a location service confirms the technical architecture meets the relevant standard at the point of testing. Enforcement scrutiny evaluates whether the implemented controls functioned correctly in production, across the full range of device types and network configurations actually used by players. These are distinct tests, and a system can pass certification while failing enforcement.

Is IP Blocking Sufficient as a Standalone Territorial Control?

No. IP blocking operates at the network layer, preventing connection requests from IP address ranges associated with prohibited jurisdictions. It is fast, cheap, and widely deployed as a first filter. It is also the weakest control in the location-verification stack and is treated by every regulator covered here as insufficient on its own.

GLI-33 Event Wagering Systems v1.1, in its Location Fraud Prevention requirements, requires that the event wagering system examine the IP address upon each Remote Wagering Device connection to a network to ensure a known Virtual Private Network (VPN) or proxy service is not in use. This framing is instructive: IP examination under GLI-33 is a fraud-detection step within VPN and proxy detection, not the primary location-verification method. GLI-19 v3.0 is equally direct: where a remote player device’s only available location data source is an IP address, the geolocation method may use a registered mobile device’s location data as a supporting source under specific conditions. IP-address-only geolocation is not a standalone solution under any of the four regulatory frameworks examined here. It is, at best, a supporting signal.

The practical vulnerability is well-documented. Industry commentary observes that advanced geolocation technology can detect many VPN connections, but that the real failure point is operators who simply choose not to implement adequate detection. That observation points directly to the enforcement risk: IP blocking without active VPN and proxy detection leaves a known circumvention route open.

The GLI-19 and GLI-33 Technical Architecture for Compliant Geofencing

GLI-19 v3.0 section 2.7.4 requires that location detection use a confidence radius, and that the confidence radius be entirely located within the permitted boundary. This is a precision requirement, not merely a binary in/out determination. The standard requires use of accurate location data sources including Wi-Fi, GSM, and GPS, and mandates that boundary polygons be based on audited maps approved by the regulatory body. These polygons must account for discrepancies between mapping sources and variances in geospatial data.

GLI-33 v1.1 adds a session re-verification requirement that compliance teams must operationalise explicitly. Each player must pass a location check prior to completing the first wager after logging in. Subsequent checks must occur prior to completing wagers after a period of 30 minutes since the previous location check, or as otherwise specified by the regulatory body. If a check indicates the player is outside the permitted boundary, or if location cannot be confirmed, the wager must be rejected and the player notified. Each violation must be recorded in a timestamped log with the unique player ID and detected location.

“The geolocation method shall monitor and flag for investigation any games played by a single player account from geographically inconsistent locations (e.g., sessions identified that would be impossible to travel between in the time reported).”, GLI-19 Standards for Interactive Gaming Systems v3.0, Section 2.7

This cumulative monitoring requirement turns location verification into an ongoing analytics obligation. A location service provider cannot simply log each check in isolation. It must maintain the analytical capacity to identify impossible travel patterns across a player’s session history, which implicates both the geolocation technology and the operator’s back-office monitoring infrastructure.

Source: Gaming Laboratories International, GLI-19 Standards for Interactive Gaming Systems v3.0, Sections 2.7.4, C.5.1, C.5.2, GLI-33 Standards for Event Wagering Systems v1.1, Location Fraud Prevention and Location Service Provider Monitoring requirements.

Device Fingerprinting: The Fraud Layer, Not the Location Layer

Device fingerprinting collects and hashes attributes of the connecting device: operating system, browser version, screen resolution, installed fonts, hardware identifiers, and similar signals. It is a powerful anti-fraud tool and is increasingly mandated by regulators as a component of location-fraud prevention. Its function in the regulatory framework is to detect and block circumvention of geolocation, not to perform the geolocation itself.

GLI-33’s Location Fraud Prevention section requires that the event wagering system incorporate a mechanism to detect the use of remote desktop software, rootkits, virtualization, and any other programs identified as having the ability to circumvent location detection. The specific requirement is to detect and block devices which indicate system-level tampering, including rooting and jailbreaking. GLI-19 contains parallel requirements. This is where device fingerprinting becomes a regulatory obligation: it is the technical mechanism through which rooting, jailbreaking, virtualisation, and remote desktop activity are detected.

GLI-33’s Location Service Provider Monitoring requirements add an audit dimension. The location service provider must utilise closed-source databases covering IP, proxy, and VPN data, and these databases must be frequently updated and periodically tested for accuracy and reliability. The service must also undergo frequent updates to maintain capabilities against evolving location fraud risks. This is an ongoing maintenance obligation, not a one-time certification deliverable. A location service provider whose fraud databases are stale, or whose fingerprinting signatures have not been updated to detect new root-detection bypass tools, is not meeting the standard even if the original certification was valid.

AGCO Standard 3.02: The Operational Benchmark in Ontario

The AGCO Registrar’s Standards for Internet Gaming state the territorial requirement plainly at Standard 3.02: games on gaming sites shall be provided only within Ontario, unless conducted in conjunction with the government of another province. The requirements beneath that standard are what give it operational depth.

Standard 3.02.1 requires dynamic monitoring of player location. Standard 3.02.2 requires that operators put in place mechanisms to detect software, programs, virtualisation and other programs capable of circumventing player location detection. The AGCO Go-Live Compliance Guide makes both requirements subject to pre-launch evidence validation: operators must demonstrate, before going live, the accuracy and effectiveness of their location controls across the majority of expected player device and network connection types, and must show compliance with both 3.02.1 and 3.02.2 explicitly. This is not a post-launch compliance obligation. The evidence must exist before the first player session begins.

The Go-Live Compliance Guide’s Technology Compliance Confirmation requires operators to provide a detailed description of how their Standard 3.02 controls have been validated, including confirmation of accuracy across different device types and network configurations. Operators must also confirm that common circumvention methods are detected and prevented. The AGCO’s approach embeds a functional testing obligation into the go-live process: theoretical architectural compliance is insufficient without demonstrated operational effectiveness.

The AGLC Standards and Requirements for Internet Gaming (SRIG), issued in March 2026 for Alberta’s market, replicate this structure. Section 4.2 requires that registered operators ensure games are provided only within Alberta, and that at a minimum the gaming system must detect and dynamically monitor the location of players. The AGLC Go-Live Compliance Guide adds that operators must confirm how controls are implemented to ensure players must be within Alberta, echoing the AGCO’s pre-launch validation model. For operators entering Alberta’s market following the registration deadline, the same evidence-before-operations framework applies.

NJ DGE Chapter 69O: Patron Location as a Game-Enable Gate

New Jersey’s Division of Gaming Enforcement (DGE) addresses territorial restriction through N.J.A.C. 13:69O-1.2, which sets the operational sequence in regulatory code. Under subsection (e), where an internet or mobile gaming system cannot confirm that a patron is in an authorised location, the system shall not accept wagers. For mobile gaming, this means play is confined to the property boundaries of an approved casino hotel facility. For internet gaming, the rule is that wagering shall only occur within the State of New Jersey, unless the DGE has authorised participation in gaming pursuant to a reciprocal agreement with another jurisdiction where such gaming is not inconsistent with federal law.

The DGE framework links location verification to the broader operator security architecture. N.J.A.C. 13:69O-1.4 requires that internet and mobile gaming systems utilise sufficient security to ensure patron access is appropriately limited to the account holder, and mandates strong authentication as a baseline. The DGE can also require operators to describe in their internal controls the method for ascertaining the location from which test accounts access the internet gaming system, per Chapter 69O’s testing provisions. The DGE’s scrutiny therefore extends to whether location controls function correctly under test conditions, not just in live play.

The DGE also requires an annual independent system integrity and security assessment, submitted to the Division, covering scope, methodology, findings, recommended corrective action, and the casino licensee’s response. Location controls fall within the scope of a system integrity assessment. Any gap identified in that assessment but not remediated before the next review creates a documented, evidenced compliance failure.

The UKGC and MGA: Outcome-Based Frameworks and the Enforcement Precedent

The UKGC and MGA do not publish prescriptive geolocation specifications of the type found in Chapter 69O or the AGCO’s Registrar’s Standards. Both operate on outcomes-based frameworks for technical controls, with the UKGC’s Remote Technical Standards setting functional outcomes rather than implementation blueprints. For MGA licensees, the accountability principle in the MGA’s Technical Infrastructure guidelines for Remote Gaming places the obligation squarely on the licensee regardless of third-party infrastructure. See the UKGC vs MGA licence comparison for how the two frameworks diverge on technical obligations more broadly.

For the UKGC, the enforcement record provides the most instructive guidance on what the Commission considers adequate. According to regulatory enforcement reporting, Evolution AB agreed to a settlement following a licence review. The investigation found that two operators used unlicensed websites to bypass technical restrictions and provide Evolution’s content to British players. The UKGC’s director of enforcement stated that Evolution’s approach created a significant gap between documented controls and their real-world effectiveness. Evolution’s response included terminating the operator relationships and materially increasing investment in ring-fencing technology.

“Their AML assessment was outdated and failed to adequately consider the risk posed by unlicensed operators distributing their games, creating a significant gap between documented controls and their real-world effectiveness.”, UKGC Director of Enforcement, John Pierce

The Evolution settlement is not an AML case repurposed as a geolocation precedent. It is a direct finding that a B2B supplier bears liability for the territorial reach of its content distribution, and that the supplier’s documented controls must match real-world effectiveness. For any B2B supplier relying on downstream operators to implement adequate geoblocking, this case is the operative risk model. Documented controls that are not operationally implemented offer no protection.

The MGA’s Compliance Audit Manual (MGA/G/001) and its Technical Infrastructure guidelines for Remote Gaming require licensees to maintain the integrity and availability of gaming and financial transaction logs at all times, and confirm that accountability for all technical standards rests with the licensee regardless of third-party infrastructure. The MGA’s audit procedures test whether technical controls are implemented and functioning, not merely documented. For MGA licensees using third-party location services, the accountability principle means that a third-party service failure is a licensee compliance failure.

Comparing the Four Regulatory Frameworks

Dimension UKGC MGA DGE (New Jersey) AGCO (Ontario)
Location standard type Outcomes-based (RTS); enforcement-defined Outcomes-based, audit-tested Prescriptive rule (Chapter 69O) Standards-based with mandatory requirements (RStIG 3.02)
IP-only geolocation accepted? No, enforcement has penalised bypass No, audit tests implementation No, system must confirm patron location No, dynamic monitoring required
VPN/proxy detection required? Expected, covered by ring-fencing obligation Implied under technical integrity Covered by system security standards Explicit, Standard 3.02.2
Re-verification during session? Yes, ongoing, no fixed interval specified Yes, continuous availability required Yes, session integrity maintained Yes, reasonable intervals (Standard 3.02.1)
Pre-launch evidence obligation? No formal pre-launch validation gate Audit-triggered post-launch Internal controls filed before implementation Technology Compliance Confirmation required before go-live
B2B supplier liability? Yes, enforcement precedent established Yes, licensee accountability principle Operator-led, affiliate arrangements regulated Operator and supplier both accountable
Key reference RTS, Gambling Act 2005 MGA/G/001, Tech Infrastructure guidelines N.J.A.C. 13:69O-1.2(e) RStIG 3.02, Go-Live Compliance Guide

What Passes Certification Does Not Guarantee Enforcement Survival

The gap between certification and enforcement readiness is the central operational risk in location-control compliance. GLI certification of a geolocation module confirms the architecture met the relevant GLI standard at the time of test. It does not confirm that the module functions correctly across every device type, network configuration, or circumvention technique your players will actually use. The AGCO’s go-live evidence requirement closes part of this gap for Ontario by requiring pre-launch validation across expected device and network types. The DGE’s annual independent assessment creates a recurring audit point. Neither the UKGC nor the MGA has a formal pre-launch technical gate for location controls, meaning the first substantive test may occur during an enforcement investigation.

GLI-19’s Location Service Provider Audit requirement, in Section C.5.1, requires the operator or third-party location service provider to undergo a specific audit to assess and measure its continued ability to detect and mitigate existing and emerging location fraud risks. The word “continued” confirms this is a recurring obligation. A location service that was audited at certification and then not re-evaluated as new circumvention techniques emerge is not meeting the standard. Compliance teams should build a regular review cadence into their contract terms with location service providers, treating the initial certification as the floor rather than the finish line. For an overview of how the GLI certification pathway interacts with jurisdiction acceptance, the GLI Certification hub provides the relevant architecture.

Enforcement actions across multiple jurisdictions in 2026 illustrate the enforcement dynamic for operators who deploy inadequate or homegrown geolocation. According to industry sources, regulators stated that some operators’ geolocation solutions either did not function correctly or were not being implemented. Critics specifically contrasted inadequate approaches with proven third-party solutions that had been rigorously tested. Regulatory responses in multiple states included immediate injunctive action. The pattern confirms what enforcement precedent has established at the supplier level: inadequate location controls carry both financial and operational licence risk.

Building a Defensible Architecture

A compliance-grade location control architecture for a multi-jurisdictional operator requires layering all three mechanisms while understanding the regulatory function each serves. Active geolocation with a confidence-radius methodology, using multiple data sources (GPS, Wi-Fi, GSM) rather than IP address alone, is the primary obligation. It must re-verify location at the intervals each jurisdiction specifies: 30 minutes under GLI-33, reasonable intervals under AGCO Standard 3.02.1, and session-continuous under the DGE’s system integrity requirements. All violations must be logged with player IDs, timestamps, and detected locations.

IP blocking sits at the perimeter as a first filter and as a VPN and proxy detection mechanism. It reduces the volume of out-of-jurisdiction connection attempts that reach the geolocation layer, but it cannot substitute for that layer. The GLI-33 requirement to examine IP address upon each connection explicitly positions this as fraud detection rather than location verification. Operators should maintain updated IP databases that include commercial VPN, proxy, and datacenter ranges, and should treat any connection from a known VPN exit node as requiring enhanced scrutiny rather than automatic pass.

Device fingerprinting operates as the anti-tamper layer. Its regulatory mandate under GLI-19 and GLI-33 is to detect system-level tampering including rooting, jailbreaking, virtualisation, and remote desktop activity. These are the technical vectors through which a player can present a false location to an otherwise functional geolocation service. A fingerprinting solution that is not updated to detect current tampering techniques is not meeting the standard, and the obligation to update falls on the operator, not just the location service provider.

For B2B suppliers providing gaming content to operators across multiple jurisdictions, enforcement precedent is the operative guideline. Documented ring-fencing controls must be operationally effective. Supplier compliance teams should confirm, for each distribution relationship, whether the downstream operator’s location controls meet the standards of the jurisdiction being served. Where a B2B supplier cannot confirm this, the risk sits with the supplier.

Operators requiring detailed legal analysis of jurisdiction-specific location control obligations should engage qualified legal counsel in each relevant jurisdiction, particularly where reciprocal gaming agreements, pooled liquidity arrangements, or multi-provincial operations introduce cross-border complexity into the territorial restriction framework. For a broader grounding in the AGCO’s standards-based approach and how it applies to technical obligations across the Ontario framework, the AGCO regulatory profile is the appropriate starting point. To begin a location control audit or technical review, consult your regulatory affairs team or qualified compliance advisor in your jurisdiction.

Key Resources

GLI-19 Standards for Interactive Gaming Systems v3.0, Gaming Laboratories International. Sections 2.7 (Location Requirements) and C.5 (Location Services). Available at gaminglabs.com.

GLI-33 Standards for Event Wagering Systems v1.1, Gaming Laboratories International. Location Fraud Prevention and Location Service Provider Monitoring sections. Available at gaminglabs.com.

AGCO Registrar’s Standards for Internet Gaming, Alcohol and Gaming Commission of Ontario. Standard 3.02 and accompanying requirements 3.02.1 and 3.02.2. Updated 29 May 2025. Available at agco.ca.

AGCO Internet Gaming Go-Live Compliance Guide, Alcohol and Gaming Commission of Ontario. Technology Compliance Confirmation requirements for Standard 3.02 controls. Available at agco.ca.

N.J.A.C. Chapter 69O, Internet and Mobile Gaming, New Jersey Division of Gaming Enforcement. Subsections 13:69O-1.2 (General requirements) and 13:69O-1.4 (System standards and operational controls). Available at njconsumeraffairs.gov.

AGLC Standards and Requirements for Internet Gaming (SRIG), Alberta Gaming, Liquor and Cannabis. Section 4.2 (Location Requirements). Issued in March 2026. Available at aglc.ca.

Matt Denney

Matt Denney

Editorial · gamingcompliance.io

Reads the primary source so you don't have to. Fifteen years inside iGaming compliance: operator, supplier, and crown-corporation lottery.

Related coverage · also tagged Technical Standards

Browse all →

Technical Standards

Alberta iGaming: Geolocation, IP Blocking, and Cross-Provincial Player Rules Under the SRIG

Aug 4 · 16 min read

Technical Standards

Seed Value Logging and RNG Audit Trails: What Regulators Actually Inspect

Jul 9 · 14 min read

Technical Standards

Live Dealer Casino in Alberta: Studio Approval, Streaming Standards, and AGLC SRIG Requirements

Jun 20 · 16 min read

The Tuesday brief, every week.

One email. Every regulator change we surface, every standard we re-index, every enforcement decision we read. No marketing, no fluff.

Unsubscribe with one click. We'll never share your address.