Custom casino app development for licensed operators in the Netherlands.
A native casino, sports betting or lottery app that complies with the Dutch Remote Gambling Act (Wet Kansspelen op Afstand). Includes CRUKS integration, duty-of-care layer, Wwft onboarding and GLI-19-compliant RNG from the first sprint, not as a last-minute tick box before release.
Since 1 October 2021, the Dutch online gambling market has been open to licensed operators. The Remote Gambling Act (KOA) and its accompanying Decree on Remote Gambling impose a dense set of technical, organisational and duty-of-care requirements that go well beyond what an ordinary B2C app needs to do. The Dutch Gaming Authority (Kansspelautoriteit, KSA) assesses not only organisation and policy, but the technology itself: how the game flow is structured, how the integration with the Central Exclusion Register for Gambling (CRUKS) works, how duty-of-care interventions are embedded in the software, and how gameplay transactions are stored in the Control Database.
We build casino, sports betting and lottery apps for parties active in that field or wanting to become so. Not a front end on a rented platform with your logo on it, but custom applications in which your own wallet, your own duty-of-care model and your own brand play the central role. For the generic app layer we draw on our app development practice, for the wallet and payout layer on our payment platform work, and for the security stack required by the KSA (Dutch Gambling Authority) and our own information security policy baseline, we rely on the patterns from ISO 27001-compliant software development.
The gambling market this app is entering is concentrated: a handful of large licence holders — Holland Casino Online, TOTO, Unibet, Bet365, BetCity — dominate visibility, alongside niche licence holders in poker, horse racing, esports or fantasy sports. The difference between winning and losing rarely lies in the slots library (Pragmatic Play, Evolution, Play'n GO, NetEnt), which is largely shared. It lies in registration conversion, the speed of Wwft onboarding, how natural the duty-of-care layer feels, and how retention mechanisms work without crossing the line set by Borka.
Three types of gambling app we build.
Not every licence holder is the same. We broadly map our work to three use cases, depending on licence type, target audience and which game types fall under your KSA licence.
For casino and slot operators · fixed sprint budget
Native casino app with external game providers
An iOS and Android app for a casino licence holder that controls its own wallet, accounts, duty-of-care features and data, while integrating slots, table games and live casino from external providers (Pragmatic, Evolution, NetEnt) through standardised aggregator integrations. The app is built natively for performance, supports distribution via the App Store and Google Play within the rules both stores set for gambling products, and has a full-stack wallet layer that manages balances, bonuses, free-play vouchers and deposit limits. Onboarding runs through iDIN or bank account linking, with automated KYC and sanctions list screening.
Own wallet managementProvider aggregatoriDIN onboardingLive casino streaming
For sports betting and racing operators · fixed sprint budget
Sports and betting app with live odds
A native app for sports betting licence holders with live odds from a feed provider (Sportradar, Betgenius, Stats Perform), a match catalogue with deep markets per event, in-play betting and cash-out, plus a horse racing or esports strand where your licence permits. The odds engine and risk management remain with the feed supplier or your own trading desk; we build the mobile betting experience, bet slip management, the promotions engine and the duty-of-care layer around it. Push notifications are configured to the KSA guideline on responsible marketing, and bonuses follow the Borka restrictions.
Live odds feedsIn-play bettingCash-outTrading desk integration
For lottery, social casino or fantasy sports · fixed sprint budget
Lottery, fantasy sports or social casino without real-money stakes
For state lottery or lotto operators, fantasy sports platforms and social casino apps that fall outside KOA because there is no real-money stake, or that sit within a differently defined licence category. Here the regulation is weighted differently — Wwft is sometimes less relevant, but in-app purchases under the App Store and Play Store policies are not, and the duty-of-care architecture remains important for preventing cross-border play and catching the transition to gambling for money. We build the same audit trail and monitoring foundation there, as this also adds value for a free-to-play proposition for advertising partners and regulators.
In-app purchasesSocial leaderboardsFree-to-playLottery draws
What a KSA-compliant casino app can do as standard.
A list of features that almost always appear in a Dutch casino, sports betting or lottery app. Not everything needs to be in version one, but the KSA requirements span almost every layer, so delaying a single compliance feature means delaying the entire release.
Real-time CRUKS integrationEvery login attempt is checked against the Central Exclusion Register for Gambling (CRUKS). Players registered in CRUKS are refused without ever placing a stake, and existing sessions are ended immediately if a player appears in CRUKS during play.
Wwft onboarding and KYCIdentity verification via iDIN or an accredited KYC provider, sanctions list screening, PEP checks and risk-based enhanced due diligence. A full audit trail for each step, so the KSA regulator and your own compliance officer can reconstruct every onboarding.
Self-exclusion and cooling-offIn-app self-exclusion that can be set by the player and passed directly on to CRUKS, short and long cooling-off periods, and a return flow with a mandatory duty-of-care conversation. No hidden menus or dark-pattern friction: manageable within two taps from any screen.
Loss, deposit and time limitsPlayer-set limits for daily, weekly and monthly losses and deposits, plus the default limits the Betting and Gaming Act requires for new accounts. Reductions take effect immediately, while increases only apply after the statutory waiting period and with explicit confirmation.
Duty-of-care intervention engineA behavioural model that monitors playing time, stake escalation, losing streaks and session length. When signal thresholds are met, a built-in intervention is triggered: a pop-up, a cool-down pause, a call from an agent or an automatic temporary suspension. The decision model is periodically validated against gambling research.
RNG and GLI-19 complianceFor in-house games: certified RNG with independent audit. For external slot and game providers: a certification chain the KSA accepts, with traceability on every game round down to the hash seal.
Control Database integrationEvery gameplay transaction, deposit, withdrawal, bonus award and duty-of-care event is mirrored in real time to the Control Database, as the KSA requires. Immutable storage with audit-proof hashing.
Wallet, deposits and withdrawalsA proprietary wallet with balances, bonus pots and pending withdrawals, linked to iDEAL for deposits and bank transfer for withdrawals. No credit cards for deposits, in line with KOA guidance, and withdrawals only to a previously verified bank account in the player's name.
Age verification and account verificationStrictly 24+ for high-risk game types and 18+ for the rest, with verification via iDIN or passport scan at the time of the first deposit. No demo or access for minors, including for screenshots of games.
Reality checks and session monitoringPeriodic notifications about session length and net stake within a game, with explicit confirmation required to continue playing. Optional auto-logout after a duration set by the player, and a dashboard with play history that the player can always consult.
Borka-compliant push and in-app marketingNo untargeted advertising to 18 to 24-year-olds, no push messages to self-excluded or cooling-off players, and an opt-out layer that can be managed per channel and frequency. Promotions with clear stake and wagering conditions, displayed in plain Dutch.
End-to-end encryption and EU data residencyTLS 1.3 in transit, AES-256 at rest, key management in an EU HSM, and no US region in either primary or backup. Gaming account data and duty-of-care events are treated as special category personal data with separate access controls.
Fraud and collusion detectionReal-time monitoring for bot behaviour, multi-accounting, collusion between accounts in arbitrage, and chargeback abuse. Triggers are followed up both manually and automatically, with an audit trail to the risk function.
Audit export for the KSA and your accountantOne-click exports for regulatory reporting, accountant review and any incident investigations. Standard formats in which the KSA guidelines and your own internal audit function can read the material without a translation key.
When custom is the right choice.
Many licence holders start on a white-label platform from a provider such as Playtech, EveryMatrix or Pronet Gaming. For a first launch, that is a sound route: fast time-to-market, and much of the compliance is already covered by regulation. However, there are four moments when custom development becomes the better choice.
Your own brand experience
Differentiation beyond generic white-label UX
You find that your brand and your promises to customers are getting lost in a UI that also runs for five of your competitors. The duty-of-care tone, the promotions layer and the retention flow get stuck on standard components you cannot adapt. A dedicated native app is then the logical next step.
Wallet and data under your control
You want to own the player data
On a white-label, the wallet, CRM and responsible-gaming engine sit with your platform provider. When the contract ends or a vendor issue arises, migrating is a nightmare. With your own wallet and back-end layer, you own the relationship and can switch providers (slots, sportsbook) without your players noticing.
Verticals beyond the standard
Niche verticals such as poker, esports or horse racing
Standard white-labels cover slots, live casino and sportsbook well, but for a poker room, a horse-racing app or an esports betting platform the standard flow falls short. A custom app in which your vertical specialism takes centre stage is often the only route.
Leadership in duty of care
You want to go beyond the KOA minimum
The KSA raises the bar on duty of care in the market every year. Operators who do not wait for tightening, but want to lead themselves with a sophisticated responsible-gaming engine (player-level behavioural modelling, early-signal intervention, agent coaching tools), rarely achieve that layer on a white-label at their own pace.
From land-based to online
Licensed physical casinos expanding digitally
You hold a physical casino licence and want to launch an online offering alongside your venue. A white-label leaves the cross-channel layer untouched: loyalty across on-property and mobile, a single wallet across locations, on-property activation via QR. Custom development is often the only way to deliver that omnichannel story.
How a project for a licensed operator runs.
Building a casino app for the Dutch market is not the same as building a consumer app. We work through a number of steps that take the KSA review into account from the outset, so that the application or change notification does not run into technical surprises.
1
Introduction and licence context
We discuss which type of licence you hold or are applying for, which gaming verticals it covers, whether there is a group structure with an EU licence behind it, and which supplier relationships are already in place (white-label, sportsbook feed, providers). That determines the direction of the project scope.
2
Compliance blueprint
Together with your compliance officer, legal adviser or external KSA consultant, we produce a blueprint: what the CRUKS integration looks like, which duty-of-care architecture, which Control Database implementation and which audit flow. This blueprint becomes the framework for the build and the basis for the notification file submitted to the KSA.
3
Architecture and security design
Tech stack choice (native iOS and Android), backend on EU cloud, encryption approach, wallet architecture, integration blueprint with providers and feeds. For the security layer we draw on the patterns from ISO 27001-compliant software development, particularly for key management, access control and logging.
4
Build in sprints with a compliance review per release
A working build every two weeks. A test group, usually your own internal KSA officer plus a number of compliance staff, plays in a staging environment with a test CRUKS integration. Each sprint closes with a short compliance review before the feature may go live.
5
Penetration test, RNG audit and KSA certification file
External penetration test of the app and backend, RNG and game-flow audit by a GLI- or eCOGRA-accredited lab where relevant, and compilation of the certification file that accompanies your KSA application or change notification. Issues raised by the penetration test and audit are resolved before go-live.
6
Soft launch and ongoing maintenance
Phased rollout, first to a closed test group and then to a wider audience, with publication on the App Store and Google Play in line with the rules both stores set for gambling apps. After that, ongoing maintenance covering security patches, regulatory changes and further development of the duty-of-care layer.
Tech stack and architecture choices.
We make a few choices early with you, because they shape the entire rest of the build and because the KSA has specific expectations for them.
Mobile stack
Native iOS and Android
For casino apps we almost always opt for native: Swift for iOS, Kotlin for Android. Cross-platform (React Native, Flutter) is fine for lighter use cases, but live-casino streaming, anti-tampering, anti-rooting and the App Store acceptance requirements for gambling products are easier to get right with native. For the back office and agent tools we often work in a React web app.
Backend
EU cloud only, with HSM keys
AWS Frankfurt, Microsoft Azure West Europe or a Tier IV EU data centre, with key management in a Hardware Security Module under EU control. No US region for primary or backup. For parties with particularly strict requirements we can run on-premises or in a private cloud setup, for example a hosted Kubernetes within your own infrastructure.
Wallet engine
Proprietary wallet layer on a hardened payment foundation
We build the wallet, covering balances, bonuses, free spins and pending withdrawals, as a service of its own rather than outsourcing it to a provider. This gives you ownership of the player relationship and makes provider changes possible. For the payment foundation we draw on our payment platform expertise, with PSD2-compliant flows, iDEAL integration and withdrawal management to accounts in the player's own name.
Game layer
Provider aggregator or proprietary RNG
For slots, live casino and table games we work with an aggregator such as SoftSwiss, Hub88, Relax or EveryMatrix Casino Engine, or directly with provider APIs. For in-house games we build the RNG and game-outcome engine to GLI-19 level, with independent audit. The choice depends on the scope of your licence and your ambitions for differentiation.
AI layer
Fraud detection and duty-of-care models
We build models for fraud detection, multi-account screening and behavioural duty-of-care signals separately, with attention to explainability and governance. For this we align with the approach from our AI development practice, including a DPIA, EU AI Act classification and human review of critical interventions.
Identification and signing
iDIN, eIDAS and account verification
Identification via iDIN as the main route for Dutch players, with a fallback to passport scan plus a KYC provider for edge cases. For self-exclusion confirmations and limit increases, where it carries significant legal weight, we use an eIDAS-compliant signing flow so that consent holds up as evidence.
Compliance frameworks we design against as standard.
With a KOA app, compliance isn't an extra check; it's the architecture. These are the frameworks we design into every project from sprint one.
A
Remote Gambling Act (Wet Kansspelen op Afstand) and the Remote Gambling Decree (Besluit kansspelen op afstand)
The parent Act and its implementing decree set the framework for who may offer games, which game types are permitted, and what player protection applies. The technical annexes to the decree cover, among other things, the Control Database, gaming system requirements and the standards the software must meet. We design to those standards and document explicitly where we touch them.
B
CRUKS — Central Register for Exclusion from Gambling (Centraal Register Uitsluiting Kansspelen)
The CRUKS integration is functionally the centrepiece of the duty-of-care layer. A check against CRUKS is made at every login and immediately before every game round. Delay in that check is not an option: if the integration fails temporarily, we end the session rather than let play continue. We build this fail-closed behaviour in by default, even when some product managers push for a smoother experience.
C
Wwft and anti-money laundering policy
Player onboarding is a trigger under the Wwft (Dutch Anti-Money Laundering and Anti-Terrorist Financing Act). Identification, sanctions list screening, PEP checks and risk-based enhanced due diligence (CDD-plus) are built into the flow. Thresholds for enhanced checks are set in the decision logic, and every onboarding step is held in an audit trail with immutable storage for the retention period the Wwft prescribes.
D
Duty of care under Article 4a of the Betting and Gaming Act (Wet op de kansspelen)
The duty of care is not a box-ticking exercise. We build a behavioural model that monitors play times, stake escalation, losing streaks and session length, with graduated interventions ranging from a pop-up to a call from an agent to temporary account closure. The decision model is periodically validated against independent gambling research and adjusted when the Gaming Authority (KSA) shifts the standard.
E
GDPR and special category personal data
Play history, duty-of-care events and KYC data are high-risk or special category personal data under the GDPR. We carry out a DPIA for every project, limit data collection to what is strictly necessary, and build retention and deletion policies into the data layer itself. Play history is automatically pseudonymised or deleted after the statutory retention period, without manual intervention.
F
Decree on untargeted advertising for remote gambling (Borka)
The advertising restrictions under Borka affect the app's marketing layer: push, in-app, email and paid channels. We build filters based on age, CRUKS status, cooling-off status and risk profile, so a campaign cannot accidentally reach a player who isn't eligible. Frequency and channel opt-outs can be set at player level.
G
GLI-19 and game outcome integrity
For the game layer (RNG, RTP, jackpot distribution and return-to-player reporting), we work to the GLI-19 standard, which the KSA accepts. For in-house games, an independent laboratory provides certification; for external providers, we only work with partners who have had their games tested to this standard.
H
App Store and Play Store policies for gambling products
Apple and Google have specific restrictions on gambling apps: proof of licence, regional restrictions, age verification, no native in-app purchase integration for real-money gambling, and separate distribution routes for some sub-categories. These policies change, so we maintain up-to-date checklists and build the release flow to respect the right subset for each category.
Frequently asked questions.
What we often hear from compliance officers, CTOs and product managers at licensed operators.
Do you also work for operators without a KSA licence?
No. We work for parties with a current KSA licence or an active application in progress, and in those cases we set up the technology in line with Dutch requirements in advance. We do not build for unlicensed operators; that would breach the Remote Gambling Act and it's not something we're willing to put our name to. For EU licence holders who specifically want to enter the Dutch market and are preparing their KSA application, we are a suitable partner.
How about App Store and Play Store acceptance?
Apple and Google have specific rules for real-money gambling apps: a valid local licence must be demonstrably in place, age verification at account level, separate distribution routes in some sub-categories, and strictly no native in-app purchase integration for real-money gambling. We build the release flow so your app complies with the current version of those policies, and we know the practical pitfalls (rejection reasons, app review questions) that often come up specifically in the Dutch market.
How often does the KSA update its standards, and how do you handle that?
The KSA regularly updates its technical standards and policy rules, for example on duty of care, advertising (Borka), CRUKS functionality and reporting requirements. We continuously monitor KSA publications and the Staatsblad and have a fixed process for implementing changes: impact analysis, implementation plan, compliance review, deployment, and notification to the KSA where required. For existing clients, this is covered under the ongoing management contract.
What is your experience with Holland Casino Online, TOTO, Unibet and Bet365?
We mention them because they are the most visible benchmarks in the Dutch market, not because we work for them. We know licence holders and CTOs at licensed operators from networking conversations and industry events, and we look at public information about their technology and duty-of-care approaches to understand the market context. We can share a reference from our current portfolio under NDA.
Can you also build a sports betting app, or only casino?
Both, and also lottery, horse racing, bingo, poker, fantasy sports and social casino variants. The shared layer (wallet, KYC, duty of care, KSA (CRUKS) integration, audit) is 70 to 80 per cent identical; the game-specific layer differs. For sports betting we often work with a feed provider and your own or an external trading desk, for casino with provider aggregators, and for lottery with an in-house draw engine or an established lottery platform partner.
How much of the compliance architecture is reusable between clients?
A lot. KSA (CRUKS) integration, Wwft onboarding, duty-of-care engine, Controledatabank pipeline and audit export are components we tailor per client to the specific licence and risk appetite, but the underlying patterns are broadly reusable. That shortens lead times and reduces the risk of compliance gaps. The game-specific layer, branding and duty-of-care tone are, of course, fully aligned with your brand and proposition.
How do you manage the risk of GDPR fines and KSA sanctions?
We build in a way that keeps privacy and compliance risks structurally low: a DPIA per project, data minimisation, granular logging, audit-proof storage, and periodic security testing. Ultimate responsibility for compliance rests with you as the licence holder, but we deliver a technical foundation that makes supervisory conversations with the KSA and the Dutch Data Protection Authority easier. Our information security policy describes the framework within which we work.
Do you work alongside our current white-label provider, or do we have to switch?
In practice it is often a gradual transition. We can start alongside your white-label setup — for example, a dedicated front-end app on the existing backend, or a specific vertical or duty-of-care layer on top of the existing platform — and take over components in stages where that adds value. A hard cutover is rarely advisable; there is too much risk of data loss, player friction and compliance gaps during the switchover.
What determines the scope and pace of such a project?
Four factors weigh most heavily: the breadth of the gaming verticals in your licence (casino, sports, lottery, poker, each adding complexity), how far you want to manage your wallet and data yourselves rather than relying on an aggregator, the level of security and duty-of-care you want to achieve beyond the KOA minimum, and whether the app needs to serve one or several EU markets. We provide a reasoned scope after the discovery phase, not a list price upfront.
A no-obligation introductory call of half an hour. We listen to your licence context, compliance approach, supplier stack and product ambitions, and give you direction you can act on. Afterwards, you and we decide whether a follow-up conversation is worthwhile.
From idea to app in one day. Validate your idea first with a working prototype.Discover OneDayBuild →
Cookies on appfront.nl
Appfront uses cookies and similar technologies to keep the website working properly, for analytics and for marketing. You choose what you allow. Read more in our privacy policy.