Fanatics fined US$20,000 for Colorado self-exclusion breach

4 September 2026 at 7:51am UTC-4
Email, LinkedIn, and more

The Colorado Limited Gaming Control Commission has issued a US$20,000 fine to Fanatics after the brand sent promotional messages to a customer who had enrolled in Colorado’s self-exclusion program.

The fine was issued during the Commission’s monthly meeting, following an agreement between Fanatics and the Colorado Division of Gaming over the violation.

Article continues below ad
GLI email

The customer signed up for a five-year self-exclusion from Fanatics Sportsbook in January 2026. Despite this, a member of the operator’s VIP team sent the individual a promotional text message the following month on 1 February, followed by a second promotional message on 17 February.

Fanatics identified the issue after the first message and notified its VIP leadership team, with the operator then distributing training materials to customer-facing VIP staff and acknowledging the violations as part of its agreement with the Colorado Division of Gaming.

Under the state’s sports betting regulations, licensed operators like Fanatics must follow responsible gaming requirements, including preventing those who have signed up for self-exclusion from receiving direct marketing via text message, phone calls, and emails.

Article continues below ad
G2E web email

Colorado’s self-exclusion program allows individuals to voluntarily block themselves from regulated gambling in the state for one, three, or five years.

Fanatics had also committed through its responsible gaming strategy not to intentionally market to known self-excluded individuals.

In addition to paying the US$20,000 fine to the Colorado Division of Gaming, Fanatics must also conduct an audit of its self-exclusion list in relation to text-messaging marketing sent between January 2024 and March 2026.

Article continues below ad
PayNearMe

It must also improve regulatory risk and responsible gaming training for all VIP staff members.

This comes as Colorado continues to strengthen customer protections across its regulated sports betting market, with state lawmakers passing SB 26-131, which would prohibit credit card use for online betting and establish restrictions to prevent excessive gambling, back in May.

CiG Insignia
Locations:
Verticals:
Sectors:

Dig Deeper

The Backstory

Self-exclusion breaches move to the center of enforcement

Colorado’s US$20,000 fine against Fanatics fits into a broader regulatory pattern: self-exclusion systems are no longer being treated as passive databases that operators can check after the fact. They are now core compliance infrastructure, and failures tied to marketing, account access or VIP handling are drawing enforcement even when the breach is limited in scope.

The Fanatics case was narrow but instructive. A customer enrolled in Colorado’s self-exclusion program for five years in January 2026. The next month, a member of the operator’s VIP team sent that person two promotional text messages. Fanatics identified the issue after the first message, alerted VIP leadership and distributed training material, but the second message still followed on Feb. 17. The Colorado Limited Gaming Control Commission accepted a settlement that requires the company to pay the fine, audit text-message marketing against its self-exclusion list from January 2024 through March 2026 and improve training for VIP staff.

The size of the penalty is modest by industry standards, but the facts place it within a larger debate about whether sportsbooks’ customer-retention systems are built to defer to responsible gambling protections. Colorado regulators did not allege that the customer gambled after enrolling. The violation was the contact itself — direct marketing to someone who had taken formal steps to be blocked from gambling.

Australia has shown how quickly failures can scale

The most severe recent example came in Australia, where Betchoice Corp., trading as Unibet, was fined AU$1,014,120 after the Australian Communications and Media Authority found more than 100,000 violations tied to the country’s National Self-Exclusion Register. As reported in Unibet’s penalty for Australian self-exclusion failures, the regulator found that 954 customer accounts were not closed after users joined the register. Forty-five accounts remained open for at least 190 days.

That case underscored a key regulatory principle: harm does not need to materialize as a wager for a breach to matter. The ACMA said the accounts should have been closed promptly even though self-excluded customers did not bet during the exclusion period. It also found that 45 customers were later able to use old accounts after their self-exclusion ended, rather than being required to open new ones, allowing thousands of bets.

Australia’s framework is explicit. Once a person registers with BetStop, wagering providers must close linked accounts, stop marketing and prevent the person from using online betting services for the exclusion period. The rules also treat account reactivation after exclusion as a compliance risk, requiring a new account rather than reopening an old one. The national register’s public guidance says self-exclusion can run from three months to a lifetime through BetStop’s self-exclusion periods.

Colorado’s case differs in scale and law, but the logic is similar. A self-excluded person has made an affirmative request not to be contacted or enabled. Regulators increasingly view operator systems as responsible for honoring that request automatically, including across marketing teams that may sit outside core compliance functions.

Marketing has become a particular flashpoint

Marketing to self-excluded customers has become one of the clearest regulatory red lines because it directly conflicts with the purpose of exclusion. In Australia, the ACMA recently warned Buddybet, Ultrabet, Topbet and VicBet after finding they sent marketing material to people registered with BetStop. As detailed in the Australian regulator’s warning to betting companies, Buddybet also failed to close accounts connected to self-excluded customers.

Those enforcement actions show that regulators are looking beyond whether bets were accepted. They are examining whether operators have integrated exclusion lists into customer relationship management tools, promotions systems, email databases, text campaigns and account workflows. The practical compliance challenge is that marketing systems are often segmented by brand, channel, product and customer tier. A user excluded in one part of the system must be suppressed everywhere else.

That is why the Fanatics audit requirement is significant. Colorado regulators did not stop with a fine for the two texts. They required the operator to review text-marketing activity over more than two years against self-exclusion records. That kind of retrospective audit can expose whether an incident was isolated or part of a broader systems gap.

The Colorado order also puts VIP departments under scrutiny. VIP teams are designed to provide individualized service, fast responses and tailored engagement. Those same features can increase regulatory risk if staff members rely on manual judgment, fragmented customer notes or incentives to maintain contact with high-value accounts. In self-exclusion cases, the compliance expectation is binary: the customer is off-limits.

VIP programs face scrutiny beyond exclusion lists

The Fanatics matter landed as VIP programs across the U.S. betting industry were already drawing political and regulatory attention. FanDuel recently rejected calls to shut down its VIP program after Sen. Richard Blumenthal and Reps. Paul Tonko and Valerie Foushee asked the operator about its treatment of high-value customers and its use of personalized promotions. The inquiry followed allegations by a former VIP customer who said the operator exploited his gambling addiction after he placed US$18.5 million in bets and lost more than US$1.5 million.

In FanDuel’s response to congressional pressure over VIP practices, the company said VIP customers are covered by the same responsible gambling safeguards as other users and that VIP staff receive responsible gambling training. It also said VIP employees are paid fixed salaries rather than commissions tied to betting or losses.

The FanDuel episode and the Fanatics fine involve different companies and different allegations, but they point to the same tension. Operators say VIP programs are customer service functions. Critics say they can become retention engines for customers who may be showing signs of harm. Regulators are now testing whether responsible gambling controls work inside those programs, not just in standard account-opening and wagering systems.

For Fanatics, the Colorado breach was a direct self-exclusion violation rather than a broader allegation about inducement. Still, the involvement of a VIP staff member matters. It shows why training, account flags and automated suppression tools must reach employees who communicate one-to-one with customers, not just bulk marketing teams.

Colorado is pairing penalties with prevention

Colorado has moved on both enforcement and education as its sports betting market matures. The state’s self-exclusion program allows people to block themselves from regulated gambling for one, three or five years. Licensed operators must prevent those individuals from receiving direct marketing by text message, phone or email, and Fanatics had also committed not to intentionally market to known self-excluded customers through its responsible gaming strategy.

The state also has pursued preventive initiatives. The Colorado Division of Gaming arranged a partnership between IC360 and the Problem Gambling Coalition of Colorado to bring gambling education to college-aged people at NCAA institutions, junior colleges and community colleges. The effort, described in IC360’s partnership with the Problem Gambling Coalition of Colorado, was framed as a way to provide tools and information before gambling harms develop.

That preventive approach is relevant to the Fanatics action because young adults and highly engaged bettors are central to the online sports betting market. Education can reduce risk, but regulators still expect operators to maintain hard controls once a customer self-excludes. The policy model is increasingly two-track: inform consumers before harm escalates and punish companies when they fail to honor formal limits.

Colorado lawmakers have also shown interest in tightening the market’s guardrails. In May, they passed SB 26-131, which would prohibit credit card use for online betting and establish restrictions intended to prevent excessive gambling. The Fanatics settlement therefore arrives amid a broader push to reduce frictionless betting behaviors and strengthen customer protections.

State-by-state penalties point to a national compliance test

Self-exclusion enforcement is not confined to Colorado or Australia. In Pennsylvania, regulators fined operators a combined US$282,205, with the largest penalty issued to BetMGM for 152 instances in which a person on the Pennsylvania Gaming Control Board’s self-exclusion list was allowed to gamble. The action, covered in Pennsylvania’s gaming fines against igaming operators, reinforced that licensed online operators must prevent self-excluded people from signing up or placing real-money wagers.

Taken together, the cases show a maturing enforcement environment. Early U.S. sports betting oversight focused heavily on licensing, tax revenue, geolocation and market access. Responsible gambling compliance is now becoming more operational and evidence-based. Regulators are asking whether exclusion data flows properly through marketing systems, VIP programs, account closures, reactivation rules and betting platforms.

The stakes for operators are larger than individual fines. Self-exclusion programs depend on public trust. If customers believe exclusion will not stop marketing or account access, the tool loses credibility. For regulators and lawmakers, that can justify stricter rules on advertising, payments, VIP treatment and platform design.

Fanatics’ penalty is therefore best understood as a warning shot. A two-text breach produced a fine, a multiyear audit and mandated training upgrades. In a market where customer engagement tools are sophisticated and personalized, regulators are making clear that responsible gambling blocks must be just as precise.