Charity

Seit meiner Jugend engagiere ich mich mit viel Herzblut für Projekte, die ich für wichtig und unterstützenswert halte. Ich hatte das große Glück, dass soziales Engagement in meiner Familie immer groß geschrieben wurde. Wir wurden schon sehr früh motiviert mit offenen Augen durch unsere Welt zu gehen, aufmerksam zu sein, nach rechts und links zu schauen. Denn es gibt wirklich unzählige Möglichkeiten wie man sich einbringen und einsetzen kann. Bei mir fing es damit an, dass ich als Schülerin auf die Barrikaden gegangen bin, wenn Tiere für die Herstellung von Kosmetikprodukten leiden mußten und gequält wurden. Dass war dann auch das erste Mal, dass ich auf die Arbeit von PETA aufmerksam wurde.

Später habe ich dann angefangen regelmäßig als Jugend-Gruppenleiterin mit Kindern und Jugendlichen aus vorwiegend sozialschwachen Familien zu arbeiten, Projekte anzuschieben und mit ihnen auf betreute Reisen zu gehen.

Es gibt so viele Möglichkeiten sich in seinem Umfeld zu engagieren – und das hat nichts mit Geld zu tun – viel mehr mit Interesse, etwas Zeit und dem Glauben an das, was man unterstützt und voran treibt. Herzblut eben!

An dieser Stelle möchte ich euch auf den nachfolgenden Seiten einige Projekte etwas näher vorstellen, die seit vielen Jahren mein Leben begleiten – und wer weiß, vielleicht habt ihr ja Lust euch selbst zu engagieren!

How Payment Security Standards Protect UK Bettors, Based on Our Analysis at Betzella

When UK residents place bets online, they are sharing financial data with platforms that process billions of pounds in transactions each year. The UK Gambling Commission reported that the remote gambling sector generated gross gambling yield of approximately £6.9 billion in the 2022–2023 period, meaning the volume of payment data flowing through these systems is enormous. What stands between a bettor’s bank details and potential fraud is a layered architecture of security standards, regulatory mandates, and technical protocols that have evolved significantly over the past two decades. Understanding how these systems work gives bettors a clearer picture of where their money is actually protected — and where gaps can still exist.

PCI DSS: The Foundational Standard for Card Data Protection

The Payment Card Industry Data Security Standard, universally abbreviated as PCI DSS, was established in 2004 through a collaboration between Visa, Mastercard, American Express, Discover, and JCB. It was formalised under the Payment Card Industry Security Standards Council, which was founded in 2006. Any business that stores, processes, or transmits cardholder data must comply with PCI DSS, and online gambling operators accepting card payments are no exception.

PCI DSS version 4.0, released in March 2022, introduced significant changes from the previous 3.2.1 version. One of the most consequential updates was the expanded focus on multi-factor authentication, now required for all access into the cardholder data environment rather than just administrative access. The standard also introduced a more flexible, customised approach to compliance, allowing organisations to demonstrate security objectives through alternative methods rather than prescriptive controls — a shift that acknowledges how diverse modern payment architectures have become.

For UK bettors, PCI DSS compliance means that a licensed operator cannot store the full 16-digit card number alongside the CVV and expiry date in plain text. Tokenisation — the process of replacing sensitive card data with a non-sensitive equivalent called a token — is the dominant method operators use to meet this requirement. When a bettor saves a card for future deposits, the platform typically stores a token issued by a payment processor, not the actual card number. The real data sits in the processor’s secure vault, which operates under the most stringent PCI DSS compliance tier, known as Level 1.

UK Regulatory Requirements and the Role of the FCA

PCI DSS is an industry standard, not a law. In the UK, the legal framework for payment security is shaped primarily by the Financial Conduct Authority, which supervises payment service providers under the Payment Services Regulations 2017 — the domestic implementation of the European Union’s revised Payment Services Directive, known as PSD2. Although the UK left the EU, the Payment Services Regulations 2017 remain in force and the FCA has continued to develop its own supervisory approach independently since Brexit.

One of the most visible outcomes of PSD2 implementation is Strong Customer Authentication, or SCA. Introduced in phases between 2019 and 2021, SCA requires that electronic payments above certain thresholds be authenticated using at least two independent factors from the categories of knowledge (something the user knows), possession (something the user has), and inherence (something the user is). In practical terms, this is why UK bettors making a deposit will frequently encounter a prompt from their bank asking them to approve the transaction through their banking app, enter a one-time passcode sent by SMS, or use biometric verification.

The UK Gambling Commission adds another layer. Its licence conditions require operators to conduct customer due diligence and maintain anti-money laundering controls under the Proceeds of Crime Act 2002 and the Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017. These obligations intersect with payment security because they mandate that operators verify the source of funds for high-value transactions, which simultaneously protects the operator from being used as a conduit for financial crime and protects bettors from fraudulent accounts being opened in their name.

Analysis published at http://betzella.com/ reflects how these regulatory layers interact in practice, particularly in how licensed platforms balance friction in the payment journey against the security obligations imposed by both the FCA and the Gambling Commission — a balance that has become increasingly complex as real-time payment rails have expanded.

Encryption, TLS Protocols, and the Technical Layer of Protection

Beyond compliance frameworks, the actual security of payment data in transit depends on Transport Layer Security, the cryptographic protocol that encrypts data moving between a bettor’s browser or app and the operator’s servers. TLS 1.2 became the baseline standard around 2015, and TLS 1.3, which was finalised by the Internet Engineering Task Force in August 2018, offers meaningful improvements including reduced handshake latency and the elimination of several cipher suites that had proven vulnerable to downgrade attacks.

Operators subject to PCI DSS version 4.0 are required to disable earlier SSL and early TLS versions, meaning that a properly compliant UK gambling platform should only be negotiating connections using TLS 1.2 or 1.3. Bettors can verify this independently through browser developer tools, which display the protocol version used for any given connection. A padlock in the browser address bar indicates an encrypted connection, but it does not by itself confirm the protocol version or certificate validity beyond the basics.

Certificate management is another area where technical security meets operational discipline. Extended Validation certificates, while no longer displaying the green address bar in most modern browsers since 2019, still provide a higher level of identity verification than Domain Validation certificates. An operator using an EV certificate has undergone verification of its legal entity, not just its domain ownership. For bettors, this distinction matters when assessing whether a platform has invested in a more rigorous identity verification process for its web presence.

Betzella’s analysis of payment infrastructure across licensed UK operators also highlights the growing role of 3D Secure 2.0, the updated authentication protocol that replaced the original 3D Secure standard. The original version, introduced in 1999, was widely criticised for its poor user experience and high cart abandonment rates. 3D Secure 2.0, developed by EMVCo and rolled out from 2019 onwards, supports risk-based authentication, meaning that low-risk transactions can be processed with minimal friction while higher-risk ones trigger additional verification steps. This risk-scoring approach uses data points including device fingerprinting, transaction history, and geolocation.

Open Banking and Emerging Payment Methods: New Security Considerations

The expansion of open banking in the UK, facilitated by the Open Banking Implementation Entity established following the Competition and Markets Authority’s 2016 retail banking market investigation, has introduced new payment pathways that carry their own security architecture. Under open banking, bettors can authorise direct account-to-account payments without entering card details at all, removing a significant category of data exposure. The payment is authenticated through the bettor’s own bank interface, which is subject to the bank’s own SCA implementation.

By the end of 2023, the UK had approximately 7 million active open banking users according to data from the Open Banking Implementation Entity, and adoption within the gambling sector has grown as operators seek alternatives to card payments following the UK Gambling Commission’s credit card gambling ban, which took effect in April 2020. That ban, which prohibited the use of credit cards for gambling transactions, pushed operators and bettors toward debit cards, e-wallets, and bank transfer methods — all of which have distinct security profiles.

E-wallets such as PayPal, Skrill, and Neteller introduce an intermediary layer that means the gambling operator never directly handles the bettor’s bank account or card details. The security of the transaction then partly depends on the e-wallet provider’s own compliance posture, which is regulated separately under the FCA’s e-money institution framework. Neteller and Skrill, for instance, are both regulated by the FCA as e-money institutions, meaning they are subject to the Payment Services Regulations 2017 and their own PCI DSS obligations.

Cryptocurrency deposits, while offered by some operators, sit outside most of these frameworks. There is no PCI DSS equivalent for blockchain transactions, and the FCA’s registration regime for cryptoasset businesses under the Money Laundering Regulations focuses on anti-financial crime controls rather than consumer data protection in the traditional sense. Betzella notes that bettors using cryptocurrency should understand that the pseudonymous nature of blockchain transactions does not equate to the same consumer protection infrastructure that governs card and bank transfer payments.

The cumulative effect of PCI DSS compliance, FCA-mandated SCA, TLS encryption, 3D Secure 2.0 risk authentication, and the structural shift away from credit card payments creates a substantially more secure environment for UK bettors than existed even a decade ago. However, security standards are not static guarantees — they are maintained through continuous audit cycles, technology updates, and regulatory oversight. A bettor’s most practical protection remains using licensed operators that appear on the UK Gambling Commission’s register, verifying that payment pages use current TLS protocols, and enabling strong authentication on any e-wallet or banking app used for gambling transactions.

Neben den Projekten bei denen ich Schirmherrschaften oder Patenschaften übernommen habe, habe ich vor einigen Jahren auch meinen eigenen Verein HerzPiraten gegründet. Zu all dem und noch mehr findet ihr hier alles Wichtige  Viel Spaß beim einlesen!