Dgoj license

Buying Your Way Into Spain: The M&A Route to a DGOJ Licence and Who Runs the Due Diligence

Acquiring an existing Spanish gambling operator is the fastest realistic path to market entry under the DGOJ framework. But the licence doesn’t transfer automatically — a misstep during the transaction can leave the buyer holding a company without the regulatory standing it paid for.

The acquisition route works by buying the legal entity that holds the licence. The authorisation stays inside the same corporate wrapper rather than triggering a fresh application from scratch. That compresses the market-entry timeline significantly compared with applying directly. What it doesn’t do is simplify the diligence.

Instead, the buyer inherits a layered obligation running across corporate law, tax, AML compliance, responsible-gambling history, and live regulatory standing with DGOJ — all simultaneously. Each workstream has its own specialists, its own document set, and its own capacity to kill the deal. A tax exposure and a responsible-gambling enforcement record require different experts, different questions, and different remediation logic.

The buyer who treats this as a standard M&A transaction — relying on generic financial and legal review — consistently underestimates how much regulatory exposure travels with the target. Most of it won’t appear on the balance sheet.

How acquiring a licensed Spanish operator actually works

The standard route is to buy the Spanish company that already holds the licence, then complete the legal, regulatory, and corporate steps required for the ownership change. A DGOJ licence doesn’t transfer as a standalone asset — it stays attached to the licensed entity. So acquiring that entity means taking it in full: history, obligations, and permissions included.

That’s the core logic. Market access comes through a share purchase, not a fresh application. In practice, the distinction is significant. A share deal means inheriting the company’s entire legal and regulatory footprint — open DGOJ inspections, player-fund liabilities, AML obligations, all of it. An asset deal transfers none of that, and crucially, no licence either, since the licence belongs to the legal entity, not to individual assets.

The appeal is speed and a known path to market entry. The complexity lands squarely in due diligence: confirming the licence is valid, that regulatory standing is clean, and that what the buyer is taking on is actually worth the price and the risk.

Who leads the due diligence process and how the workstreams divide

The buyer leads diligence. Their M&A lead or in-house counsel sets the timeline, assigns workstreams, and consolidates findings into a decision package — the substantive work itself sits with the specialist advisers.

For a deal on the M&A route to a DGOJ licence, that division matters more than in a standard corporate acquisition. General M&A lawyers cover contracts, employment, and litigation exposure fine. DGOJ-facing issues are different: licence conditions, operator obligations, management-fit requirements. These need local counsel with active gaming-regulatory experience. A generalist here risks missing sector-specific obligations that only surface in the regulator’s own filings.

MGL Solutions works with buyers across exactly this gap — providing gaming-specific regulatory due diligence, DGOJ filing preparation, and compliance workstream support where in-house teams or generalist advisers lack the sector depth to run it themselves.

The process runs in four stages:

  • Data room: the seller populates a virtual data room with corporate, financial, regulatory, and operational documents; a well-prepared seller pack accelerates Q&A and signals fewer hidden risks

  • Information requests (Q&A): each workstream team submits written queries; answers become part of the evidentiary record and feed directly into SPA representations

  • Report drafting: each adviser produces a standalone report; the M&A lead reconciles findings across streams and flags items requiring price adjustment or deal protection

  • Negotiation: diligence findings drive warranty scope, indemnity carve-outs, and any conditions precedent tied to regulatory clearances

One team prepares the questions. A separate team validates the answers. The buyer makes the commercial call. How clean that call looks depends almost entirely on how well the regulatory workstream was staffed at the start.

Review scope across legal, financial, tax, and commercial streams

Four buckets structure buy-side diligence: legal, financial, tax, and commercial. Each tests a different part of the target’s risk profile.

Stream

Primary question

Gaming-specific focus

Legal

Do we own what we think we’re buying?

DGOJ licence status, corporate title, contracts, employment, IP, litigation

Financial

Is reported performance real and repeatable?

Revenue quality, player concentration, bonus liabilities, working-capital cycle

Tax

What hidden charges follow the shares?

Four-year lookback on corporate and gaming-tax positions, transfer-pricing exposure

Commercial

Can the business grow under new ownership?

Market position, player database value, product roadmap, supplier dependencies

For a licensed gaming operator, each stream feeds directly into pricing and conditions precedent. Legal diligence confirms the licence is in good standing with DGOJ and that no undisclosed regulatory proceedings could trigger suspension. Financial diligence stress-tests whether GGR is genuinely recurring or propped up by unsustainable promotions — a distinction that can shift valuation by several turns of EBITDA. Tax diligence covers the statutory four-year lookback period Spanish law requires; liabilities from that window travel with the shares regardless of what the seller discloses. Commercial diligence asks whether the player database and tech stack hold value independently of the current management team — which they often don’t, and that dependency needs to be priced, not assumed away.

Compliance, AML, responsible-gambling, and player-fund liabilities

In a share deal, the buyer steps into the company’s shoes — liabilities included. Whatever DGOJ or SEPBLAC have not yet actioned travels with the entity, not with the seller.

Liability type

Travels with company?

Typical buyer protection

Historical AML failures / SEPBLAC findings

Yes

Indemnity + escrow holdback

DGOJ sanctions (advertising, bonusing, self-exclusion)

Yes

Rep + warranty; price reduction

Unpaid player prizes / consumer claims

Yes

Specific indemnity; disclosure schedule

Responsible gambling breaches

Yes

Remediation covenant pre-closing

Corporate criminal liability (Ley 10/2010)

Yes

Criminal compliance rep; escrow

Third-party agent / affiliate violations

Yes

Vendor warranties; AML agent audit

Segregated player-fund shortfalls

Yes

Escrow or retention until reconciled

Tax assessments (four-year lookback)

Yes

Tax indemnity; locked-box mechanism

Diligence findings have to land in the contract — specifically, not generically. A pattern of self-exclusion failures warrants its own indemnity. General warranties cap exposure at negotiated limits, and those limits routinely fall short of actual regulatory fine risk in Spain, where DGOJ sanctions for responsible-gambling violations have reached six figures per infraction.

Corporate criminal liability under Ley 10/2010 attaches to the entity itself, which means a compliance programme audit and documented whistleblowing channels are not optional extras before a buyer accepts any representations at face value. No compliance programme evidence, no credible rep.

Foreign investment screening and parallel regulatory approvals

Non-EU/EFTA buyers picking up a Spanish gaming asset face more than one regulatory clock running at once.

Under Real Decreto 571/2023, acquiring 10% or more in a strategic sector requires prior Council of Ministers authorisation before the deal takes legal effect. Close without it and the transaction risks being declared void. Gambling sits close enough to media and digital infrastructure that strategic-sector exposure needs to be assessed before signing, not after.

Where full authorisation doesn’t apply, mandatory declarations to the Registro de Inversiones Exteriores still do — forms DP-1, D-1A, or D-1B depending on structure. Skipping a declaration won’t void the deal, but it does trigger administrative sanctions. Listed targets add CNMV disclosure obligations on top of that.

Each track — FDI screening, Registro filings, CNMV reporting, DGOJ notification — runs on its own timeline and answers to a different body. That’s four parallel processes, and misaligning them against the DGOJ timetable is one of the more consistent sources of closing delays in Spanish gaming M&A.

DGOJ approval timing: what must happen before closing and what follows after

In most deals, the key obligation is post-closing notification — but the exact path depends on how control changes, how the transaction is structured, and whether additional regulatory touchpoints apply.

Pre-closing vs. post-closing: the core split

  • Share acquisition (direct control change): DGOJ requires prior notification. If the acquirer has no prior Spain record, engaging the regulator informally before signing is standard — not optional caution.

  • Indirect change of control (upstream holding company transfer): triggers the same scrutiny as a direct deal. The licensed entity must file even when no Spanish company formally changes hands.

  • Corporate restructurings and mergers: assessed individually. Some forms require DGOJ sign-off before closing can complete on a licence-preserving basis — others do not, and assuming the wrong category is a common mistake.

Documents typically assembled for filing:

  • Acquirer corporate structure and beneficial ownership chain

  • Suitability and fit-and-proper evidence for incoming directors and shareholders

  • Draft or executed SPA (redacted where permitted)

Signing conditions to build in:

Where prior approval is required, include DGOJ acknowledgement as a condition precedent. Where it is not, set a firm post-closing notification deadline. Either way, treat it as a regulated transaction: the licence does not survive an ownership change on autopilot.

What the buyer inherits when the licensed company changes hands

The buyer inherits the company with all its rights and obligations — but that doesn’t mean everything carries over without a second look.

In a share purchase, the licensed entity itself doesn’t change; only its ownership does. The DGOJ licence, technical certifications, domain approvals, registered payment methods, and responsible-gambling programme conditions all stay formally attached to the Spanish entity. Travelling automatically is not the same as continuing without scrutiny.

Item

Continues automatically

Needs notification or review

DGOJ operating licence

Yes

Ownership change must be notified

Technical platform certification

Yes

Only if platform provider changes

Domain names and brand registrations

Yes

If rebranding follows closing

AML programme and SEPBLAC filings

Yes (programme stays)

Material changes require update

Player fund guarantees and bank bonds

Yes (until renewal)

New owners may need to re-execute

Management fit-and-proper approvals

No

New directors require DGOJ review

Payment service provider contracts

Depends on contract terms

Change-of-control clauses common

Pending licence conditions or sanctions

Yes — fully inherited

No opt-out available to buyer

Two variables that often get underweighted: remaining licence term and open regulatory conditions. An operator with two years left on its licence and unresolved compliance conditions is not the same asset as one with a recent renewal and a clean slate — pricing them identically is a mistake. Both factors belong in the valuation model and in the SPA warranties, not left to post-closing discovery.

Pricing a Spanish gambling operator when the licence cannot be sold separately

Because the DGOJ licence attaches to the legal entity, buyers cannot separate what they pay for market access from what they pay for the business. There is no standalone licence asset to price — only the company that holds it.

Due diligence has to decompose value across: verified EBITDA and revenue quality, customer concentration, compliance track record, remaining licence term, and the cost of any open regulatory or AML exposure. A clean compliance record and strong player retention justify a premium. Sanctions history, pending DGOJ inspections, or under-provisioned player funds compress it.

Two scenarios define the downside. First: if regulatory action triggered by the change of control could impair the licence post-closing, the acquirer is buying an uncertain right to keep operating — not a business. Second: if continuity requires replacing key personnel or IT infrastructure that cannot transfer, those remediation costs belong in the valuation model. Parking them in a post-closing contingency understates the actual purchase price.

Deal protections, SPA clauses, and how diligence findings become contract terms

Diligence findings shape the contract directly: they feed into representations and warranties, specific indemnities for identified risks, disclosure schedules that cap seller liability, and escrow or holdback arrangements tied to regulatory exposure.

W&I insurance rarely covers DGOJ-related regulatory tail risk without heavy carve-outs — so in gaming deals, buyers negotiate specific indemnities for AML, responsible-gambling, or player-fund shortfalls instead. Those indemnities often run uncapped or with extended survival periods. Escrows and holdbacks get sized against the actual cost of probable remediation, not a percentage of deal value. Disclosure schedules carry real weight here: anything the seller properly discloses against a representation shifts risk to the buyer. Privilege strategy around what gets disclosed — and how it’s framed — matters as much as the underlying facts.

When a DGOJ contingent liability can’t be quantified at signing, buyers should push for two things: cooperation covenants that obligate the seller to support post-closing regulatory filings, and explicit cost-allocation language covering remediation if the regulator raises historic compliance concerns after close. Without that language, “we’ll figure it out later” tends to mean protracted disputes at exactly the wrong moment.

DGOJ filings for ownership, beneficial control, and post-closing management changes

DGOJ expects a complete ownership-and-control picture from day one. Changes to directors, financing, or service arrangements after closing can reopen that scrutiny.

A change-of-control filing typically covers:

  • Ultimate beneficial owners (UBOs): Full identification of anyone with direct or indirect influence — through funds, trusts, or multi-layer holdcos. Nominee arrangements that obscure the real controller are the most common weak point regulators flag.

  • Significant shareholders: Threshold-based disclosure of all parties with qualifying stakes in the licensed entity and its group.

  • Directors and senior management: Suitability and background checks for incoming board members. Replacing a director post-closing is not a routine HR matter — it can reopen regulatory scrutiny of the entire management team.

  • Group structure and financing: The full corporate chain, plus how the acquisition was funded, including intercompany loan arrangements.

  • Key service providers: Outsourcing agreements, platform contracts, and intercompany support services that materially affect the licensed operation may need disclosure or re-approval.

Private-equity structures with multiple fund vehicles are a known friction point — incomplete chains are common, and DGOJ will not move forward until every layer is accounted for. Undisclosed post-closing changes to outsourced technology or payment arrangements carry the same risk: the share purchase agreement may be signed, but the filing process stalls anyway.

Leave a Reply

Your email address will not be published. Required fields are marked *