DDData Desk Open the partner account
Data Desk / Overview
The data layer around the account

What the account knows about you

A gambling account is also a data record. Opening it creates a file — identity, login, activity, source-of-funds, safer-gambling and consent categories — most of it held because a licence demands it, all of it subject to rights you can exercise: to read it back, to correct it, to move it, to object to its use and, within limits, to have it erased. This reference explains that layer as mechanism, not as legal advice.

Field 01

Field 01An account is a data record with a purpose for every field

The first thing to internalise is that almost nothing on a gambling account is there by accident. A regulated operator holds identity data because its licence obliges it to verify who you are; it holds transaction data because it must keep a record of money in and out; it holds safer-gambling data because the licence requires it to offer and apply limits. Each of those is a lawful basis and a purpose, and the rules about data are mostly rules about keeping the purpose and the data matched — collected for one reason, not quietly reused for another. How a verification check itself works, and which document proves what, belongs to KYC Guide; this desk starts after the check and asks what was stored, why, for how long, and what you can do about it.

The life of a data field A data field is collected, used for a stated purpose, retained for a period set by a duty, and then deleted or anonymised; a legal retention duty can block the final step COLLECT → USE → RETAIN → DELETE / ANONYMISE COLLECTat sign-up/check USEa stated purpose RETAINset by a duty ERASEwhen the purpose ends PURPOSE LIMIT Data collected for one purpose should not be quietly reused for an unrelated one; a new use usually needs its own basis, often consent. This is what an access request lets you check. THE RETENTION WALL Where a licence or anti-money-laundering duty requires a record to be kept, erasure cannot remove it before its period ends. A lawful refusal, if it is explained.
Figure 1 — the life of a data field. Collected for a purpose, used for that purpose, retained for a period a duty sets, and then deleted or anonymised. A legal retention duty is the wall that stops the last step. Illustrative.
  • Indigo — data you can access and move
  • Tangerine — a retention edge or a limit on a right
  • Green — consent granted, or a purpose that has cleanly ended

Read this way, the useful question changes from “what does the casino know about me” to “which category is this field in, and which basis and period govern it”. Those categories and periods are what this desk is about.

Field 02

Field 02The categories an operator commonly holds

The exact list is in the privacy notice for your account, but the shape is stable across licensed operators. Six categories cover almost everything: identity, account and login, activity and transactions, source of funds, safer-gambling and consent records. Knowing which category a field sits in tells you most of what you need: whether you can have it erased, how long it lives, and who else may receive it.

IDENTITYName, date of birth, address and the document data checked at verification. Held under a licence duty; usually the longest-lived category and the least removable.
ACCOUNTEmail, a hashed password, security settings, device and session records. Log data is usually short-lived; the account shell persists while the account does.
ACTIVITYDeposits, withdrawals, stakes and game or market history — the transaction record. Kept to run the account and to meet anti-money-laundering duties.
SOURCESource-of-funds and source-of-wealth evidence for larger balances. The tightest purpose limit and the sharpest retention edge on the whole file.
SAFER PLAYDeposit and loss limits, self-exclusion and cooling-off entries, and any vulnerability notes. Often kept deliberately longer, so the controls keep working.
CONSENTA dated record of the choices you made — marketing consent, cookies, the terms version accepted. Consent has to be provable, so its record is kept.
The categories, in detail

What data an account holds

Each category, the field codes inside it, and what each is for — with the one you can actually remove.

Field 03

Field 03Consent is not the only basis — and usually not the important one

A common misunderstanding is that everything an operator does with your data rests on consent you can withdraw. It does not. Running the account, verifying you, taking and paying money and keeping records are typically done on a contract basis or a legal obligation, neither of which you can switch off while still using the service. Consent covers the things that are genuinely optional — most importantly marketing. That split is why “withdraw consent” is not a way to make an operator forget your account, and why the marketing switch is the one that matters most in practice.

The bases, and what each one means for you
BasisTypical useCan you stop it?
ConsentMarketing emails, optional cookies, some profilingundefined
ContractRunning the account, taking deposits, paying withdrawals
Legal obligationIdentity checks, anti-money-laundering records, tax reportingundefined
Legitimate interestFraud prevention, some security monitoringundefined
The bases, in detail

Consent versus contract

Why marketing is the switch that matters, how to withdraw consent, and why you cannot consent away the rest.

Field 04

Field 04Every field has a retention clock, and the longest ones are the legal ones

Data is kept for a period, and the period is usually set by the reason the data exists. Activity records tied to anti-money-laundering duties often carry a multi-year minimum; login logs are often kept for weeks or months; marketing profiles last while consent lasts. This is why a later erasure request can reach some fields and not others: the request cannot shorten a period a legal duty fixed. A privacy notice should state the periods — or at least the criteria that determine them — and a subject access request is entitled to ask for them.

The retention wall, in one line

Erasure removes data whose purpose has ended. Where a duty requires the record, the record stays until the period ends — and a refusal that names that duty is lawful, while a refusal that names nothing is worth escalating.

The clock, in detail

How long data is kept

Retention periods by category, why the legal ones are longest, and how to ask what period applies to a field.

Field 05

Field 05You can read the file back — the subject access request

The most useful right on the desk is the simplest: you can ask for a copy of the personal data an operator holds about you, and for the details around it — purposes, categories, recipients and retention. This is a subject access request. It needs no special form and no reason, it is usually free, and the general model gives the operator one month from when it can confirm who is asking. The reply must give you the data in an intelligible form, not a summary, and it must tell you the surrounding facts even where you already know them.

The subject access request clock A request is made, identity is confirmed, a one-month clock runs which may be extended once for complexity, and the operator responds ASK → VERIFY IDENTITY → ONE MONTH → RESPONSE REQUESTno reason needed IDENTITYclock has not started 30 DAYS+2 months if complex RESPONSEa copy + the details ESCALATEif it is late WHAT A RESPONSE MUST CONTAIN A COPY OF THE DATA The personal data held, in an intelligible form, with any coded abbreviations explained. The data itself, not a summary of it. THE DETAILS AROUND IT Purposes, categories, recipients, retention and the source — even where you already know. Ask for a written copy; keep the date.
Figure 2 — the subject access request clock. Ask, confirm identity, wait one month (extendable once for complexity), receive the data and the details, and escalate if it is late. Schematic of the general model.
  • Ask in writing From the email on the account, naming the data you want and the date.
  • Confirm identity fast The clock does not run until the operator can confirm who is asking.
  • Ask for the details too Purposes, categories, recipients, retention and the source, not just the raw data.
  • Keep the dates The day you asked and the day the month expires are what a regulator will ask about.
The request, in detail

How to make an access request

What to ask for, what the reply must contain, the clock, the extensions, the fees and the escalation route.

Field 06

Field 06Erasure, portability and objection all have a shape — and it is not absolute

The rights beyond access are each narrower than they sound. Rectification fixes data that is wrong or incomplete. Erasure reaches data whose purpose has ended, but not data a duty requires. Portability gives you the data you provided in a machine-readable format, on a consent or contract basis. Objection targets processing on legitimate interest, and always wins against direct marketing. Restriction freezes the use of data while a dispute is resolved. Knowing the reach of each is what turns a vague “I want my data deleted” into a request an operator has to answer on the merits.

Which right reaches which data Access, rectification, erasure, portability, objection and restriction rights, shown against the data each one usually reaches RIGHT → REACHES → TYPICAL LIMIT ACCESSthe personal data held about you, and the details around itnone, except identity check RECTIFICATIONanything inaccurate or incompleteevidence may be asked for ERASUREdata whose purpose has endedlegal retention duty PORTABILITYdata you provided, in a machine-readable formatconsent or contract basis OBJECTIONprocessing on legitimate interest, incl. direct marketingnot for lawful RESTRICTIONfreezes use of data while a dispute is resolvedstored, not used GENERAL MODEL, NOT LEGAL ADVICE — THE LAW THAT APPLIES TO YOU DIFFERS BY JURISDICTION.
Figure 3 — which right reaches which data. Each right, what it reaches, and its typical limit. A general model, not legal advice; the law that applies to you differs by jurisdiction.
Your rights, in detail

The rights map

All six rights, what each reaches, the exceptions, and the order of escalation when a request is refused.

Field 07

Field 07How to use this desk

Start with the categories if you want to know what is held, the access request if you want to see it, consent if you want to stop marketing, retention if you want to know how long it lives, third parties if you want to know who else has it, and deletion or portability if you want to act. Each page is answer-first, shows the mechanism, and states its own limits. None of it replaces the privacy notice that applies to your account or advice from a data-protection authority where you live — and it is not a way around any self-exclusion, any licensing rule or any law.

  • Answer-first
  • No legal advice
  • No named operators
  • Mechanism over opinion
  • Worked examples
  • Compliance on every page

Affiliate disclosure and risk warning

Every affiliate link on this page and in the header is a sponsored link to a partner operator, and we may be paid if you open an account through it, at no extra cost to you. That link pays us; it does not improve any decision, it is not a ranking, and it is never a recommendation to play. Nothing on this page is legal, financial, tax or data-protection advice, and nothing here is a prediction about any event or market, or a view on any operator. 18+ only. Every stake is money at risk and can be lost in full. The data rights explained here — access, rectification, erasure, portability, objection, restriction, consent and retention — are general descriptions of how the mechanisms usually work, not a statement of the law that applies to you: data-protection and record-keeping rules differ between countries, states and provinces and change over time, and an operator may lawfully hold data that a rights request cannot remove, because a licence or anti-money-laundering duty requires it. This page does not name any operator and is not a substitute for that operator’s privacy notice or for advice from a data-protection authority or a qualified adviser. Never stake money you cannot afford to lose, never borrow to play, and never chase losses with a larger stake. Gambling can cause serious financial harm, including debt and damage to relationships and mental health. Free and confidential support is available in most countries through national gambling-harm helplines, for players and for the people around them.