What the account knows about you
A gambling account is also a data record. Opening it creates a file — identity, login, activity, source-of-funds, safer-gambling and consent categories — most of it held because a licence demands it, all of it subject to rights you can exercise: to read it back, to correct it, to move it, to object to its use and, within limits, to have it erased. This reference explains that layer as mechanism, not as legal advice.
Field 01An account is a data record with a purpose for every field
The first thing to internalise is that almost nothing on a gambling account is there by accident. A regulated operator holds identity data because its licence obliges it to verify who you are; it holds transaction data because it must keep a record of money in and out; it holds safer-gambling data because the licence requires it to offer and apply limits. Each of those is a lawful basis and a purpose, and the rules about data are mostly rules about keeping the purpose and the data matched — collected for one reason, not quietly reused for another. How a verification check itself works, and which document proves what, belongs to KYC Guide; this desk starts after the check and asks what was stored, why, for how long, and what you can do about it.
- Indigo — data you can access and move
- Tangerine — a retention edge or a limit on a right
- Green — consent granted, or a purpose that has cleanly ended
Read this way, the useful question changes from “what does the casino know about me” to “which category is this field in, and which basis and period govern it”. Those categories and periods are what this desk is about.
Field 02The categories an operator commonly holds
The exact list is in the privacy notice for your account, but the shape is stable across licensed operators. Six categories cover almost everything: identity, account and login, activity and transactions, source of funds, safer-gambling and consent records. Knowing which category a field sits in tells you most of what you need: whether you can have it erased, how long it lives, and who else may receive it.
What data an account holds
Each category, the field codes inside it, and what each is for — with the one you can actually remove.
Field 03Consent is not the only basis — and usually not the important one
A common misunderstanding is that everything an operator does with your data rests on consent you can withdraw. It does not. Running the account, verifying you, taking and paying money and keeping records are typically done on a contract basis or a legal obligation, neither of which you can switch off while still using the service. Consent covers the things that are genuinely optional — most importantly marketing. That split is why “withdraw consent” is not a way to make an operator forget your account, and why the marketing switch is the one that matters most in practice.
| Basis | Typical use | Can you stop it? |
|---|---|---|
| Consent | Marketing emails, optional cookies, some profiling | undefined |
| Contract | Running the account, taking deposits, paying withdrawals | undefined |
| Legal obligation | Identity checks, anti-money-laundering records, tax reporting | undefined |
| Legitimate interest | Fraud prevention, some security monitoring | undefined |
Consent versus contract
Why marketing is the switch that matters, how to withdraw consent, and why you cannot consent away the rest.
Field 04Every field has a retention clock, and the longest ones are the legal ones
Data is kept for a period, and the period is usually set by the reason the data exists. Activity records tied to anti-money-laundering duties often carry a multi-year minimum; login logs are often kept for weeks or months; marketing profiles last while consent lasts. This is why a later erasure request can reach some fields and not others: the request cannot shorten a period a legal duty fixed. A privacy notice should state the periods — or at least the criteria that determine them — and a subject access request is entitled to ask for them.
The retention wall, in one line
Erasure removes data whose purpose has ended. Where a duty requires the record, the record stays until the period ends — and a refusal that names that duty is lawful, while a refusal that names nothing is worth escalating.
How long data is kept
Retention periods by category, why the legal ones are longest, and how to ask what period applies to a field.
Field 05You can read the file back — the subject access request
The most useful right on the desk is the simplest: you can ask for a copy of the personal data an operator holds about you, and for the details around it — purposes, categories, recipients and retention. This is a subject access request. It needs no special form and no reason, it is usually free, and the general model gives the operator one month from when it can confirm who is asking. The reply must give you the data in an intelligible form, not a summary, and it must tell you the surrounding facts even where you already know them.
- Ask in writing From the email on the account, naming the data you want and the date.
- Confirm identity fast The clock does not run until the operator can confirm who is asking.
- Ask for the details too Purposes, categories, recipients, retention and the source, not just the raw data.
- Keep the dates The day you asked and the day the month expires are what a regulator will ask about.
How to make an access request
What to ask for, what the reply must contain, the clock, the extensions, the fees and the escalation route.
Field 06Erasure, portability and objection all have a shape — and it is not absolute
The rights beyond access are each narrower than they sound. Rectification fixes data that is wrong or incomplete. Erasure reaches data whose purpose has ended, but not data a duty requires. Portability gives you the data you provided in a machine-readable format, on a consent or contract basis. Objection targets processing on legitimate interest, and always wins against direct marketing. Restriction freezes the use of data while a dispute is resolved. Knowing the reach of each is what turns a vague “I want my data deleted” into a request an operator has to answer on the merits.
The rights map
All six rights, what each reaches, the exceptions, and the order of escalation when a request is refused.
Field 07How to use this desk
Start with the categories if you want to know what is held, the access request if you want to see it, consent if you want to stop marketing, retention if you want to know how long it lives, third parties if you want to know who else has it, and deletion or portability if you want to act. Each page is answer-first, shows the mechanism, and states its own limits. None of it replaces the privacy notice that applies to your account or advice from a data-protection authority where you live — and it is not a way around any self-exclusion, any licensing rule or any law.
- Answer-first
- No legal advice
- No named operators
- Mechanism over opinion
- Worked examples
- Compliance on every page
Affiliate disclosure and risk warning
Every affiliate link on this page and in the header is a sponsored link to a partner operator, and we may be paid if you open an account through it, at no extra cost to you. That link pays us; it does not improve any decision, it is not a ranking, and it is never a recommendation to play. Nothing on this page is legal, financial, tax or data-protection advice, and nothing here is a prediction about any event or market, or a view on any operator. 18+ only. Every stake is money at risk and can be lost in full. The data rights explained here — access, rectification, erasure, portability, objection, restriction, consent and retention — are general descriptions of how the mechanisms usually work, not a statement of the law that applies to you: data-protection and record-keeping rules differ between countries, states and provinces and change over time, and an operator may lawfully hold data that a rights request cannot remove, because a licence or anti-money-laundering duty requires it. This page does not name any operator and is not a substitute for that operator’s privacy notice or for advice from a data-protection authority or a qualified adviser. Never stake money you cannot afford to lose, never borrow to play, and never chase losses with a larger stake. Gambling can cause serious financial harm, including debt and damage to relationships and mental health. Free and confidential support is available in most countries through national gambling-harm helplines, for players and for the people around them.