DDData Desk Open the partner account
Data Desk / Security
Keeping the file, and losing it

Security, and what a breach means

Data you cannot protect is data you should not hold. This page covers the ordinary controls behind an account — hashed passwords, encryption, access control, monitoring — and the breach notice you should expect when something goes wrong, with the steps worth taking the moment one reaches you.

Field 01

Field 01The controls a competent operator runs

The security of your account data rests on a small set of well-understood controls. Passwords are stored hashed, not in plain text. Data is encrypted in transit and usually at rest. Access is limited by role, so only the staff who need a record can open it. Activity is logged and monitored, so unusual access is detectable. Data is minimised, so less is exposed if something fails. And the operator runs access reviews and tests its defences. None of this is exotic; it is the baseline a licence generally requires, and a privacy notice or security page should describe it at least in outline.

HASHINGPasswords stored as one-way hashes with a per-user salt, so the password cannot be read back.
ENCRYPTIONData encrypted in transit and, for sensitive categories, at rest.
ACCESSRole-based limits: a support agent does not see what a compliance officer sees.
MONITORINGLogged access and anomaly detection, so unusual reads or exports are noticed.
MINIMISELess data held means less data exposed; a design choice, not an afterthought.
Field 02

Field 02Passwords are stored hashed, and you can test the claim

When you set a password, a competent operator stores a hash of it: a value computed by a one-way function, with a per-account salt and a deliberately slow algorithm, so that the stored value cannot be turned back into the password even if it leaks. This is why the operator can reset your password but should never be able to tell it to you. There is a simple test of the claim: a service that can email you your own password in plain text is storing it recoverably, and that is a red flag about the rest of its security. If you want to know what is held, an access request returns the categories of data; the password itself is not something the operator can produce.

The plain-text red flag

If a service can show you or email you your own password, it is storing it in a way it should not be. Change it there and anywhere it was reused.

Field 03

Field 03What a personal-data breach actually is

A data breach is any security incident leading to accidental or unlawful destruction, loss, alteration or unauthorised disclosure of personal data — not only a hacker emptying a database. It includes the obvious case of data exposed to the wrong people, and the less obvious ones: a misconfigured storage bucket, a laptop lost with data on it, an insider who reads records they should not, or records altered by a fault. The scale and the sensitivity of what was affected decide how serious it is, and the assessment is the operator’s to make — and to justify if it gets it wrong.

CONFIDENTIALITY

Data seen or taken by someone who should not have it — the classic breach.

AVAILABILITY

Data lost or made unavailable — a deletion fault or ransomware.

INTEGRITY

Data altered without authority — a corrupted or tampered record.

Field 04

Field 04The notice you should get, and when

Under the general model, an operator must notify its data-protection authority within a short window — commonly 72 hours — of becoming aware of a breach likely to risk people’s rights, unless the breach is unlikely to result in a risk. Where a breach is likely to result in a high risk to you, it must also tell you without undue delay. A good notice says what happened, what categories of data were involved, what the likely consequences are, what the operator is doing and what you can do — and names a contact. A notice that is vague about what leaked, or silent, is the version worth chasing and, if need be, reporting.

TO AUTHORITY~72 hoursfrom awareness
TO YOUIf high riskwithout undue delay
MUST SAYWhat leakedcategories and consequences
MUST NAMEA contactso you can ask more
Field 05

Field 05What to do when a breach notice reaches you

Move on the accounts the leaked details touch, not only the one that told you. Change the password on the breached account and on any account where you reused the same email and password, and turn on a second factor. Expect phishing that quotes the breached details convincingly, because the leak is what makes the message credible. If the notice is thin, ask the operator’s data-protection contact the specific questions — what categories, what consequence, what they are doing — and if the answers do not come, the data-protection authority in your country is the route. The financial risk on a gambling account is real, so treat a leaked payment detail as urgent.

  • Change it here and everywhere reused The same email/password pair elsewhere is the real exposure.
  • Turn on a second factor The cheapest control that survives a leaked password.
  • Expect targeted phishing A leak makes a phishing message credible; treat unexpected links with suspicion.
  • Ask the specific questions Categories, consequences and remedies — and escalate if unanswered.
The rights that follow

The rights map

A breach can trigger access, rectification and complaint rights; see how each is exercised.

Affiliate disclosure and risk warning

Every affiliate link on this page and in the header is a sponsored link to a partner operator, and we may be paid if you open an account through it, at no extra cost to you. That link pays us; it does not improve any decision, it is not a ranking, and it is never a recommendation to play. Nothing on this page is legal, financial, tax or data-protection advice, and nothing here is a prediction about any event or market, or a view on any operator. 18+ only. Every stake is money at risk and can be lost in full. The data rights explained here — access, rectification, erasure, portability, objection, restriction, consent and retention — are general descriptions of how the mechanisms usually work, not a statement of the law that applies to you: data-protection and record-keeping rules differ between countries, states and provinces and change over time, and an operator may lawfully hold data that a rights request cannot remove, because a licence or anti-money-laundering duty requires it. This page does not name any operator and is not a substitute for that operator’s privacy notice or for advice from a data-protection authority or a qualified adviser. Never stake money you cannot afford to lose, never borrow to play, and never chase losses with a larger stake. Gambling can cause serious financial harm, including debt and damage to relationships and mental health. Free and confidential support is available in most countries through national gambling-harm helplines, for players and for the people around them.