DDData Desk Open the partner account
Data Desk / Access requests
Reading the file back

How to make a subject access request

The right to see your own data is the most useful right on this desk, and the easiest to get wrong. This page sets out what to ask for, what the operator must send back, the clock it runs on, and what to do when the reply is late, partial or missing the part you asked about.

Field 01

Field 01A subject access request is a copy, not a conversation

A subject access request is a demand for a copy of the personal data an operator holds about you, plus the information that makes it intelligible: the purposes, the categories, the recipients, the retention period and the source. It is not a customer-service enquiry and not a favour — under the general model it is a right with a deadline. You do not need a reason, a form or a template, and in most regimes the first request is free. The reply must give you the data itself in an intelligible form, with any internal codes or abbreviations explained, not a summary that paraphrases it.

Copy, not summary

“We hold your identification and transaction data” is not a subject access response. You are entitled to the data — the fields and their values — with the codes explained.

Field 02

Field 02How to ask so that the request is easy to enforce

The version of a request that a regulator can act on is the version with evidence behind it. Send it in writing, from the email address on the account, to the data-protection contact the privacy notice names — or to the operator’s ordinary support address if no contact is stated. Say clearly that it is a subject access request, name the data you want (all of it, or the categories you care about), give the account reference, and date it. Keep a copy. That record is what establishes the deadline started, and it is the thing you will be asked for if the response is late.

  • In writing, from the account email It anchors the request to the account and gives you a copy of what was sent.
  • Name it as a subject access request The label matters; a vague enquiry can be handled as ordinary support.
  • Ask for the data and the details Purposes, categories, recipients, retention and source — plus the fields themselves.
  • Date it and keep it The day you asked is the day the clock starts once identity is confirmed.
  • Ask for the format A structured export (CSV/JSON) is easier to check than a PDF of screenshots.
Field 03

Field 03What the reply must contain

A complete response has two halves. The first is a copy of the personal data held — the fields and their values, with any codes expanded so the document is intelligible. The second is the surrounding information: the purposes of processing, the categories of data, the recipients or categories of recipient, the retention period or the criteria that set it, the source of the data where it was not collected from you, and the existence of the other rights. Where data about you is interwoven with data about someone else, the operator may redact the other person’s part — but not by withholding yours.

The subject access request clock A request is made, identity is confirmed, a one-month clock runs which may be extended once for complexity, and the operator responds ASK → VERIFY IDENTITY → ONE MONTH → RESPONSE REQUESTno reason needed IDENTITYclock has not started 30 DAYS+2 months if complex RESPONSEa copy + the details ESCALATEif it is late WHAT A RESPONSE MUST CONTAIN A COPY OF THE DATA The personal data held, in an intelligible form, with any coded abbreviations explained. The data itself, not a summary of it. THE DETAILS AROUND IT Purposes, categories, recipients, retention and the source — even where you already know. Ask for a written copy; keep the date.
Figure 2 — the subject access request clock. Ask, confirm identity, one month (extendable once for complexity), then the copy and the details; escalate if late. Schematic of the general model.
What a complete reply contains, and why
ItemWhat it isWhy it matters
A copyThe personal data held, intelligible, codes explainedThis is the core of the right
PurposesWhy each category is processedLets you spot a purpose you did not expect
CategoriesThe kinds of data heldTells you whether anything is missing
RecipientsWho, or which kind of body, received itThe item privacy notices are usually vaguest about
RetentionThe period, or how it is decidedExplains why an erasure request will not reach some fields
SourceWhere data not from you came fromRelevant for screening or anti-fraud data
Field 04

Field 04The clock, and the one extension it allows

Under the general model — the EU and UK GDPR being the codification most others mirror — the operator must respond without undue delay and within one month. Two things move the clock. First, it does not start until the operator can confirm who is asking, which is why prompt identity confirmation is the practical way to keep the month short and why a slow identity check can feel like a silent refusal. Second, the operator may extend by up to two further months where the request is genuinely complex or you have made several; if it does, it must tell you within the first month and give its reasons.

STANDARD1 monthfrom identity confirmation
EXTENSION+2 monthsonce, for complexity
COSTFreeusually, on a first request
SILENCEA breachescalate it
Field 05

Field 05Fees, and the refusals that are (and are not) allowed

A first request is normally free. An operator may charge a reasonable fee, or refuse, only in defined situations — a request that is manifestly unfounded or excessive, or a further copy you have asked for — and it should tell you which ground it is relying on. It may also refuse part of a request where an exemption applies: data about another person, data protected by legal privilege, or data whose disclosure would undermine a crime-prevention duty. What is not allowed is a blanket refusal with no ground, silence past the deadline, or a reply that answers a request you did not make.

ALLOWED

A reasonable fee for a further copy, or a refusal of a manifestly excessive request — with the ground stated.

EXEMPTION

Redaction of another person’s data, privileged material, or data covered by a crime-prevention exemption.

NOT ALLOWED

Silence past the deadline, a blanket refusal with no ground, or a summary instead of the data.

Field 06

Field 06When the reply is late, partial or refuses with no ground

Escalation is a sequence. First, chase in writing and ask for the specific ground for any refusal; an operator that has a ground will usually name it once asked, and one that does not may simply answer. Second, if the response remains inadequate, complain to the operator’s data-protection officer formally. Third, complain to the data-protection authority in the country where you live, which can investigate and, in many regimes, order a response. The record you kept — the request, the dates and the reply — is what the authority will ask for. A gambling-specific dispute about a bet is a different route, and belongs with the operator’s regulator rather than the data-protection authority.

Where the rights sit

The rights map

Access is one of six; see what rectification, erasure, portability, objection and restriction each reach.

Affiliate disclosure and risk warning

Every affiliate link on this page and in the header is a sponsored link to a partner operator, and we may be paid if you open an account through it, at no extra cost to you. That link pays us; it does not improve any decision, it is not a ranking, and it is never a recommendation to play. Nothing on this page is legal, financial, tax or data-protection advice, and nothing here is a prediction about any event or market, or a view on any operator. 18+ only. Every stake is money at risk and can be lost in full. The data rights explained here — access, rectification, erasure, portability, objection, restriction, consent and retention — are general descriptions of how the mechanisms usually work, not a statement of the law that applies to you: data-protection and record-keeping rules differ between countries, states and provinces and change over time, and an operator may lawfully hold data that a rights request cannot remove, because a licence or anti-money-laundering duty requires it. This page does not name any operator and is not a substitute for that operator’s privacy notice or for advice from a data-protection authority or a qualified adviser. Never stake money you cannot afford to lose, never borrow to play, and never chase losses with a larger stake. Gambling can cause serious financial harm, including debt and damage to relationships and mental health. Free and confidential support is available in most countries through national gambling-harm helplines, for players and for the people around them.