How to make a subject access request
The right to see your own data is the most useful right on this desk, and the easiest to get wrong. This page sets out what to ask for, what the operator must send back, the clock it runs on, and what to do when the reply is late, partial or missing the part you asked about.
Field 01A subject access request is a copy, not a conversation
A subject access request is a demand for a copy of the personal data an operator holds about you, plus the information that makes it intelligible: the purposes, the categories, the recipients, the retention period and the source. It is not a customer-service enquiry and not a favour — under the general model it is a right with a deadline. You do not need a reason, a form or a template, and in most regimes the first request is free. The reply must give you the data itself in an intelligible form, with any internal codes or abbreviations explained, not a summary that paraphrases it.
Copy, not summary
“We hold your identification and transaction data” is not a subject access response. You are entitled to the data — the fields and their values — with the codes explained.
Field 02How to ask so that the request is easy to enforce
The version of a request that a regulator can act on is the version with evidence behind it. Send it in writing, from the email address on the account, to the data-protection contact the privacy notice names — or to the operator’s ordinary support address if no contact is stated. Say clearly that it is a subject access request, name the data you want (all of it, or the categories you care about), give the account reference, and date it. Keep a copy. That record is what establishes the deadline started, and it is the thing you will be asked for if the response is late.
- In writing, from the account email It anchors the request to the account and gives you a copy of what was sent.
- Name it as a subject access request The label matters; a vague enquiry can be handled as ordinary support.
- Ask for the data and the details Purposes, categories, recipients, retention and source — plus the fields themselves.
- Date it and keep it The day you asked is the day the clock starts once identity is confirmed.
- Ask for the format A structured export (CSV/JSON) is easier to check than a PDF of screenshots.
Field 03What the reply must contain
A complete response has two halves. The first is a copy of the personal data held — the fields and their values, with any codes expanded so the document is intelligible. The second is the surrounding information: the purposes of processing, the categories of data, the recipients or categories of recipient, the retention period or the criteria that set it, the source of the data where it was not collected from you, and the existence of the other rights. Where data about you is interwoven with data about someone else, the operator may redact the other person’s part — but not by withholding yours.
| Item | What it is | Why it matters |
|---|---|---|
| A copy | The personal data held, intelligible, codes explained | This is the core of the right |
| Purposes | Why each category is processed | Lets you spot a purpose you did not expect |
| Categories | The kinds of data held | Tells you whether anything is missing |
| Recipients | Who, or which kind of body, received it | The item privacy notices are usually vaguest about |
| Retention | The period, or how it is decided | Explains why an erasure request will not reach some fields |
| Source | Where data not from you came from | Relevant for screening or anti-fraud data |
Field 04The clock, and the one extension it allows
Under the general model — the EU and UK GDPR being the codification most others mirror — the operator must respond without undue delay and within one month. Two things move the clock. First, it does not start until the operator can confirm who is asking, which is why prompt identity confirmation is the practical way to keep the month short and why a slow identity check can feel like a silent refusal. Second, the operator may extend by up to two further months where the request is genuinely complex or you have made several; if it does, it must tell you within the first month and give its reasons.
Field 05Fees, and the refusals that are (and are not) allowed
A first request is normally free. An operator may charge a reasonable fee, or refuse, only in defined situations — a request that is manifestly unfounded or excessive, or a further copy you have asked for — and it should tell you which ground it is relying on. It may also refuse part of a request where an exemption applies: data about another person, data protected by legal privilege, or data whose disclosure would undermine a crime-prevention duty. What is not allowed is a blanket refusal with no ground, silence past the deadline, or a reply that answers a request you did not make.
A reasonable fee for a further copy, or a refusal of a manifestly excessive request — with the ground stated.
Redaction of another person’s data, privileged material, or data covered by a crime-prevention exemption.
Silence past the deadline, a blanket refusal with no ground, or a summary instead of the data.
Field 06When the reply is late, partial or refuses with no ground
Escalation is a sequence. First, chase in writing and ask for the specific ground for any refusal; an operator that has a ground will usually name it once asked, and one that does not may simply answer. Second, if the response remains inadequate, complain to the operator’s data-protection officer formally. Third, complain to the data-protection authority in the country where you live, which can investigate and, in many regimes, order a response. The record you kept — the request, the dates and the reply — is what the authority will ask for. A gambling-specific dispute about a bet is a different route, and belongs with the operator’s regulator rather than the data-protection authority.
The rights map
Access is one of six; see what rectification, erasure, portability, objection and restriction each reach.
Affiliate disclosure and risk warning
Every affiliate link on this page and in the header is a sponsored link to a partner operator, and we may be paid if you open an account through it, at no extra cost to you. That link pays us; it does not improve any decision, it is not a ranking, and it is never a recommendation to play. Nothing on this page is legal, financial, tax or data-protection advice, and nothing here is a prediction about any event or market, or a view on any operator. 18+ only. Every stake is money at risk and can be lost in full. The data rights explained here — access, rectification, erasure, portability, objection, restriction, consent and retention — are general descriptions of how the mechanisms usually work, not a statement of the law that applies to you: data-protection and record-keeping rules differ between countries, states and provinces and change over time, and an operator may lawfully hold data that a rights request cannot remove, because a licence or anti-money-laundering duty requires it. This page does not name any operator and is not a substitute for that operator’s privacy notice or for advice from a data-protection authority or a qualified adviser. Never stake money you cannot afford to lose, never borrow to play, and never chase losses with a larger stake. Gambling can cause serious financial harm, including debt and damage to relationships and mental health. Free and confidential support is available in most countries through national gambling-harm helplines, for players and for the people around them.