Who else receives your data
Your account data does not stop at the operator. Payment providers, verification and anti-fraud services, the suppliers behind the products, cloud and email providers, analytics, and sometimes regulators and law enforcement all handle parts of it. This page explains who receives what, and why the recipient list is one of the items you can demand.
Field 01The recipients behind an account, by function
A gambling account is assembled from services, and each service that touches your data is a recipient. Payment providers see the money and its references. Identity-verification and anti-fraud services see your identity data and device signals. Game and sports-data suppliers deliver the products, sometimes with their own account link. Cloud and email providers host the account and send the notices. Analytics and marketing tools see behavioural and consent data. Regulators, tax authorities and law enforcement receive data where the law compels it. The list is not sinister, but it is long, and an operator should categorise it in its privacy notice.
| Recipient type | Sees | Why |
|---|---|---|
| Payment providers | Amounts, method, references | To move money in and out |
| Verification / anti-fraud | Identity data, device signals | To verify and to detect fraud |
| Game & data suppliers | Activity within the product | To deliver the games and markets |
| Cloud & email | Account data at rest, notices | To run and to communicate with the account |
| Analytics / marketing | Behaviour and consent data | Only on the basis the analytics relies on |
| Regulators / authorities | Records, on a legal duty | Where the law requires disclosure |
Field 02Processors versus controllers — and why the difference matters to you
A processor handles your data on the operator’s instructions and does not decide what is done with it; the operator remains responsible and must have a written contract with the processor. A controller decides its own purposes — an anti-fraud body or a regulator often acts independently. The distinction matters because it decides who answers your request: for a processor’s handling you raise it with the operator, while an independent controller may have to answer to you directly. When a notice names “partners” without saying which role they play, that ambiguity is itself a fair thing to query in an access request.
One question that clears it up
Ask: “For each recipient, is it acting as a processor on your instructions or as an independent controller?” The answer tells you who is accountable for that part.
Field 03International transfers and the safeguards behind them
Data frequently leaves the country it was collected in — a cloud region, a support centre, a supplier elsewhere. Where the law restricts transfers, the operator must rely on a legal transfer mechanism: an adequacy decision, standard contractual clauses, or another approved safeguard. The mechanism should be disclosed, and the operator should be able to tell you the countries involved. In an access request, the recipient question extends to transfers: for each category you can ask where it is sent and on what safeguard. A vague “we may transfer data internationally” is the sentence to ask to be made specific.
A country recognised as providing equivalent protection — the simplest mechanism.
Standard contractual clauses binding the recipient to protections, used where there is no adequacy finding.
The safeguard has to be real and disclosed; “may transfer internationally” is not an answer.
Field 04How to ask for the recipient list
The recipients, or the categories of recipient, are one of the items a subject access request must return. The precise ask is: “For each category of my personal data, please list the recipients or categories of recipient to which it has been or will be disclosed, stating whether each is a processor or controller, the countries involved, and the transfer safeguard where applicable.” That phrasing converts a generic privacy notice into a list you can actually read. If the reply names categories but no roles or countries, ask once more for the specifics, and treat a second non-answer as the point to escalate.
How to make an access request
The recipient list is part of the standard reply; this page shows how to ask so it is usable.
Affiliate disclosure and risk warning
Every affiliate link on this page and in the header is a sponsored link to a partner operator, and we may be paid if you open an account through it, at no extra cost to you. That link pays us; it does not improve any decision, it is not a ranking, and it is never a recommendation to play. Nothing on this page is legal, financial, tax or data-protection advice, and nothing here is a prediction about any event or market, or a view on any operator. 18+ only. Every stake is money at risk and can be lost in full. The data rights explained here — access, rectification, erasure, portability, objection, restriction, consent and retention — are general descriptions of how the mechanisms usually work, not a statement of the law that applies to you: data-protection and record-keeping rules differ between countries, states and provinces and change over time, and an operator may lawfully hold data that a rights request cannot remove, because a licence or anti-money-laundering duty requires it. This page does not name any operator and is not a substitute for that operator’s privacy notice or for advice from a data-protection authority or a qualified adviser. Never stake money you cannot afford to lose, never borrow to play, and never chase losses with a larger stake. Gambling can cause serious financial harm, including debt and damage to relationships and mental health. Free and confidential support is available in most countries through national gambling-harm helplines, for players and for the people around them.