DDData Desk Open the partner account
Data Desk / What data
The register, category by category

What data a gambling account holds

The authoritative list is in the privacy notice for your account, but the shape is stable: six categories, each with its own purpose and its own life. This page walks the register field by field, says what each category is for, and flags the one category you can actually have removed.

Field 01

Field 01Why data splits into categories at all

Categories exist because the rules attach to purposes, and a purpose is what decides a field’s basis, its life and its reachability. Identity data is held to meet a licence duty, so it lives long and resists erasure. Marketing data is held on consent, so it dies the moment you withdraw. Grouping fields by category is how both the operator and you keep track of which field is which — and it is why a blanket “delete everything” request cannot be answered with a blanket yes. The categories below are the common shape, not a universal law; an operator’s own notice names its actual list.

CATEGORIES6the common shape
LONGEST LIFEIdentitylicence duty
MOST REMOVABLEMarketingconsent-based
SHARPEST EDGESourcepurpose-limited
Field 02

Field 02Identity — who you are, held under a licence duty

Name, date of birth, residential address, and the data read from the document or database that verified you at onboarding. This category exists because a licensed operator must know its customer; it is not held for marketing and it is not optional. Two consequences follow. First, it is usually the longest-lived category, with a multi-year floor tied to record-keeping duties. Second, erasure rarely reaches it, because the record of who was verified is exactly what the duty requires be kept. What rectification can do here is fix an inaccuracy — a misspelled name, an old address — and the operator should update it and pass the correction on to recipients where the law requires.

Verified once, corrected later

If a name is misspelled in your identity record, that is a rectification request, not an erasure request. Ask for the specific field to be corrected, and ask which recipients were told.

Field 03

Field 03Account and login — how you reach it, and how it is protected

Your email, a hashed password, security settings such as two-factor enrolment, and device or session records. The password point is worth stating precisely: a competent operator stores a one-way hash of your password, computed so it cannot be reversed, usually with a per-account salt and a deliberately slow function. That is why an operator can reset your password but should never be able to tell you what it is, and why an email that displays your own password is a red flag about how it is stored. Device and session logs are typically shorter-lived than the account shell — they exist for security and fraud detection, and they age out on a schedule.

EMAILThe account identifier and the channel for notices; kept while the account exists, and for a period after, for legal notices.
PASSWORDStored as a one-way hash, never as the password. Not something the operator can produce on request.
SECURITYTwo-factor enrolment, recovery settings and trusted-device markers — security data, not marketing data.
SESSIONSIP, device and session records for fraud detection; usually the shortest-lived category on the file.
Field 04

Field 04Activity and transactions — the record of money and of play

Deposits, withdrawals, stakes, bonuses taken and the game or market history of the account. This is the operational record: it is what reconciles your balance, it is what a dispute is decided on, and it is what anti-money-laundering duties require be kept. In terms of your rights it is a mixed category — the transaction record carries a legal retention floor, while some of the finer-grained activity detail used for personalisation may not, and can fall to erasure or objection. When you make an access request, this is usually the bulkiest part of the reply, and the part most worth asking to be sent as a structured export rather than a PDF.

Deposits & withdrawals
Payment method, amount, date, status and reference. Kept to reconcile and to meet AML duties.
Stakes & settlements
Market or game, stake, odds or outcome, and result. The operational record of play.
Bonus records
Grants, wagering progress and forfeitures — part operational, part promotional.
Personalisation
Derived preferences used to tailor content; often the part erasure can reach.
Field 05

Field 05Source of funds — the category with the sharpest limit

Where a larger balance or an unusual pattern triggers it, operators must ask how the money was earned and where it came from — source of funds, and sometimes source of wealth. This evidence is the most purpose-bound data on the file: it was collected to meet a specific duty, so reusing it for anything else is a purpose-limit problem, and its retention is tied to that duty. It is also sensitive, so it is the category most worth checking in an access request — you have a right to see what was collected, why, and who received it. Verification itself — which document proves what — is KYC Guide’s territory; here the question is what happened to the evidence afterwards.

Source of funds, in one sentence

It is collected under a legal duty, used only for that duty, kept only as long as the duty requires, and visible to you through an access request.
Field 06

Field 06Safer-gambling — the category kept on purpose

Deposit and loss limits, session or reality-check settings, cooling-off periods, self-exclusion entries and any vulnerability notes. This category is unusual because some of it is often kept longer on purpose: a self-exclusion marker has to persist so that it keeps working, and operators may keep it beyond ordinary retention to honour it. That is a lawful reason to hold data that a later erasure request cannot remove, and it is a good illustration of the general rule that a right is limited by the duty it meets. It is also sensitive data with special handling, which is why access to it is worth asking for explicitly.

KEPT ON PURPOSE

A self-exclusion marker is retained so it continues to apply — an erasure request will not remove it, and should not.

SENSITIVE

Vulnerability or safer-gambling notes are sensitive data with extra protections and tighter purpose limits.

YOU CAN SEE IT

An access request reaches this category like any other; ask for it by name.

Affiliate disclosure and risk warning

Every affiliate link on this page and in the header is a sponsored link to a partner operator, and we may be paid if you open an account through it, at no extra cost to you. That link pays us; it does not improve any decision, it is not a ranking, and it is never a recommendation to play. Nothing on this page is legal, financial, tax or data-protection advice, and nothing here is a prediction about any event or market, or a view on any operator. 18+ only. Every stake is money at risk and can be lost in full. The data rights explained here — access, rectification, erasure, portability, objection, restriction, consent and retention — are general descriptions of how the mechanisms usually work, not a statement of the law that applies to you: data-protection and record-keeping rules differ between countries, states and provinces and change over time, and an operator may lawfully hold data that a rights request cannot remove, because a licence or anti-money-laundering duty requires it. This page does not name any operator and is not a substitute for that operator’s privacy notice or for advice from a data-protection authority or a qualified adviser. Never stake money you cannot afford to lose, never borrow to play, and never chase losses with a larger stake. Gambling can cause serious financial harm, including debt and damage to relationships and mental health. Free and confidential support is available in most countries through national gambling-harm helplines, for players and for the people around them.