The GDPR is the European data protection law that gives people rights over their personal data, including the right to access it, correct it and have it erased.
Gambling operators hold identity documents, transaction history and behavioural profiles. The GDPR sets what they may keep, for how long, and what they must delete on request.
A player asks a casino to delete their account data. The operator deletes the marketing profile and contact permissions, and tells the player that identity documents and transaction history are retained under anti money laundering law with the retention period stated.
Partly. It can retain identity and transaction records under anti money laundering law and self-exclusion records while the exclusion runs. Marketing data must be deleted.
The data protection authority for your country, which is the Information Commissioner Office in the United Kingdom and the national supervisory authority in each EU market.