GDPR (General Data Protection Regulation)

What is GDPR?

The GDPR is the European data protection law that gives people rights over their personal data, including the right to access it, correct it and have it erased.

Why it matters

Gambling operators hold identity documents, transaction history and behavioural profiles. The GDPR sets what they may keep, for how long, and what they must delete on request.

Example

A player asks a casino to delete their account data. The operator deletes the marketing profile and contact permissions, and tells the player that identity documents and transaction history are retained under anti money laundering law with the retention period stated.

Common misunderstandings

  • The right to erasure is not absolute. Article 17(3) lets a controller refuse where the data is needed to meet a legal obligation or to defend a legal claim. See the guide on data deletion at /knowledge-hub/guides/casino-wont-delete-my-data.
  • A blanket refusal is still wrong. Marketing and preference data has no retention obligation and must be deleted even when transaction records are kept.

Frequently asked questions

Can a casino refuse to delete my data?

Partly. It can retain identity and transaction records under anti money laundering law and self-exclusion records while the exclusion runs. Marketing data must be deleted.

Who do I complain to about a refusal?

The data protection authority for your country, which is the Information Commissioner Office in the United Kingdom and the national supervisory authority in each EU market.

Related terms

Browse the full gambling glossary