Casino Will Not Delete Your Data: What GDPR Actually Says

The right to erasure is real and it is not absolute. Gambling operators must keep some records by law. Here is what they can keep, what they must delete, and who to complain to.

Can a casino refuse to delete my data?

Partly, yes. The right to erasure under Article 17 of the GDPR is not absolute. Article 17(3) allows a controller to refuse where keeping the data is necessary to comply with a legal obligation, or to establish, exercise or defend legal claims. Gambling operators sit squarely in both. They are required to keep transaction and identity records under anti money laundering law, and they must keep self-exclusion records or the exclusion could not be enforced. What they cannot do is refuse the whole request. Marketing profiles, preference data and contact permissions have no retention obligation once the relationship ends, and those must go.

What they must keep and what they must delete

The correct outcome is usually a split, not a yes or a no.

Usually retained

Identity verification documents and transaction history, held under anti money laundering obligations for a period set by national law. Records connected to a self-exclusion, for as long as the exclusion runs. Records needed to defend a legal claim or a regulatory investigation.

Usually deleted

Marketing profiles and segmentation data. Email and SMS contact permissions. Behavioural and preference data used for promotion. Anything the operator kept on consent alone, once consent is withdrawn.

An operator that answers a deletion request with a flat refusal, citing anti money laundering in general terms and nothing specific, has not done the exercise properly.

How to make the request

  1. Write to the data protection officer or the privacy address in the operator's privacy policy. Use the words request for erasure under Article 17 and give the account details they need to find you.
  2. Say explicitly whether this is a self-exclusion request. If it is not, say so, because operators often treat the two as the same thing and they are not.
  3. Ask for three things: what will be deleted, what will be retained, and the specific legal obligation and retention period relied on for each retained category.
  4. Note the deadline. A controller must respond within one month, extendable by two further months for complex requests, and it must tell you if it is extending.
  5. Ask about backups. The UK Information Commissioner's Office accepts that immediate deletion from backups is often not feasible, provided the data is put beyond use and not restored into live systems.
  6. If the answer is a blanket refusal with no legal basis given, complain to the data protection authority for your country. That is the ICO in the United Kingdom and the national supervisory authority in each EU market.

Which authority handles this

Data deletion is a data protection matter, not a gambling matter. Complain to the data protection authority, not the gambling regulator.

The gambling regulator still has an interest in one situation. If the operator is sending you marketing after a self-exclusion, that is a licence condition problem as well as a data protection one, and it is worth reporting to both.

Erasure request outcomes

Erasure request outcomes
Data categoryUsual outcomeBasisWhat to check
Marketing profile and contact permissionsDeletedNo retention obligation once consent is withdrawnConfirm marketing actually stops
Identity and verification documentsRetainedAnti money laundering obligationAsk for the retention period and the law relied on
Transaction and betting historyRetainedAnti money laundering and legal claimsAsk for the retention period
Self-exclusion recordRetained while the exclusion runsThe exclusion cannot be enforced without itConfirm it is used only for exclusion, not marketing

Article 17(3) of the GDPR sets out the grounds on which erasure may be refused. National law sets the retention periods.

Frequently Asked Questions

Does self-exclusion mean my data is deleted?

No. It means the opposite for that record. The operator has to keep enough information to enforce the exclusion. Ask for marketing data to be deleted separately and say clearly that you are not treating the two as the same request.

How long does the operator have to reply?

One month, extendable by two further months for complex requests. The operator must tell you if it is extending and why.

Who do I complain to if they refuse?

The data protection authority for your country, which is the ICO in the United Kingdom. If the refusal also involves marketing after self-exclusion, report it to the gambling regulator as well.

Sources

Related Glossary Terms

Verified against 2 primary sources. Last reviewed August 26, 2026.

Browse the Expert Knowledge Hub