The right to erasure is real and it is not absolute. Gambling operators must keep some records by law. Here is what they can keep, what they must delete, and who to complain to.
Partly, yes. The right to erasure under Article 17 of the GDPR is not absolute. Article 17(3) allows a controller to refuse where keeping the data is necessary to comply with a legal obligation, or to establish, exercise or defend legal claims. Gambling operators sit squarely in both. They are required to keep transaction and identity records under anti money laundering law, and they must keep self-exclusion records or the exclusion could not be enforced. What they cannot do is refuse the whole request. Marketing profiles, preference data and contact permissions have no retention obligation once the relationship ends, and those must go.
The correct outcome is usually a split, not a yes or a no.
Identity verification documents and transaction history, held under anti money laundering obligations for a period set by national law. Records connected to a self-exclusion, for as long as the exclusion runs. Records needed to defend a legal claim or a regulatory investigation.
Marketing profiles and segmentation data. Email and SMS contact permissions. Behavioural and preference data used for promotion. Anything the operator kept on consent alone, once consent is withdrawn.
An operator that answers a deletion request with a flat refusal, citing anti money laundering in general terms and nothing specific, has not done the exercise properly.
Data deletion is a data protection matter, not a gambling matter. Complain to the data protection authority, not the gambling regulator.
The gambling regulator still has an interest in one situation. If the operator is sending you marketing after a self-exclusion, that is a licence condition problem as well as a data protection one, and it is worth reporting to both.
| Data category | Usual outcome | Basis | What to check |
|---|---|---|---|
| Marketing profile and contact permissions | Deleted | No retention obligation once consent is withdrawn | Confirm marketing actually stops |
| Identity and verification documents | Retained | Anti money laundering obligation | Ask for the retention period and the law relied on |
| Transaction and betting history | Retained | Anti money laundering and legal claims | Ask for the retention period |
| Self-exclusion record | Retained while the exclusion runs | The exclusion cannot be enforced without it | Confirm it is used only for exclusion, not marketing |
Article 17(3) of the GDPR sets out the grounds on which erasure may be refused. National law sets the retention periods.
No. It means the opposite for that record. The operator has to keep enough information to enforce the exclusion. Ask for marketing data to be deleted separately and say clearly that you are not treating the two as the same request.
One month, extendable by two further months for complex requests. The operator must tell you if it is extending and why.
The data protection authority for your country, which is the ICO in the United Kingdom. If the refusal also involves marketing after self-exclusion, report it to the gambling regulator as well.
Verified against 2 primary sources. Last reviewed August 26, 2026.