What Data a Casino Holds on You, and Your Real Rights
A licensed online casino holds your identity documents, address history, payment details, betting and deposit records, and often income or wealth evidence gathered for source-of-funds checks — and by law it must keep most of that data for years after you close your account, even if you formally ask it to delete everything. Anti-money-laundering rules override the ordinary data-protection right to erasure for exactly this category of record. What you do keep, in the EU/UK under GDPR and in Canada under PIPEDA, is a strong right to see what’s held about you, to get it corrected, and to receive a portable copy — plus a right to have non-AML data deleted once it’s no longer needed. This guide sets out what a casino actually holds, why erasure requests get lawfully refused for AML-relevant records, what rights survive that refusal, and how to make a subject access request that gets a real answer.
This assumes you’re already familiar with why casinos collect identity documents in the first place — see our KYC verification guide and withdrawal ID documents guide for the mechanics of what’s requested and when. If you’re worried about how a closed account’s data is being handled specifically, see our guide on what happens when a casino closes your account. This piece focuses purely on the data-privacy side: what’s held, who can see it, and what you can actually make an operator do about it.
What data a licensed casino actually holds on you
The exact set varies by operator and by how deep any source-of-funds review went, but a licensed casino that’s processed even a single withdrawal typically holds:
| Category | Typical contents |
|---|---|
| Identity data | Passport/ID/driving licence scan, date of birth, nationality, a selfie or liveness-check video |
| Address data | Current and sometimes historical addresses, utility bills or bank statements used as proof |
| Payment data | Masked card details, e-wallet account identifiers, bank account details used for deposits/withdrawals |
| Financial/source-of-funds data | Payslips, employment contracts, bank statements, sale contracts or inheritance documentation, where an enhanced review was triggered |
| Account and behavioural data | Every deposit, wager, win, loss and withdrawal; session times and duration; device and IP metadata; responsible-gambling tool usage and any self-exclusion status |
| Communications | Support chat transcripts, emails, and records of any complaint raised |
| Risk and compliance flags | Internal notes from KYC/AML review, sanctions or politically-exposed-person (PEP) screening results, fraud or multi-accounting flags |
Some of this — betting and behavioural data especially — is also used for responsible-gambling monitoring; see our responsible gambling tools guide for how that data feeds deposit limits, reality checks and self-exclusion. Sanctions and PEP screening results are a normal part of standard onboarding at every licensed operator, not a sign you’re specifically suspected of anything.
Why AML law forces retention even after you ask for deletion
Anti-money-laundering law is not data-protection law, and where the two conflict, the AML retention duty generally wins for the specific records it covers. In the UK, the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 require a “relevant person” (which includes gambling operators subject to these regulations) to keep customer due diligence records and transaction records for five years, beginning from the date the transaction is complete or the business relationship ends — with an absolute cap of no more than ten years for certain transaction records. Only once that retention window has actually expired must the personal data be deleted, and even then there are carve-outs: if the operator is separately required by another law to keep it, if it’s needed for ongoing or reasonably anticipated legal proceedings, or if you’ve given specific consent to further retention.
This isn’t a loophole operators invented — it’s the explicit design of the framework. Under the UK GDPR, the right to erasure (Article 17) simply does not apply where processing is necessary to comply with a legal obligation, among other listed exceptions (freedom of expression, public-interest tasks, archiving, and the establishment or defence of legal claims). The Gambling Commission’s own guidance on the interaction between GDPR and gambling regulation is direct about this: operators must retain compliance-relevant records for a minimum of five years after a customer relationship ends, and data-subject rights such as erasure “may not apply” where the lawful basis for holding the data is a legal obligation rather than consent. In practice, if you have an open account, an active due-diligence file, or you’re within the five-year AML retention window, an erasure request covering that data will very likely be lawfully refused — and the operator has to tell you so, in writing, with the reason and your right to complain to the regulator.
The same logic applies to self-exclusion records specifically: if you’ve self-excluded, the operator (and any shared self-exclusion scheme it participates in) needs to retain proof of that exclusion to actually enforce it and to demonstrate compliance during a regulatory audit — asking to have your own self-exclusion record deleted would be self-defeating in any case, since the record is what stops you being let back in.
What rights you genuinely have — by jurisdiction
EU and UK: GDPR / UK GDPR
Under the GDPR (and its near-identical UK GDPR post-Brexit form), you have several distinct rights, each with its own scope:
- Right of access (Article 15). You can request confirmation of what personal data is held about you, a copy of it, and information on why it’s processed, who it’s shared with, and how long it will be kept. This right is not blocked by AML retention — you’re entitled to know what’s held even while it’s lawfully retained.
- Right to rectification (Article 16). Incorrect data (a misspelled name, an old address still shown as current) must be corrected.
- Right to erasure (Article 17). Applies where data is no longer necessary for the purpose collected, consent is withdrawn (where consent was the lawful basis), or processing was unlawful — but does not apply where the operator has a legal obligation to keep the data, which covers most AML-relevant records for their statutory retention period.
- Right to data portability (Article 20). Applies to data you provided yourself, processed by automated means, on the basis of consent or a contract — you can ask for it in a structured, machine-readable format to move to another provider. This right is narrower than access: it doesn’t cover data the operator generated about you (like internal risk scores), only what you gave it.
- Right to restrict processing (Article 18) and right to object (Article 21) sit between access and erasure — useful if you dispute the accuracy of data or object to a specific use (e.g. marketing) without needing the data deleted outright.
A request for any of these can be made verbally or in writing (an email is enough); the organisation has one calendar month to respond, extendable by up to two further months for genuinely complex requests, and must tell you within the first month if it’s taking the extension and why. It cannot charge a fee for a straightforward request, and can only refuse on defined grounds (a legal obligation covering the data, or the request being manifestly unfounded or excessive) — not simply because complying is inconvenient.
Canada: PIPEDA
The Personal Information Protection and Electronic Documents Act (PIPEDA) governs private-sector data handling for most Canadian businesses (three provinces — Alberta, British Columbia and Quebec — have their own equivalent private-sector laws that can apply instead). Its Principle 9 (Individual Access) gives you the right to be told what personal information an organisation holds about you, how it’s being used, who it’s been disclosed to, and to challenge the accuracy of that information — broadly similar in spirit to GDPR access, though PIPEDA does not include an explicit, codified “right to erasure” of the kind Article 17 provides. Organisations must respond within 30 days of a written request, generally at free or minimal cost, and any charge must be disclosed and agreed to in advance. If a Canadian-facing operator refuses or ignores a request, the Office of the Privacy Commissioner of Canada (OPC) is the body that investigates PIPEDA complaints.
Flag: PIPEDA’s practical treatment of AML-driven retention specifically (i.e. whether Canadian AML/FINTRAC-type record-keeping duties for gambling operators create an equivalent override to the UK’s) was not independently verified against a primary Canadian source during this research and should be treated as reasoned by analogy with the UK/EU position rather than confirmed for Canada — see unverified_claims.
How to make a subject access request that actually gets answered
- Identify the right controller. Send the request to the operator’s own data-protection contact (its privacy notice will name it, or an email like dpo@ or privacy@ the operator’s domain) — not to the regulator. Regulators (the ICO, the OPC) handle complaints if the operator fails to respond properly; they don’t process the request itself.
- State clearly which right you’re exercising. “I am making a subject access request under UK GDPR Article 15” (or, in Canada, “an access request under PIPEDA Principle 9”) removes any ambiguity about what you’re asking for and starts the statutory clock.
- Be specific if you want a faster, cleaner answer. A narrowly scoped request (“all KYC and SOF documents and decisions from my account between these dates”) is usually processed faster than an unlimited “all data you hold,” though you’re entitled to ask for everything.
- Expect an identity check. Operators (and the ICO’s own request service) will typically ask for proof of ID and address before processing — this is standard practice to stop someone else’s data being disclosed to the wrong person, not a stalling tactic on its own.
- Track the deadline. One calendar month from receipt in the UK/EU; 30 days in Canada. If the operator asks for ID verification first, the clock generally starts once that’s supplied.
- If you’re refused, ask for the specific legal basis. A lawful refusal under the legal-obligation exemption must name the obligation (in practice, usually the AML retention rule) and tell you about your right to complain to the regulator and, in the UK/EU, to seek a judicial remedy.
- Escalate to the regulator if the response is late, incomplete, or unexplained. In the UK, that’s the Information Commissioner’s Office (ICO); in Canada, the Office of the Privacy Commissioner of Canada (OPC); in Malta, data-protection complaints go to Malta’s Information and Data Protection Commissioner rather than the MGA (the MGA handles gambling-specific complaints — see our KYC delays and escalation guide for the gambling-specific complaints ladder).
What to expect back
A properly handled request should return: confirmation of whether data is held, a copy of it in an accessible format, an explanation of the purposes of processing, categories of recipients it’s shared with (payment processors, KYC vendors, fraud databases, the regulator on request), the retention period or the criteria used to set it, and — if any exemption applies to part of the data — which part, and why. It’s normal and lawful for the response to include the caveat that identity, transaction and due-diligence records are being retained under the AML retention rule and won’t be deleted until that period lapses, even though you can still see and query them under your access right in the meantime.
FAQ
Can I make a casino delete all my data?
Not while an AML retention obligation applies to it. In the UK, gambling operators must keep customer due diligence and transaction records for five years after the relationship ends (in some cases longer), and the GDPR’s right to erasure explicitly does not apply where processing is necessary to comply with that kind of legal obligation. Once the retention period genuinely expires, the operator must delete the data unless a further exemption applies (an ongoing legal obligation, active legal proceedings, or your own consent to keep it).
What is a subject access request?
A formal request to an organisation asking what personal data it holds about you, why, and who it’s shared with, plus a copy of that data. Under UK/EU GDPR it must be answered within one month (extendable to three for complex requests); under Canada’s PIPEDA, within 30 days. It can be made verbally or in writing and, for a standard request, should be free.
Does GDPR apply to a Curaçao- or Kahnawà:ke-licensed casino?
GDPR applies based on whose data is being processed and where the operator targets its services, not solely on where it’s licensed — an operator marketing to and processing the data of EU/UK residents is generally within scope regardless of its gambling licence’s jurisdiction. That said, enforcement against an operator with no EU/UK establishment or assets can be practically difficult, which is a separate question from whether the legal obligation exists. Flag: this is a general description of GDPR’s extraterritorial scope, not a verified finding about any specific Curaçao- or Kahnawà:ke-licensed operator’s compliance status.
Can I get a copy of my betting history from a casino?
Yes — betting, deposit and withdrawal history is personal data about you, and a subject access request should return it (or a clear explanation of how to access it, since some operators provide this directly through account statements rather than a bespoke export). This is separate from the source-of-funds documents you may have submitted, which will also be covered by the same request.
Sources
- Information Commissioner’s Office (ICO) — Make a subject access request
- Information Commissioner’s Office (ICO) — Right to erasure — guidance for organisations
- Gambling Commission — Gambling regulation and the General Data Protection Regulation (GDPR)
- UK legislation.gov.uk — The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, Regulation 40 (record-keeping)
- Office of the Privacy Commissioner of Canada — Accessing your personal information — businesses
- Office of the Privacy Commissioner of Canada — PIPEDA Fair Information Principle 9 — Individual Access