Skip to the copy
WIRE

Connecting to the wire

Desk story / History

GDPR and Online Casinos: What European Players Should Know

A European player sat down one day and thought: why does this casino know everything about me. The answer is GDPR. The casino is required to know. The player is required to consent to it.

Copy sheetSM365
Filed
Byline
Bri Sutton
Length
827 words, about 4 minutes
Copy ID
SM365-C4848E4C
gdpr online casino data protection requirements showing european player privacy regulations
gdpr online casino data protection requirements showing european player privacy regulations

General Data Protection Regulation, GDPR, came into effect in the European Union on May 25, 2018. It changed how companies, including online casinos, handle personal data.

Before GDPR, casinos collected personal information loosely: name, address, payment information, betting history. The collection was extensive. The privacy protections were minimal. A casino operator could sell your data to third parties. They could use your information to market products you had never agreed to. There was no penalty for misuse because there was no law against it.

GDPR imposed structure. A casino must now tell you, clearly and upfront, what data they collect, why they collect it, who has access to it, and how long they keep it. You have the right to request deletion of your data. You have the right to request a copy of everything they have collected about you. You have the right to object to certain uses.

For players, this means: a European casino cannot legally track your behavior secretly. They must disclose their tracking. They cannot sell your data to advertisers without your explicit consent. They cannot use dark patterns (deceptive design) to trick you into agreeing to data collection.

A player sitting down at an online casino in France will see a privacy notice. It will say: "We collect the following information for the following purposes. Your data is retained for X amount of time. You have the following rights." This was not standard before GDPR. This is now required.

The Practical Implications

For a player, GDPR is useful. You can request deletion of your gambling history. You can access a complete download of every bet you have placed, every deposit and withdrawal, every correspondence with the casino. This is useful if you are disputing losses or trying to understand your play patterns.

The right to be forgotten is powerful. A player can request that a casino delete their account and all associated data. The casino has thirty days to comply. After deletion, the player should be off all marketing lists. The casino cannot legally contact you with promotional offers.

However, GDPR has exceptions. A casino can retain your data if retention is necessary for regulatory compliance. If a player disputes a charge with their credit card company, the casino needs to retain transaction records to defend themselves. If a player was banned for suspected fraud, the casino can retain that information to prevent re-registration.

Casino operators have responded by building more complex privacy architectures. They collect less data than they would prefer but collect enough to meet regulatory and business requirements. Marketing data is segregated from operational data. Third-party access is restricted. Data retention periods are shortened.

GDPR protects privacy, but it does not prevent the casino from operating. It simply requires transparency.

For problem gamblers, GDPR offers a tool: request deletion. A player in crisis can request that the casino delete their account, betting history, and contact information. The casino must comply. The player is off the marketing list. The player will not receive targeted promotion.

This is valuable because casinos have been known to market aggressively to problem gamblers. A player with a documented gambling problem, in some jurisdictions, still receives marketing emails. GDPR allows the player to stop this directly.

The Enforcement Problem

The strength of GDPR depends on enforcement. Regulators in each country have authority to investigate violations and impose fines. The fines are meaningful: up to 4 percent of annual revenue or twenty million Euros, whichever is higher.

In practice, enforcement is sparse. Regulators are under-resourced. A casino with millions of users has fewer incentives to violate GDPR blatantly if the fine would be fifty million Euros. But a casino with thousands of users might calculate that the fine is acceptable relative to the revenue they gain from selling data or using data for aggressive marketing.

Some casinos have been fined for GDPR violations. Most violations have been around insufficient consent (users not meaningfully told what they were agreeing to) or data retention (keeping data longer than they said they would). Actual unauthorized sale of data or use of data for impermissible purposes is harder to prove and less common.

What Players Should Do

Read the privacy notice. It is legal documents, but it is written in plain language now because of GDPR. You will see what data is collected and why. Ask yourself if you are comfortable with that level of tracking.

If a casino wants to use your data for marketing and you do not want that, you can usually opt out. Declining marketing does not prevent you from gambling. It prevents the casino from promoting to you.

If you open an account and never use it, request deletion. The casino has no legitimate reason to keep data on a user who never placed a bet.

If you are self-excluding, request that the casino delete your data simultaneously. This prevents the casino from using your past behavior to re-engage you after self-exclusion ends.

Share the copy