What Personal Data Online Casinos Handle
Opening an account on an online gambling platform involves far more than a username and password. Basic data typically includes full name, date of birth, address, and email — collected already at the first step of registration.
Beyond that, providers often collect more sensitive data because of their regulatory obligations. This includes copies of identity documents, requested as part of KYC verification — covered in more detail on the KYC verification page.
A third category covers technical and behavioral data: IP address, device and browser type, login times, and transaction and gameplay history. This is typically recorded for security, fraud prevention, and regulatory purposes.
Each category serves a different purpose and is subject to a different level of protection.
GDPR Principles in Brief
The GDPR (General Data Protection Regulation) has set the framework for handling personal data across the EU since 2018. It applies to any provider that processes the data of EU residents, regardless of where the company itself is based.
The regulation rests on a handful of core principles, summarized below.
[INFOGRAPHIC: The seven GDPR principles summarized visually]
| Legal Concept | What It Means | Source Type | Verified |
|---|---|---|---|
| Lawfulness and fairness | Processing must have a legal basis and be transparent | EU regulation (2016/679) | 2026-09-22 |
| Purpose limitation | Data may only be used for the stated purpose | EU regulation (2016/679) | 2026-09-22 |
| Data minimization | Only the necessary amount of data should be requested | EU regulation (2016/679) | 2026-09-22 |
| Accuracy | Data must be kept up to date and correct | EU regulation (2016/679) | 2026-09-22 |
| Storage limitation | Data may only be kept as long as necessary | EU regulation (2016/679) | 2026-09-22 |
| Integrity and confidentiality | Data must be protected from unauthorized access | EU regulation (2016/679) | 2026-09-22 |
| Accountability | The data controller must be able to demonstrate compliance | EU regulation (2016/679) | 2026-09-22 |
These aren't abstract legal text — in practice, they determine what data an operator can request and how long it can be kept.
What Legal Basis Allows Your Data to Be Processed
Under GDPR, every instance of data processing needs a specific legal basis — it isn't enough for the data to simply be useful to the provider. Four legal bases come up most often in the online gambling industry.
Contract performance covers data without which the service — account operation or a payout, for example — couldn't technically function. Legal obligation covers data required by regulation, typically the documentation tied to KYC and AML checks.
Legitimate interest applies to things like fraud prevention or maintaining system security, provided it doesn't disproportionately override the user's own interests. Consent, meanwhile, typically applies to marketing — sending a newsletter, for example — and it's the one legal basis the user can freely withdraw at any time.
What Rights the User Has
GDPR doesn't only impose obligations on data controllers — it also grants specific rights to the people whose data is processed. These rights apply to every regulated platform serving EU users, regardless of where the company is based.
| Right | What It Means in Practice | How It's Typically Exercised |
|---|---|---|
| Right of access | Find out what data is held about you | Written request to the controller |
| Right to rectification | Request correction of inaccurate data | Support request, sometimes with supporting documents |
| Right to erasure | Request deletion once the legal basis no longer applies | Written request, after identity verification |
| Right to restrict processing | Request a temporary halt to processing | Written, reasoned request |
| Right to data portability | Request data in a structured, transferable format | Written request to the controller |
| Right to object | Object to certain processing purposes | Written statement to the controller |
| Right to withdraw consent | Withdraw previously given consent at any time | Account settings or support |
One important nuance: the right to erasure isn't unlimited. If a law requires certain data to be retained — because of AML regulation, for instance — the controller can't disregard that obligation simply because the user requests deletion.
How to Exercise These Rights in Practice
Exercising these rights usually starts with a written request sent to the provider's data protection contact or support team. Many platforms provide a dedicated form or email address for this in the account settings.
Before submitting a request, it helps to state clearly which right is involved — access, erasure, rectification, or otherwise — since this affects what data and in what form the user receives back. The provider will typically also ask for identity verification, to confirm the request genuinely comes from the account holder.
Illustrative example (not actual Dukat.bet data — always verify this on the operator's official site): under the GDPR framework, controllers are typically expected to respond within one month, though this deadline can be extended for more complex requests.
If a response doesn't arrive on time, or the user disagrees with the response received, they have the right to file a complaint with the relevant data protection authority.
How Long Your Data Is Kept, and Who It May Be Shared With
Retention periods aren't uniform — they depend on why the data was collected and which law applies. Marketing data is typically kept only as long as consent remains in place, while documentation collected for regulatory purposes — AML compliance, for instance — often has to be retained for a set period even after the account is closed.
This isn't a discretionary choice by the provider; it stems from the anti-money-laundering obligations that apply to it, covered in more detail on the security page.
Data sharing also happens within a regulated framework. Payment providers, identity-verification partners, and — where legally required — authorities can gain access to certain data, strictly to the extent necessary.
Sharing for marketing purposes — with third-party advertising partners, for example — is typically subject to separate consent, which the user can withdraw at any time.
Practical Tips for Informed Data Sharing
Before registering, it's worth spending a few minutes reading the privacy policy, even though this feels tedious to many people. It reveals what data is requested, how long it's kept, and who it might be shared with.
It's also worth making sure you only upload identity documents through the provider's official interface — never by email or an unofficial channel — which significantly reduces the risk of misuse. If someone posing as official support asks for this kind of data through a different channel, that's typically a sign of a phishing attempt.
You can read more about account registration and the data involved on the open an account page.
You'll find details of dukatbet.org's own editorial data-handling practices on the privacy policy page. This is separate from how the operator, Dukat.bet, handles player data, which is always best confirmed through the operator's own official channels.