What Does Your Casino Actually Know About You, and Can You Make It Forget?

Somewhere on a server, there’s a file with your name on it. Every spin, every deposit, every late-night session, every risk score a system has assigned you. You’re entitled to read the whole thing, for free, and the casino can’t refuse. Here’s how, and what happens when you ask them to delete it.
By Brian Taylor | 29 July 2026
You have the right to request a copy of everything a casino holds on you. Of all the rights UK players hold, this is the one almost nobody uses, and it happens to be one of the most powerful. Once you understand what’s actually in your file, you’ll understand why operators would prefer you never asked.
I’ll start with the scale of it. People imagine their casino account as a login, a balance and a transaction history. What the operator actually holds is closer to a biography. Gambling companies are among the most data-hungry consumer businesses in Britain, partly because regulation forces them to be and partly because knowing you intimately is how they make money. The file isn’t sinister by definition. But it’s far bigger than you think, and you own the right to see every page.
What’s typically in your file
The obvious layer. Your identity documents, address history, payment methods, deposits, withdrawals and account settings, plus every verification file you’ve ever uploaded.
The behavioural layer. Every bet and every spin, stake by stake, with timestamps. Session start and end times. The games you play, the order you play them in, how your staking changes within a session, and what time of night you tend to stop.
The technical layer. Device identifiers, IP addresses, app and browser data, and the tracking that links your phone to your laptop to your tablet.
The judgement layer. This is the one that surprises people. Marketing segments deciding which offers you see. Safer gambling risk scores generated by the harm-detection systems. Anti-money-laundering risk ratings. Affordability assessments. Internal notes from support chats. Verdicts about you, written by systems and staff, that you’ve never seen.
That judgement layer is important because it drives decisions. When a casino restricts your account, holds a withdrawal, flags you for a source-of-funds review, or decides which promotions land in your inbox, it’s acting on the contents of that file. I’ve written before about how casino lobbies nudge players towards particular games, and the fuel for that nudging is exactly this data. You’re not being shown “a casino”. You’re being shown “your casino”, assembled from what the operator has learned about you. Which makes the right to read the file less an act of curiosity and more an act of basic self-defence.
The request that opens the filing cabinet
The tool is called a subject access request, and it’s beautifully simple. Under UK data protection law, you can require any organisation to hand over a copy of the personal data it holds about you, along with information about why it’s processed, who it’s shared with, and how long it’s kept. It’s free in almost all circumstances. It doesn’t need a form, a solicitor, or even the word “GDPR” spelt correctly. An email to the operator saying “I am making a subject access request for a copy of all personal data you hold about me” does the job, sent ideally to the data protection contact listed in their privacy policy, or failing that to support with a request that it be passed to the right team.
The operator then has one calendar month to respond, extendable in complex cases, and may ask you to clarify what you’re after if the request is vague, which pauses the clock. My advice is to be broad but explicit. Ask for your transaction and gameplay history, session logs, all notes and internal records relating to your account, any risk assessments or scores applied to you, records of decisions taken about your account, marketing profile data, and copies of chat and email correspondence. Spell it out, because a lazy response that sends you your deposit history and nothing else is common, and it’s not compliance.
The part operators won’t volunteer
They can’t refuse your request because it’s inconvenient, because you’re in a dispute with them, or because they suspect you’ll use the results against them. The regulator has been explicit on this. Your motive is irrelevant. The right stands.
And that’s exactly why this is such a formidable tool in a dispute. Think about the situations that you might find yourself in when you have a dispute with a casino. A withdrawal held with vague explanations. An account restricted after a win. Support telling you one thing in chat and the operator later claiming another. A source-of-funds review that arrived from nowhere. In every one of those situations, the operator’s version of events lives in your file: the internal notes, the timestamps, the risk flags, the record of what support actually logged. A subject access request drags all of it into the light. I’ve seen disputes transformed by the discovery that an operator’s own records contradicted what its complaints team had been claiming. You’re entitled to the transcript of your own treatment, and asking for it costs you nothing but a month’s patience.
I have two caveats to keep your expectations realistic. First, you’ll get your personal data, not the company’s secrets. The weightings inside their algorithms, other customers’ information, and privileged material can be withheld or redacted, and some anti-money-laundering material sits behind legal walls that no data request can breach, for the sensible reason that tipping off a suspect would defeat the point. Second, expect the response to arrive as a sprawl of spreadsheets and PDFs rather than a neat dossier. It’s raw filing cabinet, not bedtime reading. Persist anyway. The interesting material is usually in the notes fields.
The file they share with each other
Here’s the part of this topic that deserves more attention than it gets. Your file no longer necessarily stays with one operator. The industry now runs data-sharing arrangements, built with the regulator’s encouragement and tested through the data watchdog’s own sandbox process, under which operators can share certain behavioural information about customers at risk of harm, so that a person showing serious danger signs at one brand can be protected across others. The best known of these single-customer-view schemes means that, in defined circumstances, a decision made about you at one casino can follow you to the next one.
Let me be fair about the purpose, because it’s a serious one: the harm these schemes target is real, and the case for stopping a person in crisis simply hopping to the next brand is strong. I’ve no interest in scaremongering about a safety net. But players deserve to know the net exists, because almost none do. If you’ve ever wondered how a casino you’ve never played at seems oddly cautious with you from day one, cross-operator sharing is one possible answer, and your subject access request can ask about exactly this: what data has been shared about you, with whom, and under what scheme. Transparency cuts both ways, and an operator participating in industry data sharing should be able to tell you so.
Can you make them forget you?
Now the second half of this article’s title, and my answer is probably honest more than it is satisfying. Alongside the right to see your data sits the right to erasure, the so-called right to be forgotten. It’s a wide-ranging right, and casinos are not exempt from it. But it’s a qualified right, not a magic wand, and gambling is one of the industries where the qualifications bite hardest.
Close your account and ask for erasure, and a well-run operator should delete what it can, stop all marketing instantly, and retain only what the law compels, for only as long as the law compels it. “We have to keep everything forever” is not a lawful answer, and neither is ignoring the request. If you get either, ask them to specify which data they’re retaining, under which legal obligation, and for how long. An operator that can’t answer that question is telling you it hasn’t thought about it, and that’s precisely the kind of sloppiness the Information Commissioner’s Office exists to hear about. Complaints to the ICO are free, and the fines it can levy run into the millions, which tends to concentrate minds.
One habit worth adopting whether or not you ever fire off a request: read the privacy policy of any casino you join, or at least the retention and sharing sections. I know, nobody does. But after years of writing about what these companies hold, demand and decide, I’ve come to think the privacy policy is one of the more revealing documents an operator publishes. The good ones are specific about what’s kept and why. The bad ones are vague in ways that tell you exactly how seriously your data will be treated once it’s theirs.
What does your casino actually know about you? More than you’d guess, judged in ways you’ve never seen, and increasingly shared beyond the brand you gave it to. Can you make it forget? Partly: the marketing machine, yes, instantly and permanently; the legal records, no, not until the retention clocks run out. But between those two poles sits the right that matters most: simply to look. A subject access request costs nothing, takes one email, and turns the one-way mirror around. The casino has been reading your file since the day you signed up. Once in a while, it’s worth reminding them that you can read it too.