Personal data and account evidence

How to request your personal data from a casino

A subject access request asks a controller for your personal data and supporting information about its use. It is not a gambling complaint, a demand for every internal business document or a route that guarantees compensation, disclosure or complaint success. A useful request identifies the account, limits the period and names the data needed for a clear purpose.

Direct answer

Ask the verified controller for specific personal data

Find the controller named in the casino's current privacy notice, verify its secure rights-request channel independently and describe the personal data, account identifiers and proportionate date range you need. Keep a copy and record when the controller has the request and any reasonably required identity evidence. Use a separate gambling complaint if you want the operator to decide a withdrawal, balance or fairness dispute.

Check whether UK data rights apply before relying on them

The ICO guidance used here explains rights under the UK GDPR and Data Protection Act 2018. Whether those rights apply depends on the controller, the processing and the connection to the UK. A casino being accessible from Britain, using English or holding an overseas gambling licence does not by itself settle that question.

Start with the current privacy notice and terms. Record the legal entity said to control the data, its contact details, any representative or data-protection contact, the account domain and the jurisdiction claimed. If UK applicability is uncertain, state that uncertainty instead of presenting an ICO route as guaranteed. The offshore complaint route map explains why a gambling regulator, data authority, payment provider and court have different powers.

A subject access request and a gambling complaint do different jobs

Swipe sideways to see every column.

Differences between a subject access request and a gambling complaint
RouteWhat it asks forWhat it does not decide
Subject access requestYour personal data, processing information and a copy of personal data within the applicable right.Whether a bet, bonus, withdrawal, account closure or balance decision was fair.
Gambling complaintAn explanation, correction or remedy for the gambling service or account decision.Automatic access to every internal record or third-party document.
Data-protection complaintA review of how the controller handled personal data or a rights request.A gambling payout, compensation or a ruling on the underlying bet or withdrawal.

The same facts may create more than one route, but keep the questions separate. Use the casino complaints guide for the service dispute and the complaint evidence pack to preserve a dated chronology. Do not wait for a subject access response if a separate complaint or legal deadline may expire.

Verify the controller and secure destination

  1. Open the current privacy notice independently. Do not rely on an address supplied only in an unsolicited message or social-media reply.
  2. Record the legal entity. Keep the controller name separate from the casino brand, platform provider, payment firm and gambling licensee.
  3. Confirm the channel. Prefer the rights form, account portal or privacy email published on the verified domain.
  4. Save evidence of delivery. Keep the submitted text, destination, date, time, time zone and acknowledgement.
  5. Do not expose the request publicly. Account identifiers and personal records should not be posted in a review, forum or public complaint.

Choose data categories that match the task

A request does not need legal wording or the phrase subject access request to be valid, but precision can make it easier to identify the records. Ask for your personal data rather than naming every document the business may hold. The ICO says a controller may perform a reasonable and proportionate search. Some material may also be restricted, exempt or redacted, including information about another person.

Swipe sideways to see every column.

Potential personal data categories for a focused casino subject access request
Possible categoryUseful descriptionBoundary
Account and profileRegistration data, recorded status changes, restrictions and closure entries for the stated account.Do not assume this includes every company record about the brand.
Transactions and playDeposits, withdrawals, balance movements and account-linked gambling history for a defined period.UKGC account-history duties apply only within their licensed scope and do not define the full SAR right.
VerificationRequests, submissions, results communicated to the account and related correspondence.Do not demand security logic, another person's data or unrestricted fraud models.
CommunicationsAccount-linked email, chat, complaint and safer-gambling contacts within the period.Staff or third-party data may be redacted where the law permits.
Marketing and controlsConsent or preference history, limits, blocks, exclusions and recorded changes.A data record does not decide whether the operator complied with every gambling duty.

Copyable focused request builder

Replace every bracketed field. Send the request only to a verified controller channel. Do not include a password, payment-card security code, one-time code or more identity information than the controller reasonably needs.

Swipe sideways to see every column.

Fields for a focused casino subject access request
PartSuggested wording
Right and controllerI am asking [controller legal name] for access to my personal data under the applicable UK data-protection right.
Account matchMy account identifiers are [registered email], [username or account reference] and [another low-risk identifier if needed].
Purpose and periodI need the following personal data for [brief purpose], covering [start] to [end].
CategoriesPlease provide [specific categories] and the required information about purposes, recipients, retention, source and relevant automated decision-making where applicable.
Format and securityPlease provide the response in a commonly used electronic format through a secure channel. Tell me promptly if you reasonably need identity evidence or clarification.
RecordPlease acknowledge receipt and explain any restriction, redaction, extension, refusal or category you cannot locate.

Identity checks must be necessary, proportionate and secure

A controller may ask for information reasonably needed to confirm identity, particularly where it has genuine doubts. The ICO says the check should be reasonable and proportionate and that formal identification should not be demanded unless it is necessary. The controller should request needed evidence promptly, and the response period begins once it receives the required identity information.

Ask why each item is needed, whether an existing authenticated account or lower-risk identifier is sufficient, how it will be transferred and how long it will be kept. Redact irrelevant fields where the controller confirms that is acceptable. Use only the verified secure route. Never send identity documents through social media, an unverified email or a link received only from an unsolicited contact. The source-of-funds and source-of-wealth guide explains why a financial-evidence request is a separate process with its own privacy test.

Track the one-month period without promising an exact outcome date

The ICO states that a controller should respond without undue delay and normally within one month. The period can extend by up to two further months for a complex request or multiple requests, but the controller should explain the extension within the first month. The calculation can depend on when reasonably required identity evidence is received. A reasonably required clarification can pause the clock, but a controller cannot force the requester to narrow a clear request.

Record the request receipt, any identity request, secure identity submission, clarification question, clarification response, extension notice and final response. Use the ICO's current time-limit guidance for the calendar calculation. Do not infer complaint success, compensation or unlawful conduct from delay alone.

A right to personal data is not a promise of every internal document

Section 78 of the Data (Use and Access) Act 2025 clarifies that the right is limited to information the controller can provide after a reasonable and proportionate search. The ICO also describes exemptions and restrictions, third-party information and situations in which a request may be refused or charged for under the applicable rules.

A response may therefore supply personal data extracted from a document without handing over the whole document. It may redact another person's information or explain a lawful restriction. That does not make every restriction correct, but the proper next step is to record the category, explanation and missing information, then challenge it through the appropriate data-protection route. Do not claim entitlement to unrestricted fraud systems, legal advice, source code, another customer's records or every document that mentions an account.

Two fictional request and response scenarios

These cases contain no real casino, account or person. Each requested category is reconciled against one response treatment so an omission is visible without turning a restriction into an accusation. The tests also require multiple account identifiers, a bounded period, secure and limited identity handling and a separate gambling complaint.

Fictional case one: closed account and disputed withdrawal

Purpose: Obtain the requester's personal account and withdrawal records before preparing a separate gambling complaint.

Request frame: identify the account with registered email and operator account reference; cover 1 March to 30 April in the fictional account year.

Identity response: The operator must distinguish the requester from another account holder. Use the verified account portal named in the controller's privacy notice. The test requires the evidence request to remain limited to necessary data.

Swipe sideways to see every column.

Fictional case one: closed account and disputed withdrawal request and response reconciliation
Requested categoryResponse treatmentWhat the record says
Account profile and status historyDisclosedAccount status entries and dates are supplied.
Deposit and withdrawal ledgerDisclosedThe transaction ledger is supplied for the requested range.
Withdrawal status and timestamp recordsPartly disclosed or redactedCustomer-linked status events are supplied, while unrelated third-party details are redacted.
Identity and verification correspondenceRestricted with a stated reasonCorrespondence is supplied, but the response states that a limited part is restricted and explains the relied-on ground.
Support communicationsDisclosedAccount-linked chat and email copies are supplied.

Independent reconciliation: 5 of 5 requested categories are accounted for; unresolved categories: 0. This reconciliation does not decide the separate gambling complaint.

Fictional case two: account controls and safer-gambling record

Purpose: Obtain personal records about account controls and contacts without asking the SAR response to decide whether the operator acted fairly.

Request frame: identify the account with registered email and month and year of birth; cover 1 January to 31 May in the fictional account year.

Identity response: The supplied email alone does not reliably establish the requester's identity. Use a single-use encrypted upload link verified through the privacy notice. The test requires the evidence request to remain limited to necessary data.

Swipe sideways to see every column.

Fictional case two: account controls and safer-gambling record request and response reconciliation
Requested categoryResponse treatmentWhat the record says
Deposit and loss-limit historyDisclosedLimit changes and effective times are supplied.
Self-exclusion and account-restriction recordsDisclosedRecorded restriction events and account effects are supplied.
Safer-gambling contact logPartly disclosed or redactedThe requester's contact records are supplied with staff and third-party details redacted where justified.
Marketing preference historyDisclosedPreference changes and recorded times are supplied.
Account activity historyReported as not foundThe response says no additional activity record was located and describes the systems and period searched.

Independent reconciliation: 5 of 5 requested categories are accounted for; unresolved categories: 0. This reconciliation does not decide the separate gambling complaint.

Review the response by category, not by document count

  1. Confirm the account and period. Check that the response belongs to the correct requester and covers the requested dates.
  2. Reconcile every category. Mark it supplied, partly supplied, restricted with a reason, reported not found or unanswered.
  3. Keep raw evidence unchanged. Save the response, cover letter, secure-download expiry and file list before annotating a working copy.
  4. Protect other people. Do not republish personal data, identity documents or unredacted account records.
  5. Ask a precise follow-up. Name the missing category or apparent mismatch and request the controller's explanation without demanding every internal file.

Use the right escalation route

If the concern is how the controller handled the request, first use its data-protection complaint process and keep a written record. The ICO explains how to raise a data-protection complaint and what evidence to include. An ICO complaint is not a casino dispute ruling and does not promise compensation or disclosure of every requested item.

If the unresolved issue is a balance, withdrawal, account closure or gambling decision, continue that issue through the applicable gambling complaint route. Keep the account access, balance evidence, jurisdiction and requested remedy separate without treating the SAR response as the remedy.

Protect identity data and step away if the record shows harm

Store the request and response securely, remove unrestricted sharing links and redact public copies. Do not send a new deposit, verification payment or recovery fee to obtain data. Do not let an unsolicited helper take over the request or ask for an account password, one-time code or payment-card security details.

Records can reveal gambling harm. If the history shows unaffordable spending, repeated attempts to win back losses or gambling that is affecting health, finances or relationships, stop gambling and use the safer-gambling support area. A data request should not become a reason to sign in, deposit or continue gambling.

Copyable request and response evidence record

Swipe sideways to see every column.

Fields for tracking a casino subject access request
StageRecordPrivacy boundary
Controller checkPrivacy-notice URL, legal entity, contact channel, domain and check time.Do not copy identity data into a public record.
RequestDelivery time, account identifiers used, period, categories, purpose and saved text.Use the least data that reliably identifies the account.
IdentityReason requested, items, secure channel, submission time and retention explanation.Never record a password, one-time code or complete identity image here.
Clock eventsAcknowledgement, clarification, response, extension and explanation dates.Calculate with current ICO guidance rather than guessing.
Response mapEach category as supplied, partial, restricted, not found or unanswered, plus the stated reason.Keep third-party and sensitive records out of public correspondence.
Separate disputeGambling complaint issue, desired remedy, applicable deadline and route.Do not present a data complaint as a payout decision.

Primary sources and method

The editorial team reopened every controlling source on 30 September 2026 immediately before publication preparation. ICO guidance controls the UK subject-access procedure, identity, timing, security, restriction and complaint boundaries. Legislation controls the reasonable and proportionate search limit. UKGC sources are used only for account information within their licensed scope and do not replace the data-protection test. The UKGC's own SAR form was not presented as a route for requesting data from a casino. No operator, affiliate or secondary source controls this guide. Recheck the ICO sources every 30 days for the first 90 days after publication, if separately approved, then every 90 days while stable. Submit corrections through our editorial corrections process.