The Data Protection Act 2018, together with the UK GDPR, gives you real control over the data an operator holds on you, including, in many cases, the right to have it erased and the right to stop it being used for marketing.
Your right to erasure
You can ask an operator to delete the personal data it holds on you. A request can be made verbally or in writing, though putting it in writing and being clear about what you want removed gives you a record to rely on. The operator must normally respond within one calendar month, a period it can extend by up to two further months for complex or numerous requests, and it must explain its decision.
When an operator can refuse
Erasure is not absolute. An operator may need to keep certain records to meet its own legal and regulatory duties, for example anti-money-laundering obligations, where retention of five years is common under the Money Laundering Regulations 2017. Where it relies on that, it should tell you which data it is keeping and why.
You can ask. They must answer, and justify any refusal.
Stopping the marketing
Separate from erasure, you can object to your data being used for direct marketing, which an operator must then stop. If an operator ignores a valid request, you can complain to the Information Commissioner’s Office, which regulates these rights. The ICO can investigate and take action against an operator, but it does not award compensation; a claim for compensation would be a separate matter for the courts. If your data ended up in front of you because an operator ignored a self-exclusion, that can be part of a wider claim; if a balance was frozen on the back of a verification check, see your options when an account is frozen. A free assessment will tell you where you stand.
What an operator actually holds on you
A deletion request lands better when you know what you are asking to have deleted. An operator’s file on a player is usually far larger than the player imagines. It will typically include the complete account and transaction history, every deposit, wager, win and withdrawal, each one time-stamped. Alongside that sit the marketing flags recording which promotions you were sent and how you were segmented, the notes of any responsible-gambling interactions such as pop-ups displayed, limits suggested or welfare calls made, and a technical layer of device identifiers, IP addresses and session logs. Verification documents you uploaded, live-chat transcripts and email threads are all in there too, often going back years.
That inventory is exactly why anyone weighing a claim should think hard about the order of operations. A subject access request, compelling the operator to supply you with a copy of everything it holds, normally belongs before an erasure request, not after it. Erase too early and you may destroy the very records that would have shown what the operator knew about your play, and when it knew it. The account history is often the spine of a case, for the reasons set out in the evidence that recovers gambling losses, and our account audit service exists precisely to turn that raw export into a readable picture of what happened. Get the data out first; decide what to delete once you know what it shows.
Where the right to erasure genuinely runs out
It also helps to know in advance what a lawful refusal looks like, because not every no is stonewalling. Anti-money-laundering law obliges operators to retain identity and transaction records for years after a business relationship ends, and an operator citing that duty for those specific records is applying the law, not dodging you. The test is precision. A proper response erases everything it lawfully can, keeps only the categories a legal duty genuinely covers, tells you which categories those are and under which obligation each is held, and confirms that the retained data will not be used for anything beyond meeting that duty. A blanket refusal that names no legal basis, or one that quietly keeps your marketing profile alive under the banner of compliance, fails that test and is worth challenging. You can also ask for processing of whatever remains to be restricted, so the retained data sits frozen in storage rather than in active use.
Stopping the marketing without deleting the history
Erasure and the marketing objection are separate rights, and for anyone considering a claim the second is often the smarter first move. An objection to direct marketing is absolute: once made, the operator must stop, with no balancing exercise and nothing to argue about. Crucially, it leaves your account history intact, so you silence the emails, texts and push notifications while preserving the record a claim would depend on. Make the objection in writing, ask for written confirmation that it has been applied across every brand the operator runs, and state expressly that you object to your details being passed to affiliates or sister sites for marketing purposes. Operators commonly run dozens of casino brands from a single corporate group, and an objection worded for one site can leave the rest of the network still mailing you. The one-month response clock applies here just as it does to erasure, and unlike erasure there is no exemption for the operator to reach for: marketing is never something the law requires it to keep doing.
When the operator is offshore
Data rights do not stop at Dover, but enforcing them gets harder the further away the operator sits. The UK GDPR applies not only to companies established here but also to those abroad that offer services to people in the UK or monitor their behaviour, and an offshore casino that took your deposits in pounds, showed you prices in sterling and mailed you promotions is squarely within that reach. So the request is still worth making: send it in writing to the privacy or support address, keep proof that it arrived, and allow the calendar month for a response. Some offshore groups also nominate a UK or European representative for data matters; if one is named in the privacy policy, copy your request to it, because a representative with an address on this side of the world is considerably harder to ignore than a mailbox in a distant jurisdiction.
If the site simply ignores you, escalate on two tracks. Complain to the Information Commissioner’s Office, which can consider complaints about UK-linked processing wherever the company is based, and keep the silence itself on file, because a documented pattern of refusing lawful requests says something useful about how that operator treats every other obligation it has. And if your real goal is money rather than deletion, do not let the data fight distract from the claim; the practical routes are covered in getting money back from an offshore casino, and if the operator also ignored your self-exclusion, in when you can get money back after gambling on GamStop. In that situation, remember the earlier point in reverse: while a claim is live, retention is your friend, and erasure can wait until the matter is closed.
Further reading
- ICO, your right to get your data deleted (ico.org.uk).
- Data Protection Act 2018 (gov.uk/data-protection).
General information, not legal advice. We are not solicitors or a law firm. We connect clients with regulated legal partners.