The Right To Be Forgotten And Your Online Casino Account: What EU Players Need To Know In 2026

The digital landscape has shifted dramatically for EU citizens, especially those who engage with online gaming. When you sign up at an online casino, your personal data, from payment information to betting history, gets stored on operators’ servers. But what happens when you want that information erased? We’re exploring how the right to be forgotten, a cornerstone of EU data protection law, directly impacts your online casino accounts and what you can actually do about it.

Understanding The Right To Be Forgotten Under GDPR

The right to be forgotten, formally known as the right to erasure, sits at the heart of the General Data Protection Regulation (GDPR). Introduced in 2018, this fundamental right grants EU citizens the power to request deletion of their personal data under specific circumstances.

Under Article 17 of GDPR, you can demand erasure when:

It’s important to understand that this isn’t an absolute right. Organisations can refuse deletion if they have legal obligations to retain data, such as anti-money laundering (AML) requirements or fraud prevention. But, the burden falls on them to justify why they’re keeping your information.

In practice, when you exercise this right, companies must delete your personal data within 30 days (extendable to 90 days for complex requests). They must also inform any third parties they’ve shared your data with, unless it’s impossible to do so. This creates a significant operational requirement for any platform handling customer information, including online casinos.

The penalty for non-compliance is steep. Regulators can issue fines up to €20 million or 4% of annual global turnover, whichever is higher. This financial consequence motivates operators to take these requests seriously.

How This Right Applies To Online Casino Operators

Online casino operators exist in a peculiar position. They’re subject to GDPR like any other company handling EU citizen data, yet they also face conflicting legal obligations that complicate erasure requests.

The Compliance Dilemma

Most EU jurisdictions impose strict gaming regulations requiring operators to maintain comprehensive records. These include:

RequirementRetention PeriodPurpose
Customer identification 5-10 years AML/KYC compliance
Transaction history 5-7 years Tax and fraud prevention
Account activity logs 3-5 years Responsible gaming oversight
Dispute resolution records Varies Legal protection

This creates genuine tension. GDPR says you can request erasure: gaming law says operators must retain specific data. When conflicts arise, the operator’s legal team typically wins, and your erasure request gets partially denied.

But, operators must still respect your rights where legally possible. They can anonymise your data rather than delete it, removing identifiers whilst retaining activity records for compliance. They can also delete non-essential information like marketing preferences, contact details beyond verification requirements, and communication history.

Many Spanish casino players assume they have no recourse here. That’s incorrect. Legitimate EU-licensed operators (particularly those regulated by bodies like the Malta Gaming Authority or Gibraltar Regulatory Authority) understand GDPR obligations and take erasure requests seriously. They’ve invested in infrastructure to handle partial deletions and data anonymisation.

Operators licensed outside the EU or those offering services illegally in Spain treat data protection far more casually. This is one reason why choosing properly licensed platforms matters beyond just regulatory legitimacy.

Your Next Steps: Exercising Your Right With Casino Platforms

Understanding your rights means nothing without actionable steps. Here’s how to properly exercise your right to be forgotten with online casino operators.

Start With The Data Subject Access Request

Before requesting deletion, ask for a copy of what they hold. Contact the casino’s Data Protection Officer (DPO) or privacy team, look for this contact on their website under privacy policies. Request all personal data they hold on you. They’re legally bound to provide this within 30 days, free of charge.

This reveals exactly what you’re dealing with: login credentials, payment history, identity verification documents, communication logs, and behavioural tracking. Some operators also link external data from fraud prevention services.

Submit Your Erasure Request

Once you understand their data holdings, submit a formal erasure request. Be specific:

  1. State you’re exercising your right to erasure under GDPR Article 17
  2. Identify the lawful basis for deletion (withdrawal of consent is typical)
  3. Request confirmation of deletion or anonymisation
  4. Ask for notification to third parties where applicable
  5. Request written acknowledgement within 30 days

Don’t phone or use live chat. Submit requests via email to the DPO or registered privacy contact. This creates a paper trail. For additional security, consider using professional data erasure services that handle GDPR requests on your behalf.

Handle Pushback Effectively

If the operator refuses or delays, escalate to your national data protection authority. Spain’s AEPD (Autoridad Española de Protección de Datos) investigates complaints and can impose fines. Reference your GDPR rights clearly in any correspondence, operators know regulators take this seriously.

Remember: you have legitimate rights here. Proper exercise of them protects your privacy and holds operators accountable.