Gambling & Betting
Before you can bet, operators check what you can afford and where your money comes from, so your income and your bank statements go on file. Self-exclusion registers then share you across operators. Many keep the file five to ten years after your last log-in.
The read at a glance
An operator holds your bank checks next to a record of every bet.
A leak exposes your identity, your finances, and a record that can imply a gambling problem.
Anti-money-laundering and self-exclusion rules keep records for years; self-exclusion lists are held to protect you.
Play requires full identity verification and source-of-funds checks.
Industry profile reviewed 23 August 2026. Also machine-readable via the free API.
If it leaks
A betting history gets used against people by a partner, in a custody case, or by an employer. It leaks alongside the ID and bank details the account required, which makes it a fraud kit as well.
What repeats in the policies
Your payslips and bank statements go on file
In the US, a Social Security number and your precise location are a condition of playing at all. In the UK, many operators ask for payslips, bank statements and proof of where your money comes from, checked straight with your bank. They also watch every stake and loss with automated systems that can limit the account.
Shared with rival operators and with sport
In the UK, operators check you against a national self-exclusion register every time you log in, and an exclusion applies across every brand the group owns. Customers judged high-risk are pooled with competing operators. Your betting activity also goes to sports leagues, integrity bodies and gambling regulators, in the US and the UK alike.
Closing the account does not close the file
Many operators say they keep your data for five to ten years after you close the account or last log in, pointing to money-laundering rules. Others give no figure and keep it as long as they judge necessary. Asking to be shut out makes the file last longer: the record can be held a further seven years after the exclusion ends, and a permanent exclusion has no end at all.
What a company here typically holds
Worked out from the industry, not from any one company. What you actually handed over is yours to record.
What this can reveal about you
Built only from what this kind of service actually collects. A dimension that the data does not support is not listed.
Money and net worth Highly likely
Source-of-funds checks and stakes reveal it.
Mental health Possible
Play patterns are scored for addiction markers.
What lawfully stays after you leave
Two kinds of hold. Law sets it: a statute makes them keep it. They set it: a ground the company grants itself.
Self-exclusion records Law sets it 14 to 19 years
Gambling rules keep these long-term so a self-exclusion stays in force.
Identity / anti-money-laundering records Law sets it about 5 years
Money-laundering rules require ID and transaction records after an account closes.
Identity and age-check records They set it as long as they choose
To prove they checked your age or identity and to block known fraud, sometimes held by a separate verification company.
Tax and accounting records Law sets it about 6 years
Tax and company law makes them keep billing and payment records.
Records tied to a live or potential dispute They set it the limitation period of the claim
They can keep records to defend a live or possible legal claim.
Who wants this data
The records a betting account holds have a market. One US operator disclosed a breach that put roughly 1.5 million customer files up for sale: names, home addresses, dates of birth, and scrambled Social Security numbers. A UK court case separately documents a problem gambler who was profiled and sent direct marketing.
Sold or shared Possible
Play data is used to target and to retain, within regulation.
AI training Moderate
Betting patterns train risk and retention models.
Even anonymised, this can still be you
A verified identity file names you outright, and betting patterns are as distinctive as any transaction history: four of them identify 90% of people (de Montjoye et al., 2015).
Name, date of birth, postcode Typical
Fifteen demographic attributes re-identify 99.98% of Americans in a released dataset (Rocher, Hendrickx and de Montjoye, Nature Communications, 2019); date of birth, postcode, and sex alone did it for most people in the first study of the problem (Sweeney, 2000).
Location traces Typical
Four time-and-place points single out 95% of people in mobility data (de Montjoye et al., Scientific Reports, 2013).
Payment patterns Typical
Four card transactions identify 90% of people in payment data (de Montjoye et al., Science, 2015).
How you write Sometimes
Language models infer where a person lives, their income, and their sex from their writing alone, at near-human accuracy and at scale (Staab et al., ICLR 2024).
Face and voice Sometimes
A face, voice, or fingerprint template identifies a person directly; there is nothing left to anonymise, and it cannot be reissued like a password.
Browsing fingerprint Typical
Browser and device fingerprints were unique for 84% of visitors in the first large study (Eckersley, 2010), and sparse histories of what people viewed re-identified them against public reviews (Narayanan and Shmatikov, 2008).
The studies Estimating the success of re-identifications in incomplete datasets using generative models (Nature Communications 10, 3069, 2019)·Simple Demographics Often Identify People Uniquely (Carnegie Mellon University, Data Privacy Working Paper 3, 2000)·Unique in the Crowd: The privacy bounds of human mobility (Scientific Reports 3, 1376, 2013)·Unique in the shopping mall: On the reidentifiability of credit card metadata (Science 347 (6221), 2015)·Beyond Memorization: Violating Privacy via Inference with Large Language Models (ICLR 2024, 2024)·How Unique Is Your Web Browser? (Privacy Enhancing Technologies Symposium (PETS 2010), 2010)·Robust De-anonymization of Large Sparse Datasets (IEEE Symposium on Security and Privacy, 2008)
The wording that does the work
Clauses that recur across this industry, and what each one actually permits.
“to provide and improve our services”
The catch-all purpose. Analytics, profiling, personalisation and AI training all fit under it. When they want to do something new with your data, this sentence usually already allows it.
The move An objection tells them to use your data to run the service and nothing more.
“we do not sell your personal information”
Usually this means no cash changes hands. Your data can still go to ad networks, analytics firms and partners, because they count that as sharing rather than selling.
The move Use the do-not-sell switch where there is one, and put an objection in writing as well.
“service providers, partners, and affiliates”
This is how your data leaves with no name attached. Recipients are described by what they do rather than named, and you cannot send a request to a company you cannot name.
The move An access request can ask for recipients by name rather than by category, and UK and EU law put that choice with you.
“aggregated or de-identified information”
Taking your name off does not take away the pattern, and the pattern often still points at you. Policies give themselves free use of this data with no end date, on the basis that it is no longer about you.
The move If a deletion comes back as 'anonymised', keep the reply. It usually means de-identified, and it is their claim, not a fact you can check.
“retained as long as necessary, or as required by law”
They can keep it for legal duties, tax rules, fraud prevention, possible lawsuits and their own business reasons. None of those has a firm end date, so deletion turns into something you have to argue for.
The move Which reasons apply to you, and how long each runs, is a request of its own.
“you grant us a licence to use your content”
This is a contract term rather than a data setting, so a privacy request cannot undo it. A careful version ends when your account does. A broad one can be passed on, never expires and survives deletion.
The move Their terms say whether the licence ends when the account does. Close the account and log the date here.
“a soft check that will not affect your credit score”
Lets them pull records from a credit-reference agency: your identity, insolvency and bankruptcy history, court judgments against you, and an estimate of what you can afford. The reassurance covers your score only. It does not limit what they receive, and one policy adds that the outcome is passed back to them.
The move A request for your data brings back what the credit-reference agency handed them about you.
“documents proving your source of wealth”
Lets them demand payslips, bank statements, dividends, and proof of business ownership. Those files reveal far more about your finances than any bet, and they sit under the same multi-year retention as the rest of the account.
The move A request lists the financial documents they hold and why.
“retained indefinitely to prevent you from creating new accounts”
Keeps your identity on file with no end once you have shut yourself out for good or been barred. The stated reason is enforcement: you cannot be kept out unless you are remembered.
The move A request surfaces what stays behind after you are gone and on what grounds.
Their own policy is the one that binds them. Pin it down with a request, and keep the reply.