Official privacy information for UK users
bwin Casino United Kingdom Privacy Policy
This Privacy Policy explains how bwin Casino collects, uses, stores and protects personal information when you visit this United Kingdom website, create or use an account, contact support, manage privacy choices or interact with casino-related services presented through the site.
Manage your privacy
Use the privacy and account controls available on the site to review communication preferences, request access to your information or ask a question about how your data is handled.
- Review optional marketing and communication choices.
- Ask for a copy or correction of personal information.
- Raise a data protection concern through the complaints process.
- Contact the privacy team before sending sensitive documents.
Privacy request preview
This visual form helps you prepare a request. It does not submit or transmit information.
Do not enter passwords, full payment card numbers or identity-document images in an ordinary message. Use a secure upload channel when one is provided.
1. Who controls your personal information
References to “bwin Casino”, “we”, “our” or “us” in this Privacy Policy mean the operator responsible for this website and the relevant services presented under the bwin Casino brand. The applicable data controller is the legal entity identified in the account Terms and Conditions or other legal information shown when you register or use a regulated service.
The controller decides why and how personal information is processed. Some service providers process information on the controller’s documented instructions, while certain regulators, payment providers or identity-checking organisations may act as separate controllers for their own legal purposes.
2. Personal information bwin Casino may collect
The information collected depends on how you use the website and whether you only browse, contact support or interact with an account-based service. We aim to collect information that is relevant and proportionate to the stated purpose.
| Information category | Typical examples | Why it may be needed |
|---|---|---|
| Identity information | Name, date of birth, username, account identifier and verification status. | Account administration, age checks, identity verification, security and legal obligations. |
| Contact information | Email address, telephone number, postal address and communication preferences. | Service messages, security alerts, support, account recovery and optional marketing. |
| Account and activity information | Login history, settings, account events, interactions, transaction references and service usage. | Providing services, maintaining records, resolving queries and protecting the account. |
| Payment information | Payment method, masked card or account details, transaction status and ownership checks. | Processing payments, preventing fraud, reconciling transactions and meeting financial controls. |
| Verification information | Identity documents, address evidence, source-of-funds information and verification results. | KYC, anti-money-laundering controls, fraud prevention, age checks and regulatory compliance. |
| Technical information | IP address, browser, device type, operating system, cookie identifiers, session data and security logs. | Website operation, troubleshooting, analytics, fraud detection and cybersecurity. |
| Support communications | Emails, chat transcripts, complaint records, attachments and call notes where applicable. | Answering questions, investigating issues, handling complaints and improving support. |
| Safer-gambling information | Account limits, time-outs, self-exclusion status, risk indicators and support interactions. | Protecting users, reducing gambling-related harm and meeting regulatory responsibilities. |
Information from other sources
We may receive information from payment providers, identity-verification services, fraud-prevention databases, regulatory bodies, public records, device-security services or organisations used to support safer-gambling and self-exclusion controls. Where required, we provide privacy information within the period set by applicable law.
How personal information moves through the service
Each stage is subject to access controls, purpose limits and appropriate retention rules.
3. How and why personal information is used
Under UK data protection law, personal information must be processed using an appropriate lawful basis. The basis depends on the particular purpose and may affect which individual rights apply.
| Purpose | Likely lawful basis | Practical explanation |
|---|---|---|
| Providing and administering services | Contract | To create and maintain an account, provide requested functionality and communicate about the service. |
| Age, identity and financial-crime checks | Legal obligation and legitimate interests | To verify eligibility, prevent fraud and meet gambling, financial and regulatory requirements. |
| Account and website security | Legitimate interests and legal obligation | To identify suspicious activity, secure sessions, investigate misuse and maintain reliable systems. |
| Safer-gambling measures | Legal obligation, substantial public interest or legitimate interests, as applicable | To apply limits, exclusions, risk controls and interventions designed to reduce harm. |
| Customer support and complaints | Contract, legal obligation and legitimate interests | To answer questions, resolve disputes, keep an audit trail and improve service quality. |
| Service analytics and improvement | Legitimate interests or consent where required | To understand performance, identify errors and improve navigation, content and accessibility. |
| Direct marketing | Consent or legitimate interests where permitted | To send optional offers or updates, subject to communication choices and applicable electronic-marketing rules. |
| Legal claims and regulatory enquiries | Legal obligation and legitimate interests | To establish, exercise or defend legal rights and respond to authorised requests. |
Lawful basis map
The bars illustrate the breadth of processing activities that may rely on each basis. They do not represent percentages of users or records.
Special-category and criminal-offence information
Some safer-gambling, vulnerability, legal or fraud-prevention matters may involve sensitive information or information connected with alleged offences. Such information is processed only where an additional legal condition applies and with safeguards appropriate to its sensitivity.
4. Cookies, device information and online preferences
Cookies and similar technologies may be used to keep the website functioning, remember settings, protect sessions, measure performance and support optional personalisation or advertising. Technologies that are not strictly necessary are used in line with the consent choices presented to you where consent is required.
Strictly necessary
Used for core functions such as session security, load balancing, privacy choices and account access.
Performance
Helps identify page errors, loading problems and patterns in how visitors navigate the website.
Functional
May remember language, display settings or other optional choices that make the experience more convenient.
Marketing
May support audience measurement or relevant promotional communications when the required permission is available.
Fraud prevention
Device and network signals may be used to identify unusual access patterns or attempted misuse.
Your control
You can review available cookie choices through the privacy settings and may also adjust browser controls.
5. Profiling and automated processing
Automated tools may help detect fraud, protect accounts, prioritise security checks, assess transaction risk, support safer-gambling measures, select service messages or understand how the website is used. These tools may analyse account, transaction, device and behavioural information.
Where a decision is based solely on automated processing and produces legal or similarly significant effects, appropriate safeguards will be applied. Where the law provides the right, you may ask for human involvement, express your point of view and challenge the decision.
6. Who personal information may be shared with
Personal information is not shared without a purpose. Access is limited to recipients that need the information for service delivery, security, payment, verification, legal or regulatory functions.
| Recipient | Reason for sharing | Safeguard |
|---|---|---|
| Payment and banking providers | To authorise, process, reconcile or investigate transactions. | Only transaction and identity information needed for the payment purpose is supplied. |
| Identity and verification providers | To confirm identity, age, address, payment ownership or source-of-funds information. | Contractual, technical and access-control measures are applied. |
| Hosting, security and support suppliers | To operate systems, prevent attacks, store records and provide customer assistance. | Suppliers are expected to follow documented instructions and confidentiality duties. |
| Fraud-prevention organisations | To detect suspicious behaviour, account misuse, identity fraud or payment risk. | Information is shared where proportionate and legally permitted. |
| Regulators and public authorities | To comply with gambling, tax, financial-crime, consumer-protection or law-enforcement duties. | Requests are assessed for authority, scope and necessity. |
| Professional advisers | For legal advice, auditing, insurance, dispute resolution or corporate governance. | Professional confidentiality and need-to-know access apply. |
| Business successors | In connection with a reorganisation, transfer, merger or sale involving the service. | Confidentiality and data-protection requirements continue to apply. |
International transfers
Some providers or group systems may be located outside the United Kingdom. When personal information is transferred internationally, we use an approved transfer mechanism or another lawful safeguard, such as UK adequacy regulations, recognised contractual protections or a permitted legal exception. Additional technical and organisational measures may be used where appropriate.
7. How personal information is protected
bwin Casino uses proportionate technical and organisational measures intended to protect information against accidental loss, unauthorised access, alteration, disclosure or destruction. No online service can guarantee absolute security, so users also play an important role in protecting account access.
Privacy and security control layers
The meters show the relative emphasis placed on complementary control areas rather than a security score or guarantee.
Steps you can take
- Use a strong, unique password that is not shared with another website.
- Keep one-time codes and account recovery links private.
- Log out on shared devices and keep your browser and operating system updated.
- Check that messages and pages use the expected bwin Casino domain before entering account details.
- Contact support promptly if you notice an unfamiliar login, transaction or profile change.
8. How long personal information is retained
Information is kept only for as long as reasonably necessary for the purpose for which it was collected, including service, legal, accounting, fraud-prevention, safer-gambling and dispute-resolution requirements.
Retention periods vary by record type. When a period ends, information is securely deleted, irreversibly anonymised or retained in a restricted archive where continued storage is required by law or for legal claims.
Retention decision timeline
Exact periods depend on the record, the purpose and applicable gambling, financial and data-protection requirements.
Information is used to operate the website, administer services and manage support or security matters.
Selected records remain available for account queries, transaction checks, complaints and fraud prevention.
Records may be retained for statutory, regulatory, anti-money-laundering or legal-claims periods.
Information is removed, anonymised or kept only in a restricted form where a lawful reason remains.
9. Your UK data protection rights
Depending on the circumstances and lawful basis, you may have the right to access, correct, erase, restrict, transfer or object to the use of your personal information. You may also withdraw consent for future processing where consent is the basis relied upon.
Access
Ask whether your information is being processed and request a copy of eligible personal information.
Correction
Ask for inaccurate information to be corrected or incomplete information to be completed.
Erasure
Ask for deletion where no overriding legal, regulatory, security or claims-related reason requires retention.
Restriction
Ask for processing to be limited while accuracy, lawfulness or an objection is being considered.
Objection
Object to certain processing based on legitimate interests and to direct marketing at any time.
Portability
Request eligible information in a structured, commonly used and machine-readable format.
Submitting a rights request
Provide enough information to identify the account and describe the records or processing involved. We may request reasonable identity evidence before releasing or changing information. This protects your information from unauthorised disclosure.
Your request pathway
Clear details at the start can reduce follow-up questions and help the request reach the correct team.
Requests are normally handled without charge. A reasonable fee or refusal may apply where a request is manifestly unfounded or excessive, as permitted by law. You will be told if additional time is required for a complex request.
10. Marketing and communication choices
Service communications about security, account administration, legal changes or transactions are separate from optional marketing. You may be able to choose whether to receive promotional messages by email, SMS, telephone, push notification or other available channels.
You can object to direct marketing or withdraw a marketing consent at any time. Use the preference control in the relevant message, update available account settings or contact support. A limited suppression record may be kept to ensure your opt-out continues to be respected.
11. Children and age restrictions
bwin Casino services intended for gambling are restricted to adults aged 18 or over. We do not knowingly provide an account-based gambling service to children. Age and identity checks may be used to support this restriction.
A parent or guardian who believes a child has provided personal information should contact the privacy team promptly. Information may be restricted while the matter is investigated and appropriate protective action is taken.
12. Data protection questions and complaints
You may raise a concern if you believe your information has been handled incorrectly, a privacy request has not been addressed properly or this policy does not explain a processing activity clearly enough.
How to make a complaint to bwin Casino
- Describe what happened and the outcome you are seeking.
- Include relevant dates, account references and copies of previous correspondence.
- Do not include passwords, one-time codes or full payment card numbers.
- Use a secure document-upload route if evidence is requested.
We will acknowledge and investigate data protection complaints in line with applicable UK requirements. Since 19 June 2026, organisations are required to operate a process for handling data protection complaints under changes introduced by the Data (Use and Access) Act 2025.
Escalating a concern
You also have the right to complain to the Information Commissioner’s Office. We encourage you to contact bwin Casino first so that the issue can be investigated directly, but this does not affect your right to approach the regulator.
13. UK privacy law and regulatory context
This Privacy Policy is intended to reflect the transparency principles of the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations and relevant amendments introduced by the Data (Use and Access) Act 2025.
Gambling-related processing may also be necessary to meet licence, age-verification, safer-gambling, fraud-prevention and anti-money-laundering responsibilities. Consent is therefore not the lawful basis for every use of personal information.
14. Changes to this bwin Casino Privacy Policy
This policy may be updated when services, technology, suppliers, legal requirements or regulatory guidance change. The date at the top of the page shows when this version was last updated.
Material changes may also be highlighted through the website, account area or an appropriate communication channel. Previous processing remains subject to the legal requirements that applied at the relevant time.
15. Contacting bwin Casino about privacy
Contact the privacy or support team when you need help understanding this policy, exercising a right, correcting account information, changing communication choices or raising a data protection complaint.
Include the email address or account reference connected with your enquiry, but do not send passwords, one-time codes or full payment credentials.
Your information, your choices
Review or update your bwin Casino privacy preferences
Use the privacy controls to review optional cookies and communications, or contact the team when you need help with personal information connected to this United Kingdom website.





