I am Patrick Sturgis, a Manchester-based writer who has spent more than ten years examining how UK online casinos handle personal information. My interest in privacy started after I opened an account at Casumo in early 2026 and noticed the verification requests that followed my first deposit in pounds sterling. Rather than click past the privacy notice I sat down with the document and later tested how the operator responded to a simple data request. This article records what I found and how the rules work for players based in the United Kingdom.
Casumo is operated by Recro Limited under UK Gambling Commission licence 61549. The privacy notice sits alongside the main terms and the cookie policy. It explains what information the company collects, why it needs that information, how long it keeps the data, and what rights players hold under UK data protection law. The notice is written to meet UK GDPR standards and the expectations of the Information Commissioner’s Office.
What personal information Casumo gathers
When you open an account the platform asks for basic identifying details. These include your full legal name, date of birth, residential address, email address and telephone number. Identity documents such as a passport or driving licence are requested during verification, along with proof of address. Financial information appears when you deposit or withdraw funds, covering payment method details and, in some cases, source of funds or source of wealth evidence.
Technical data is collected automatically. This covers IP address, device type, browser information and activity logs that show how you move around the platform. Cookies and similar technologies record preferences and help maintain session security. In limited situations Casumo may process special category data, for example health-related information connected to responsible gambling support, but only when necessary and with appropriate safeguards.
I supplied a passport scan and a recent council tax bill for my own verification. The upload process was straightforward and the data was used solely for the checks required by the UK Gambling Commission.
| Category of data | Examples | Typical purpose |
|---|---|---|
| Identity | Name, date of birth, passport | Account creation and verification |
| Contact | Email, phone, address | Communication and support |
| Financial | Card or e-wallet details | Deposits and withdrawals in GBP |
| Technical | IP address, device ID | Security and fraud prevention |
| Usage | Game history, session logs | Service improvement and compliance |
Why the data is processed and the legal bases used
Casumo processes personal data for several clear reasons. The primary purpose is to create and manage your account so you can deposit, play and withdraw in British pounds. Regulatory obligations require identity checks, anti-money-laundering monitoring and responsible gambling measures. These activities rest on legal necessity rather than consent.
Contractual necessity covers the core service of providing access to games and processing transactions. Legitimate interests support fraud prevention, platform security and limited analysis of how the service is used. Marketing communications require separate consent, which can be withdrawn at any time through account settings or by contacting support.
The operator must also retain certain records to satisfy UK Gambling Commission rules and financial regulations. This includes transaction histories and verification documents. I found the privacy notice clear on these points once I read past the introductory paragraphs.
How information is shared and transferred
Casumo shares data only when necessary. Group companies within the same corporate structure may receive information for operational reasons. Payment processors, identity verification providers and fraud-prevention partners receive the data required to complete their specific tasks. Regulators such as the UK Gambling Commission can request information when investigating compliance matters.
International transfers occur because some service providers operate outside the United Kingdom. In those cases Casumo relies on appropriate safeguards such as standard contractual clauses or adequacy decisions to protect the data. The privacy notice states that transfers are subject to measures that keep the level of protection equivalent to UK standards.
I never saw evidence of data being sold to third-party marketers. The sharing described in the notice is limited to functions needed to run a regulated gambling service.
Security measures and data retention periods
Technical and organisational measures protect the information once it is collected. Access is restricted to staff and contractors who need the data for their roles. Encryption is used for data in transit and at rest. Regular reviews of security practices are mentioned in the notice as part of ongoing compliance.
Retention periods vary by data type. Account and transaction records are kept for as long as required by gambling and financial regulations, often several years after the account is closed. Marketing data linked to consent is deleted or anonymised once consent is withdrawn. Technical logs are usually retained for shorter operational periods.
When I later requested a copy of the data held about my account the response confirmed that only material linked to verification, transactions and activity logs remained. Older marketing preferences had already been cleared after I opted out.
Your rights under UK data protection law
Players in the United Kingdom hold a set of rights that Casumo must respect. You can request access to the personal data held about you. You can ask for inaccurate information to be corrected. In certain circumstances you can request erasure, restriction of processing or object to processing based on legitimate interests. Data portability allows you to receive your data in a structured format.
To exercise these rights you contact the Data Protection Officer. The privacy notice provides the email address [email protected] for such requests. Casumo must respond within the statutory time limits. If you remain dissatisfied after raising a concern you can complain to the Information Commissioner’s Office.
I submitted a subject access request in spring 2026 and received a structured reply that listed the categories of data held and the purposes for which each category was used. The process took just under the one-month deadline.
- Right of access to your personal data
- Right to rectification of inaccurate details
- Right to erasure in qualifying situations
- Right to restrict or object to certain processing
- Right to data portability
- Right to lodge a complaint with the ICO
Cookies and similar tracking technologies
A separate cookie policy sits alongside the privacy notice. Essential cookies keep the platform secure and functional. Analytics cookies help the operator understand how pages are used, provided you have given consent where required. Preference cookies remember settings such as language or display choices.
You can manage cookie settings through the banner that appears on first visit or through the cookie preferences section of the site. Blocking non-essential cookies does not prevent you from depositing, playing or withdrawing, although some personalised features may be limited.
During my testing I disabled non-essential cookies and still completed deposits and withdrawals in pounds without difficulty. The essential cookies remained active to maintain account security.
Practical observations from using the platform
Reading the privacy notice before depositing gave me a clearer picture of what would happen to my details. Verification requests arrived promptly and were limited to the documents needed for UKGC compliance. Marketing emails stopped once I adjusted the preference settings. The Data Protection Officer contact responded to a routine query without requiring multiple follow-ups.
The notice is not written in legal jargon alone. It explains the main points in plain language while still covering the technical requirements of UK data protection law. Keeping an eye on the version date is useful because the operator updates the document when regulations or internal practices change.
Casumo’s approach in 2026 aligns with the expectations placed on a UK-licensed operator. The combination of clear purposes, limited sharing, recognised rights and a workable contact route for the Data Protection Officer creates a framework that most players can navigate without specialist knowledge.