1. Introduction
This Privacy Policy sets out how Grosvenor Casino Reading South collects, uses, stores, shares and protects personal data relating to customers, prospective customers and visitors to its services. The Policy applies to individuals who interact with the premises, website or associated digital access points.
Personal data is handled in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Where operations are subject to licensing conditions imposed by the UK Gambling Commission (UKGC), personal data required to meet those conditions is processed on a lawful basis as described in this document.
Questions about the handling of personal data can be directed to the contact details in Section 9 of this Policy.
2. Data Collected
The following categories of personal data are collected and processed:
- Identity data: full name, date of birth and government-issued identification details required for age and identity verification.
- Contact data: postal address, email address and telephone number.
- Financial data: payment information and transaction records necessary for processing deposits, withdrawals and account activity.
- Verification data: documentation submitted to satisfy Know Your Customer (KYC) and anti-money laundering (AML) requirements.
- Technical data: IP address, browser type, device identifiers and session information collected when accessing digital services.
- Usage data: records of activity associated with an account, including betting and gaming history where applicable.
- Communications data: records of correspondence between the user and customer support or compliance teams.
Special category data is not collected unless required by law or obtained with explicit consent.
3. How Personal Data Is Used
Personal data is processed for the following purposes:
3.1 Account operation and service delivery
- To create and maintain customer accounts.
- To verify identity.
- To process transactions.
- To provide access to services in accordance with applicable Terms and Conditions.
3.2 Legal and regulatory compliance
- To meet obligations under the Gambling Act 2005, UKGC Licence Conditions and Codes of Practice (LCCP), anti-money laundering legislation and counter-terrorist financing rules.
- Under LCCP condition 17.1.1, customer name, address and date of birth must be verified before gambling activity is permitted.
Regulatory compliance is a primary legal basis for a significant portion of data processing.
3.3 Fraud prevention and security
- To detect, investigate and prevent fraudulent activity, money laundering and other unlawful conduct affecting the service or its customers.
- To maintain the security and integrity of systems and data.
3.4 Responsible gambling obligations
- To monitor account activity in line with responsible gambling duties under UKGC licence conditions.
- To identify indicators of potential harm and apply appropriate interventions where required.
3.5 Legal proceedings and dispute resolution
- To establish, exercise or defend legal claims.
- To respond to lawful requests from regulatory or law enforcement authorities.
3.6 Service improvement and internal analysis
- To analyse usage patterns in order to improve service quality, security and compliance processes.
- This does not include selling personal data to third parties.
4. Legal Bases for Processing
Processing of personal data is carried out under the following legal bases provided by UK GDPR:
- Performance of a contract: account creation, transaction processing and service access.
- Legal obligation: KYC/AML verification, regulatory reporting and UKGC compliance.
- Legitimate interests: fraud prevention, security monitoring and internal analysis.
- Consent: marketing communications where consent has been separately obtained.
Where processing is based on consent, that consent may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
5. Data Sharing and Disclosure
Personal data is not sold. Data may be shared with the following categories of recipients where a lawful basis exists:
- Regulatory authorities: including the UK Gambling Commission, HM Revenue and Customs (HMRC) and the Financial Conduct Authority (FCA), where required by law or regulation.
- Law enforcement agencies: where disclosure is required by court order, legal obligation or for the prevention or detection of crime.
- Identity and payment verification providers: third-party services used to carry out KYC, AML and payment processing checks.
- Group companies: other entities within the same corporate group, where necessary for operational or compliance purposes.
- Professional advisers: legal, audit and compliance advisers subject to confidentiality obligations.
All third parties with access to personal data are required to handle it in accordance with applicable data protection law.
6. Data Retention
Personal data is retained only for as long as necessary to fulfil the purposes for which it was collected, including compliance with legal, regulatory and accounting requirements.
In practice, records relating to customer accounts and transactions are typically retained for at least the minimum period required under AML legislation and UKGC licence conditions. When data is no longer required, it is securely deleted or anonymised.
7. Your Rights Under UK GDPR
Individuals in the United Kingdom have the following rights in relation to their personal data:
- Right to be informed: to receive clear information about how personal data is used, as set out in this Policy.
- Right of access: to request a copy of the personal data held (subject access request).
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of personal data in certain circumstances, subject to overriding legal obligations.
- Right to restrict processing: to request that use of personal data is limited in specific situations.
- Right to data portability: to receive personal data in a structured, commonly used format where processing is based on consent or contract.
- Right to object: to object to processing based on legitimate interests, including direct marketing and associated profiling.
To exercise any of these rights, contact details in Section 9 should be used. A response will be provided within the period required by law, generally one calendar month.
If the response is not satisfactory, a complaint can be lodged with the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection. Further information is available at ico.org.uk.
8. Data Security
Appropriate technical and organisational measures are implemented to protect personal data against unauthorised access, loss, alteration or disclosure. These measures include, where appropriate:
- Encryption of data in transit.
- Access controls and restrictions.
- Regular review of security practices.
Security obligations in relation to customer data are informed by UKGC licence conditions, which set enforceable standards for protection of customer information.
9. Contact and Data Protection Enquiries
For questions about this Privacy Policy, to exercise data subject rights, or to raise a concern about the handling of personal data, contact:
Grosvenor Casino Reading South
Data Protection Enquiries
[Contact address and email to be inserted by the operator]
If a concern relates specifically to data protection compliance and remains unresolved after contacting the above, it may be escalated to the Information Commissioner’s Office (ICO).
10. Changes to This Policy
This Privacy Policy may be updated from time to time to reflect changes in law, regulatory requirements or internal practices. The current version of the Policy is made available through official service channels. Periodic review of this document is recommended to remain informed about the handling of personal data.

