This Privacy Policy sets out how personal data of customers and visitors is collected, used, stored, shared and protected in connection with the online gambling and betting services of Genting Casino Liverpool Renshaw Street. It applies to all personal data processed in relation to access to, and use of, those services. By using the services, you acknowledge that your personal data will be handled in accordance with this Privacy Policy.
Processing of personal data is carried out in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Licence Conditions and Codes of Practice (LCCP) issued by the Gambling Commission. Where this Privacy Policy refers to regulatory obligations, such obligations are binding and are not subject to individual variation.
1. Who The Data Controller Is
For the purposes of data protection law, Genting Casino Liverpool Renshaw Street is the data controller in respect of personal data processed through the online services. The casino is licensed and regulated by the Gambling Commission. The relevant account number and current licensed status are available on the Gambling Commission public register, and a link to that register is displayed on every screen from which customers can access gambling facilities, in line with remote licence conditions.
Data protection enquiries may be directed to the contact details set out in Section 9 of this Privacy Policy.
2. Data Collected
Personal data is collected only to the extent necessary to provide the services, meet regulatory requirements and fulfil legal obligations. Categories of personal data processed include:
- Identity data: full name, date of birth, and details from government-issued identification documents.
- Contact data: email address, postal address and telephone number.
- Account data: username, account history, transaction records and login activity.
- Verification data: documents and information obtained as part of Know Your Customer (KYC) and anti-money laundering (AML) checks.
- Financial data: payment details, deposit and withdrawal records, and information used for financial risk assessment.
- Usage data: records of gambling activity, session data and interaction logs.
- Communications data: records of correspondence with the support team.
- Technical data: IP address, browser type, device identifiers and cookie data.
Special category data is not collected unless required by law or where explicit consent has been provided.
3. Legal Bases For Processing
Personal data is processed on one or more of the following legal bases under UK GDPR:
- Contract: where processing is necessary to provide the services, administer and manage a user account, and perform obligations under the terms and conditions.
- Legal obligation: where processing is required to comply with AML and counter-terrorist financing legislation, Gambling Commission licence conditions, tax law and other applicable legal or regulatory requirements.
- Legitimate interests: where processing is carried out for purposes such as fraud prevention, security, responsible gambling monitoring and service improvement, provided such interests are not overridden by the rights and freedoms of the data subject.
- Consent: where explicit consent has been obtained, for example for marketing communications and the use of non-essential cookies.
Where processing is based on legitimate interests, a balancing assessment is carried out to ensure that those interests do not override fundamental rights and freedoms.
4. Use Of Personal Data
Personal data may be used for the following purposes:
- To verify identity and age before providing access to gambling services.
- To operate, administer and manage user accounts in line with applicable terms and conditions and relevant law.
- To conduct AML, counter-terrorist financing (CTF) and fraud prevention checks.
- To perform financial risk assessments where required under Gambling Commission guidance, including checks relating to affordability and harm prevention.
- To share data with financial institutions where permitted and required for financial risk checks, and solely for that purpose. Where such checks may be conducted, users are informed in advance or at the point of significant loss, in accordance with guidance from the Information Commissioner’s Office (ICO).
- To fulfil responsible gambling obligations, including monitoring for indicators of harm and, where a cross-operator harm-prevention scheme applies, sharing relevant data with other licensed operators, subject to ICO guidance.
- To respond to enquiries and provide customer support.
- To send marketing communications where valid consent has been given, and to action any withdrawal of that consent.
- To comply with requests or directions from the Gambling Commission, the ICO, law enforcement bodies or other competent authorities.
5. Cookies And Tracking Technologies
Cookies and similar tracking technologies are used on the website. Non-essential cookies, including those used for analytics and behavioural advertising, are only deployed where explicit consent has been provided. Cookie preferences can be managed at any time through the website’s consent management interface.
The consent mechanism presents opt-in and opt-out options with equal prominence. Dark patterns and deceptive design practices are not used in the consent interface. Non-essential cookies are not set before consent is obtained.
All third-party trackers active on the site are disclosed in the cookie notice. Where advertising is used, contextual targeting is preferred over behavioural profiling based on tracking data. Browser fingerprinting and silent tracking pixels are not deployed without a lawful basis and appropriate disclosure.
6. Data Retention
Personal data is retained only for as long as necessary for the purposes for which it was collected, subject to the following mandatory retention periods:
- Records of customer identification and verification: retained for five years from the date the business relationship with the customer ends.
- Supporting records related to KYC and AML checks: retained for five years from the end of the business relationship.
- Internal and external suspicious activity reports: retained for five years from the date each report was made.
After expiry of the applicable retention period, personal data is deleted unless:
- a legal or court requirement mandates continued retention;
- the data subject has agreed to continued retention; or
- there are reasonable grounds to believe that retention is necessary for legal proceedings.
Personal data not subject to mandatory AML retention periods is retained in line with data minimisation principles and is deleted when it is no longer necessary for the original purpose for which it was collected.
7. Sharing Of Personal Data
Personal data is shared only where there is a lawful basis for doing so. Recipients may include:
- Regulatory and law enforcement authorities: the Gambling Commission, ICO, HMRC, the police and other competent bodies, where required by law, regulation or licence conditions.
- Identity and fraud verification providers: third-party services engaged to conduct KYC, AML and financial risk checks.
- Financial institutions: where data sharing is required for affordability or financial risk assessments under ICO-backed schemes, and solely for that purpose.
- Cross-operator harm-prevention schemes: where required or permitted to share information about high-risk customers with other licensed operators to prevent gambling-related harm, subject to ICO guidance and proportionality requirements.
- IT and infrastructure service providers: data processors engaged to provide hosting, maintenance and related services, subject to data processing agreements requiring protection of personal data to a standard equivalent to that applied by the data controller.
Personal data is not sold to third parties.
8. Your Data Protection Rights
Under UK GDPR, individuals have the following rights in relation to their personal data:
- Right of access: to request a copy of the personal data held about them.
- Right to rectification: to request correction of inaccurate or incomplete personal data.
- Right to erasure: to request deletion of personal data where it is no longer necessary for the purposes for which it was collected, subject to legal and regulatory retention obligations.
- Right to restriction of processing: to request limitation of processing in certain circumstances, for example while the accuracy of data is being verified.
- Right to object: to object to processing based on legitimate interests, including any related profiling.
- Right to data portability: to receive personal data in a structured, commonly used and machine-readable format, where processing is based on consent or contract and is carried out by automated means.
- Right to withdraw consent: to withdraw consent at any time for processing based on consent, including marketing communications and non-essential cookies, without affecting the lawfulness of processing carried out before withdrawal.
To exercise any of these rights, contact the company using the details provided in Section 9. A response is provided within one calendar month of receipt of a valid request. If you are dissatisfied with the response, you have the right to lodge a complaint with the ICO at ico.org.uk.
9. Contact And Complaints
For data protection enquiries, requests to exercise data protection rights, or complaints in relation to this Privacy Policy, contact:
Genting Casino Liverpool Renshaw Street
Data Protection Enquiries
Email: [email protected]
If you believe that personal data has not been handled in accordance with applicable data protection law, a complaint may also be made directly to the Information Commissioner’s Office.
10. Changes To This Privacy Policy
This Privacy Policy is reviewed periodically and updated where required by changes in law, regulatory guidance or data processing activities. Where changes are material, affected users are notified before they take effect, in line with obligations under the LCCP and the Consumer Rights Act 2015. The current version of this Privacy Policy is always available on the website. Continued use of the services after notification of material changes constitutes acknowledgement of the updated Privacy Policy.

