Last reviewed: 2025
- Introduction
This Privacy Policy explains how personal data is collected, used, stored, shared and protected in connection with the services of Grosvenor Casino Huddersfield. The policy applies to individuals who visit the premises, access services, or otherwise interact with the company.
Processing of personal data is carried out in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Operations are conducted under a licence issued by the Gambling Commission of Great Britain. Data processing practices reflect data protection law and the requirements set out in the Gambling Commission’s Licence Conditions and Codes of Practice (LCCP).
Queries regarding this policy and requests to exercise data protection rights can be submitted using the contact details set out in Section 10.
- Who the Data Controller Is
For the purposes of UK GDPR, Grosvenor Casino Huddersfield is the data controller for personal data processed in connection with its services. As data controller, the company determines the purposes and means of processing personal data.
The company is licensed and regulated by the Gambling Commission. Operations are subject to the LCCP, including conditions relating to customer identity verification (Condition 17.1.1), fair and transparent terms and practices (Condition 7.1), and the protection of children and vulnerable persons (Code of Practice Section 3).
- Personal Data Collected
The following categories of personal data may be collected and processed:
- Identity data: full name, date of birth, government-issued identification documents.
- Contact data: postal address, email address, telephone number.
- Financial data: payment information and transaction records required for regulatory compliance.
- Verification data: records generated during customer due diligence and identity verification checks.
- Behavioural data: records of activity relevant to responsible gambling assessments and account monitoring.
- Special category data: where legally required, special category data, including biometric data, may be processed strictly to comply with obligations imposed by the Gambling Commission and applicable anti-money laundering legislation.
Special category data is not collected or processed beyond what is required by law or regulatory obligation.
- Lawful Bases for Processing
Personal data is processed on the following lawful bases under UK GDPR:
- Legal obligation: to comply with requirements imposed by the Gambling Commission, the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, and other applicable legislation.
- Contract: to fulfil obligations to the customer, including account management and transaction processing.
- Legitimate interests: for fraud prevention, security, and the improvement of internal compliance processes, where those interests are not overridden by the rights and freedoms of data subjects.
- Consent: for specific processing activities where consent is required, such as certain marketing communications. Consent can be withdrawn at any time.
- Use of Personal Data
Personal data may be used for the following purposes:
- To verify identity before permitting access to services, in accordance with LCCP Condition 17.1.1. Information will be provided in advance on what identification documents or information may be required and how they should be supplied.
- To conduct customer due diligence and ongoing monitoring as required under anti-money laundering legislation.
- To assess and manage responsible gambling obligations, including the identification of at-risk behaviour and the administration of self-exclusion arrangements.
- To maintain records required by the Gambling Commission, including self-exclusion records, which must be retained to enable the implementation of self-exclusion periods.
- To prevent fraud and comply with financial crime prevention requirements.
- To respond to regulatory enquiries and cooperate with the Gambling Commission and law enforcement where required by law.
- Marketing and Data Profiling
Marketing communications are sent only where permitted by law, either on the basis of consent or, where applicable, legitimate interests. Recipients have the right to opt out of marketing communications at any time.
In line with regulatory requirements in force from 1 May 2025, online gambling businesses must provide granular opt-in options for specific product types and marketing channels. Where this is applicable to services provided by Grosvenor Casino Huddersfield, such options will be presented clearly and records of preferences will be maintained.
Personal details such as postcode or job title are not used for risk assessment purposes where such use is restricted under current Gambling Commission rules. Risk assessments of the type governed by those rules are carried out only with publicly available data, as required.
- Data Sharing
Personal data is not sold. Personal data may be shared with the following categories of recipients:
- The Gambling Commission, where required for regulatory compliance or investigation.
- Law enforcement authorities, where required by law, including for anti-money laundering and fraud prevention purposes.
- Third-party service providers that process data on behalf of the company under appropriate data processing agreements and that are bound by confidentiality and security obligations.
- Other regulatory or statutory bodies where there is a legal requirement to disclose information.
- Data Retention
Personal data is retained only for as long as necessary for the purposes for which it was collected, subject to legal and regulatory requirements.
In accordance with the Gambling Commission’s guidance on gambling regulation and UK GDPR, data relating to regulatory compliance must be available for at least five years after the end of the relationship with a customer. This includes customer due diligence records, identity verification documents, and self-exclusion records, as required under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017.
Where a right to erasure is exercised, the request will be assessed against legal and regulatory retention obligations. In some cases, the company is required by law to retain certain records even where a deletion request has been made. The outcome of any such request will be communicated to the requester.
- Your Rights Under UK GDPR
Individuals have the following rights in relation to their personal data:
- Right of access: to request a copy of the personal data held about them.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of data, subject to legal and regulatory retention requirements.
- Right to restriction: to request limitation of the processing of data in certain circumstances.
- Right to object: to object to processing based on legitimate interests.
- Right to data portability: to receive personal data in a structured, commonly used format where processing is based on consent or contract.
- Right to withdraw consent: where processing is based on consent, to withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.
To exercise any of these rights, a written request should be submitted using the contact details in Section 10. A response will be provided within one calendar month of receipt of the request.
If the response is not considered satisfactory, a complaint may be lodged with the Information Commissioner’s Office (ICO), the supervisory authority for data protection in the United Kingdom.
- Contact Details
For questions about this Privacy Policy, to exercise data protection rights, or to raise a concern about the handling of personal data, contact:
Data Protection enquiries
Grosvenor Casino Huddersfield
[Insert postal address]
[Insert contact email]
If a complaint remains unresolved, the Information Commissioner’s Office can be contacted via ico.org.uk.
- Changes to This Policy
This Privacy Policy is reviewed periodically and updated when required by changes in law, regulatory guidance, or internal practices. The date at the top of this document shows when the policy was last reviewed. Continued use of the services following an update constitutes acknowledgement of the revised policy.
