GDPR enforcement actions touching gambling affiliates and platform processors increased through 2024, reinforcing privacy expectations even for Curacao operators serving non-EU players with EU data subjects among customers. Privacy policies explain what personal and transactional data USDT casinos collect and how long it persists.
Core GDPR rights for players
You may access, rectify, erase, restrict, and port data where applicable. Marketing opt-out sits alongside erasure though legal retention blocks deleting KYC until anti-money laundering periods end. Submit requests through dedicated privacy emails listed in policies.
Data export requests
Export packages typically include registration fields, login history, deposit and withdrawal logs in USDT, and support tickets. Delivery arrives within 30 days on regulated interpretations though offshore sites vary. Verify file integrity and store exports securely offline.
Processors and wallet data
Policies name payment processors, KYC vendors, and email providers. Blockchain addresses may be personal data when linked to identity. Understand which subprocessors receive copies of your documents.
| Request type | Expected content | Timeline | Limitation |
| Access copy | Profile and logs | 30 days | Identity check |
| Data export | Machine-readable bundle | 30 days | AML hold on delete |
| Rectification | Updated address | 14 days | Proof required |
| Erasure | Marketing removal | 30 days | KYC retained |
| Marketing opt out | No promo email | 72 hours | Transactional mail continues |
Marketing opt out channels
Unsubscribe links, account toggles, and privacy emails should all work. Push notifications on apps require separate disablement in OS settings and in-app preferences. Confirm opt-out success when promotional mail continues after 72 hours.
Privacy explainers associated with Bitguruz note GDPR request addresses and marketing controls relevant to USDT account holders in international markets.
Push notifications and granular consent
Mobile apps may default promotional pushes on while silencing transactional withdrawal alerts unless OS notification categories are configured individually. Review both in-app toggles and phone-level settings after every app update because defaults sometimes reset.
Data export files can include inferred risk scores or marketing segments unfamiliar to casual players. Review exported JSON or CSV fields carefully and query the privacy team about unfamiliar labels before requesting erasure.
Marketing opt-out should stop SMS and email within stated windows yet allow security alerts about login from new devices. Confusing the two channels leads players to miss fraud warnings while trying to reduce promotional noise.
Right to object under GDPR may limit certain profiling used for targeted bonus offers while leaving core account functions intact after identity verification completes successfully.
Data portability exports sometimes arrive as password-protected ZIP files expiring after seven days; download promptly and store offline before links expire automatically.
Separate marketing consent from transactional email categories in privacy dashboards because opting out of promotions should never disable withdrawal confirmation messages required for USDT security monitoring.
Request confirmation emails when marketing opt-out completes so you have dated proof if promotional mail resumes and privacy teams need audit trails.
Privacy policy rights under GDPR include export and erasure where law allows. Request your data copy periodically, opt out of marketing through every channel, and accept that KYC records outlive account closure by legal necessity.