Privacy and Your Data at Licensed Online Blackjack Sites

Open an account at a licensed US blackjack site and you create a file on yourself deeper than almost anything else in ordinary consumer life.

10 yrs minimum retention for gameplay and location logs
90 days minimum retention for authentication attempt logs
5 yrs federal floor for identity and transaction records
20 state consumer privacy laws now in force

The short answer

  • What is in the file: legal name, address history, date of birth, full Social Security number, images of a government ID and at many sites a liveness selfie.
  • Why: federal anti-money-laundering law and state gaming rules compel most of it. Very little is a marketing decision.
  • The asymmetry: your play is rebuildable for at least 10 years, but the record of who signed in is kept only 90 days.
  • Deletion: usually fails, because privacy statutes except data a business must retain under a legal obligation.
  • Offshore: the same documents leave your hands, and no access right, deletion right or regulator comes with them.
WHAT GOES IN THE FILE

What a Licensed Operator Collects

Four categories, gathered across the seven regulated iGaming states. Most of it is compelled by rule rather than chosen by a marketing department.

01

Identity data

Legal name, address history, date of birth, full Social Security number, front and back ID images and often a liveness selfie.

02

Financial data

Every deposit, receipt, withdrawal, disbursement and transfer, plus separate lists and filings above set thresholds.

03

Location data

Your position fixed at login and monitored dynamically for the length of the session, not sampled once at sign-up.

04

Session and gameplay data

Every hand, stake, hit, stand, split and double, logged so the session can be recreated years later.

Identity Data

Registration is not a username and a password. 31 C.F.R. 1021.410 requires a casino to obtain and keep “the name, permanent address, and social security number of the person involved” whenever a deposit, account or credit line is established. New Jersey adds a 21-and-over check and multi-source authentication against credential numbers rather than a typed date of birth. The operator ends up holding your legal name, address history, date of birth, full SSN, images of the front and back of a driver’s license or passport, and at many sites a liveness selfie matched to the document photo.

Financial Data

The same federal section preserves “each statement, ledger card or other record of each deposit account or credit account with the casino, showing each transaction (including deposits, receipts, withdrawals, disbursements or transfers).” On top of that running ledger, four separate triggers create records and filings of their own. Money that leaves the account also has a tax dimension, covered on our page on taxes on winnings.

TriggerThresholdWhat it createsAuthority
Credit extensionAbove $2,500A separate required list31 C.F.R. 1021.410
Check, money order or traveler’s checkFace value of $3,000 or moreA separate required list31 C.F.R. 1021.410
Currency transactionAbove $10,000A currency transaction report31 C.F.R. 1021.311
Funds or assets the operator finds suspiciousAt or above $5,000A suspicious activity report31 C.F.R. 1021.320

You are never told a suspicious activity report exists

The rule forbids it. No casino “shall disclose a SAR or any information that would reveal the existence of a SAR,” so you will never learn that your account generated one.

Location Data

Readers underestimate this one most, because location is not sampled once at sign-up. Pennsylvania’s rule at 58 Pa. Code 809a.7 requires the platform to fix your position at login, block play until you are inside an authorized area and keep monitoring dynamically through the session. New Jersey’s general internet gaming requirements say the system “shall employ a mechanism to detect the physical location of a patron upon logging into the gaming system and as frequently as specified” in the operator’s approved submission. A three-hour session produces a continuous geographic trace, kept because a regulator demands it. See how geolocation works and why routing around it backfires under VPNs and online casinos.

What the geolocation vendor logs

GeoComply, the vendor behind most of these checks, states in its own privacy policy that it collects IP address, device model, device ID, device fingerprint, operating system version, browser version and type, precise location and “device indicators of location masking.”

Session and Gameplay Data

The broadest obligation is N.J.A.C. 13:69O-1.8, New Jersey’s mandatory logging rule. Subsection (d) requires the system to “maintain all information necessary to recreate patron game play and account activity during each patron session, including any identity or location verifications.” That is meant literally: every hand, every stake, every hit, stand, split and double, every session start and stop, every deposit and withdrawal, rebuildable years later. The same section logs account creation and termination timestamps, every promotional offer issued to you and every manual adjustment to your data, and both New Jersey and Pennsylvania keep the result of every authentication attempt for at least 90 days. New Jersey’s $2,500 lifetime-deposit acknowledgment only works because cumulative deposits are tracked for the life of the account. The log is identical at live dealer tables. See account security for the part you control.

TWO LAYERS OF MANDATE

Why the File Is So Deep

Federal money-laundering law builds the first layer. State gaming regulation builds a second one, for an entirely different reason.

A casino with gross annual gaming revenue above $1 million is a “financial institution” under 31 C.F.R. 1010.100(t)(5). That classification pulls online blackjack operators into the Bank Secrecy Act architecture governing banks and money services businesses: customer identification, transaction recordkeeping, currency reporting, suspicious activity reporting. None of it is negotiable at the account level, and an operator that quietly collected less would be committing a federal compliance failure, not doing you a favor.

State gaming regulation adds the second layer for a different reason. The logging rules exist so a regulator can rebuild a disputed hand, verify a game behaved the way its approved prototype behaved, confirm you were physically in-state and audit what the operator owed. Those are the mechanisms behind everything in what you are entitled to in a regulated state.

What the recordkeeping buys you

  • A regulator can rebuild a disputed hand rather than take the operator’s word for it.
  • A game can be checked against the behavior of its approved prototype.
  • Your physical presence in-state at the time of play can be confirmed.
  • What the operator owed you can be audited, and a wrongly voided payout reversed.

What it costs you

  • The same records hand a private company a complete picture of your habits.
  • None of the collection is negotiable at the account level.
  • There is no lighter-touch licensed option, because collecting less would be a federal compliance failure.
  • Your access to the file ends at account closure. The file itself does not.

That is the honest tradeoff of a licensed market: the recordkeeping that lets a regulator reverse a wrongly voided payout is the same recordkeeping that hands a private company a complete picture of your habits. The licensing process assumes you accept both.

THE LOPSIDED CLOCKS

How Long the Records Live

Retention is not one number. It runs on four separate clocks, and the gap between the longest and the shortest is the thing worth knowing before you need it.

10 yrs gameplay, account activity, identity and location verifications
5 yrs identity, account and transaction records
5 yrs a suspicious activity report and its supporting documents
90 days authentication attempt logs

The asymmetry: your play outlives your logins by years

Records that reconstruct how you played are kept for no less than 10 years, while the log of who successfully or unsuccessfully signed in is kept for as little as 90 days. A dispute about a hand dealt years ago can still be resolved from the file. A dispute about who was logged into your account a few months ago may have nothing left to check.

Record typeMinimum retentionAuthority
Identity, account and transaction recordsFive years31 C.F.R. 1010.430(d)
Suspicious activity report and supporting documentsFive years from filing31 C.F.R. 1021.320
Gameplay, account activity, identity and location verificationsNo less than 10 yearsN.J.A.C. 13:69O-1.8(d); 58 Pa. Code 809a.6
Authentication attempt logsAt least 90 daysN.J.A.C. 13:69O-1.8(h); 58 Pa. Code 809a.6

The federal baseline is blunt: 31 C.F.R. 1010.430(d) reads, “All records that are required to be retained by this chapter shall be retained for a period of five years.” The gaming clock runs twice as long, and Pennsylvania’s interactive gaming system requirements set the same 10-year floor in nearly identical wording. Closing your account therefore changes your access, not the data: the operator keeps the file because two levels of government require it, and a state deletion right collides with those mandates and loses, for reasons below. What closure does affect is your money and your standing as a customer, handled under account closures.

FOUR SETS OF HANDS

Who Receives a Copy

The file does not stay with the brand you signed up to. Four categories of recipient see some or all of it, on very different terms.

The Regulator

Gaming regulators do not merely have a right to ask. New Jersey’s logging rule requires systems to let the Division of Gaming Enforcement query and export data in the formats it specifies. That is standing technical access, not a subpoena relationship, and its counterparts elsewhere operate the same way.

Vendors

A licensed operator is a patchwork of specialists: geolocation, identity verification, payment processing, live studios, game suppliers and the independent testing labs that certify the games. Under state privacy law these are “processors,” or “service providers” in California’s terminology. A processor may handle your data only on the controller’s documented instructions, must be bound by a written contract limiting what it can do, and cannot repurpose your information for its own ends. The operator stays legally accountable for all of it. You do not sue the geolocation vendor; you complain about the operator. New Jersey reinforces this by prohibiting operators and related vendors from retaining patron account information without the permit holder’s express written consent.

Affiliates and Marketing Partners

Large operators sit inside groups running land-based casinos, loyalty programs and sportsbooks, and sharing within a corporate family is usually treated as disclosure to an affiliate rather than a sale. Advertising and analytics partners are different, and much likelier to fall inside the “sale” or “sharing” definitions that trigger an opt-out.

Law Enforcement

The Bank Secrecy Act exists so these records are available to investigators, and the constitutional backstop most people assume they have is not there. In United States v. Miller, 425 U.S. 435, decided April 21, 1976, the Supreme Court held that a customer has no Fourth Amendment interest in records held by a financial institution, because the information was “voluntarily conveyed to the banks and exposed to their employees in the ordinary course of business.” That third-party reasoning is what makes casino financial records reachable.

The one question nobody has answered yet

The Court carved out an exception in Carpenter v. United States, No. 16-402 (2018), requiring a warrant for historical cell-site location records. Whether a gaming geolocation trail resembles Miller or Carpenter is unsettled.

THE FILE AS A TARGETING MODEL

Profiling, Offers and the VIP Problem

Everything logged for compliance doubles as a behavioral model, and none of it needs any extra collection to become a targeting signal.

Session length, bet sizing, deposit timing, login hour, how fast you reload after busting: it is all in the file already. Reload bonuses, cashback and “we miss you” emails come out of it.

The ethical tension is real and should not be softened. Online gambling revenue is extraordinarily concentrated among heavy losers. Research by David Forrest and Ian McHale, published in the Journal of Gambling Studies in 2024 and covering 139,152 accounts across seven operators representing 85.5 percent of Britain’s online betting market, found the revenue split below.

89.2 percent of net revenue from the top 20 percent of account holders
66.94 percent from the top 5 percent of account holders
37.43 percent from the top 1 percent alone
59.78 percent from the top 1 percent on virtual casino products, the category including software blackjack

The same profile does two jobs

The data is British and US figures may differ, but the structure travels: a business with those economics has an obvious incentive to find its heaviest losers early and treat them well, and the profile flagging a valuable customer is the same one flagging a person in trouble.

Regulators have addressed the sharpest edge rather than the whole problem. Michigan runs a responsible gaming database through which a player can self-exclude from regulated online gaming, sports betting or both for one year or five years; operators must suppress direct marketing to anyone on it and keep audit evidence of that suppression. New Jersey requires deposit, spend and time limits on daily, weekly and monthly settings. Those are floors. Nothing stops a legal operator from assigning a host to someone losing heavily who has never asked for help.

WHAT YOU CAN ACTUALLY DEMAND

Your Rights, and Which Ones Survive

No federal consumer privacy statute covers this, so your rights depend on where you live. As of Aug. 25, 2026, 24 states have enacted comprehensive consumer privacy laws and 20 are in force.

Indiana, Kentucky and Rhode Island took effect Jan. 1, 2026. The newest four, Alabama, Louisiana, Oklahoma and Vermont, do not take effect until 2027. The overlap with the iGaming map is what matters here, and it is uneven: a Pennsylvania player has strong gaming-regulatory protection and essentially no general privacy law to invoke. Check your own position through the state-by-state index.

Regulated iGaming stateGeneral consumer privacy lawIn force since
ConnecticutYesJuly 1, 2023
DelawareDelaware Personal Data Privacy ActJan. 1, 2025
New JerseyNew Jersey Data Privacy ActJan. 15, 2025
Rhode IslandYesJan. 1, 2026
MichiganNoneNot applicable
PennsylvaniaNoneNot applicable
West VirginiaNoneNot applicable

The text of the Delaware Personal Data Privacy Act is public, and California’s law is the most developed of the lot. The California Privacy Protection Agency describes six rights: to know, delete, correct, opt out of sale or sharing, limit the use of sensitive personal information and receive equal service for exercising any of them. Businesses must also honor a browser opt-out preference signal such as Global Privacy Control. The definition of sensitive personal information at Civil Code 1798.140(ae) maps almost exactly onto a casino file, covering “a consumer’s social security, driver’s license, state identification card, or passport number,” account log-in and financial account credentials, and “a consumer’s precise geolocation.” California’s Delete Act platform, DROP, opened to consumers Jan. 1, 2026, and registered data brokers had to begin processing requests through it on Aug. 1, 2026. That reaches downstream brokers rather than the operator, but it is a real lever against the marketing tail.

Rights that survive against a casino

  • See what is held on you.
  • Correct errors in the record.
  • Stop sale and sharing with advertising partners.
  • Limit secondary use of sensitive data.
  • Delete the marketing residue no statute requires anyone to keep.

The right that usually fails

  • Deletion. Civil Code 1798.105(d) lists exceptions to the deletion duty, one being retention reasonably necessary to comply with a legal obligation.
  • Every statute on the same template carries an equivalent exception.
  • Against a casino that exception swallows nearly the whole request, because the five-year and 10-year mandates above are precisely the obligations it was written for.

Do not assume the banking carve-out applies

Most of these laws also carve out data governed by the Gramm-Leach-Bliley Act, but that carve-out was drafted for banks and lenders. A casino’s status as a financial institution under 31 C.F.R. 1010.100 is a separate definition and should not be assumed to trigger it.

What survives is real but narrower than advertised. If an operator refuses even that, escalate to your state attorney general and to the gaming regulator, using our complaint filing page.

WHEN THE FILE LEAKS

Breaches and the Notice You Are Owed

Notice is legally owed everywhere. The speed of it, and what counts as personal information, is not a national standard.

All 50 states, the District of Columbia, Guam, Puerto Rico and the Virgin Islands have security breach notification laws, so notice is legally owed everywhere. What counts as personal information, how fast notice must go out and whether the attorney general must be told are state questions, not a national standard.

Gambling companies are a proven target

In September 2023 Caesars Entertainment disclosed in a filing with the Securities and Exchange Commission that an intruder had acquired a copy of its loyalty program database, including driver’s license numbers and Social Security numbers for a large number of members. The attackers reached the company through a third-party IT vendor, which is the processor risk described above in its worst form.

New Jersey’s annual independent security assessment requirement answers this class of failure directly; the technical controls and their limits are covered under encryption and data protection.

THE OTHER HALF OF THE MARKET

Offshore: The Same Documents, None of the Rights

Everything above assumes a regulator with jurisdiction and a statute you can point to. Offshore, neither exists.

Send a passport scan to a site licensed in Curacao or Anjouan and it lands in a corporate structure whose ownership you cannot verify, on servers in a country nobody told you about, kept for a period nobody has to disclose. No access request, no deletion right, no attorney general with authority over the recipient.

The questionLicensed US operatorOffshore site
Who can compel the fileA state regulator with standing technical accessNobody with authority over the recipient
How long it is keptPublished minimums of five and 10 yearsA period nobody has to disclose
Where it is storedWith a licensed operator that stays accountable for its vendorsServers in a country nobody told you about
Right to see the fileYes, in a state with an access rightNo access request
Right to deleteNarrow, and mostly defeated by retention mandatesNo deletion right at all
Who owns the companyA permit holder on a public regulator fileA corporate structure you cannot verify

Curacao’s reformed regime under the Landsverordening op de kansspelen, in force since Dec. 24, 2024, does impose conditions on paper, including a complaints procedure and alternative dispute resolution. The gap is verification: a published requirement with no inspectable compliance record and no demonstrated way to force an operator’s hand is a different animal from a New Jersey obligation a regulator actually audits. That distinction runs through our comparison of offshore versus licensed sites and our survey of offshore licensing regimes.

The document upload is the underrated risk

A folder holding millions of passport images, driver’s licenses, utility bills and selfies is an unusually valuable target, and losing it hurts far more than a leaked password list, because you cannot reissue your face or your date of birth. Our ID verification guide separates a legitimate request from a pretextual one.

FIVE THINGS THAT ACTUALLY HELP

Practical Steps Worth the Time

You cannot opt out of the compelled collection. You can control the timing, the spread and the marketing tail.

1

Read three sections of the privacy policy, not all of it

The categories of third parties receiving your data, the retention schedule and the sale or sharing disclosure. If any is vague, treat the vagueness as the finding.

2

Use the marketing opt-outs on day one

Do it before a first deposit rather than after an offer has found you. Turn off promotional email, SMS and push, opt out of sale and sharing where your state allows it, and switch on Global Privacy Control in your browser.

3

Know what will not go away

Marketing consent is revocable. KYC records, transaction history, geolocation logs and gameplay reconstruction are not, for five to 10 years minimum. Do not open an account expecting to erase it later.

4

Concentrate rather than scatter

Every extra account is another copy of your passport in another company’s storage. Two researched operators beat six you joined for the bonuses.

5

Upload documents in the product, never by email

Emailed attachments sit unencrypted in two mailboxes indefinitely. Confirm the license first through our guide to verifying a license, and in a state with an access right, ask for your file once: one request reveals more about a company’s real practices than any policy document.

THE SHORT VERSION

A Price, and It Should Be Paid Knowingly

The deepest file any consumer business holds on you, in exchange for the only dispute process that works.

A licensed US casino holds a deeper and longer-lived record of you than almost any other business you deal with, largely because federal and state law say it must. That is a fair price for protected balances and a real dispute process, but it is a price, and it should be paid knowingly. The offshore alternative does not trade privacy for freedom: it takes the same documents and removes every mechanism you would use to do anything about them.

Researched and last reviewed Aug. 25, 2026. Retention schedules and state privacy statutes change; confirm current requirements with the regulator or attorney general before relying on anything here. General information about industry data practices, not legal advice about your circumstances.