- Introduction
This Privacy Policy sets out how personal data is collected, processed, stored and protected in connection with services provided by Genting Casino Derby Riverlights. The policy applies to all individuals who interact with the casino, including customers, visitors to the premises and users of any associated digital services.
Personal data is handled in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. By using the services of Genting Casino Derby Riverlights, you acknowledge that your personal data will be processed as described in this Privacy Policy.
- Data Controller
Genting Casino Derby Riverlights acts as the data controller in respect of personal data collected through its services and premises. As data controller, Genting Casino Derby Riverlights determines the purposes and means of processing your personal data.
Questions regarding this Privacy Policy or the exercise of data protection rights may be submitted in writing to the address associated with the registered premises or using the contact details set out in Section 9.
- Personal Data Collected
The following categories of personal data are collected and processed, depending on the nature of your interaction:
3.1 Identity and Contact Data
Full name, date of birth, residential address, email address, telephone number and government-issued identification documents provided for verification purposes.
3.2 Financial Data
Payment details, transaction records, deposit and withdrawal history, and information relating to source of funds where required for regulatory compliance.
3.3 Account and Activity Data
Records of gaming activity, visit history, account preferences, self-exclusion status and responsible gambling interactions.
3.4 Technical and Device Data
IP addresses, browser type, device identifiers and usage data collected when you access any digital services operated by Genting Casino Derby Riverlights.
3.5 Compliance and Verification Data
Information collected for identity verification, age verification and anti-money laundering checks, including documentation submitted in support of those processes.
- Purposes and Legal Bases for Processing
Personal data is processed only where a lawful basis exists under UK GDPR. The primary purposes and the corresponding legal bases are set out below.
Purpose - Legal basis:
- Opening and managing your account - Performance of contract
- Identity and age verification - Legal obligation
- Anti-money laundering checks - Legal obligation (Money Laundering Regulations 2017)
- Detecting and preventing fraud and crime - Legal obligation and legitimate interests
- Monitoring responsible gambling indicators - Legal obligation and legitimate interests
- Administering self-exclusion arrangements - Legal obligation
- Communicating with you about your account - Performance of contract
- Direct marketing and product promotion - Legitimate interests or consent
- Profiling and segmentation for service improvement - Legitimate interests
- Compliance with regulatory requirements - Legal obligation
Where processing is based on legitimate interests, those interests have been assessed so as not to override your fundamental rights and freedoms. Where processing is based on consent, you may withdraw that consent at any time. Withdrawal of consent may affect the ability to provide certain services but does not affect the lawfulness of processing carried out before consent was withdrawn.
- Responsible Gambling and Monitoring
In line with the Gambling Commission’s licensing conditions, gambling activity is monitored to identify indicators of potential harm. This includes processing data relating to gambling patterns, frequency of play, deposit behaviour and interactions with responsible gambling tools.
If indicators of concern are identified, steps may be taken such as restricting access, initiating contact with you or applying account controls. This processing is carried out to meet regulatory obligations and to protect the well-being of customers.
Genting Casino Derby Riverlights participates in self-exclusion schemes as required by the Gambling Commission. Information relating to self-exclusion status may be shared with other operators or scheme administrators where required by regulation.
- Sharing of Personal Data
Personal data is not sold. Personal data may be shared with third parties only where necessary and where a lawful basis exists. Recipients may include:
- Group companies within the Genting corporate structure for account management and regulatory compliance
- Identity verification and credit reference agencies for age and identity checks
- Anti-money laundering and fraud prevention agencies
- Payment processors and financial institutions for processing transactions
- Information technology service providers supporting systems and infrastructure
- Regulatory authorities, including the Gambling Commission, and law enforcement bodies where required by law
- Self-exclusion scheme operators where required by licensing conditions
- Legal and professional advisers where necessary for legal proceedings or compliance matters
All third parties with whom personal data is shared are required to process that data in accordance with applicable data protection law and contractual instructions.
- Data Retention
Personal data is retained for as long as necessary to fulfil the purposes for which it was collected, including compliance with legal, regulatory and accounting obligations.
Records relating to anti-money laundering compliance are retained for a minimum period of five years from the end of the business relationship or the date of the transaction, in accordance with the Money Laundering Regulations 2017. Other categories of data may be retained for longer periods where required by applicable law or regulatory guidance.
At the end of the relevant retention period, personal data is securely deleted or anonymised.
- Your Data Protection Rights
Under UK GDPR, you have the following rights in relation to your personal data:
- Right of access: to request a copy of the personal data held about you.
- Right to rectification: to request correction of inaccurate or incomplete personal data.
- Right to erasure: to request deletion of your personal data in certain circumstances, subject to legal and regulatory obligations to retain data.
- Right to restriction: to request restriction of the processing of your personal data in certain circumstances.
- Right to object: to object to processing carried out on the basis of legitimate interests, including direct marketing.
- Right to data portability: to request provision of your personal data in a structured, commonly used and machine-readable format where processing is based on consent or contract.
- Right to withdraw consent: where processing is based on consent, to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.
To exercise any of these rights, a written request should be submitted using the contact details set out in Section 9. A response will be provided within one calendar month of receipt of the request. In complex cases, this period may be extended by a further two months, and notification of any such extension will be provided.
- Contact Details
For queries relating to this Privacy Policy or to exercise data protection rights, please write to the Data Protection contact at Genting Casino Derby Riverlights at the address of the registered premises.
- Complaints
If you are not satisfied with the response to a data protection query or rights request, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the supervisory authority for data protection matters in the United Kingdom.
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Website: ico.org.uk
- Changes to This Privacy Policy
This Privacy Policy may be updated from time to time to reflect changes in practices, legal obligations or regulatory requirements. The current version is available at the premises of Genting Casino Derby Riverlights and through official digital channels. Periodic review of the policy is recommended.

