AI Account Profiling at Offshore Casinos: Your Data Protection Rights When an Algorithm Closes Your Account

Table of Contents

If an offshore casino closed your account, blocked your withdrawal, or voided your winnings following what appears to be an automated security or risk assessment, and you received a generic notice citing “security systems,” “automated review,” or “risk detection,” this guide explains the data protection rights that apply to that decision and how to exercise them. The legal position differs materially depending on whether you are an EU or UK player, and it changed significantly in the UK in early 2026. Both positions are addressed directly below.

This guide covers automated account decisions by offshore casino operators: those licensed by the Curaçao Gaming Authority (“CGA”), the Malta Gaming Authority (“MGA”), and the Gibraltar Gambling Division, and unlicensed operators. Curaçao-licensed operators are not subject to UKGC oversight and carry materially weaker player protection frameworks than UK-licensed operators. UKGC-licensed operators are out of scope for the casino-side analysis but remain relevant where UK data protection rules are discussed.

Key Points

  • EU GDPR Article 22 (Regulation (EU) 2016/679, OJ L 119, 4.5.2016) restricts decisions based solely on automated processing that produce legal effects or significantly affect the data subject. An automated permanent account closure, withdrawal block, or winnings forfeiture is a strong candidate for the Article 22 threshold. This applies to EU players regardless of where the casino is licensed.
  • The UK position changed on 5 February 2026. Section 80 of the Data (Use and Access) Act 2025 (2025 c.18) repealed the old UK GDPR Article 22 and replaced it with Articles 22A to 22D. The new framework is less restrictive on automated decisions generally, but it requires mandatory safeguards including information about the decision, an opportunity to make representations, and the ability to obtain human intervention.
  • An offshore licence does not exempt an operator from GDPR. EU GDPR Article 3(2) brings non-EU controllers within scope where they target or monitor people in the EU. The equivalent UK GDPR provision does the same for people in the UK. An offshore casino accepting UK and EU deposits, tracking player behaviour, and applying risk profiling systems is a strong candidate for both territorial tests.
  • The right of access under GDPR Article 15 is your most immediately practical tool. Following CK v Magistrat der Stadt Wien (Dun and Bradstreet Austria GmbH), Case C-203/22, ECLI:EU:C:2025:117, the operator must provide meaningful, understandable information about the logic actually applied to your account, not a generic description of its system. Trade secret claims cannot justify a blanket refusal.
  • No reported UK or EU judgment has yet squarely decided an Article 22 claim arising from an automated offshore casino closure. The analysis in this article applies established general GDPR authority to the casino context.
  • Player Protection Legal operates on a no-win, no-fee basis. You pay nothing upfront, and we are only paid if we successfully recover funds on your behalf.

Use the checker below to identify which data protection regime applies to your account closure and what rights it gives you before reading the full analysis.

Rights Regime Checker Answer five questions to identify which data protection framework applies to your account closure and what rights it gives you.
1. Where were you located when your account was closed?
2. When did the account closure or restriction occur?
3. What type of automated decision was made against your account?
4. What did the closure notice say?
5. Which jurisdiction licensed the casino?

The DSAR is your most practical first step. Article 15 of both EU GDPR and UK GDPR gives you the right to access your personal data and to receive specified information about how it is processed. Article 15(1)(h) specifically entitles you to information about automated decision-making, including meaningful information about the logic involved and the significance and envisaged consequences of that processing.

Following CK v Magistrat der Stadt Wien (Dun and Bradstreet Austria GmbH), Case C-203/22, ECLI:EU:C:2025:117, a response consisting only of "we use proprietary algorithms to assess fraud risk" is difficult to reconcile with Article 15(1)(h). The CJEU held that the explanation must enable the person to understand the procedure and principles actually applied and the influence of relevant data on the result. The controller cannot invoke trade secrecy as a blanket justification for refusing to provide this information, although it may balance trade secret and third-party rights through a supervisory authority or court rather than unrestricted disclosure to the individual.

In practical terms, your DSAR should specifically request:

  • All risk, fraud, AML, responsible gambling, and bonus abuse flags and scores associated with your account, and their changes over time
  • The input data used for the relevant assessment, including account activity, session data, deposit and withdrawal patterns, and device signals
  • The output or recommendation supplied to any human decision-maker prior to the account closure
  • Records identifying whether a human reviewed the automated output before the closure, and if so, what the review involved
  • The date and time of the automated scoring and the final decision
  • Information required by Article 15(1)(h) about the logic, significance, and envisaged consequences of the processing
  • The source of any data received from third-party KYC, fraud, or screening providers
  • All personal data held about your account including communications, transactions, game history, and any model reason codes or rule triggers

The one-month response deadline under GDPR Article 12(3) applies. Where necessary because of complexity, the controller may extend by a further two months, but must notify you within the first month. A DSAR survives account closure: Article 15 is a data subject right against any controller processing your data, not a right contingent on an ongoing customer relationship. "You are no longer a customer" is not a valid Article 15 exemption.

The Right to Human Review and Contest

Under EU GDPR Article 22(3), where an automated decision is taken under a permitted exception, the controller must implement suitable measures including at least the right to obtain human intervention, the right to express a point of view, and the right to contest the decision. Under UK GDPR Article 22C, the same safeguards apply to significant solely automated decisions from 5 February 2026.

Human intervention means genuine human involvement, not a perfunctory rubber-stamp of the machine's output. The reviewer must have actual authority and competence to examine the relevant data, consider the player's position, and depart from the automated recommendation. A review process that simply reruns the same algorithm, or one in which the reviewer has no authority to override the system and routinely does not do so, does not satisfy this requirement.

The right to contest the decision entitles you to provide factual representations about the specific profiling output. If the system flagged your account based on betting patterns that are explainable by a documented reason, if the account history demonstrates continuous play by a single individual, if the AML flag was triggered by a legitimate and documentable source of funds, or if the bonus abuse determination rested on a term you were not shown at the relevant time, these are the representations you are entitled to make and the controller must genuinely consider them.

The right to obtain human review is not a guarantee of a different outcome. The human reviewer need not agree with you. The right is to genuine engagement with your representations, not to reversal.

Your Step-by-Step Challenge Process

The following sequence moves from least to most formal. Each stage builds the evidential record for the next.

Step 1: Preserve everything immediately

Before any other step, preserve the following while your account and its history are still accessible: the exact closure or restriction notice including date, wording, and any reference to security systems or automated review; the casino's privacy notice in force at the date of the closure; the terms and conditions in force at the date of the closure; your account transaction history, game history, and any withdrawal requests; and all communications with the casino.

Step 2: Send a combined DSAR and automated-decision rights request

Within the first month of the account closure, send a single written request to the casino's data protection officer or compliance department that:

  • Requests all personal data held about you under GDPR Article 15
  • Specifically requests the Article 15(1)(h) information about automated decision-making including the logic, inputs, outputs, and significance
  • Asks whether the final account decision was made without meaningful human involvement
  • Invokes your right to human intervention and to contest the decision under Article 22(3) (for EU players) or Article 22C (for UK players from 5 February 2026)
  • Requests the name and contact details of the casino's data protection officer and its Article 27 representative if applicable

Step 3: Assess the response

When the casino responds, examine whether it has provided specific, individualised information about the logic applied to your account, or only a generic description of its systems. Following Dun and Bradstreet Austria, the former is required. Examine whether a human reviewed the decision and, if so, what that review involved. Examine what profiling data has been disclosed and whether the inputs were accurate.

Where the casino claims AML or legal obligation as the basis for withholding information, examine whether the specific prejudice-based analysis required by the ICO's SAR exemption guidance has been applied, or whether a blanket exemption has been claimed without justification.

Step 4: File a complaint with the relevant supervisory authority

For UK players, the ICO accepts data protection complaints under Data Protection Act 2018, s.165. The ICO recommends raising the complaint within three months of the last meaningful contact with the organisation. File the complaint with the full DSAR exchange, the closure notice, and a specific explanation of which rights were breached and how.

For EU players, EU GDPR Article 77 allows a complaint with a supervisory authority, particularly in the Member State of habitual residence, place of work, or place of the alleged infringement. A Malta-based casino with its main establishment in Malta may be subject to the one-stop-shop mechanism with Malta's data protection authority as the lead supervisory authority. A Curaçao-based or Gibraltar-based casino without an EU establishment may be subject to complaints in any Member State where the alleged infringement occurred.

Step 5: Pursue a civil claim and instruct Player Protection Legal

GDPR Article 82 provides that any person who has suffered material or non-material damage as a result of an infringement has the right to receive compensation from the controller. In UI v Österreichische Post AG, Case C-300/21, ECLI:EU:C:2023:370, the CJEU confirmed that infringement, damage, and causation are cumulative conditions: infringement alone is not damage. Damage includes both material loss and non-material harm including distress. UK Data Protection Act 2018, s.168, supplements the compensation regime and recognises damage including distress.

The civil claim is separate from the ICO complaint. Where the casino has infringed your GDPR rights in connection with an account closure or winnings forfeiture, the financial loss arising from that infringement may be compensable. Our specialist gambling law attorneys handle offshore casino disputes involving GDPR account closure claims from formal complaint through to legal proceedings on a no-win, no-fee basis.

Where the closed account also held funds deposited via open banking, the chargeback route is unavailable and the GDPR challenge becomes the primary recovery mechanism — our guide to open banking casino deposits and what to do when no chargeback exists covers the alternative routes. For Curaçao-licensed operators specifically, the practical limits of civil enforcement are addressed in our analysis of whether a UK court judgment can be enforced against a Curaçao casino.

Evidence to Preserve

Preserve the following before any account restriction occurs and immediately on receiving a closure notice.

Closure and restriction records:

  • The exact closure or restriction communication with full date, time, wording, and any reference to automated systems, security systems, or algorithm-based decisions
  • Any appeal or review request submitted and the casino's response

Privacy and terms documentation:

  • The casino's privacy notice in force on the date of the closure, including any provisions on automated decision-making and profiling
  • The terms and conditions in force on the date of the closure, including any bonus rules or withdrawal conditions

Account and payment records:

  • Full account transaction history showing deposits, bets, withdrawal requests, and balance entries
  • Bank or card statements showing deposits with merchant descriptors
  • Any withdrawal request confirmation or refusal

DSAR and correspondence:

  • The DSAR as submitted, with evidence of delivery
  • The casino's response, including any disclosed personal data, scores, flags, and explanatory letters
  • All emails, live-chat transcripts, and support tickets with the casino

Regulatory records:

  • Screenshot of the casino's licence page and regulatory seal at the time of closure
  • FCA register or equivalent entry for the casino's data protection officer or representative where identifiable

When the Challenge Is Less Likely to Succeed

Not every automated account closure involves a breach of data protection rights. The challenge is weaker in the following circumstances.

  • The decision involved genuine, documented human review by a reviewer with actual authority to depart from the machine recommendation, who examined the underlying evidence and made an independent decision. Where the human involvement was meaningful rather than nominal, the automated decision rights framework may not apply.
  • The casino has provided a specific, individualised explanation of the logic applied to your account and a genuine opportunity to contest the outcome, and the result following human review is the same. Having received the required safeguards, the remaining challenge is to the underlying gambling dispute, not the data protection breach.
  • The DSAR response shows that the input data relied upon was accurate and that the profiling output was proportionate to the actual account activity. Where the data is accurate and the processing was lawful, the data protection route may not produce a different outcome.
  • The casino's AML legal obligation specifically authorises the automated closure under a statutory provision that itself lays down suitable safeguards, and those safeguards were provided. This is a narrow category: a general monitoring obligation does not satisfy it.

Where your situation falls outside these categories, contact us for a free initial consultation. Where an account closure was followed by a casino debt demand such as a bonus clawback or a reversed withdrawal demand, our guide to when an offshore casino debt becomes unenforceable against you covers the consumer law defences available in parallel with the data protection routes addressed in this article.

US Players

The United States does not have a single federal analogue to EU GDPR Article 22 applicable generally to casino accounts. Federal analysis focuses on the Unlawful Internet Gambling Enforcement Act, which is primarily a payments enforcement statute and does not address automated decision-making rights.

The most relevant US framework is at state level. California's final automated decision-making technology ("ADMT") regulations, adopted by the California Privacy Protection Agency in September 2025, became effective on 1 January 2026. However, business compliance with the ADMT-specific requirements is not required until 1 January 2027. Whether a casino account closure qualifies as a covered "significant decision" under those regulations has not been established.

Other state statutes contain profiling opt-out rights framed around decisions producing legal or similarly significant effects, including Colorado Revised Statutes §6-1-1306, Virginia Code §59.1-577, and Connecticut General Statutes §42-518. These require verification against current consolidated texts and applicability thresholds before reliance.

What to Monitor Going Forward

  • ICO final ADM and profiling guidance: The ICO opened consultation on updated automated decision-making and profiling guidance on 31 March 2026, closing it on 29 May 2026. As of the date of this article, final updated guidance is expected in Winter 2026. Check the ICO's guidance publication plan for the published version before relying on pre-DUAA Article 22 materials.
  • MGA AI Gaming Charter: The MGA launched a targeted consultation on a proposed voluntary AI Gaming Charter on 8 May 2026, developed with the Malta Digital Innovation Authority. Monitor MGA publications for any finalised charter, which would provide sector-specific AI governance guidance relevant to MGA-licensed operators.
  • EU AI Act application: Regulation (EU) 2024/1689, which entered into force on 1 August 2024, with most provisions applicable from 2 August 2026, classifies certain AI systems as high-risk under Annex III. Casino customer risk scoring and account profiling systems are not expressly listed as a standalone Annex III category. Monitor the European Commission for any delegated acts or Annex III amendments that would change this classification.
  • CJEU and national court decisions on casino automated decisions: No reported EU or UK judgment has yet squarely applied Article 22 to an offshore casino account closure. Monitor CJEU, national court, and supervisory authority publications for any decision specifically addressing automated decision-making in the online gambling context.
  • Player Protection Legal: We publish ongoing analysis of GDPR automated decision-making developments, ICO enforcement decisions, and offshore casino regulatory updates in our online casino legal news and case updates.