Effective Date: 25/05/2026
Data Controller: toponlinecasinosiceland.is
Data Protection Officer Contact: [email protected]
This Privacy Policy ("Policy") is issued by toponlinecasinosiceland.is ("the Controller," "we," "us") pursuant to the transparency obligations set out in Articles 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council ("GDPR") and applicable national data protection legislation. This Policy constitutes the Controller's complete and current disclosure of personal data processing activities arising from your use of our online gaming platform, website, mobile application, and all associated player-facing services. It is structured to follow your actual journey with us — tracing data governance decisions at each stage of interaction. Submit all privacy enquiries to [email protected].
Article 1 — The Controller and Scope of This Policy
toponlinecasinosiceland.is, registered, is the data controller within the meaning of Article 4(7) GDPR and bears legal responsibility for all personal data processing described herein. This Policy applies to every natural person interacting with the Controller's platform in any capacity — including anonymous visitors, registered account holders, and former players whose data is retained under statutory obligations following account closure. It does not apply to legal entities. Processing activities arising from circumstances not described in this Policy will be accompanied by a separate, purpose-specific notice at the relevant point of collection. The Controller designates [email protected] as the primary contact point for all data protection communications, data subject right requests, and formal complaints. All such communications will be acknowledged within five working days and substantively responded to within thirty calendar days, subject to the extension provisions of Article 12(3) GDPR.
Article 2 — Data Processing During Platform Visits
Plain summary: Before you register, we collect limited technical data automatically. We also ask for your cookie preferences. Neither identifies you personally at this stage.
When you access toponlinecasinosiceland.is — whether on desktop, mobile browser, or application — our systems automatically receive and temporarily process technical data generated by your device and network connection. This encompasses your Internet Protocol address, device type and model, browser identity and version, operating system, referring URL, pages visited, interaction patterns, session duration, and error logs. This automatic collection is necessary to deliver a functioning, secure platform and constitutes processing under the Controller's legitimate interests pursuant to Article 6(1)(f) GDPR — specifically interests in platform security, fraud prevention, technical stability, and aggregate usage analysis. No individual behavioural profiles are constructed from anonymous visit data.
Simultaneously, the platform presents a cookie consent interface through which you may manage your preferences across four defined categories. Strictly necessary cookies, providing session management, authentication, and core security functions, are deployed without consent as essential operational tools, expiring within twenty-four hours. Functional cookies, preserving language selection and display preferences, persist for up to twelve months and are deployed on the basis of necessity for the service requested. Analytical cookies, collecting anonymised performance data for platform improvement purposes, are retained for thirteen months and activated only upon affirmative consent. Marketing cookies, supporting personalised offer display and affiliate attribution, persist for twenty-four months and are strictly consent-dependent. Cookie preferences may be reviewed and modified at any time through the Cookie Settings panel in the platform footer, without restriction to core service access.
Article 3 — Data Processing at Account Registration and Verification
Plain summary: Creating an account requires your identity details. Before you can play for real money, the law requires us to verify who you are using official documents.
The establishment of a player account requires submission of personal identity data comprising your full legal name, date of birth, email address, country of residence, and chosen account credentials. This data is processed on the basis of Article 6(1)(b) GDPR as necessary for the performance of the contract entered into between you and the Controller upon account creation. Prior to the activation of real-money transactional functionality, the Controller is legally obligated under applicable anti-money laundering legislation and gambling licensing requirements to conduct identity verification ("Know Your Customer" or "KYC"). This requires the submission of a valid government-issued photographic identification document, documentary proof of current residential address dated within ninety days of submission, and in defined circumstances, a contemporaneous selfie image submitted alongside the identification document for biometric verification purposes.
KYC data is processed by the Controller's designated identity verification partner — a regulated entity operating under a formal data processing agreement that restricts use of the data to the verification purpose only — on the basis of compliance with a legal obligation pursuant to Article 6(1)(c) GDPR. Registration and KYC data is not shared with any third party beyond the verification provider except where required by regulatory or law enforcement authority. Players who decline or fail to complete identity verification will be restricted from real-money activity in accordance with the Controller's regulatory obligations. KYC documentation is retained for five years following permanent account closure in compliance with anti-money laundering regulatory requirements.
Article 4 — Data Processing During Game Sessions
Plain summary: Every game session generates records we must keep. We also monitor gameplay patterns to protect players who may be experiencing gambling-related harm — but only humans make welfare decisions, never algorithms alone.
Each interaction with the Controller's game library generates gameplay data comprising game titles accessed, wager amounts placed, session start and end timestamps, win and loss outcomes, bonus activation and completion records, responsible gambling tool interaction logs, and session frequency patterns. This data is processed on two concurrent legal bases. Pursuant to Article 6(1)(b) GDPR, gameplay records are necessary for the performance of the gaming contract — specifically for the calculation of outcomes, application of bonus terms, and maintenance of accurate account records. Pursuant to Article 6(1)(f) GDPR, gameplay data is further processed to monitor statistical indicators associated with disordered gambling behaviour, including but not limited to escalating session frequency, progressive loss acceleration, repeated override of voluntary limit-setting tools, and deviation from established play patterns.
Where such indicators are identified through automated analysis, the relevant data is flagged for review by a designated member of the Controller's player welfare team. No welfare intervention — whether proactive contact, account control, or referral to external support services — is initiated by automated means alone. Human review is applied to every flagged case prior to any action, in compliance with Article 22 GDPR safeguards. Players retain the right to object to this profiling activity under Article 21 GDPR by submitting a written request to [email protected], whereupon the Controller will cease the profiling unless compelling legitimate grounds are demonstrated. Gameplay records are retained for three years from session date.
Article 5 — Data Processing During Financial Transactions
Plain summary: Every deposit and withdrawal creates a financial record we must keep for up to seven years under law. Your full card number is never stored on our systems.
Each deposit, withdrawal, and bonus transaction generates financial data including payment method category, partial payment identifier where technically applicable, transaction amount, currency, timestamp, and the reference number assigned by the relevant payment service provider. This data is processed under Article 6(1)(b) GDPR to execute the contractual transaction requested, and under Article 6(1)(c) GDPR to comply with mandatory record-keeping obligations imposed by applicable tax legislation and anti-money laundering regulation. Full payment card numbers are never stored on the Controller's systems. Card data is processed exclusively within the Payment Card Industry Data Security Standard ("PCI DSS") compliant environment maintained by the Controller's payment processing partner, which operates under a binding data processing agreement restricting use to transaction execution only.
Financial data is shared with payment service providers as processors, and with regulatory authorities, financial intelligence units, or law enforcement agencies where disclosure constitutes a legal obligation or arises from a lawful documented demand. All payment processors operating outside the European Economic Area are subject to Standard Contractual Clauses pursuant to Article 46(2)(c) GDPR before any international transfer of financial data occurs. Financial transaction records are retained for seven years from transaction date, and account identity records linked to financial activity are retained for five years following account closure, both in compliance with applicable statutory requirements.
Article 6 — Your Data Subject Rights and Controls
Plain summary: You have seven rights. None require justification. All are free. All are answered within thirty days. If we cannot comply fully due to a legal obligation, we explain precisely why in writing.
Under the GDPR, you are entitled to exercise the following rights in relation to personal data held by the Controller. The right of access under Article 15 entitles you to a complete copy of all data held, together with processing information, recipients, retention periods, and data source. The right to rectification under Article 16 requires correction of inaccurate or incomplete data. The right to erasure under Article 17 entitles you to deletion where grounds exist and no statutory retention obligation applies; where mandatory retention prevents full compliance, the retained data and applicable legal basis will be identified in writing. The right to restriction under Article 18 permits suspension of processing pending dispute resolution. The right to data portability under Article 20 entitles you to receive data in a structured, machine-readable format or request direct transmission where processing is automated and consent- or contract-based. The right to object under Article 21 permits objection to legitimate interest processing including profiling, with immediate cessation for direct marketing objections. The right to withdraw consent under Article 7(3) permits termination of consent-based processing without detriment to prior lawful processing.
All requests are submitted in writing to [email protected] with sufficient identifying information for verification. Response within thirty calendar days, extendable by sixty days with notice where justified. No fee is charged. Unsatisfied data subjects retain the unconditional right to escalate to their national supervisory authority or seek judicial remedy.
Article 7 — Third-Party Sharing, Security and Policy Governance
The Controller does not sell, license, or commercially transfer personal data under any circumstances. Disclosure occurs only to service providers acting as processors under binding data processing agreements; regulatory and law enforcement authorities where legally required; responsible gambling exclusion registers where self-exclusion obligations apply; and business successors in the event of a merger or acquisition, subject to prior written player notification. All processors outside the EEA are subject to Standard Contractual Clauses under Article 46(2)(c) GDPR.
Security measures maintained by the Controller include TLS 1.2 or higher for data in transit; AES-256 encryption for sensitive data at rest; role-based access controls with full logging and quarterly audit; PCI DSS-compliant payment handling; regular independent penetration testing; and a documented breach response protocol providing for supervisory authority notification within seventy-two hours and individual notification without undue delay pursuant to Articles 33 and 34 GDPR.
This Policy is subject to periodic review. Material amendments are communicated to registered users by email in advance of the revised effective date. Continued platform use following notification constitutes acknowledgement of the revised Policy.
toponlinecasinosiceland.is | [email protected]