Affiliate Disclosure
The main focus of globalcasinobonus.com is to provide you with objective online casino reviews and guides. To sponsor our model, we include affiliate links in our content. If you register through such a link, we will receive a small commission at the cost of the casino; this does not affect the terms of your own deal. We do not compromise on the quality of our service and list only licensed operators that have been checked and tested based on our methodology.
Advertiser Disclosure
This independent comparison website helps consumers choose the best available gambling product matching their needs. We offer a high-quality advertising service by featuring only established brands of licensed operators in our reviews. Please note that although we endeavour to provide you with up-to-date information, we do not compare all operators on the market.

Data Protection (UK/EU GDPR) – GlobalCasinoBonus

Last updated: 31 August 2025

At GlobalCasinoBonus we handle personal data with care and in line with the UK GDPR / EU GDPR. This page summarises our data protection principles, technical and organisational measures, vendor controls, rights handling, and incident response.

1) GDPR Principles We Follow

  • Lawfulness, fairness, transparency – clear purposes and notices.
  • Purpose limitation – use data only for the stated purpose.
  • Data minimisation – collect the least amount necessary.
  • Accuracy – keep data accurate and up to date where relevant.
  • Storage limitation – keep data no longer than needed.
  • Integrity & confidentiality – protect with appropriate security.
  • Accountability – document what we do and why.

2) Technical & Organisational Measures (TOMs)

  • Transport security – HTTPS/TLS for all pages and forms.
  • Perimeter protectionCloudflare CDN, WAF, DDoS mitigation, bot management.
  • Hosting security – patched servers, principle of least privilege, restricted admin access, activity logs.
  • Access controls – MFA for admin accounts, role-based permissions, session timeouts, unique credentials.
  • Data minimisation – we do not process payments or ID documents on our site; contact data is limited to what you send us.
  • Backups & continuity – regular backups; tested restore procedures.
  • Vulnerability management – timely updates to CMS/plugins; security monitoring and alerts.
  • Encryption – encryption in transit (TLS); at-rest encryption provided by our hosting where available.
  • Environment hygiene – staging/production separation; least-privilege API keys; secret rotation when needed.
  • Staff & contractors – confidentiality obligations and need-to-know access.

3) Processors & Vendors

We use trusted service providers (“processors”) to operate the Website, including Cloudflare (DNS/CDN/WAF/DDoS), secure hosting, web analytics (consent-based), anti-spam/security tools, email services, and affiliate networks (for click attribution). We require appropriate contractual safeguards and process data only on documented instructions.

4) International Data Transfers

Where personal data is transferred outside the UK/EU/EEA by our processors (for example global network routing via Cloudflare), we rely on recognised safeguards such as adequacy decisions, the UK IDTA, EU Standard Contractual Clauses (SCCs), or equivalent mechanisms.

5) Data Retention

  • Contact enquiries: typically up to 12 months after resolution.
  • Server & security logs (incl. Cloudflare): typically up to 90 days for security/troubleshooting.
  • Analytics (if consented): typically 14–26 months in aggregated form.
  • Cookie preferences: typically 6–12 months, or until cleared by you.

6) Data Subject Requests (Your Rights)

Depending on your jurisdiction, you may request access, rectification, deletion, restriction, objection, or portability, and withdraw consent for consent-based processing. To exercise rights, email [email protected]. We may ask for information to verify identity.

7) DPIAs & High-Risk Processing

We assess new projects or tools for privacy risks. Where processing could be high-risk, we perform a Data Protection Impact Assessment (DPIA) and apply additional safeguards before deployment.

8) Security Incidents & Breach Response

  • Detection – monitoring via hosting/Cloudflare/security tools; triage alerts.
  • Containment – isolate affected systems, rotate secrets, block malicious traffic.
  • Assessment – determine scope, data categories, likelihood of risk to individuals.
  • Notification – where legally required, notify the supervisory authority (e.g., UK ICO) and affected individuals within applicable timelines.
  • Post-incident – root-cause analysis and remediation to prevent recurrence.

9) Children

Our Website is for adults aged 18+. We do not knowingly collect data from children. If you believe a minor has provided personal data, contact us and we will delete it.

10) Contact & Supervisory Authority

Questions about this Data Protection statement: [email protected].
UK supervisory authority: Information Commissioner’s Office (ICO).

This page provides general information and does not constitute legal advice. Your specific obligations may vary based on your stack and jurisdictions.