Legal

Privacy Policy

This policy explains what personal data Top 10 Ireland Casinos collects when you use this website, why we collect it, how long we keep it and the rights you can exercise. It is written to be read, not to be skipped — if anything here is unclear, please ask us.

Version 4.1 · Last updated: 24 July 2026

1. Who we are

Top 10 Ireland Casinos (“we”, “us”, “our”) publishes this website at top10irelandcasinos.com as an independent informational resource about online casinos available to adults in Ireland. We are the data controller for personal data processed through this site.

We are a publisher, not a gambling operator. We do not run games, accept bets or hold player funds, and we never receive your casino account credentials, deposits, balances or gambling history. Once you leave our site for an operator, that operator becomes the controller of whatever data you give it, under its own privacy policy.

You can reach us at [email protected] or through our contact page.

2. Policy in brief

You can read every page here without giving us your name. We do not sell personal data, we do not run advertising networks that track you across the web, and we do not build behavioural profiles. We collect a small amount of technical data to keep the site running and secure, optional analytics data only if you consent, and whatever you choose to send us if you contact us directly.

3. Data we collect

3.1 Data you give us voluntarily

  • Contact enquiries. If you use our contact form or email us, we receive the name, email address, subject and message you supply. Our contact form does not transmit data to a server of ours — it validates your entries in your browser and then opens your own email application, so your message reaches us as an ordinary email.
  • Corrections and reports. If you report an error, a factual dispute or a problem with an operator, we process the details you send so we can investigate and reply.
  • Anything else you choose to include. Please do not send us financial details, identity documents, casino passwords or information about your health. We do not need any of it and we would rather not hold it.

3.2 Data collected automatically

  • Technical and server log data. Our hosting provider records IP address, request time, page requested, HTTP status, referring page, browser type and operating system. This happens for every website you visit and is necessary to serve pages and to detect abuse.
  • Device and display information. Screen size and language settings, so pages render correctly.
  • Consent state. Your cookie choice is stored locally in your browser so we do not have to ask you again on every page.

3.3 Analytics data (only with your consent)

If you accept optional cookies, we collect aggregated statistics about which guides are read, how visitors arrive, roughly which region they are in at country or county level, and where people leave a page. We use this to decide what to write next and to find broken pages. It is not used to identify you, and we do not combine it with any contact data you send us.

3.4 What we never collect

  • Payment card numbers, bank details or any financial credentials — we take no payments from visitors.
  • Casino account usernames, passwords, balances, deposits or betting activity.
  • Special category data such as health, ethnicity, political opinions, religious beliefs or biometric data.
  • Data purchased from brokers or scraped from social media to enrich a profile.

4. Why we use it and our lawful bases

Under Article 6 of the GDPR every processing activity needs a lawful basis. Ours are set out below.

Purposes of processing and corresponding lawful bases
Purpose Data used Lawful basis
Delivering pages and keeping the site available IP address, request logs, device data Legitimate interests — operating the service you asked for
Security, abuse prevention and fraud detection IP address, request patterns, logs Legitimate interests — protecting the site and its visitors
Answering your enquiry or correction report Name, email, message content Legitimate interests, or performance of a request you initiated
Remembering your cookie preference Local browser storage entry Legitimate interests — honouring the choice you made
Understanding which content is useful (analytics) Aggregated usage statistics Consent — withdrawable at any time
Measuring referrals to operators we work with Aggregated click counts, no visitor identity Legitimate interests — verifying commercial reporting
Meeting legal, accounting and regulatory obligations Correspondence records where relevant Legal obligation

Where we rely on legitimate interests, we have weighed our interest against your privacy and concluded the processing is limited, expected and not intrusive. You may object at any time — see section 10.

5. Cookies and similar technologies

We use a deliberately small number of cookies and browser storage entries. Non-essential cookies are set only after you accept them in our cookie notice, and you can choose “essential only” without losing access to any content.

Our Cookie Policy lists each item, its purpose and its lifespan, and explains how to change your choice or clear stored data at any time.

6. Who we share data with

We do not sell personal data and we do not trade it. We share limited data with:

  • Our hosting and content delivery provider, which processes server logs in order to serve the site. It acts on our instructions under a written data processing agreement.
  • Our analytics provider, if and only if you have accepted optional cookies. Data is aggregated and configured to minimise identifiability.
  • Our email provider, which transmits and stores correspondence you send us.
  • Professional advisers such as accountants or legal counsel, where strictly necessary and subject to confidentiality.
  • Authorities, where we are legally required to disclose information or need to establish, exercise or defend a legal claim.

A note on affiliate links

When you follow an advertising link to an operator, the operator records the referral so it can attribute any commission to us. We receive aggregated reporting — counts of clicks and sign-ups — not your name, your account details or what you played. We do not pass any personal data about you to operators, and we do not receive your gambling activity from them.

7. International transfers

We prefer suppliers who process data within the European Economic Area. Where a provider processes data outside the EEA, we rely on an adequacy decision by the European Commission, or on the Commission’s Standard Contractual Clauses together with a transfer impact assessment and any supplementary safeguards that assessment identifies. You can ask us which mechanism applies to a specific supplier and we will tell you.

8. How long we keep data

Retention periods by data category
CategoryRetention period
Server and security logsUp to 90 days, then deleted or irreversibly anonymised
Contact correspondence24 months after the matter is closed, unless a longer period is needed for a legal claim
Corrections and operator complaint records36 months, so we can track patterns of behaviour across our review cycle
Aggregated analyticsUp to 26 months in identifiable form; aggregated totals may be kept longer
Cookie consent recordUp to 12 months, or until you clear your browser storage
Records required by law (e.g. accounting)For the period the relevant legislation requires

When a retention period ends we delete the data or anonymise it so it can no longer identify you.

9. How we protect data

  • The entire site is served over HTTPS with modern TLS, so traffic between your browser and our server is encrypted.
  • Access to correspondence and administrative systems is restricted to the individuals who need it and protected by strong, unique credentials and multi-factor authentication.
  • We practise data minimisation: we do not build a visitor database, and we have no login area or user accounts to compromise.
  • Software, dependencies and server configuration are kept patched, and our published pages are static, which materially reduces the attack surface.
  • We keep no card or financial data of any kind, because we never take payments from visitors.

No system is completely secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Data Protection Commission within 72 hours of becoming aware of it and inform affected individuals where the law requires.

10. Your rights under the GDPR

As a data subject in Ireland or elsewhere in the EEA, you have the right to:

  • Be informed about how your data is used — this policy is part of meeting that obligation.
  • Access a copy of the personal data we hold about you.
  • Rectification of data that is inaccurate or incomplete.
  • Erasure of your data where there is no overriding reason for us to keep it.
  • Restrict processing while a dispute about accuracy or lawfulness is resolved.
  • Data portability — receive data you provided in a structured, machine-readable format.
  • Object to processing based on legitimate interests, including any direct marketing.
  • Withdraw consent at any time where consent is the basis, without affecting processing already carried out lawfully.
  • Lodge a complaint with a supervisory authority.

To exercise any right, email [email protected]. We respond within one month and will tell you promptly if we need an extension for a complex request. There is no charge, though we may ask for information to confirm we are dealing with the right person — and if we hold no data about you, we will say so plainly.

11. Children and age restrictions

This website is intended solely for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18, and we do not create content designed to appeal to children or young people.

If you believe a person under 18 has sent us personal data, contact [email protected] and we will delete it without delay. Parents and guardians can find practical device-level controls in our responsible gaming guide.

12. Third-party sites and operators

Our pages link to gambling operators, regulators and support organisations. Those sites are controlled by other parties and have their own privacy policies and cookie practices, over which we have no influence. This policy covers only what happens on top10irelandcasinos.com.

Before registering with any operator we recommend reading its privacy policy, checking what identity documents it requires for verification, and confirming how it handles marketing preferences and self-exclusion requests.

13. Automated decisions and profiling

We do not carry out automated decision-making that produces legal effects for you, and we do not profile visitors for advertising. Our editorial scores are produced by people applying a published methodology — see how we review casinos — not by an algorithm acting on visitor data.

14. Changes to this policy

We update this policy when our practices, suppliers or legal obligations change. The version number and date at the top of the page always reflect the current text. Where a change materially affects your rights we will highlight it on the site for a reasonable period rather than relying on you to notice a new date.

15. Contact and complaints

For any privacy question, request or concern, write to [email protected], or use our contact form and select the data protection subject. We aim to reply to privacy correspondence within five working days and to resolve requests within one month.

If you are not satisfied with our response you can complain to the Irish supervisory authority:

Data Protection Commission (Ireland)

6 Pembroke Row, Dublin 2, D02 X963, Ireland
Website: dataprotection.ie

If you live in another EEA country you may instead complain to your local data protection authority. Contacting us first is usually quicker, but you are never obliged to.