This online casino Swish privacy policy explains how personal data is collected, used, shared and protected for players in Sweden.
Data controller details:
The personal data processed depends on how you use the service, which payments you make and which verification or security checks are required.
| Data category | Examples | Primary use |
|---|---|---|
Identity | Name, address, personal ID, date of birth, e-ID | Age, identity and account verification |
Account | Account ID, settings, limits, self-exclusion, bonus status | Account operation and player controls |
Payment | For an online casino with Swish: deposits, withdrawals, payment requests, payment confirmations and transaction references | Payments, ownership and fraud checks |
Gameplay | Games, stakes, wins/losses, sessions | Settlement, history and duty of care |
Compliance | KYC documents, source of funds, risk assessments | AML, fraud and regulatory checks |
Device | IP address, device/browser data, security logs | Security and service reliability |
Communications | Support messages, complaints, requests, marketing preferences | Support, requests and preferences |
Identity |
|---|
| Examples |
| Name, address, personal ID, date of birth, e-ID |
| Primary use |
| Age, identity and account verification |
Account |
|---|
| Examples |
| Account ID, settings, limits, self-exclusion, bonus status |
| Primary use |
| Account operation and player controls |
Payment |
|---|
| Examples |
| For an online casino with Swish: deposits, withdrawals, payment requests, payment confirmations and transaction references |
| Primary use |
| Payments, ownership and fraud checks |
Gameplay |
|---|
| Examples |
| Games, stakes, wins/losses, sessions |
| Primary use |
| Settlement, history and duty of care |
Compliance |
|---|
| Examples |
| KYC documents, source of funds, risk assessments |
| Primary use |
| AML, fraud and regulatory checks |
Device |
|---|
| Examples |
| IP address, device/browser data, security logs |
| Primary use |
| Security and service reliability |
Communications |
|---|
| Examples |
| Support messages, complaints, requests, marketing preferences |
| Primary use |
| Support, requests and preferences |
The table shows the main categories; the actual processing depends on which functions and checks are used.
A Swish casino online processes personal data to operate the gambling account, provide requested services, keep the platform secure and meet Swedish and EU legal obligations.
The main purposes are:
Personal data is processed for defined purposes and under the legal basis that applies to each type of processing.
For a casino online Swish service, processing can rely on performance of a contract, compliance with legal obligations, legitimate interests where your rights do not override those interests, or consent where Swedish or EU rules require it.
Optional marketing, analytics and non-essential cookies use the legal basis required for the relevant processing.
For the payment journey, payment data can be processed alongside BankID verification. The payment service and BankID remain separate services with their own personal-data processing.
Other recipients or processors can include:
For payment data, a provider receives only the information needed for its role, subject to the applicable contract and legal requirements.
For an online casino with Swish, personal data can be disclosed to Spelinspektionen, law-enforcement bodies, tax authorities, financial-intelligence authorities, courts or other competent bodies where disclosure is required or permitted by law.
Records can also be retained or disclosed where needed to establish, exercise or defend legal claims.
Where personal data is processed outside the EEA, an applicable GDPR transfer mechanism is used when required, such as an adequacy decision or approved contractual safeguards. The published policy must reflect the actual supplier arrangements.
Data retention keeps personal data only as long as needed for the purpose for which it was collected or for a period required by gambling, anti-money-laundering, accounting, tax, consumer or other applicable law.
Retention periods can differ by data category.
Retention schedule:
At a Swish casino online, where a legal retention requirement prevents deletion, the data is restricted to the permitted purpose and removed or anonymised when the obligation ends where appropriate.
Your GDPR rights may include the right to:
These rights are not absolute. Gambling, anti-money-laundering or other legal obligations can require certain records to be kept or used even after an account is closed.
To exercise a right, contact [CLIENT TO CONFIRM: privacy contact]. We may need to verify your identity before acting on the request.
At an online casino with Swish, self-exclusion data is used to enforce exclusions, prevent prohibited access and meet responsible-gambling obligations.
Licensed operators must check Spelpaus.se before allowing gambling where the register applies. A Spelpaus exclusion also affects direct gambling marketing from licensed operators during the exclusion period.
Self-exclusion information is not used to encourage gambling.
Cookies and similar technologies can be used for:
Analytics, personalisation or marketing technologies that are not strictly necessary should be used only in line with the implemented consent setup and applicable Swedish and EU rules.
Cookie categories, purposes, providers and retention periods:
Gambling marketing to Swedish consumers must follow applicable moderation and targeting rules. Direct gambling marketing is not sent to excluded players where the law prohibits it.
For a casino online Swish service, marketing preferences include unsubscribe or preference controls for permitted marketing messages.
Data security relies on technical and organisational measures to protect personal data against unauthorised access, loss, alteration or disclosure.
Measures can include access controls, logging, encryption or pseudonymisation where appropriate, supplier controls and monitoring for suspicious activity.
No system can guarantee absolute security. Personal-data incidents are assessed and handled under applicable GDPR notification requirements.
The service is not intended for people under 18. Identity and age checks form part of account registration, and minors are not permitted to gamble.
Privacy questions and complaints should first be sent to privacy@swishcasino.se so the matter can be reviewed.
You also have the right to lodge a complaint with Integritetsskyddsmyndigheten (IMY), the Swedish Authority for Privacy Protection, where applicable.
This online casino Swish privacy policy can be updated when services, suppliers, legal requirements or personal-data processing change.
The published version shows the effective date and material changes are communicated where required.
Effective date: 1 December 2025