1. Introduction
This Privacy Policy sets out how Grand Casino Dunedin collects, holds, uses, and discloses personal information about individuals who access the services or interact with the casino in any capacity. It applies to all personal information handled in connection with casino and betting operations.
This document is intended to be read alongside the Information Privacy Principles contained in the Privacy Act 2020, which is the primary legislation governing the collection and handling of personal information in New Zealand. By using the services or providing personal information to Grand Casino Dunedin, you acknowledge that you have read and understood this policy.
Handling of personal information is carried out in a manner that is lawful, transparent, and consistent with obligations under New Zealand law, including the Privacy Act 2020, the Gambling Act 2003, the Anti-Money Laundering and Countering Financing of Terrorism Act 2009 (AML/CFT Act), and applicable regulations administered by the Department of Internal Affairs (DIA).
2. What Personal Information Is Collected
Grand Casino Dunedin collects personal information that is necessary to provide services, meet legal obligations, and comply with regulatory requirements. The categories of personal information that may be collected include:
- Full legal name
- Date of birth
- Physical address
- Occupation
- Government-issued identification details
- Contact information, including email address and phone number
- Information about the nature and purpose of your relationship with the casino
- Account activity and transaction records
- Location data where required for access verification purposes
Only information that is necessary for the purposes described in this policy is collected. Personal information is not collected beyond what is required by law or reasonably necessary to provide services.
3. How Personal Information Is Collected
Personal information is generally collected directly from you when you register an account, complete identity verification, contact support, or otherwise interact with the services.
In some cases, personal information may be collected from third parties where permitted by law, such as from identity verification services, credit and fraud checking agencies, or regulatory bodies.
Technical information may also be collected through automated means, including access logs and authentication records, where required for security, compliance, or fraud prevention purposes.
4. Why Personal Information Is Collected
4.1 Legal and Regulatory Obligations
A significant portion of the personal information collected is required by law. Under the AML/CFT Act 2009, customer due diligence and identity verification must be conducted. This requires the collection and verification of your full name, date of birth, physical address, occupation, and information about the nature and purpose of your relationship with Grand Casino Dunedin. These obligations exist independently of any commercial relationship and cannot be waived.
Under the Online Casino Gambling Act 2026 and associated Minimum Standards, licensed operators must collect and retain specified customer information for the duration of their licence and for a period of seven years following licence expiry, cancellation, or surrender.
4.2 Service Delivery
Personal information is used to manage accounts, process transactions, verify identity, and ensure that services are provided in accordance with applicable law and internal policies.
4.3 Harm Minimisation and Responsible Gambling
Personal information may be used in connection with harm minimisation obligations, including identifying patterns of behaviour that may indicate problem gambling and facilitating access to problem gambling support services where appropriate.
5. How Personal Information Is Held and Protected
Grand Casino Dunedin holds personal information on secure systems with restricted access. Technical and organisational measures are in place to protect personal information against unauthorised access, disclosure, alteration, or loss. These measures include:
- Encryption of data in transit and at rest
- Access controls aligned with recognised information security standards
- Multi-factor authentication for sensitive account activities such as login, registration of new payment methods, and password resets
Personal information is retained for as long as it is required for the purposes for which it was collected, or as required by law. When personal information is no longer required, it is disposed of securely.
6. Disclosure of Personal Information
Grand Casino Dunedin treats personal information as confidential. Personal information is not used or shared except in the following circumstances:
- Where you have consented to the disclosure
- Where disclosure is necessary to provide services to you
- Where disclosure is required or authorised by law
Personal information may be disclosed to the following recipients:
- Department of Internal Affairs - for regulatory and licensing obligations under gambling legislation
- New Zealand Police - where there is a legal obligation or lawful request
- Other casinos and gaming businesses - where you are a patron subject to an exclusion order
- Problem gambling service providers - on your request, in connection with harm minimisation
- Government agencies with legal authority - where compelled by statute or court order
Personal information is not sold to third parties. Personal information is not used for direct marketing without your consent.
7. Overseas Disclosure
In some circumstances, personal information may be processed or stored by service providers located outside New Zealand. Where this occurs, reasonable steps are taken to ensure that overseas recipients handle personal information in a manner consistent with the Privacy Act 2020. The relevant countries will be identified in account documentation or provided on request.
8. Your Rights
Under the Privacy Act 2020, you have the right to:
- Request access to personal information held about you
- Request correction of personal information that is inaccurate, incomplete, or misleading
- Make a complaint if you believe there has been a breach of the Information Privacy Principles
To exercise any of these rights, contact Grand Casino Dunedin using the details provided in section 10 of this policy. Access and correction requests will be responded to within the timeframes required by law.
9. Data Breaches
In the event of a privacy breach that is likely to cause serious harm, the Office of the Privacy Commissioner and affected individuals will be notified in accordance with obligations under the Privacy Act 2020. Internal procedures are maintained for identifying, assessing, and responding to privacy breaches.
10. Contact and Complaints
Questions about this policy, requests to access or correct personal information, or complaints about how Grand Casino Dunedin has handled personal information can be directed to the company using the contact details published on the official website or provided in account documentation.
If you are not satisfied with the response to a complaint, the matter may be referred to the Office of the Privacy Commissioner, which is the independent authority responsible for overseeing compliance with the Privacy Act 2020 in New Zealand.
For complaints relating to gambling regulation and licensing matters, the Department of Internal Affairs is the relevant regulatory authority. The DIA can be contacted via [email protected] for matters relating to online casino providers.
11. Changes to This Policy
This Privacy Policy may be updated from time to time to reflect changes in law, regulation, or internal practices. The current version of this policy is available on the website. You are encouraged to review this policy periodically. Continued use of the services following any update constitutes acknowledgement of the revised policy.