Data Privacy · Republic Act No. 10173 · Effective 1 January 2026
ggpa Casino
Privacy Policy
ggpa Casino is committed to protecting the personal data of every Filipino player on our platform. This Privacy Policy explains exactly what information we collect, why we collect it, how we use and store it, who we share it with, and — most importantly — what rights you have over your own data under Philippine law.
Six Things ggpa Commits to on Privacy
These are ggpa's core privacy commitments to Filipino players. The complete legal text follows in the detailed sections below.
We Collect Only What We Need
ggpa collects personal data strictly limited to what is necessary for account operation, identity verification, payment processing, and compliance with PAGCOR and Anti-Money Laundering regulations. We do not harvest data speculatively.
Your Data Is Encrypted and Secured
All personal data transmitted between your device and ggpa's servers is protected by 256-bit SSL/TLS encryption — the same standard used by Philippine banks. Stored data is encrypted at rest and access-controlled by role-based permissions.
We Do Not Sell Your Data
ggpa does not sell, rent, or trade your personal data to third-party marketers or data brokers. Data is shared only with the service partners required to operate the ggpa platform — payment processors, KYC providers, and game studios — under strict data processing agreements.
You Control Your Data
As a Philippine data subject under RA 10173, you have the right to access, correct, delete, restrict, and object to the processing of your personal data held by ggpa. All rights requests are processed within the legally mandated timeframe.
Data Is Retained Only as Long as Needed
ggpa retains personal data only for as long as your account is active and for the legally required periods after closure — typically five years for AML and PAGCOR reporting compliance. Data beyond the retention period is securely deleted or anonymised.
We Notify You of Breaches
In the unlikely event of a personal data breach, ggpa will notify affected Players and the National Privacy Commission (NPC) within 72 hours of confirmed discovery, in full compliance with the Data Privacy Act's breach notification requirements.
Contents
- 1. Introduction & Scope
- 2. Data Controller
- 3. Data We Collect
- 4. Legal Basis for Processing
- 5. How We Use Your Data
- 6. Cookies & Tracking
- 7. Data Sharing
- 8. International Transfers
- 9. Data Retention
- 10. Your Rights (RA 10173)
- 11. Data Security
- 12. Children & Minors
- 13. Breach Notification
- 14. Third-Party Links
- 15. Policy Updates
- 16. Contact & DPO
This Privacy Policy is issued by ggpa Casino ("ggpa," "we," "us," "our") and applies to all personal data collected from individuals who access or use the ggpa platform at ggpa.cam, including registered account holders, visitors who browse the site without registering, and individuals who contact ggpa through any support channel.
ggpa operates as an online casino and sports betting platform serving Filipino players under PAGCOR oversight. The collection and processing of personal data is an operational necessity — we cannot verify player identity, process financial transactions, comply with AML obligations, or maintain responsible gaming controls without processing certain categories of personal information.
This Privacy Policy is intended to fulfil ggpa's disclosure obligations under Republic Act No. 10173, the Data Privacy Act of 2012 (DPA), and its implementing rules and regulations as enforced by the National Privacy Commission (NPC). It should be read together with ggpa's Terms & Conditions and Responsible Gaming Policy.
For the purposes of the Data Privacy Act of 2012, ggpa Casino is the personal information controller in respect of the personal data processed on the ggpa platform. ggpa determines the purposes and means of processing your personal data and is responsible for ensuring that such processing complies with applicable Philippine data protection law.
ggpa has appointed a Data Protection Officer (DPO) responsible for overseeing compliance with the DPA, handling data subject rights requests, and acting as the primary point of contact with the National Privacy Commission. The DPO may be contacted at the address provided in Section 16 of this policy.
ggpa collects personal data across three categories depending on how you interact with the platform:
| Category | Data Types | Collection Method |
|---|---|---|
| Identity Data | Full legal name, date of birth, nationality, government-issued ID type and number (e.g. PhilSys, passport, driver's licence) | Registration form; KYC document submission |
| Contact Data | Email address, mobile phone number, residential address (city/province) | Registration form; account settings updates |
| Financial Data | GCash number, PayMaya number, bank account name and number (BPI/BDO/Metrobank), USDT wallet address, deposit/withdrawal transaction records | Payment processing; transaction logs |
| Gaming Activity Data | Games played, bet amounts, win/loss records, session durations, bonus usage, sports bets placed, poker hand histories | Platform activity logs (automatic) |
| Technical Data | IP address, device type and OS, browser type, session token, login timestamps, geolocation (country/city level) | Server logs; browser cookies (automatic) |
| Communications Data | Live chat transcripts, email correspondence, support ticket content | Customer support interactions |
ggpa does not collect sensitive personal information as defined under RA 10173 (e.g., health data, political opinions, religious beliefs) unless such information is voluntarily disclosed by a Player in the context of a responsible gaming or self-exclusion request, in which case it is treated with the heightened protection applicable to sensitive data under the DPA.
ggpa processes personal data only where a valid legal basis under Section 12 or Section 13 of the Data Privacy Act applies. The specific legal bases relied upon for ggpa's principal processing activities are as follows:
- Contractual Necessity: Processing required to create and manage your ggpa account, process deposits and withdrawals, provide access to games and promotional features, and operate the platform you have contracted to use.
- Legal Obligation: Processing required to comply with PAGCOR licensing conditions, Anti-Money Laundering Act (AMLA) reporting obligations, Bureau of Internal Revenue requirements, and orders from competent courts or law enforcement agencies.
- Legitimate Interest: Processing for fraud prevention, platform security, abuse detection, and improving the ggpa user experience — where those interests are not overridden by your privacy rights as a data subject.
- Consent: Processing for direct marketing communications (promotional emails, push notifications) where you have given explicit, freely-given, informed consent. You may withdraw this consent at any time through Account Settings or by contacting ggpa support.
ggpa uses personal data for the following specific purposes:
- Creating and maintaining your ggpa account, including verifying your identity and age at registration and at first withdrawal.
- Processing and reconciling deposits and withdrawals via GCash, PayMaya, BPI, BDO, Metrobank, and USDT.
- Detecting and preventing fraud, money laundering, collusion, bonus abuse, and unauthorised account access.
- Complying with PAGCOR's responsible gaming requirements, including enforcing self-exclusion orders and deposit limits you have activated.
- Providing customer support through live chat and email, and maintaining records of support interactions for quality assurance.
- Sending you transactional communications — deposit confirmations, withdrawal notifications, account security alerts — that are necessary regardless of marketing preferences.
- Sending you promotional communications — bonus offers, free spin alerts, VIP tier updates — where you have opted in to marketing.
- Generating anonymised aggregate analytics to improve platform performance, game selection, and user experience.
- Meeting ggpa's AML reporting obligations to PAGCOR and the Anti-Money Laundering Council (AMLC) where transactions trigger mandatory reporting thresholds.
ggpa.cam uses cookies and similar tracking technologies to operate the platform correctly and to improve the player experience. The following categories of cookies are used:
- Strictly Necessary Cookies: Required for the platform to function — session authentication, secure login state, CSRF protection tokens, and load balancing. These cannot be disabled without breaking core platform functionality.
- Functional Cookies: Remember your preferences such as language settings, last-played game category, and notification preferences across sessions.
- Analytics Cookies: Collect anonymised aggregate data about how players navigate the platform — page visits, session lengths, game category preferences — to improve the ggpa experience. No personally identifiable data is included in analytics reports.
- Security Cookies: Support ggpa's fraud detection and bot prevention systems by recording login device fingerprints and IP addresses associated with account sessions.
ggpa does not use third-party advertising or social media tracking cookies. You may manage cookie preferences through your browser settings. Note that disabling strictly necessary cookies will impair your ability to log in and use the ggpa platform.
ggpa shares personal data only with the categories of third parties listed below, each bound by data processing agreements that require them to maintain confidentiality and process data solely for the specified purposes:
- Payment Processors: GCash (Mynt), PayMaya (Voyager Innovations), and Philippine banking institutions (BPI, BDO, Metrobank) — to process deposits and withdrawals. Financial data is shared only to the extent required to complete the specific transaction.
- KYC Verification Providers: Third-party identity verification services used to authenticate government-issued IDs against national registries as required under PAGCOR and AMLA regulations.
- Game Studio Providers: Licensed game providers (such as JILI, Pragmatic Play, PG Soft) receive anonymised player session tokens necessary to load and operate their game software within the ggpa platform. No personally identifiable data is passed to game providers.
- Cloud Infrastructure: ggpa's platform is hosted on enterprise-grade cloud infrastructure. Server providers process technical data (logs, session data) under data processing agreements as sub-processors.
- Regulatory Authorities: PAGCOR, the Anti-Money Laundering Council (AMLC), the National Privacy Commission (NPC), and law enforcement agencies where disclosure is required by law, court order, or legitimate regulatory request.
The majority of ggpa's data processing takes place within the Philippines. Where personal data is transferred to service providers operating data centres outside the Philippines — for example, globally distributed cloud infrastructure or international game studio providers — ggpa ensures that such transfers comply with Section 21 of the Data Privacy Act, which requires adequate data protection safeguards equivalent to those provided by Philippine law.
ggpa implements appropriate safeguards for international transfers through standard contractual clauses, data processing agreements, and assessment of the receiving country's data protection framework. Players who have concerns about international data transfers may contact ggpa's Data Protection Officer for details of the specific safeguards applicable to their data.
ggpa retains personal data for as long as necessary to fulfil the purposes for which it was collected and to comply with applicable legal obligations. The following retention periods apply:
| Data Category | Retention Period | Basis |
|---|---|---|
| Account & identity data | Duration of account + 5 years after closure | PAGCOR & AMLA compliance |
| Financial transaction records | 5 years from transaction date | AMLA; BIR requirements |
| KYC documents | 5 years after account closure | PAGCOR licensing obligations |
| Gaming activity logs | 3 years from date of each session | PAGCOR audit requirements |
| Customer support records | 3 years from last interaction | Dispute resolution; legitimate interest |
| Technical / server logs | 12 months rolling | Security monitoring; fraud detection |
| Marketing consent records | Duration of consent + 3 years | Proof of lawful processing |
Upon expiry of the applicable retention period, personal data is either permanently deleted from ggpa's systems or irreversibly anonymised so that it can no longer be linked to an identifiable individual. Anonymised data may be retained indefinitely for statistical and analytical purposes.
As a data subject under the Data Privacy Act of 2012, you have the following rights in relation to your personal data held by ggpa. ggpa will respond to all valid rights requests within fifteen (15) calendar days of receipt, or within such extended period as permitted under the DPA where the complexity of the request requires additional processing time.
Right to be Informed
The right to know that your personal data is being collected and processed, the purpose of processing, and your rights as a data subject — fulfilled by this Privacy Policy.
Right to Access
The right to obtain a copy of your personal data held by ggpa, including information on how it has been processed and with whom it has been shared.
Right to Rectification
The right to have inaccurate or incomplete personal data corrected. For most data, this can be done directly in Account Settings. Corrections to KYC documents require submission to ggpa support.
Right to Erasure
The right to request deletion of your personal data where it is no longer necessary for the purpose it was collected, subject to ggpa's overriding legal retention obligations under PAGCOR and AMLA.
Right to Object
The right to object to processing based on legitimate interest, including direct marketing. Marketing objections are honoured immediately upon request.
Right to Restriction
The right to request that ggpa restricts processing of your data in certain circumstances — for example, while a rectification request is being assessed.
Right to Data Portability
The right to receive your personal data in a structured, commonly used, machine-readable format and to have it transmitted to another controller where technically feasible.
Right to Damages
The right to be compensated for damages sustained from inaccurate, incomplete, outdated, false, unlawfully obtained, or unauthorised use of your personal data.
To exercise any of the above rights, submit a written request to ggpa's Data Protection Officer at [email protected] with the subject line "Data Subject Rights Request." You will be asked to verify your identity before the request is processed. If you are unsatisfied with ggpa's response, you have the right to lodge a complaint with the National Privacy Commission at privacy.gov.ph.
ggpa implements technical and organisational security measures proportionate to the nature and sensitivity of the personal data processed. Current security measures include:
- 256-bit SSL/TLS encryption for all data in transit between Players' devices and ggpa's servers.
- Encryption of sensitive stored data, including financial data, identity documents, and authentication credentials.
- Role-based access controls ensuring that ggpa staff can only access personal data necessary for their specific operational function.
- Two-factor authentication (2FA) required for all ggpa staff accounts with access to production systems handling personal data.
- Regular third-party penetration testing and security audits of ggpa's infrastructure.
- Intrusion detection systems and 24/7 security monitoring of platform infrastructure.
- Staff data protection training conducted annually and upon onboarding, covering RA 10173 obligations and ggpa's internal data handling procedures.
While ggpa takes all reasonable technical and organisational precautions, no internet-based platform can guarantee absolute security. Players are encouraged to maintain strong, unique passwords for their ggpa account and to activate 2FA through Account Settings.
ggpa Casino is strictly prohibited from accepting registrations from individuals under 21 years of age. ggpa does not knowingly collect, store, or process the personal data of minors. Age verification is a mandatory step in the ggpa registration process, and KYC verification confirms date of birth against a government-issued ID before any withdrawal is permitted.
In the event of a personal data breach that is likely to result in risk to the rights and freedoms of affected Players, ggpa will:
- Notify the National Privacy Commission (NPC) within 72 hours of confirming the breach, as required under NPC Circular No. 16-03 and the Data Privacy Act.
- Notify affected data subjects without undue delay, providing clear information about the nature of the breach, the categories of data involved, the likely consequences, and the measures ggpa has taken or proposes to take to address the breach.
- Maintain a record of all data breaches, including those not required to be reported to the NPC, as required under RA 10173's accountability provisions.
Breach notifications to Players will be sent to the email address registered to the affected ggpa account. ggpa strongly recommends that Players ensure their registered email address is current and accessible.
ggpa.cam may contain links to or integrations with third-party services — including payment providers such as GCash and PayMaya, and game studios accessed through ggpa's lobby. Once you navigate to or interact with a third-party service, ggpa's Privacy Policy no longer applies. Third-party services operate under their own privacy policies, which ggpa does not control.
ggpa recommends that Players review the privacy policies of any third-party service they interact with through or alongside the ggpa platform. ggpa is not liable for the data practices of third-party services.
ggpa may update this Privacy Policy from time to time to reflect changes in our data processing practices, applicable law, or PAGCOR regulatory requirements. The updated effective date will be shown at the top of this page.
For material changes — those that significantly affect how ggpa processes your personal data or your rights as a data subject — ggpa will provide at least seven (7) days' advance notice to registered Players via the email address on their account, alongside a notice on the ggpa platform homepage.
Continued use of the ggpa platform following the effective date of a policy update constitutes your acknowledgment of the revised Privacy Policy. If you do not agree with the updated policy, you should close your ggpa account before the effective date.
For questions, concerns, or formal requests relating to this Privacy Policy or ggpa's processing of your personal data, please contact ggpa's Data Protection Officer through the following channels:
- Email (DPO / Privacy Matters): [email protected] — use the subject line "Privacy / DPO Request" for all data subject rights requests and privacy complaints. Responses within 15 calendar days.
- Live Chat (General Privacy Queries): Available 24/7 on ggpa.cam for general privacy questions. For formal rights requests requiring identity verification, email is the required channel.
- National Privacy Commission (NPC): If you are unsatisfied with ggpa's response to a privacy complaint, you have the right to file a complaint with the NPC. The NPC is the Philippine government body responsible for enforcing RA 10173. Contact details are published on the NPC's official government website.
ggpa is committed to resolving all privacy concerns raised by Filipino players promptly, transparently, and in full compliance with the Data Privacy Act and its implementing rules. We take every data subject rights request seriously and treat privacy complaints with the same priority as financial disputes.
Back to TopYour Data Is Safe at ggpa Casino
PAGCOR regulated, DPA compliant, and built with Filipino players' privacy at the core. Explore ggpa Casino — 600+ games, instant GCash payouts, and a platform that respects your data as much as your time.