What Happens to My Personal Documents If a Casino Gets Blocked in India?

What Happens to My Personal Documents If a Casino Gets Blocked in India

The question almost every Indian casino player should be asking is the one most are not: when a site disappears from the Indian internet, what happens to everything you handed over to access it?

The blocking wave that swept across India from October 2025 through January 2026 removed more than 7,800 gambling-related websites from accessible Indian internet. For every site on that list, there were players who had submitted their Aadhaar cards, PAN cards, address proofs and face photographs to complete KYC verification before making withdrawals. Those documents did not disappear when the site did. They are still somewhere. This guide explains where, what the risks genuinely are and what you can do about it starting today.

What Blocking a Casino Site Actually Means?

Most players imagine that when the government blocks a website, something decisive and comprehensive happens. The reality is considerably narrower than that and understanding the gap is important for understanding why your data may still be at risk.

What the government did and what it did not do?

Under Section 14 of the Promotion and Regulation of Online Gaming Act 2025, the government has the authority to direct internet service providers and app stores to block access to gambling platforms. This is the same kind of block used for other banned content under the Information Technology Act. ISPs in India receive instructions to prevent their customers from reaching those URLs or IP addresses.

That is the extent of the action. The government did not seize the casino’s servers. It did not issue a data deletion order. It did not freeze the company’s ability to operate in other markets. It did not contact the licensing authority in Curaçao or Malta and request that player data be protected or destroyed. The Indian blocking order simply means that someone trying to access the site from an Indian IP address will get an error. The site itself continues to function normally for users in every other country.

Where are your documents right now?

Your KYC documents are stored on the casino’s servers, which are hosted in whatever jurisdiction the operator is based. Most offshore casinos accepting Indian players are registered in Curaçao, Malta, Gibraltar, or Cyprus. Their servers may be hosted on cloud infrastructure in Europe, the United States, or Southeast Asia.

Before the blocking order, those servers were accessible to Indian users. After the blocking order, they are still running, still holding the same data, still under the same security practices or lack thereof. The only thing that changed is that Indian residents cannot reach the website’s front end. The database behind that front end is entirely unchanged.

The data protection gap in PROGA 2025

This is the gap that privacy advocates and consumer groups have pointed to since the blocking campaign began. The legal framework for blocking gambling sites and the legal framework for protecting the personal data of Indian citizens are two entirely separate systems. PROGA authorises access blocking. India’s Digital Personal Data Protection Act 2023 governs data rights. These two laws do not automatically interact.

When a site is blocked under PROGA, no corresponding obligation is automatically triggered under the DPDP Act requiring the operator to delete Indian player data. A player whose data is held by a blocked offshore casino occupies a genuinely awkward legal position: they are protected in theory by data rights legislation but have no immediate enforcement mechanism against a foreign company that is now largely cut off from the Indian market.

What Are the Real Risks to Your Data?

Acknowledging the data protection gap is not the same as saying your data is definitely being misused. The risk exists on a spectrum and it is worth being honest about where on that spectrum most blocked casino situations actually fall.

Three categories of risk, honestly assessed

Risk category Likelihood What it means in practice
Operator actively misusing your data Low to moderate Most casino operators are businesses seeking profit from gaming, not from document fraud. Deliberate misuse by the operator is less common than negligent data storage.
Third-party breach of unprotected database Moderate A casino that has lost its main Indian market may reduce IT security investment. Poorly maintained databases are more vulnerable to external breaches.
Data sold or traded without your consent Low to moderate Data brokers do purchase and trade KYC datasets in underground markets. This is more common at scale than targeted individual misuse.

What Indian fraud statistics tell us?

India’s experience with data-driven fraud is not theoretical. Cyber fraud losses in India surged by 206 percent between 2023 and 2024, rising from approximately Rs 7,465 crore to Rs 22,845 crore in a single year, according to data provided by the Ministry of Home Affairs. The Indian Cyber Crime Coordination Centre projected that losses could reach Rs 1.2 lakh crore in 2025.

The most common fraud patterns linked to leaked identity data in India include SIM card activation using stolen Aadhaar details, digital arrest scams where fraudsters use real personal data to convince victims their Aadhaar was linked to criminal activity, eKYC-based loan fraud through digital NBFCs and mule bank account creation. In the Bengaluru fraud ring exposed in 2025, criminals obtained real Aadhaar details and used AI tools to create over 200 synthetic identities for financial fraud.

In October 2023, cybersecurity firm Resecurity discovered that the personal information of approximately 815 million Indian citizens, including Aadhaar and passport details, was being offered for sale on dark web forums. The leaked dataset included names, addresses, phone numbers and Aadhaar card details. The incident highlighted both the scale of India’s data exposure problem and the active criminal market for this information.

The specific combination that creates the highest risk

Individual documents carry different risk profiles. Your Aadhaar number alone, without biometric authentication, is limited in what it enables. Your PAN number alone requires additional authentication for most financial fraud. But the combination that most casino KYC processes collect together: your full Aadhaar scan, your PAN card and a clear selfie of your face holding the document, is the exact package that enables the most dangerous forms of identity fraud in India’s current eKYC-heavy financial ecosystem.

That combination is sufficient for attempting biometric eKYC-based loan applications at digital lenders that still rely primarily on document verification and image matching rather than live biometric confirmation. It is also sufficient for SIM activation, mule account creation and in the hands of technically capable fraudsters, synthetic identity construction.

The biometric lock, described in detail in Section 4, addresses this risk directly. It does not protect the documents themselves, but it breaks the authentication chain that makes the most dangerous misuse possible.

Your Legal Rights Under the DPDP Act 2023

India’s Digital Personal Data Protection Act 2023 is the primary legal framework that addresses your rights regarding personal data held by any entity, including offshore companies. Understanding what it actually gives you and where its practical limits are, matters for deciding how to respond.

What does the Act say about extraterritorial scope?

Section 3(b) of the DPDP Act gives the law extraterritorial reach. It covers the processing of personal data of Indian data principals regardless of where that processing occurs. This means that an offshore casino holding your Aadhaar and PAN data is, in principle, subject to India’s data protection obligations, even though its servers are in a foreign country.

This mirrors how the European Union’s GDPR works. GDPR applies to any entity processing EU citizen data regardless of where the company is based. India’s DPDP Act uses a similar construction, extending its reach beyond India’s geographic borders to protect Indian citizens’ data wherever it sits.

Your right to erasure explained

Section 12 of the DPDP Act gives you the right to request deletion of your personal data from any entity holding it. This right applies when the original purpose for which the data was collected no longer exists, or when you withdraw your consent for the data to be held.

A blocked casino that is no longer serving Indian players can reasonably be argued to no longer have a legitimate purpose for retaining your KYC documents. You deposited and withdrew funds. The KYC purpose was served. The site no longer operates in your jurisdiction. Requesting deletion on these grounds is legally coherent under the Act.

How to send a data deletion request?

Write a formal email to the casino’s official support or data protection contact address. Include the following: your registered account email, the documents you submitted, the date of submission and this specific phrase: I am exercising my right to erasure under India’s Digital Personal Data Protection Act 2023 and, where applicable, the EU General Data Protection Regulation. I request deletion of all personal data including identity documents held in connection with my account.

Send it, save the sent copy with a timestamp and follow up in 30 days if you receive no response. The paper trail is what matters most.

The honest gap between legal rights and practical enforcement

Having a legal right and being able to enforce it are not the same thing. India’s Data Protection Board, which was established under the DPDP Act to handle complaints and enforcement, is still building its operational capacity. Enforcement against a foreign company whose website is already blocked in India requires cross-border regulatory cooperation that takes months to years to produce any outcome.

What this means practically is that your deletion request is very unlikely to produce immediate compliance from an operator who has already walked away from the Indian market. The value of the request is not in the immediate outcome. It is in the documented evidence that you took action to protect your data, which matters if fraud attributable to that data surfaces later in a credit dispute, an FIR filing, or a regulatory complaint.

Legal and technical protections work in parallel, not as substitutes. The technical steps described in the next section are available to you right now, at no cost and protect you regardless of what the casino does with your deletion request.

The Six Protective Steps to Take Right Now

These steps are listed in order of urgency. The first two take under five minutes combined and provide the most immediate protection.

1. Lock your Aadhaar biometrics

This is the single most impactful action available to you. UIDAI allows you to lock the biometric component of your Aadhaar, which means no one can use your fingerprint or iris scan for Aadhaar authentication while the lock is active. This directly blocks eKYC-based loan fraud, which requires biometric confirmation in addition to your Aadhaar number.

How to lock your Aadhaar biometrics?

  1. Visit myaadhaar.uidai.gov.in
  2. Log in with your registered mobile number and OTP.
  3. Navigate to My Aadhaar, then Aadhaar Services, then Biometric Settings.
  4. Enable the biometric lock then the process takes under two minutes.

You can temporarily unlock it when you need biometric authentication somewhere, such as a bank branch or government office and re-lock immediately after. The lock and unlock process is available 24 hours a day.

2. Check Sanchar Saathi for unauthorised SIM cards

The government’s Sanchar Saathi portal at sancharsaathi.gov.in allows you to see every mobile number registered under your identity documents. Criminals with access to Aadhaar data have been documented activating SIM cards in victims’ names through corrupt telecom officials or exploiting verification gaps. Those SIM cards are then used to intercept OTPs, run scam calls and open mule accounts.

Log into Sanchar Saathi and check the full list of numbers registered under your Aadhaar. Any number you did not personally register should be reported for deactivation immediately through the portal’s reporting function. The deactivation process typically takes three to seven business days.

3. Pull your credit reports from all four bureaus

Check your credit report on CIBIL, Experian, CRIF and Equifax. Each bureau maintains independent records. A loan taken in your name at a lender that reports to Experian but not CIBIL will show on Experian but not on CIBIL alone. Checking all four covers you comprehensively.

What to look for: any loan account, credit card, or line of credit you did not apply for and any hard inquiry you did not authorise. A hard inquiry means someone ran a credit check in your name as a precursor to a loan application. If you find either, raise a dispute with the relevant bureau immediately and consider filing an FIR with the cybercrime cell.

4. Enable mAadhaar authentication alerts

The mAadhaar app, available on both Android and iOS, can be configured to send you a notification every time your Aadhaar number is used for authentication anywhere. This gives you real-time visibility without requiring you to manually check anything. If someone attempts to use your Aadhaar for eKYC at a lender and the biometric lock is not active, or if they attempt other forms of Aadhaar-based authentication, you receive an immediate alert.

5. Send a formal data deletion request to the casino

Using the template described in Section 3, send a written email to the casino’s official support or data protection contact. Cite the DPDP Act 2023 explicitly. Keep a timestamped copy of the email. Follow up in 30 days if you receive no acknowledgment.

Some offshore operators, particularly those licensed in Malta or Gibraltar under more demanding regulatory frameworks, have data protection officers and formal deletion processes that they take seriously even after a market exit. Others will not respond. Both outcomes are worth documenting.

6. Monitor your Income Tax portal

Log into the Income Tax e-filing portal at incometax.gov.in and check whether any new entities, returns, or unusual activity appear under your PAN number. PAN misuse for shell company registration sometimes surfaces here before anywhere else. A company registered in your name without your knowledge is one of the more damaging forms of PAN fraud because it creates tax liabilities that can take years to resolve.

Checking once is useful. Checking quarterly for the first year after submitting documents to a now-blocked casino is better practice.

FAQs

1. Does the government delete casino data when they block a site?

No. The government’s blocking action under PROGA 2025 is an access block, meaning Indian ISPs are instructed to prevent their customers from reaching the site’s URLs. The blocking order has no component that requires the casino operator to delete, return, or protect the data they already collected. The casino’s servers continue to run normally in their host country.

2. Can I find out whether my data has already been misused?

There is no single portal that shows whether your personal data has been used fraudulently. The closest you can get is a combination of monitoring tools. Sanchar Saathi shows SIMs under your Aadhaar. Credit bureau reports show loan inquiries and accounts. Your Income Tax portal shows entities linked to your PAN. The mAadhaar app shows authentication events. Used together, these cover the main channels through which Aadhaar and PAN fraud manifests.

3. What if the casino does not respond to my deletion request?

A lack of response is the most common outcome, particularly from operators who have exited the Indian market. Keep the timestamped copy of your sent email regardless. If fraud attributable to that data surfaces later, you have documented that you took action to exercise your rights. You can also lodge a complaint with India’s Data Protection Board once it is fully operational, referencing the deletion request and the lack of response.

4. My blocked casino was licensed in Malta. Is my data more protected than with a Curaçao-licensed site?

Generally yes. The Malta Gaming Authority operates under European Union law, which means the casino is subject to GDPR in addition to Indian data protection obligations. GDPR imposes strict data security standards and deletion obligations. Operators licensed in Malta have more regulatory accountability and more practical enforcement risk if they mishandle personal data. Curaçao-licensed sites operate under a much lighter regulatory framework and have minimal data security obligations that can be enforced from outside Curaçao.

5. Should I file a police complaint if I find an unauthorised SIM or loan in my name?

Yes, immediately. An unauthorised SIM registered under your Aadhaar should be reported both through Sanchar Saathi for deactivation and to your local cybercrime cell with documentation. An unknown loan account on your credit report should be disputed with the bureau and also reported to your local cybercrime police station. The I4C cybercrime reporting portal at cybercrime.gov.in accepts online complaints. File them promptly because these records matter for any subsequent investigation.

6. If I never submitted KYC to the blocked casino, is my data at risk?

If you only registered an account but never submitted identity documents, your risk is considerably lower. The data the casino holds may include your email address, phone number, IP address and financial transaction records, but not the high-value identity documents that enable the most serious fraud. It is still worth checking Sanchar Saathi and your credit reports as general good practice, but the acute risks described in this guide are specifically related to having submitted Aadhaar, PAN and face photographs.

7. Can the casino sell my documents to someone else?

Selling or trading personal data without consent is a violation of the DPDP Act in India and of GDPR for EU-licensed operators. Whether it happens is a separate question from whether it is legal. There is documented evidence of personal data from Indian citizens, including Aadhaar details, being traded in underground markets. The risk exists and the protective steps described in this guide are the practical response to it.

Relevant news