Privacy Policy
What information this portal collects, why, who else sees it, how long it is kept, and the rights you have under British Columbia and Canadian privacy law.
Contents — 22 sections
- Who is responsible & Privacy Officer
- What this policy covers
- What we collect
- Why we may collect it — the legal basis
- How we use it
- Identity verification & automated decisions
- Payment information & PCI DSS
- Service providers & processors
- Storage & processing outside Canada
- Disclosure to government & law enforcement
- Self-exclusion data sharing
- Marketing & CASL
- Cookies & tracking
- How long we keep it
- Your rights & how to exercise them
- Security
- If there is a breach
- People under 19
- Changes to this policy
- Complaints
- Contact
- Version history
1. Who is responsible & Privacy Officer
The British Columbia Lottery Corporation (BCLC) is responsible for the personal information collected through this website. BCLC is a provincial Crown corporation and a public body under British Columbia's Freedom of Information and Protection of Privacy Act (FIPPA). FIPPA — not the private-sector Personal Information Protection Act — is the law that governs how BCLC may collect, use, disclose, retain and protect your personal information, and it is the law that gives you a right of access to it.
Privacy compliance is the responsibility of BCLC's Privacy Officer, who is an employee of BCLC:
- Privacy Officer, British Columbia Lottery Corporation
- Email: privacy@dailygrandcontest.co — a BCLC-operated mailbox, monitored by the BCLC privacy team
- Post: Privacy Officer, British Columbia Lottery Corporation, 74 West Seymour Street, Kamloops, BC, V2C 1E2, Canada
The Privacy Officer handles access and correction requests under FIPPA, complaints and breach notification, and is BCLC's point of contact for the Office of the Information and Privacy Commissioner for British Columbia (OIPC).
A formal FIPPA access request may also be made directly to BCLC's Freedom of Information office. A request sent to the Privacy Officer at either address above is routed there and is treated as received on the day it arrives.
2. What this policy covers
This policy covers the personal information BCLC collects through this website — enquiries and support messages, account and verification details submitted through this site's forms, marketing sign-ups, play and prize records shown to you here, and technical and cookie data from your visit.
This policy does not cover third-party websites we link to, which have their own privacy policies. Where the national game requires it, limited information is shared with the Interprovincial Lottery Corporation (ILC); that sharing is described in section 10.
3. What we collect
- Account details: name, date of birth, residential address, email address, phone number and password.
- Verification data: images of the government-issued identification you upload to confirm age and residency, and the result of the check.
- Payment information: the payment method type, the last four digits of a card, the cardholder name, transaction amounts, dates and reference numbers. See section 7 — we do not receive or store full card numbers, expiry dates or CVV codes.
- Play data: the lines associated with your account, results and prize records, where these are shown to you through this site.
- Responsible-gambling data: limits you have set, cooling-off periods, and any self-exclusion status. This is treated as sensitive.
- Communications: emails, support messages and form submissions, including anything you choose to put in them.
- Technical data: IP address, approximate location derived from it, device and browser type, operating system, referring page, pages viewed and timestamps — used to confirm you are in B.C., to keep accounts secure and to detect fraud.
- Cookie and consent data: your consent choices and the identifiers described in our Cookies Policy.
We do not knowingly collect health information, biometric templates, government identifiers beyond what verification requires, or information about race, religion, political opinion, sexual orientation or trade-union membership. Please do not send us any of it.
4. Why we may collect it — the authority under FIPPA
A public body may not collect personal information simply because it would be useful. FIPPA section 26 sets out the only permitted grounds: collection expressly authorised under an Act (s.26(a)), collection for the purposes of law enforcement (s.26(b)), information that relates directly to and is necessary for a program or activity of the public body (s.26(c)), and collection with your consent given in the manner FIPPA prescribes (s.26(d)). Once collected, use is limited by s.32 and disclosure by s.33. Where we collect information directly from you, s.27(2) requires us to tell you the purpose, the legal authority and who to contact about it — this section is that notice.
| Category | Authority under FIPPA | If you don't provide it |
|---|---|---|
| Account details | s.26(c) — relates directly to and is necessary for operating the lottery scheme BCLC is authorised to conduct and manage; collected directly from you under s.27 | An account cannot be opened |
| Identity & residency verification | s.26(a) — expressly authorised under an Act: age and residency limits under the Gaming Control Act (B.C.), and AML obligations under federal law | Play and withdrawal are not possible |
| Payment information | s.26(c) for operating the account, and s.26(a) for AML and tax record-keeping | Deposits and withdrawals cannot be processed |
| Play and prize records | s.26(c), and s.26(a) for the gaming records BCLC is required to retain | Plays cannot be recorded or prizes paid |
| Responsible-gambling data | s.26(a) and s.26(c) — regulatory obligation; and s.26(d) consent where you set a limit or exclude yourself | Limits and exclusions cannot be enforced |
| Fraud, AML & security monitoring | s.26(b) — law enforcement purposes — together with s.26(a) and s.26(c); disclosure to authorities under s.33 | Not optional |
| Essential cookies & security logs | s.26(c) — necessary to deliver the online service you asked for and to keep it secure | The site cannot function |
| Analytics & advertising cookies | s.26(d) — your express, opt-in consent, withdrawable at any time | Nothing; the site works normally |
| Marketing messages | s.26(d) consent under FIPPA, plus separate express consent under CASL | Nothing; you simply receive no marketing |
Any question about the authority for a particular collection can be put to the Privacy Officer at privacy@dailygrandcontest.co.
5. How we use it
We use personal information to open and run an account; confirm you are eligible to play; process plays, payments and prizes; operate responsible-gambling tools; meet legal, regulatory and tax obligations; prevent and detect fraud, money laundering and unauthorised access; respond to support requests; keep the site secure and working; and — only with your consent — measure how the site is used and send you marketing.
We do not sell personal information, and we do not disclose it for another organisation's independent marketing purposes.
6. Identity verification & automated decisions
Confirming your age and B.C. residency is a regulatory requirement. Identification you provide is used for that purpose, for AML obligations and for fraud prevention. It is not used for marketing and is not disclosed to advertisers.
Automated decision-making. Identity verification, geolocation checks and fraud and AML screening are partly automated: a system compares what you submit against reference data and risk rules, and can automatically pass a check, flag it for manual review, or decline it. An automated decline can prevent you from opening an account, playing or withdrawing.
Your right to a human review. If an automated check goes against you, you can ask for it to be reviewed by a person. Email privacy@dailygrandcontest.co, say what was refused and when, and we will have someone who was not involved in the automated outcome look at it and reply within 30 business days. We will explain the general reason for the outcome, except where telling you would compromise an investigation or breach a legal prohibition — as with AML reporting, where the law forbids us from telling you.
7. Payment information & PCI DSS
Card payments are processed by PCI DSS compliant payment service providers. Card details are entered directly into the provider's hosted fields or gateway. We do not receive, process or store full card numbers, expiry dates or CVV/CVC codes, and they never touch our servers.
What we do hold is the transaction record: the payment method type, the last four digits, the cardholder name, the amount, the currency, the date and the provider's reference. Payment card data is handled by those providers under their own privacy policies and under the PCI Data Security Standard.
8. Service providers & processors
We use third-party providers to run the service. Under FIPPA they are our service providers: they handle personal information on our behalf, under written contract, only on our instructions, only for the purposes we set, with confidentiality and security obligations and no right to reuse the data. FIPPA's duty to protect personal information (s.30) applies to information in their hands as much as in ours, and the offences and duties in s.30.5 bind their employees too. The categories are:
| Category | What they do | What they receive |
|---|---|---|
| Identity verification (KYC) | Confirm age, identity and B.C. residency; check documents for tampering | Name, date of birth, address, ID images, check result |
| Payment gateways & processors | Take deposits and send withdrawals | Cardholder name, payment credentials entered directly with them, amount, transaction metadata |
| AML & fraud screening | Sanctions and PEP screening, transaction monitoring, device and geolocation risk checks | Name, date of birth, IP address, device signals, transaction data |
| Hosting & infrastructure | Run the servers, storage, backups and content delivery for this site | Everything transmitted to the site, including server logs |
| Email delivery | Send transactional email and, with consent, marketing email | Email address, name, message content, open and click events |
| Analytics (only with consent) | Measure how the site is used | Pseudonymous identifier, pages viewed, device and approximate location |
| Advertising & conversion measurement (only with consent) | Measure ad performance and, where enabled, remarketing | Pseudonymous advertising identifier, pages viewed, conversion events |
We will name the specific providers in each category on request — email privacy@dailygrandcontest.co and we will tell you who they are and where they process data. The named third parties currently used for cookies and tracking are listed in our Cookies Policy.
9. Storage & processing outside Canada
Some information is stored or accessed outside Canada
Some of the service providers described in section 8 — in particular identity verification, email delivery, analytics and advertising measurement — store personal information on servers outside Canada, or access it from outside Canada, and some use sub-processors in further countries.
How the rules changed. Until 25 November 2021, FIPPA section 30.1 required a public body to store personal information in Canada and to access it only from Canada, with narrow exceptions. That section was repealed, together with section 30.2, which had required public bodies to report foreign demands for disclosure. Storage and access outside Canada are therefore no longer prohibited — but they are not unregulated either.
What still governs it. Three FIPPA duties continue to apply, and they are the ones that matter to you:
- Authority to disclose — s.33. Sending personal information to a service provider, in or outside Canada, is a disclosure. It is lawful only if a paragraph of section 33 authorises it — in our case, disclosure to a service provider performing services for BCLC, for the purpose the information was obtained for or a consistent purpose. Anything not authorised by s.33 does not leave, wherever the server is.
- Duty to protect — s.30. We must make reasonable security arrangements against unauthorised access, collection, use, disclosure or disposal. The OIPC's position is that this duty travels with the information: where a jurisdiction's legal protections are inadequate, sending personal information there is itself a breach of s.30. Choosing the country is part of securing the data, not separate from it.
- Assessment before the fact. BCLC assesses the privacy risk of an initiative, including where information will be stored and accessed, in a privacy impact assessment before the initiative proceeds, in line with the directions and guidance issued for public bodies. We do not add a new destination country first and assess it afterwards.
What that means in practice. While personal information is outside Canada, it is subject to the laws of the country it is in. That includes laws that can compel disclosure to foreign courts, law-enforcement agencies and security services — potentially without your knowledge and without a Canadian court being involved. Since the repeal of s.30.2 there is no longer a statutory duty on us to report such a foreign demand, so we tell you plainly: contractual protections do not override the local law that applies to the recipient, remedies in those countries may be weaker than in British Columbia, and we will not claim otherwise. Where we are lawfully able to tell you that a foreign authority has demanded your information, we will.
We keep information in Canada where a provider offers that option, limit what leaves to what the provider actually needs, and require encryption in transit and at rest.
For the current list of countries in which a specific provider stores or accesses your information, contact the Privacy Officer at privacy@dailygrandcontest.co.
10. Disclosure to government & law enforcement
FIPPA section 33 lists the only circumstances in which a public body may disclose personal information. Several of them do not depend on your consent, and in some cases the law forbids us from notifying you. Specifically:
- FINTRAC. Large cash transactions, large virtual-currency transactions and transactions with reasonable grounds for suspicion are reported to Canada's financial intelligence unit. The law prohibits telling you that a suspicious transaction report has been made, so you will not be notified.
- Police and law enforcement. Where there are reasonable grounds to believe an offence has been or may be committed, or in response to a lawful demand, warrant, production order or subpoena.
- The gambling regulator. The Independent Gambling Control Office (IGCO), for investigations, audits and compliance under the Gaming Control Act (B.C.).
- Tax authorities. The Canada Revenue Agency and provincial tax authorities where a legal obligation or lawful demand applies.
- Courts. Where required by court order, or where necessary to establish, exercise or defend a legal claim.
- Emergencies. Where there is an imminent risk to someone's life, health or safety.
We disclose only what the request or obligation actually requires, we check that a demand is lawful and falls within section 33 before acting on it, and we push back on requests that are overbroad. Where we are permitted to tell you about a disclosure, we will.
11. Self-exclusion data sharing
If you enrol in Game Break, B.C.'s voluntary self-exclusion program, that fact cannot be kept private within the gambling system — an exclusion that nobody can see cannot be enforced. Your identity and exclusion details are entered into our self-exclusion register and shared with the systems and, where facial-recognition or door-check processes are used, with the staff and venues that need to enforce the ban at gambling facilities and online. That sharing is a disclosure authorised by FIPPA s.33 for the purpose the information was collected for.
We record and act on your exclusion status so that we do not send you marketing, do not target you with advertising, and do not process play through this site during the exclusion period. Self-exclusion records are treated as sensitive, are retained for the term of the exclusion and for 7 years afterwards for audit and enforcement, and are not used for any purpose other than administering and enforcing the exclusion and meeting regulatory obligations.
12. Marketing & CASL
We send commercial electronic messages only in accordance with Canada's Anti-Spam Legislation (CASL), which applies to us regardless of FIPPA. That means:
- Express opt-in consent. We do not add you to a marketing list because you opened an account, made an enquiry or bought something. Consent is a separate, deliberate action: an unticked box you tick yourself. We record what you consented to, when, and how.
- Sender identification. Every marketing message identifies who is sending it and on whose behalf, and includes a valid postal address and a working email address or web link, kept valid for at least 60 days after the message is sent.
- Unsubscribe in every message. Every commercial message contains a clearly set out unsubscribe mechanism that works for at least 60 days and takes no more than two clicks. We action unsubscribes without delay and in any event within 10 business days, with no requirement to log in, give a reason or contact support.
- No marketing to excluded or under-age individuals, and none to anyone enrolled in Game Break.
- Transactional messages continue. Unsubscribing from marketing does not stop service messages — security alerts, verification requests, payment confirmations, changes to terms and legally required notices — because those are not commercial electronic messages.
To withdraw marketing consent, use the unsubscribe link in any message or email privacy@dailygrandcontest.co.
13. Cookies & tracking
We use essential cookies to run the site, and — only with your consent — analytics and advertising cookies. You choose through the consent banner on your first visit, and you can change or withdraw your choice at any time using the "Cookie settings" control in the footer. Full details, including the named third parties, the identifiers used and their lifetimes, are in our Cookies Policy.
14. How long we keep it
We keep personal information only as long as we need it, and no longer. These are the actual periods:
| What | How long | Why |
|---|---|---|
| Account records (identity, contact details, account history) | 7 years after the account is closed | Federal AML record-keeping requirement |
| Play, draw and prize records | 7 years from the transaction | AML and gaming record-keeping; prize claim and audit |
| Payment and transaction records | 7 years from the transaction | AML and tax record-keeping |
| Copies of identification documents | 12 months after verification succeeds, then deleted — only the verification result, method and date are kept for 7 years | Minimise holding of high-risk documents while keeping proof the check was done |
| Failed or abandoned verification attempts | 90 days | Fraud prevention and re-attempt handling |
| Self-exclusion records | Term of the exclusion plus 7 years | Enforcement and regulatory audit |
| Responsible-gambling limit history | 5 years | Regulatory audit of limit changes |
| Support and complaint correspondence | 3 years after the matter is closed; complaints escalated to the regulator, 7 years | Service quality, dispute resolution, regulatory review |
| Server, access and security logs | 12 months | Security, fraud detection, incident investigation |
| Marketing consent records | 3 years after consent is withdrawn | CASL requires proof of consent |
| Cookie consent records | 12 months, or until withdrawn | Proof of the choice you made |
| Analytics data | 14 months | Trend analysis; then deleted or aggregated |
| AML reports and supporting records | 7 years minimum, longer if an investigation is open | Federal legal obligation |
Where a record is under legal hold — an open investigation, a regulatory review, a complaint or litigation — it is kept until that ends, even if the period above has expired. When information is no longer needed it is securely destroyed, erased or irreversibly anonymised. Anonymised statistics that can no longer identify anyone may be kept indefinitely.
15. Your rights & how to exercise them
FIPPA gives you the following rights over the information we hold about you. They are statutory rights against a public body, enforceable through the OIPC — not a courtesy.
Access — FIPPA Part 2
You can ask for the personal information we hold about you, and for the other records FIPPA gives a right of access to. Make the request in writing (email is fine) and give enough detail to identify the records.
We must respond within 30 business days of receiving the request — FIPPA section 7. FIPPA counts in days that exclude Saturdays and statutory holidays, so this is a working-day deadline, not a calendar month. Section 10 lets us extend by up to a further 30 business days where the request does not give enough detail to identify the records, where it covers a large number of records and meeting the deadline would unreasonably interfere with operations, or where we must consult another public body or a third party. A longer extension needs the Commissioner's permission. If we extend, we will tell you before the first deadline passes, why, and when to expect a reply.
There is no charge for access to your own personal information. Where FIPPA permits a fee for other records, we give you a written estimate first and you may narrow or withdraw the request, or ask for the fee to be waived.
Access can be refused or limited only on the grounds FIPPA sets out in Part 2, Division 2 — for example where disclosure would be an unreasonable invasion of a third party's privacy, would reveal information supplied in confidence or harm a third party's business interests, is subject to solicitor-client privilege, would harm a law-enforcement matter, or where another Act prohibits disclosure (as with AML reporting). If we refuse, we will say so in writing, cite the section relied on, sever and release what we can, and tell you how to ask the OIPC to review the decision.
Correction — FIPPA s.29
You can ask us to correct personal information about you that is inaccurate or incomplete. Where we agree, we correct it. Where we do not, FIPPA requires us to annotate the record with your requested correction, so that anyone who later reads it sees your position, and to tell you why we did not make the change. Either way, we notify any public body or third party to whom the information was disclosed in the year before the correction request.
Withdrawing consent
Where we rely on your consent — marketing, and analytics and advertising cookies — you can withdraw it at any time, and we stop. Withdrawal takes effect going forward and does not undo anything already done lawfully.
Most of what we hold is not held on the basis of consent: it is collected under the statutory authorities in section 4 above, and there is no consent to withdraw. Identity verification, AML records and gaming records fall in that category. The way to end that processing is to close the account, after which the retention periods in section 14 apply.
Deletion
You can ask us to delete personal information. We will delete what we are not required to keep, and tell you plainly what we must retain and for how long — see the retention table in section 14. Where information cannot be deleted, we restrict it so it is used only for the purpose that requires its retention. FIPPA gives no right of erasure, and a public body must keep personal information used to make a decision about you for at least one year after that decision; we will not claim to have deleted something we have not.
Portability
FIPPA does not give a right to data portability. We nevertheless provide the personal information you gave us, on request, in a structured, commonly used, machine-readable format (CSV or JSON), so you can keep or reuse it. Ask the Privacy Officer.
Human review of an automated decision
See section 6.
How to make a request
Email privacy@dailygrandcontest.co or write to the Privacy Officer at the BCLC address in section 1. Say that you are making a request under FIPPA, what you want, and enough detail to find the records; the clock in section 7 starts when the request reaches us. We will verify your identity before releasing anything — that check protects you, and we ask only for what is needed to confirm it is you. You may authorise someone to act for you in writing.
16. Security
We protect personal information with security appropriate to its sensitivity: encryption in transit (TLS) and at rest for identification documents and payment metadata; role-based access control on a need-to-know basis; multi-factor authentication for administrative access; logging and monitoring of access to sensitive records; segregation of production data from test environments; contractual and technical controls over processors; and secure destruction at the end of the retention period.
No system is perfectly secure. Please use a strong, unique password, enable any additional authentication offered, and tell us immediately at privacy@dailygrandcontest.co if you suspect your account or information has been compromised.
17. If there is a breach
Breach notification is a statutory duty under FIPPA section 30.5, not a discretionary courtesy. Anyone at BCLC or at one of our service providers who learns of an unauthorised disclosure must report it internally immediately. We then investigate, contain it, and assess whether the breach could reasonably be expected to result in significant harm — which includes identity theft, fraud, financial loss, damage to reputation or relationships, humiliation, and loss of employment or professional opportunity.
Where that threshold is met we will, without unreasonable delay:
- Report to the Commissioner. Notify the Office of the Information and Privacy Commissioner for British Columbia, as s.30.5 requires.
- Notify you directly — by email or, if we cannot reach you, by a conspicuous notice on this site — describing what happened, when, what information was involved, what we have done, what we are doing to reduce the harm, what you can do to protect yourself, and how to contact us with questions.
- Notify other organisations, such as payment providers or law enforcement, where doing so may reduce the risk to you.
- Keep a record of every breach, whether or not it was notifiable, for at least 24 months, and make those records available to the Commissioner on request.
We will not delay notification to complete an investigation, and we will not downplay what happened.
18. People under 19
This service is not for anyone under 19. We do not knowingly collect personal information from people under that age, and we do not market to them. If we learn that we have collected information from someone under 19, we delete it promptly and close any associated account. If you believe a minor has provided us with information, contact privacy@dailygrandcontest.co. See our Responsible Gaming page for how access by minors is prevented, including parental control software.
19. Changes to this policy
We may update this policy. The current version is always posted here with its version number and "last updated" date.
For a material change — a new purpose for using your information, a new category of recipient, a new country in which it is stored or accessed, or a longer retention period — we will give at least 30 days' notice before it takes effect, by notice on this site and, where we hold your email address, by email. A change that widens a purpose beyond the authority relied on in section 4 requires a new authority under FIPPA, not merely a new version of this page; where consent is the authority, we will ask for it rather than assume it from continued use.
20. Complaints
Raise a privacy concern with our Privacy Officer first, at privacy@dailygrandcontest.co. We acknowledge within 2 business days, investigate, and give a written response within 30 business days, telling you what we found and what we have done.
If you are not satisfied, take it to the Office of the Information and Privacy Commissioner for British Columbia (OIPC) at oipc.bc.ca. The OIPC oversees both FIPPA and PIPA, and BCLC is answerable to it as a public body under FIPPA. There are two routes:
- A request for review where you disagree with our decision on an access or correction request — including a refusal, a severing, a fee or a missed deadline. FIPPA sets a time limit for asking for a review, running from the date you are notified of our decision; the current limit is published by the OIPC, so do not sit on it.
- A privacy complaint about how we collected, used, disclosed, retained or protected your personal information. The Commissioner may investigate, audit our practices and order us to change them.
You do not need our permission for either, and you can approach the OIPC directly at any time. Raising it with us first is usually faster, but it is not a precondition.
21. Contact
Privacy Officer, British Columbia Lottery Corporation — privacy@dailygrandcontest.co, a BCLC-operated mailbox. By post: Privacy Officer, British Columbia Lottery Corporation, 74 West Seymour Street, Kamloops, BC, V2C 1E2, Canada.
For anything that is not a privacy matter, see our Support page or email support@dailygrandcontest.co.
22. Version history
| Version | In effect from | Summary of changes |
|---|---|---|
| 1.2 Current | 7 August 2026 | Corrected the governing statute back to FIPPA: BCLC is a public body, not a private-sector organisation, so FIPPA and not PIPA applies. Named BCLC as the responsible public body and its Privacy Officer as a BCLC employee; replaced the PIPA s.8 consent analysis with the collection authorities in FIPPA s.26 and the use and disclosure limits in s.32 and s.33; rewrote storage and access outside Canada around the repeal of s.30.1 and s.30.2 and the continuing duties in s.30 and s.33; set the access deadline at 30 business days under s.7 with the s.10 extension; restated correction under s.29 and breach notification under s.30.5; set out both OIPC routes — request for review and privacy complaint; removed PIPEDA and the Privacy Commissioner of Canada, which do not apply to a provincial public body; aligned the payment description with the three methods named in the Terms. |
| 1.1 | 7 August 2026 | Rewrote the rights section with response times; added the legal basis for each category; replaced vague retention wording with specific periods; added transfers outside Canada, processor categories, disclosure to government, self-exclusion sharing, breach notification, Privacy Officer, automated decisions and human review, payment data and PCI DSS, CASL requirements, portability and deletion. Incorrectly cited PIPA in place of FIPPA; corrected in 1.2. |
| 1.0 | 26 June 2026 | First published version, 12 sections. Cited FIPPA. |
To request a copy of an earlier version, email privacy@dailygrandcontest.co, quoting the version number.