Privacy Policy

Privacy Policy

What information this portal collects, why, who else sees it, how long it is kept, and the rights you have under British Columbia and Canadian privacy law.

Last updated: 7 August 2026 Version 1.2
Contents — 22 sections
  1. Who is responsible & Privacy Officer
  2. What this policy covers
  3. What we collect
  4. Why we may collect it — the legal basis
  5. How we use it
  6. Identity verification & automated decisions
  7. Payment information & PCI DSS
  8. Service providers & processors
  9. Storage & processing outside Canada
  10. Disclosure to government & law enforcement
  11. Self-exclusion data sharing
  12. Marketing & CASL
  13. Cookies & tracking
  14. How long we keep it
  15. Your rights & how to exercise them
  16. Security
  17. If there is a breach
  18. People under 19
  19. Changes to this policy
  20. Complaints
  21. Contact
  22. Version history

1. Who is responsible & Privacy Officer

The British Columbia Lottery Corporation (BCLC) is responsible for the personal information collected through this website. BCLC is a provincial Crown corporation and a public body under British Columbia's Freedom of Information and Protection of Privacy Act (FIPPA). FIPPA — not the private-sector Personal Information Protection Act — is the law that governs how BCLC may collect, use, disclose, retain and protect your personal information, and it is the law that gives you a right of access to it.

Privacy compliance is the responsibility of BCLC's Privacy Officer, who is an employee of BCLC:

  • Privacy Officer, British Columbia Lottery Corporation
  • Email: privacy@dailygrandcontest.co — a BCLC-operated mailbox, monitored by the BCLC privacy team
  • Post: Privacy Officer, British Columbia Lottery Corporation, 74 West Seymour Street, Kamloops, BC, V2C 1E2, Canada

The Privacy Officer handles access and correction requests under FIPPA, complaints and breach notification, and is BCLC's point of contact for the Office of the Information and Privacy Commissioner for British Columbia (OIPC).

A formal FIPPA access request may also be made directly to BCLC's Freedom of Information office. A request sent to the Privacy Officer at either address above is routed there and is treated as received on the day it arrives.

2. What this policy covers

This policy covers the personal information BCLC collects through this website — enquiries and support messages, account and verification details submitted through this site's forms, marketing sign-ups, play and prize records shown to you here, and technical and cookie data from your visit.

This policy does not cover third-party websites we link to, which have their own privacy policies. Where the national game requires it, limited information is shared with the Interprovincial Lottery Corporation (ILC); that sharing is described in section 10.

3. What we collect

  • Account details: name, date of birth, residential address, email address, phone number and password.
  • Verification data: images of the government-issued identification you upload to confirm age and residency, and the result of the check.
  • Payment information: the payment method type, the last four digits of a card, the cardholder name, transaction amounts, dates and reference numbers. See section 7 — we do not receive or store full card numbers, expiry dates or CVV codes.
  • Play data: the lines associated with your account, results and prize records, where these are shown to you through this site.
  • Responsible-gambling data: limits you have set, cooling-off periods, and any self-exclusion status. This is treated as sensitive.
  • Communications: emails, support messages and form submissions, including anything you choose to put in them.
  • Technical data: IP address, approximate location derived from it, device and browser type, operating system, referring page, pages viewed and timestamps — used to confirm you are in B.C., to keep accounts secure and to detect fraud.
  • Cookie and consent data: your consent choices and the identifiers described in our Cookies Policy.

We do not knowingly collect health information, biometric templates, government identifiers beyond what verification requires, or information about race, religion, political opinion, sexual orientation or trade-union membership. Please do not send us any of it.

4. Why we may collect it — the authority under FIPPA

A public body may not collect personal information simply because it would be useful. FIPPA section 26 sets out the only permitted grounds: collection expressly authorised under an Act (s.26(a)), collection for the purposes of law enforcement (s.26(b)), information that relates directly to and is necessary for a program or activity of the public body (s.26(c)), and collection with your consent given in the manner FIPPA prescribes (s.26(d)). Once collected, use is limited by s.32 and disclosure by s.33. Where we collect information directly from you, s.27(2) requires us to tell you the purpose, the legal authority and who to contact about it — this section is that notice.

CategoryAuthority under FIPPAIf you don't provide it
Account detailss.26(c) — relates directly to and is necessary for operating the lottery scheme BCLC is authorised to conduct and manage; collected directly from you under s.27An account cannot be opened
Identity & residency verifications.26(a) — expressly authorised under an Act: age and residency limits under the Gaming Control Act (B.C.), and AML obligations under federal lawPlay and withdrawal are not possible
Payment informations.26(c) for operating the account, and s.26(a) for AML and tax record-keepingDeposits and withdrawals cannot be processed
Play and prize recordss.26(c), and s.26(a) for the gaming records BCLC is required to retainPlays cannot be recorded or prizes paid
Responsible-gambling datas.26(a) and s.26(c) — regulatory obligation; and s.26(d) consent where you set a limit or exclude yourselfLimits and exclusions cannot be enforced
Fraud, AML & security monitorings.26(b) — law enforcement purposes — together with s.26(a) and s.26(c); disclosure to authorities under s.33Not optional
Essential cookies & security logss.26(c) — necessary to deliver the online service you asked for and to keep it secureThe site cannot function
Analytics & advertising cookiess.26(d) — your express, opt-in consent, withdrawable at any timeNothing; the site works normally
Marketing messagess.26(d) consent under FIPPA, plus separate express consent under CASLNothing; you simply receive no marketing

Any question about the authority for a particular collection can be put to the Privacy Officer at privacy@dailygrandcontest.co.

5. How we use it

We use personal information to open and run an account; confirm you are eligible to play; process plays, payments and prizes; operate responsible-gambling tools; meet legal, regulatory and tax obligations; prevent and detect fraud, money laundering and unauthorised access; respond to support requests; keep the site secure and working; and — only with your consent — measure how the site is used and send you marketing.

We do not sell personal information, and we do not disclose it for another organisation's independent marketing purposes.

6. Identity verification & automated decisions

Confirming your age and B.C. residency is a regulatory requirement. Identification you provide is used for that purpose, for AML obligations and for fraud prevention. It is not used for marketing and is not disclosed to advertisers.

Automated decision-making. Identity verification, geolocation checks and fraud and AML screening are partly automated: a system compares what you submit against reference data and risk rules, and can automatically pass a check, flag it for manual review, or decline it. An automated decline can prevent you from opening an account, playing or withdrawing.

Your right to a human review. If an automated check goes against you, you can ask for it to be reviewed by a person. Email privacy@dailygrandcontest.co, say what was refused and when, and we will have someone who was not involved in the automated outcome look at it and reply within 30 business days. We will explain the general reason for the outcome, except where telling you would compromise an investigation or breach a legal prohibition — as with AML reporting, where the law forbids us from telling you.

7. Payment information & PCI DSS

Card payments are processed by PCI DSS compliant payment service providers. Card details are entered directly into the provider's hosted fields or gateway. We do not receive, process or store full card numbers, expiry dates or CVV/CVC codes, and they never touch our servers.

What we do hold is the transaction record: the payment method type, the last four digits, the cardholder name, the amount, the currency, the date and the provider's reference. Payment card data is handled by those providers under their own privacy policies and under the PCI Data Security Standard.

8. Service providers & processors

We use third-party providers to run the service. Under FIPPA they are our service providers: they handle personal information on our behalf, under written contract, only on our instructions, only for the purposes we set, with confidentiality and security obligations and no right to reuse the data. FIPPA's duty to protect personal information (s.30) applies to information in their hands as much as in ours, and the offences and duties in s.30.5 bind their employees too. The categories are:

CategoryWhat they doWhat they receive
Identity verification (KYC)Confirm age, identity and B.C. residency; check documents for tamperingName, date of birth, address, ID images, check result
Payment gateways & processorsTake deposits and send withdrawalsCardholder name, payment credentials entered directly with them, amount, transaction metadata
AML & fraud screeningSanctions and PEP screening, transaction monitoring, device and geolocation risk checksName, date of birth, IP address, device signals, transaction data
Hosting & infrastructureRun the servers, storage, backups and content delivery for this siteEverything transmitted to the site, including server logs
Email deliverySend transactional email and, with consent, marketing emailEmail address, name, message content, open and click events
Analytics (only with consent)Measure how the site is usedPseudonymous identifier, pages viewed, device and approximate location
Advertising & conversion measurement (only with consent)Measure ad performance and, where enabled, remarketingPseudonymous advertising identifier, pages viewed, conversion events

We will name the specific providers in each category on request — email privacy@dailygrandcontest.co and we will tell you who they are and where they process data. The named third parties currently used for cookies and tracking are listed in our Cookies Policy.

9. Storage & processing outside Canada

Some information is stored or accessed outside Canada

Some of the service providers described in section 8 — in particular identity verification, email delivery, analytics and advertising measurement — store personal information on servers outside Canada, or access it from outside Canada, and some use sub-processors in further countries.

How the rules changed. Until 25 November 2021, FIPPA section 30.1 required a public body to store personal information in Canada and to access it only from Canada, with narrow exceptions. That section was repealed, together with section 30.2, which had required public bodies to report foreign demands for disclosure. Storage and access outside Canada are therefore no longer prohibited — but they are not unregulated either.

What still governs it. Three FIPPA duties continue to apply, and they are the ones that matter to you:

  • Authority to disclose — s.33. Sending personal information to a service provider, in or outside Canada, is a disclosure. It is lawful only if a paragraph of section 33 authorises it — in our case, disclosure to a service provider performing services for BCLC, for the purpose the information was obtained for or a consistent purpose. Anything not authorised by s.33 does not leave, wherever the server is.
  • Duty to protect — s.30. We must make reasonable security arrangements against unauthorised access, collection, use, disclosure or disposal. The OIPC's position is that this duty travels with the information: where a jurisdiction's legal protections are inadequate, sending personal information there is itself a breach of s.30. Choosing the country is part of securing the data, not separate from it.
  • Assessment before the fact. BCLC assesses the privacy risk of an initiative, including where information will be stored and accessed, in a privacy impact assessment before the initiative proceeds, in line with the directions and guidance issued for public bodies. We do not add a new destination country first and assess it afterwards.

What that means in practice. While personal information is outside Canada, it is subject to the laws of the country it is in. That includes laws that can compel disclosure to foreign courts, law-enforcement agencies and security services — potentially without your knowledge and without a Canadian court being involved. Since the repeal of s.30.2 there is no longer a statutory duty on us to report such a foreign demand, so we tell you plainly: contractual protections do not override the local law that applies to the recipient, remedies in those countries may be weaker than in British Columbia, and we will not claim otherwise. Where we are lawfully able to tell you that a foreign authority has demanded your information, we will.

We keep information in Canada where a provider offers that option, limit what leaves to what the provider actually needs, and require encryption in transit and at rest.

For the current list of countries in which a specific provider stores or accesses your information, contact the Privacy Officer at privacy@dailygrandcontest.co.

10. Disclosure to government & law enforcement

FIPPA section 33 lists the only circumstances in which a public body may disclose personal information. Several of them do not depend on your consent, and in some cases the law forbids us from notifying you. Specifically:

  • FINTRAC. Large cash transactions, large virtual-currency transactions and transactions with reasonable grounds for suspicion are reported to Canada's financial intelligence unit. The law prohibits telling you that a suspicious transaction report has been made, so you will not be notified.
  • Police and law enforcement. Where there are reasonable grounds to believe an offence has been or may be committed, or in response to a lawful demand, warrant, production order or subpoena.
  • The gambling regulator. The Independent Gambling Control Office (IGCO), for investigations, audits and compliance under the Gaming Control Act (B.C.).
  • Tax authorities. The Canada Revenue Agency and provincial tax authorities where a legal obligation or lawful demand applies.
  • Courts. Where required by court order, or where necessary to establish, exercise or defend a legal claim.
  • Emergencies. Where there is an imminent risk to someone's life, health or safety.

We disclose only what the request or obligation actually requires, we check that a demand is lawful and falls within section 33 before acting on it, and we push back on requests that are overbroad. Where we are permitted to tell you about a disclosure, we will.

11. Self-exclusion data sharing

If you enrol in Game Break, B.C.'s voluntary self-exclusion program, that fact cannot be kept private within the gambling system — an exclusion that nobody can see cannot be enforced. Your identity and exclusion details are entered into our self-exclusion register and shared with the systems and, where facial-recognition or door-check processes are used, with the staff and venues that need to enforce the ban at gambling facilities and online. That sharing is a disclosure authorised by FIPPA s.33 for the purpose the information was collected for.

We record and act on your exclusion status so that we do not send you marketing, do not target you with advertising, and do not process play through this site during the exclusion period. Self-exclusion records are treated as sensitive, are retained for the term of the exclusion and for 7 years afterwards for audit and enforcement, and are not used for any purpose other than administering and enforcing the exclusion and meeting regulatory obligations.

12. Marketing & CASL

We send commercial electronic messages only in accordance with Canada's Anti-Spam Legislation (CASL), which applies to us regardless of FIPPA. That means:

  • Express opt-in consent. We do not add you to a marketing list because you opened an account, made an enquiry or bought something. Consent is a separate, deliberate action: an unticked box you tick yourself. We record what you consented to, when, and how.
  • Sender identification. Every marketing message identifies who is sending it and on whose behalf, and includes a valid postal address and a working email address or web link, kept valid for at least 60 days after the message is sent.
  • Unsubscribe in every message. Every commercial message contains a clearly set out unsubscribe mechanism that works for at least 60 days and takes no more than two clicks. We action unsubscribes without delay and in any event within 10 business days, with no requirement to log in, give a reason or contact support.
  • No marketing to excluded or under-age individuals, and none to anyone enrolled in Game Break.
  • Transactional messages continue. Unsubscribing from marketing does not stop service messages — security alerts, verification requests, payment confirmations, changes to terms and legally required notices — because those are not commercial electronic messages.

To withdraw marketing consent, use the unsubscribe link in any message or email privacy@dailygrandcontest.co.

13. Cookies & tracking

We use essential cookies to run the site, and — only with your consent — analytics and advertising cookies. You choose through the consent banner on your first visit, and you can change or withdraw your choice at any time using the "Cookie settings" control in the footer. Full details, including the named third parties, the identifiers used and their lifetimes, are in our Cookies Policy.

14. How long we keep it

We keep personal information only as long as we need it, and no longer. These are the actual periods:

WhatHow longWhy
Account records (identity, contact details, account history)7 years after the account is closedFederal AML record-keeping requirement
Play, draw and prize records7 years from the transactionAML and gaming record-keeping; prize claim and audit
Payment and transaction records7 years from the transactionAML and tax record-keeping
Copies of identification documents12 months after verification succeeds, then deleted — only the verification result, method and date are kept for 7 yearsMinimise holding of high-risk documents while keeping proof the check was done
Failed or abandoned verification attempts90 daysFraud prevention and re-attempt handling
Self-exclusion recordsTerm of the exclusion plus 7 yearsEnforcement and regulatory audit
Responsible-gambling limit history5 yearsRegulatory audit of limit changes
Support and complaint correspondence3 years after the matter is closed; complaints escalated to the regulator, 7 yearsService quality, dispute resolution, regulatory review
Server, access and security logs12 monthsSecurity, fraud detection, incident investigation
Marketing consent records3 years after consent is withdrawnCASL requires proof of consent
Cookie consent records12 months, or until withdrawnProof of the choice you made
Analytics data14 monthsTrend analysis; then deleted or aggregated
AML reports and supporting records7 years minimum, longer if an investigation is openFederal legal obligation

Where a record is under legal hold — an open investigation, a regulatory review, a complaint or litigation — it is kept until that ends, even if the period above has expired. When information is no longer needed it is securely destroyed, erased or irreversibly anonymised. Anonymised statistics that can no longer identify anyone may be kept indefinitely.

15. Your rights & how to exercise them

FIPPA gives you the following rights over the information we hold about you. They are statutory rights against a public body, enforceable through the OIPC — not a courtesy.

Access — FIPPA Part 2

You can ask for the personal information we hold about you, and for the other records FIPPA gives a right of access to. Make the request in writing (email is fine) and give enough detail to identify the records.

We must respond within 30 business days of receiving the request — FIPPA section 7. FIPPA counts in days that exclude Saturdays and statutory holidays, so this is a working-day deadline, not a calendar month. Section 10 lets us extend by up to a further 30 business days where the request does not give enough detail to identify the records, where it covers a large number of records and meeting the deadline would unreasonably interfere with operations, or where we must consult another public body or a third party. A longer extension needs the Commissioner's permission. If we extend, we will tell you before the first deadline passes, why, and when to expect a reply.

There is no charge for access to your own personal information. Where FIPPA permits a fee for other records, we give you a written estimate first and you may narrow or withdraw the request, or ask for the fee to be waived.

Access can be refused or limited only on the grounds FIPPA sets out in Part 2, Division 2 — for example where disclosure would be an unreasonable invasion of a third party's privacy, would reveal information supplied in confidence or harm a third party's business interests, is subject to solicitor-client privilege, would harm a law-enforcement matter, or where another Act prohibits disclosure (as with AML reporting). If we refuse, we will say so in writing, cite the section relied on, sever and release what we can, and tell you how to ask the OIPC to review the decision.

Correction — FIPPA s.29

You can ask us to correct personal information about you that is inaccurate or incomplete. Where we agree, we correct it. Where we do not, FIPPA requires us to annotate the record with your requested correction, so that anyone who later reads it sees your position, and to tell you why we did not make the change. Either way, we notify any public body or third party to whom the information was disclosed in the year before the correction request.

Withdrawing consent

Where we rely on your consent — marketing, and analytics and advertising cookies — you can withdraw it at any time, and we stop. Withdrawal takes effect going forward and does not undo anything already done lawfully.

Most of what we hold is not held on the basis of consent: it is collected under the statutory authorities in section 4 above, and there is no consent to withdraw. Identity verification, AML records and gaming records fall in that category. The way to end that processing is to close the account, after which the retention periods in section 14 apply.

Deletion

You can ask us to delete personal information. We will delete what we are not required to keep, and tell you plainly what we must retain and for how long — see the retention table in section 14. Where information cannot be deleted, we restrict it so it is used only for the purpose that requires its retention. FIPPA gives no right of erasure, and a public body must keep personal information used to make a decision about you for at least one year after that decision; we will not claim to have deleted something we have not.

Portability

FIPPA does not give a right to data portability. We nevertheless provide the personal information you gave us, on request, in a structured, commonly used, machine-readable format (CSV or JSON), so you can keep or reuse it. Ask the Privacy Officer.

Human review of an automated decision

See section 6.

How to make a request

Email privacy@dailygrandcontest.co or write to the Privacy Officer at the BCLC address in section 1. Say that you are making a request under FIPPA, what you want, and enough detail to find the records; the clock in section 7 starts when the request reaches us. We will verify your identity before releasing anything — that check protects you, and we ask only for what is needed to confirm it is you. You may authorise someone to act for you in writing.

16. Security

We protect personal information with security appropriate to its sensitivity: encryption in transit (TLS) and at rest for identification documents and payment metadata; role-based access control on a need-to-know basis; multi-factor authentication for administrative access; logging and monitoring of access to sensitive records; segregation of production data from test environments; contractual and technical controls over processors; and secure destruction at the end of the retention period.

No system is perfectly secure. Please use a strong, unique password, enable any additional authentication offered, and tell us immediately at privacy@dailygrandcontest.co if you suspect your account or information has been compromised.

17. If there is a breach

Breach notification is a statutory duty under FIPPA section 30.5, not a discretionary courtesy. Anyone at BCLC or at one of our service providers who learns of an unauthorised disclosure must report it internally immediately. We then investigate, contain it, and assess whether the breach could reasonably be expected to result in significant harm — which includes identity theft, fraud, financial loss, damage to reputation or relationships, humiliation, and loss of employment or professional opportunity.

Where that threshold is met we will, without unreasonable delay:

  • Report to the Commissioner. Notify the Office of the Information and Privacy Commissioner for British Columbia, as s.30.5 requires.
  • Notify you directly — by email or, if we cannot reach you, by a conspicuous notice on this site — describing what happened, when, what information was involved, what we have done, what we are doing to reduce the harm, what you can do to protect yourself, and how to contact us with questions.
  • Notify other organisations, such as payment providers or law enforcement, where doing so may reduce the risk to you.
  • Keep a record of every breach, whether or not it was notifiable, for at least 24 months, and make those records available to the Commissioner on request.

We will not delay notification to complete an investigation, and we will not downplay what happened.

18. People under 19

This service is not for anyone under 19. We do not knowingly collect personal information from people under that age, and we do not market to them. If we learn that we have collected information from someone under 19, we delete it promptly and close any associated account. If you believe a minor has provided us with information, contact privacy@dailygrandcontest.co. See our Responsible Gaming page for how access by minors is prevented, including parental control software.

19. Changes to this policy

We may update this policy. The current version is always posted here with its version number and "last updated" date.

For a material change — a new purpose for using your information, a new category of recipient, a new country in which it is stored or accessed, or a longer retention period — we will give at least 30 days' notice before it takes effect, by notice on this site and, where we hold your email address, by email. A change that widens a purpose beyond the authority relied on in section 4 requires a new authority under FIPPA, not merely a new version of this page; where consent is the authority, we will ask for it rather than assume it from continued use.

20. Complaints

Raise a privacy concern with our Privacy Officer first, at privacy@dailygrandcontest.co. We acknowledge within 2 business days, investigate, and give a written response within 30 business days, telling you what we found and what we have done.

If you are not satisfied, take it to the Office of the Information and Privacy Commissioner for British Columbia (OIPC) at oipc.bc.ca. The OIPC oversees both FIPPA and PIPA, and BCLC is answerable to it as a public body under FIPPA. There are two routes:

  • A request for review where you disagree with our decision on an access or correction request — including a refusal, a severing, a fee or a missed deadline. FIPPA sets a time limit for asking for a review, running from the date you are notified of our decision; the current limit is published by the OIPC, so do not sit on it.
  • A privacy complaint about how we collected, used, disclosed, retained or protected your personal information. The Commissioner may investigate, audit our practices and order us to change them.

You do not need our permission for either, and you can approach the OIPC directly at any time. Raising it with us first is usually faster, but it is not a precondition.

21. Contact

Privacy Officer, British Columbia Lottery Corporationprivacy@dailygrandcontest.co, a BCLC-operated mailbox. By post: Privacy Officer, British Columbia Lottery Corporation, 74 West Seymour Street, Kamloops, BC, V2C 1E2, Canada.

For anything that is not a privacy matter, see our Support page or email support@dailygrandcontest.co.

22. Version history

VersionIn effect fromSummary of changes
1.2 Current 7 August 2026 Corrected the governing statute back to FIPPA: BCLC is a public body, not a private-sector organisation, so FIPPA and not PIPA applies. Named BCLC as the responsible public body and its Privacy Officer as a BCLC employee; replaced the PIPA s.8 consent analysis with the collection authorities in FIPPA s.26 and the use and disclosure limits in s.32 and s.33; rewrote storage and access outside Canada around the repeal of s.30.1 and s.30.2 and the continuing duties in s.30 and s.33; set the access deadline at 30 business days under s.7 with the s.10 extension; restated correction under s.29 and breach notification under s.30.5; set out both OIPC routes — request for review and privacy complaint; removed PIPEDA and the Privacy Commissioner of Canada, which do not apply to a provincial public body; aligned the payment description with the three methods named in the Terms.
1.1 7 August 2026 Rewrote the rights section with response times; added the legal basis for each category; replaced vague retention wording with specific periods; added transfers outside Canada, processor categories, disclosure to government, self-exclusion sharing, breach notification, Privacy Officer, automated decisions and human review, payment data and PCI DSS, CASL requirements, portability and deletion. Incorrectly cited PIPA in place of FIPPA; corrected in 1.2.
1.0 26 June 2026 First published version, 12 sections. Cited FIPPA.

To request a copy of an earlier version, email privacy@dailygrandcontest.co, quoting the version number.

Why play here

Built for trust, run by B.C.