Enjoy the ultimate LEGO® Sleepover
Save up to £30 and buy tickets online from £32!
Sign up to our newsletter to receive our awesome special events, exclusive offers and be the first to hear about what's coming to the Resort!
Date of birth
Antigua and Barbuda
Bonaire, Sint Eustatius and Saba
Bosnia and Herzegovina
British Indian Ocean Territory
British Virgin Islands
Central African Republic
Cocos (Keeling) Islands
Hong Kong SAR
Isle of Man
Northern Mariana Islands
Papua New Guinea
Saint Kitts and Nevis
Saint Pierre and Miquelon
Saint Vincent and the Grenadines
São Tomé and Príncipe
St Helena, Ascension, Tristan da Cunha
Svalbard and Jan Mayen
Trinidad and Tobago
Turks and Caicos Islands
U.S. Outlying Islands
U.S. Virgin Islands
United Arab Emirates
Wallis and Futuna
At Merlin ("we", "us", "our"), we regularly collect and use personal data about consumers who visit our attractions or hotels, or browse our websites. Personal data is any information that can used to identify you as an individual. The protection of your personal data is very important to us, and we understand our responsibilities to handle your personal data with care, to keep it secure and to comply with legal requirements.
Please read this Policy carefully. It provides important information about how we use personal data and explains your legal rights. This Policy is not intended to override the terms of any contract that you have with us (for example, Wi-Fi terms and conditions or annual pass terms) or any rights you might have available under applicable data protection laws.
We will make changes to this Policy from time to time for example, to keep it up to date or to comply with legal requirements or changes in the way we operate our business. We will make sure that you are aware of any significant changes by sending an email message to the email address you most recently provided to us or by posting a notice on each relevant website so that you are aware of the impact to the data processing activities before you continue to engage. We encourage you to regularly check back and review this policy so that you will always know what information we collect, how we use it, and who we share it with.
Merlin Entertainments Limited ("Merlin") is a British-based entertainment company, with a registered office at Link House, 25 West Street, Poole, Dorset, BH15 1LD, which operates over 100 attractions, and over 20 hotels and holiday villages in 25 countries. Our business is about creating unique, memorable and rewarding visitor experiences. A list of our attractions and a note of the companies that make up the Merlin group which help to achieve this is available at ("Merlin Group").
The entity in the Merlin Group which was originally responsible for collecting information about you will be the Data Controller. Other entities in the Merlin Group may also be Data Controllers where they control the use or processing of such data. There will be a single point of contact for all Merlin Group Data Controllers who can be contacted using the details set in section 11 below.
In relation to potential customers, historic customers and current customers and attraction visitors ("consumers"), we collect the following data:
2.1 Information Automatically Collected In The LEGOLAND Windsor Resort Mobile AppWhen you use the App, we automatically collect specific data that are required for the use of the App. This data includes:
This data is automatically sent to us, (1) so that we can make the service and the associated functions available to you; (2) to improve the functions and features of the App and (3) to prevent misuse and to rectify malfunctions and (4) to offer you a personalized guest experience. This data processing is justified on the basis that (1) the processing is required in order to fulfil the requirements of the contract between you as the data subject and us in accordance with Art. 6(1)(b) GDPR for the use of the App, or (2) we have a legitimate interest in guaranteeing the functionality and fault-free operation of the App and being able to offer a service that is in line with the requirements of the market and with the interests of the users and prevails over your rights and interests in the protection of your personal data in accordance with Art. 6(1)(f) GDPR.
In emergency circumstances, we will also collect information about you indirectly from other sources where we believe this is necessary to help ensure the security of our attractions. These other sources may include public registers and social media platforms.
We will not knowingly collect any personal data about children for the purpose of marketing without making it clear that such information should only be provided with parental consent, if this is required by applicable laws - so Merlin will only use the personal data of children as far as is permitted by law where the required parental or guardian consent has been obtained.
We will use your personal data to:
We may also send you marketing materials (where we have appropriate permissions as explained in more detail below under Section 6). This process is likely to include profiling, and more information is provided at Section 8 of this Policy about this. We will also need to use your personal data for purposes associated with our legal and regulatory obligations.
We have to establish a legal ground to use your personal data, so we will make sure that we only use your personal data for the purposes set out in this Section 4 and in Appendix 1 where we are satisfied that:
Before collecting and/or using any special categories of data we will establish an additional lawful ground to those set out above which will allow us to use that information. This additional exemption will typically be:
PLEASE NOTE: If we have previously told you that we were relying on consent as the basis of our processing activities, going forward we will not be relying on that legal basis unless we have said that are in this Policy.
PLEASE NOTE. If you provide your consent or explicit consent to allow us to process your personal data or your special categories of data, you can withdraw your consent to such processing at any time. However, you should be aware that if you choose to withdraw your consent we will tell you more about the possible consequences, including if this means that certain services (in particular where you have applied for a disabled registration ID Card pass) can no longer be provided).
As flagged above, we share data with other Merlin Group companies.
We also share the data with third parties, to help manage our business and deliver services. These third parties may from time to time need to have access to your personal data, and include:
Also, if we were to sell part of our businesses we would need to transfer your personal data to the purchaser.
We may use your personal data to send you direct marketing communications about our attractions, hotels, experiences or our related services. This will be in the form of email, post, SMS or targeted online advertisements.
Where we require explicit opt-in consent for direct marketing in accordance with the Privacy and Electronic Communications Regulations we will ask for your consent. Otherwise, for non-electronic marketing or where we can rely on the soft opt-in exemption under the Privacy and Electronic Communications Regulations, we will be relying on our Legitimate Interests for the purposes of GDPR as further detailed in section 4 and Appendix 1.
You have a right to stop receiving direct marketing at any time - you can do this by following the opt-out links in electronic communications (such as emails), or by contacting us using the details in Section 11.
We also use your personal data for customising or personalising advertisements, offers and content made available to you based on your visits to and/or usage of our attraction websites or other mobile applications, platforms or services, and analysing the performance of those advertisements, offers and content, as well as your interaction with them. We may also recommend content to you based on information we have collected about you and your viewing habits. This constitutes 'profiling', and more information is provided at Section 8 of this Policy about this.
Some entities in the Merlin Group, with whom we share your data, and our service providers who have access to your personal data, are located outside the European Union. We may also share your personal data overseas, for example if we receive a legal or regulatory request from a foreign law enforcement body. We will always take steps to ensure that any international transfer of information is carefully managed to protect your rights and interests, in particular we will either:
You have the right to ask us for more information about the safeguards we have put in place as mentioned above. Contact us as set out in Section 11 if you would like further information or to request a copy where the safeguard is documented (which may be redacted to ensure confidentiality).
'Automated Decision Making' refers to a decision which is taken through the automated processing of your personal data alone - this means processing using, for example, software code or an algorithm, which does not involve any human intervention. We do not carry out any automated decision making, however we do carry out profiling using automated processing to tailor marketing materials for a specific customer.
Where we have permissions to send a consumer marketing updates, we may use profiling to ensure that marketing materials are tailored to your preferences and to what we think you will be interested in. In certain circumstances it will be possible to infer certain information about you from the result of profiling, which could include special categories of personal data, but we will not do this unless we have obtained your explicit consent to do so.
As part of this application, we will ask you for information so that we can check to see whether you are eligible for a disabled registration ID card and for administration and granting of the disabled registration ID card. The personal information we collect about you is treated slightly differently depending on what type of information it is.
You will have explicitly consented to our use of the personal information relating to your disability and you have the right to withdraw consent (explained above). Depending on what personal information you choose to provide us, we will be collecting the following special categories of data from you:
Other personal information we will collect about you (but that is not special categories of personal data) is:
If you have made an application on behalf of a child or another adult, on the basis of a disability, then you will have explicitly consented to our use of the personal information that relates to the other adults or child's disability and you will have the right to withdraw consent (explained above). The information we collect is listed directly above.
As part of the application, you may also submit personal information about yourself (depending on whether you are carrying out the application for yourself or on behalf of another) and that we require in our legitimate interest. This includes the information list directly above.
Any personal information that is provided in and during the application process is used only for the purpose of reviewing the application and granting a disabled registration ID card.
We understand how important special categories of data is, so we will not share your special categories of data with any other person other than its supplier, Avius (registered in England and Wales with registration number: 05781390 and registered address at Dean Park House, 8-10 Dean Park Crescent, Bournemouth, Dorset, England, BH1 1HL ) who provide Merlin with survey and customer experience management software. Avius will only store the special categories of personal data for Merlin to use in its assessment of your application.
We will retain your personal data for as long as is reasonably necessary for the purposes listed in Section 4 of this Policy. In particular, where there has been no interaction from a consumer (e.g. a purchase, email open, newsletter sign up), a record will be archived after 1 year and deleted after 3 years.
Where we are required to do so to meet legal, regulatory, tax or accounting requirements, we will retain your personal data for longer periods of time, but only where permitted to do so, including so that we have an accurate record of your dealings with us in the event of any complaints or challenges, or if we reasonably believe there is a possibility of legal action relating to your personal data or dealings.
We maintain a data retention policy which we apply to records in our care. Where your personal data is no longer required and we do not have a legal requirement to retain it, we will ensure it is either securely deleted or stored in a way such that it is anonymised and the Personal Data is no longer used by the business.
With regard to the special categories of personal data we process as detailed under section 9 above (this includes the special categories of personal data stored by Avius) Merlin will destroy such data 4 weeks from receiving the special categories of personal data.
You have a number of rights in relation to your personal data. In summary, you have the right to request: access to your data; rectification of any mistakes in our files; erasure of records where no longer required; restriction on the processing of your data; objection to the processing of your data; data portability; and various information in relation to any automated decision making and profiling or the basis for international transfers. You also have the right to complain to your supervisory authority (further details of which are set out in Section 11 below). These are defined in more detail as follows:
To exercise your rights you can contact us as set out in Section 11. Please note the following if you do wish to exercise these rights:
The primary point of contact for all issues arising from this Policy, including requests to exercise data subject rights, is our Data Protection Officer. The Data Protection Officer can be contacted in the following way: Data.Protection@merlinentertainments.biz
If you have a complaint or concern about how we use your personal data, please contact us in the first instance and we will attempt to resolve the issue as soon as possible. You also have a right to lodge a complaint with your national data protection supervisory authority at any time. In the UK, the supervisory authority for data protection is the ICO (https://ico.org.uk/). We do ask that you please attempt to resolve any issues with us first, although you have a right to contact your supervisory authority at any time.
Our newsletters will be on their way to you soon!
Service is unavailable - try again in a moment.