A landmark study published in early September 2026 has revealed that nearly nine out of ten licensed UK gambling websites are failing to meet basic data privacy requirements under the UK GDPR. Researchers from Swansea University’s GREAT Centre audited 624 gambling sites and found that 86% showed at least one clear infringement linked to how they handle cookie consent banners. The findings have sent a clear signal through the British online gambling industry and raised fresh questions about how operators collect, process and share player data.
This article provides a complete, independent analysis of the Swansea University study, explains what the results mean for players and operators, examines the use of dark patterns in consent design, and explores the wider regulatory and commercial implications for the UK online casino and sports betting market. Whether you are a player concerned about your personal data, an operator reviewing compliance, or simply following the latest UK gambling news, the information below is designed to give you a clear and practical understanding of the current situation. Players who want to compare current offers while staying informed can also check the latest welcome bonuses.
What the Swansea University Study Actually Found
The research team examined cookie consent mechanisms across a large sample of licensed UK gambling websites. Their audit focused on the banners that appear when a user first visits a site and the technical behaviour that follows. The results were striking. Only 14% of the sites tested met the standards that researchers used to assess GDPR compliance. The remaining 86% displayed one or more problems.
Among the most common issues were the absence of a genuine option to reject tracking, the collection of data before any consent had been given, and the use of design techniques that steered users towards accepting the most invasive settings. Nearly a quarter of the sites offered no way for visitors to turn off tracking software. Two-thirds of operators began sending information to third-party analytics and marketing platforms before the user had made any choice. Major household names including Ladbrokes and William Hill were among those identified as collecting data prior to consent.
The study also documented the widespread presence of what are commonly called dark patterns. These are interface designs that make the privacy-friendly option harder to find or less visually prominent. In the sample, 60% of banners emphasised the least privacy-protective choice, 29% pre-selected privacy-unfriendly settings, and 47% required users to click through additional steps simply to refuse tracking. While dark patterns are not automatically illegal, their heavy concentration on sites that already failed basic consent tests raised serious concerns about whether the industry is treating data protection as a genuine priority.
Why Cookie Consent Matters in Online Gambling
Cookie and tracking technology sits at the centre of how modern online casinos and sportsbooks operate. Operators use these tools to remember player preferences, keep accounts secure, measure the effectiveness of advertising, and personalise offers. Under the UK GDPR and the Privacy and Electronic Communications Regulations, however, most of this activity requires a clear, informed and freely given consent before it can take place.
Consent must be specific, unambiguous and as easy to withdraw as it is to give. Pre-ticked boxes, hidden reject buttons, or designs that push users towards acceptance do not meet the legal standard. The Information Commissioner’s Office has spent several years pushing websites across all sectors to improve their practices. According to the regulator, around 95% of the UK’s top 1,000 websites have been brought into line. The Swansea findings suggest that the licensed gambling sector is lagging significantly behind that wider benchmark.
For players the practical effect is that personal information — including browsing behaviour, device details and sometimes more sensitive indicators of activity — may be shared with advertising and analytics companies before any meaningful choice has been made. In an industry that already handles large volumes of financial and behavioural data, the stakes of poor consent design are particularly high.
Dark Patterns and the Design of Consent Banners
One of the most important contributions of the Swansea study is its detailed documentation of dark patterns in gambling consent interfaces. These techniques are not unique to gambling, but their prevalence in this sector appears higher than average. Common examples include:
- Making the “Accept All” button large, brightly coloured and immediately visible while the “Reject” or “Manage Preferences” option is smaller, greyed out or buried in a second layer of menus.
- Pre-selecting categories of cookies that go beyond strictly necessary functions.
- Using language that frames acceptance as the helpful or default choice and rejection as complicated or incomplete.
- Failing to offer a genuine one-click reject option at the first layer of the banner.
Researchers noted that these design choices often appeared together with technical behaviours that already breached GDPR principles. In other words, sites that used manipulative design were also more likely to start processing data before consent was obtained. The combination creates a situation in which many users may believe they have controlled their privacy settings when in reality tracking has already begun.
Impact on Major UK Operators and Brands
The study named several well-known operators in its findings. Sites linked to Ladbrokes and William Hill were among those that collected data prior to consent. Hollywood Bets and Admiral Casino were cited among the 24% of sites that offered no option to disable tracking. Dafabet was listed among the small number of sites that provided no consent mechanism at all. These are not obscure or unlicensed platforms. They are brands that hold UK Gambling Commission licences and, in some cases, sponsor major football clubs.
For the companies involved the reputational risk is obvious. Players who value privacy may begin to question whether they can trust the sites they use. Affiliates and media partners may face questions about the data practices of the operators they promote. Most importantly, the findings give the Information Commissioner’s Office and the Gambling Commission concrete material to examine. While the Swansea research is an academic audit rather than a formal regulatory investigation, it provides a clear map of where problems are concentrated.
What the Findings Mean for UK Players
If you use licensed UK online casinos or sportsbooks, the study has several practical implications. First, the cookie banner you see when you arrive on a site may not give you genuine control. Even if you carefully select only necessary cookies, some operators may already have started processing data. Second, the information collected can include details that feed into marketing profiles used across the wider advertising ecosystem. Third, the gap between the industry’s public commitment to responsible practices and the reality of consent design is wider than many players might expect.
There are steps individuals can take. Using browser settings or extensions that block third-party trackers can reduce the amount of data that leaves your device. Reviewing the privacy policies of operators you use regularly can reveal how long data is retained and with whom it is shared. Where a site offers a genuine preference centre, taking the time to adjust settings remains worthwhile even if the initial banner is poorly designed. Most importantly, players should remember that a UK Gambling Commission licence does not automatically guarantee strong data protection practices. For those comparing current promotions, the latest PlayOJO Casino UK review with its 80 wager-free spins offer is worth checking. You can also browse our selection of the best mobile casinos optimised for UK players.
Regulatory Context: ICO, GDPR and the Gambling Commission
The UK GDPR, retained and adapted after Brexit, sets the core rules for personal data processing. The Privacy and Electronic Communications Regulations add specific requirements for cookies and similar technologies. The Information Commissioner’s Office is the primary enforcer of these rules and has the power to issue fines, reprimands and enforcement notices. In recent years the ICO has focused heavily on cookie compliance across the wider economy.
The Gambling Commission regulates licensed operators under a separate framework focused on the licensing objectives: keeping crime out of gambling, ensuring fairness, and protecting the vulnerable. Data protection is not the Commission’s primary remit, yet poor privacy practices can intersect with social responsibility and anti-money laundering obligations. When operators collect detailed behavioural data, questions arise about how that information is used in risk assessments, marketing to vulnerable customers, and the overall treatment of players.
The Swansea findings arrive at a time when both regulators are under pressure to demonstrate effective oversight. The contrast between the ICO’s reported success with the top 1,000 websites and the 86% non-compliance rate in the gambling sample is likely to attract attention. Operators that have not already conducted thorough reviews of their consent mechanisms would be wise to do so promptly.
Broader Industry Implications and Commercial Risks
Beyond immediate compliance risk, the study highlights a deeper cultural issue. Many gambling operators have invested heavily in sophisticated marketing technology, personalisation engines and affiliate tracking systems. These tools deliver commercial value precisely because they rely on detailed user data. When consent frameworks are weak, the entire data supply chain becomes vulnerable to challenge.
There is also a competitive dimension. Operators that invest in genuine privacy-by-design may be able to differentiate themselves with players who care about data protection. Clear, easy-to-use consent tools and transparent privacy notices can become part of a brand’s responsible gambling and customer trust messaging. Conversely, continued reliance on dark patterns risks both regulatory action and long-term damage to player confidence.
International operators serving the UK market face the same rules. A licence from the Gambling Commission brings with it the expectation that UK data protection standards will be met. The study’s findings therefore extend beyond purely domestic brands to any site targeting British customers.
Practical Steps Operators Should Consider
While this article is not legal advice, the patterns identified by the Swansea researchers point to several areas that merit urgent attention. Consent banners should offer a clear, equally prominent reject option at the first layer. No non-essential cookies or tracking scripts should fire before a choice is recorded. Preference centres should allow granular control and make withdrawal of consent straightforward. Data flows to third-party marketing and analytics platforms need careful mapping and contractual controls. Regular independent audits of both design and technical implementation can help close the gap between policy and practice.
Training for product, marketing and compliance teams is equally important. Dark patterns often arise from a combination of commercial pressure and incomplete understanding of the legal requirements. Creating internal processes that treat privacy design as a core product requirement rather than a last-minute legal checkbox can reduce the risk of similar findings in future audits.
Looking Ahead: Enforcement and Industry Response
It remains to be seen how the Information Commissioner’s Office and the Gambling Commission will respond to the Swansea University research. The ICO has previously issued reprimands and taken action against individual operators for tracking technology failures. A sector-wide pattern of non-compliance may prompt broader guidance, targeted investigations or public statements. Operators that move quickly to remediate issues will be better placed if formal scrutiny follows.
For the wider online gambling industry the episode is a reminder that data protection is not a peripheral compliance topic. It sits at the intersection of player trust, marketing effectiveness and regulatory risk. As public awareness of privacy issues continues to grow, the operators that treat consent as a genuine user right rather than a design obstacle are likely to be the ones that build more sustainable relationships with their customers.
Frequently Asked Questions
What percentage of UK gambling sites failed the privacy audit?
The Swansea University study found that 86% of the 624 licensed sites examined showed at least one GDPR-related problem in their cookie consent practices. Only 14% were assessed as compliant under the criteria used by the researchers.
Did the study name specific operators?
Yes. Examples cited included major brands such as Ladbrokes and William Hill for collecting data prior to consent, Hollywood Bets and Admiral Casino among sites that offered no reject option for tracking, and Dafabet among those that provided no consent mechanism at all.
Are dark patterns illegal?
Dark patterns themselves are not automatically unlawful, but when they result in consent that is not freely given, specific or informed they can contribute to a breach of the UK GDPR. The combination of manipulative design and pre-consent data processing is particularly problematic.
What can players do to protect their data?
Players can use browser privacy settings and tracker-blocking tools, carefully review consent options where they are available, read privacy policies, and choose operators that demonstrate clearer data practices. Reporting persistent problems to the Information Commissioner’s Office is also an option.
Will the Gambling Commission take action?
Data protection is primarily the responsibility of the Information Commissioner’s Office. However, the Gambling Commission may consider how data practices intersect with social responsibility and licensing obligations. Both regulators are likely to monitor developments closely.
Does a UK licence guarantee good privacy practices?
No. A Gambling Commission licence confirms that an operator meets the Commission’s requirements on fairness, crime prevention and player protection, but it does not automatically ensure full compliance with UK GDPR cookie and consent rules.
Conclusion
The Swansea University study published in September 2026 has exposed a significant gap between the legal requirements of UK data protection law and the everyday practices of many licensed online gambling sites. With 86% of audited websites showing problems in their consent mechanisms, the findings challenge the industry to treat privacy design with the same seriousness it applies to other areas of compliance.
For players the message is clear: the cookie banners on gambling sites often do not deliver the control they appear to offer. For operators the message is equally direct: continued reliance on dark patterns and pre-consent tracking carries regulatory, reputational and commercial risk. The operators that respond by simplifying consent, respecting genuine choice and building privacy into their products from the start will be better positioned in a market where trust is becoming an increasingly important differentiator.
As the Information Commissioner’s Office and the wider regulatory community absorb these results, the coming months will show whether the industry can close the gap quickly or whether further formal intervention will be required. In the meantime, both players and operators would benefit from treating data protection not as a technical footnote but as a core element of fair and responsible online gambling in the United Kingdom.
Always gamble responsibly. If you need support, visit BeGambleAware.org or contact the National Gambling Helpline on 0808 8020 133.







