Study finds majority of UK online gambling sites breach GDPR cookie rules
Research shows 86% of licensed British gambling websites violate GDPR privacy standards, often using deceptive cookie banners.
Researchers at the University of Swansea’s GREAT Centre tested 624 UK-licensed gambling websites and found that 86% breached GDPR rules on cookie consent. Nearly one-quarter of the sites did not provide an option to turn off tracking software, and two-thirds collected personal data before users gave permission, sending it to third-party marketing analytics. High-profile operators including Ladbrokes and William Hill were cited, while some sites, such as Dafabet, offered no consent mechanism whatsoever.
The study also documented extensive use of dark-pattern design, such as highlighting the least private option, pre-selecting invasive settings, or hiding the reject button. Legal expert Ravi Naik said the findings reveal systemic non-compliance and criticize the Information Commissioner’s Office for limited enforcement. The ICO reaffirmed its commitment to monitor and act against violations, though several operators declined to comment.
Why it matters
Non-compliant gambling sites may expose millions of users to unwanted tracking and privacy risks.
In this story
