AI News Feed
Market watch
Companies

Study: 86% of UK licensed gambling websites breach GDPR cookie rules

A study finds 86% of UK licensed gambling websites appear to breach GDPR rules on cookie consent, with many using dark patterns and harvesting data before consent.

The research, conducted by academics at Swansea University's GREAT Centre, examined 624 licensed British gambling websites and found that 86% showed at least one apparent breach of the General Data Protection Regulation (GDPR), which governs how organisations collect, store and process personal data.

The findings focus on the “cookie” banners that appear when users first visit a website, asking which information they are willing to share. Nearly a quarter (24%) of the sites tested did not offer an option to turn off tracking software that allows advertisers to follow users around the web. Operators that failed to provide such an option included Hollywood Bets, sponsor of Brentford FC, and Admiral Casino, owned by the high-street slot machine firm of the same name.

Two-thirds of operators began harvesting users' data before obtaining consent, the study found. This included well-known operators such as Ladbrokes and William Hill. While operators are allowed to collect some data for legitimate reasons – for example verifying that a customer is logging on from the UK – researchers found that data was sent to third-party analytics platforms used for marketing.

Of the websites reviewed, 2% offered no consent choice at all, including Dafabet, sponsor of Celtic FC.

Researchers also found that the vast majority of bookies and online casinos use “dark patterns” to nudge people towards accepting data sharing. These included visually emphasising the least privacy-friendly option (60%), defaulting to privacy-unfriendly settings (29%) and hiding the reject option behind a second layer (47%). The study noted that such patterns do not necessarily constitute breaches in themselves, but 86% of sites had at least one apparent GDPR breach – significantly higher than the 54% figure found in a previous study covering all types of websites.

Ravi Naik, legal director at data protection specialist AWO, said the report's findings “paint a picture of widespread and systemic non-compliance.” He added: “It is sadly no surprise to see the findings in this report, yet the consequences of non-compliance are no less damaging. The most striking thing to arise from this report is the light it casts on the failure of the Information Commissioner's Office to take meaningful enforcement action against the online gambling sector.”

AWO has previously acted for the campaign group Clean Up Gambling, which raised concerns with the ICO about gambling firms' compliance. In 2024, SkyBet was reprimanded by the ICO for unlawfully sharing users' data with advertising companies, after the campaign raised concerns through AWO about an operator that treated a customer's early-morning gambling as a sign of harm and sent personalised inducements at those times. SkyBet was not among those claimed to have breached GDPR in the Swansea University report.

The study's authors said the goal of collecting users' data was “maintaining engagement and consumer losses.” They added: “The particular risk posed by data surveillance in online gambling, given the structural overlap between profitable behavioural patterns and harmful gambling behaviours, underscores the importance of data consent design as a consumer protection issue.”

An ICO spokesperson said the regulator was committed to “monitoring compliance across the UK's most visited websites and driving long-term adherence to lawful cookie practices” and would “take action where necessary to protect people's information rights.” Evoke, the owner of William Hill, declined to comment. Entain, the owner of Ladbrokes, said any data it collected prior to consent was not used for advertising or marketing. Hollywood Bets and Admiral Casino did not return a request for comment.