UK gambling websites face privacy scrutiny over cookie consent practices

UK gambling websites face privacy scrutiny over cookie consent practices

A new academic study has placed gambling websites under renewed privacy scrutiny after researchers examined how UK-licensed operators use cookie consent banners and tracking technologies. The research assessed 624 gambling websites and found widespread problems involving consent mechanisms, data processing and interface design. The findings should not be interpreted as a regulatory ruling against every operator named in the research. Rather, they represent the results of an academic audit that identified practices the researchers regarded as inconsistent with applicable data protection requirements.

The study was conducted by researchers associated with Swansea University and was published in Computers in Human Behavior Reports in August 2026. Its authors examined how users were presented with privacy choices and whether personal information was processed before consent had been obtained. The research also included an online experiment involving 615 participants to assess how different consent banner designs could affect user decisions.

The scale of the audit makes the findings significant for the wider online gambling sector. According to the study, only 14% of the websites reviewed met the researchers' GDPR compliance criteria while 86% appeared to breach at least one of the principles assessed. The study also found that 86% of consent banners displayed at least one so-called dark pattern, showing that the privacy issue extended beyond technical tracking and into the way choices were presented to users.

Consent choices were often difficult to exercise

At the centre of the research is the cookie banner, a familiar feature that gives visitors a choice about tracking and data use. While these notices may appear routine, their design can determine whether a visitor can easily reject non-essential tracking or whether accepting it becomes the most convenient option.

The study found that 24% of the 624 gambling websites did not provide users with an option to reject tracking. A further 2% reportedly provided no consent choice at all. These findings raise questions about whether users were always presented with a meaningful opportunity to exercise control over non-essential tracking technologies.

Researchers also identified several recurring design techniques that could influence user choices. On 60% of the websites, the option associated with lower privacy was visually emphasised. In 29% of cases, privacy-unfriendly settings were pre-selected by default. Meanwhile, 47% of banners reportedly placed the rejection option behind an additional layer rather than presenting it alongside the acceptance option.

Such practices are commonly discussed under the term dark patterns. Importantly, the existence of a dark pattern does not automatically establish that a website has broken the law. The legal significance depends on the specific design, the technology being used, the nature of the data involved and the circumstances in which consent is obtained.

The researchers nevertheless concluded that the prevalence of these practices deserved greater regulatory attention because they may make it harder for individuals to exercise genuine control over their information. The study's experimental component also found that the most common banner format increased acceptance of tracking while reducing the alignment between users' stated preferences and their eventual choices.

Personal data was sometimes processed before consent

Another major issue identified by the researchers concerned what happened before a user interacted with a consent banner.

More than two-thirds of the websites audited, equivalent to 67%, were found to process personally identifiable information before obtaining consent under the criteria applied by the study. The researchers identified persistent unique identifiers in outgoing requests before users had interacted with the banner and regarded the transmission of such information to third-party analytics and marketing systems as particularly significant.

There can, however, be legitimate reasons for certain forms of data processing before a consent decision. Gambling operators may need to establish basic technical or regulatory information, such as whether a visitor is accessing a service from a permitted jurisdiction. The central issue is whether the processing goes beyond what is necessary and whether non-essential tracking begins before valid consent has been obtained.

This distinction is particularly important in a regulated gambling environment. Operators routinely handle substantial amounts of information because of age verification, identity checks, payment controls, fraud prevention and responsible gambling requirements. Not every technical request made before consent therefore carries the same legal significance.

The study's concern was focused on processing that was considered unnecessary for the immediate operation of the website and which could involve third-party analytics or marketing technologies.

Major operators were among the examples reported

The research and subsequent reporting referred to several recognisable gambling brands in connection with different aspects of the audit. Ladbrokes and William Hill were among the operators identified in relation to data being processed before consent in the researchers' testing. The findings do not by themselves establish that every activity conducted by these companies constitutes unlawful processing or that the companies have been found liable by a court or regulator.

Ladbrokes is part of Entain's group of betting and gaming brands while William Hill operates under evoke plc. Both parent companies therefore have a direct corporate connection to major gambling brands discussed in the research. Entain has publicly maintained that information collected before consent on the relevant sites was not used for advertising or marketing, according to reporting surrounding the study. Evoke did not provide a comment in that reporting.

Hollywoodbets and Admiral Casino were also cited in reporting about the research in connection with the absence of an option to disable tracking. Dafabet was among the examples reported in connection with websites that did not offer a consent choice. Again, these references reflect the researchers' testing and reporting about specific website configurations rather than independent findings of legal liability by a court.

That distinction is important when discussing privacy research involving identifiable businesses. A study can identify an apparent compliance concern without determining the final legal position. Regulatory authorities or courts may reach different conclusions after examining the precise technical implementation, lawful basis for processing and other relevant evidence.

The Sky Bet case provides a separate regulatory precedent

The broader discussion also brings attention to earlier regulatory action involving Sky Betting and Gaming.

In September 2024, the Information Commissioner's Office issued a reprimand to Bonne Terre Limited, trading as Sky Betting and Gaming, after concluding that advertising cookies had been used to process personal information without consent during a specified period in 2023. The ICO stated that information was shared with advertising technology companies before users had the opportunity to accept or reject advertising cookies.

The regulator also stated that its investigation did not find evidence of deliberate misuse aimed at vulnerable gamblers. The company made changes to its practices in March 2023 before the later reprimand was issued. This case is therefore a useful example of how cookie and advertising technology practices can become a formal data protection issue without implying that every privacy concern found elsewhere has reached the same enforcement stage.

Sky Bet is not described as one of the operators accused of non-compliance in the new Swansea study. Keeping the two matters separate is important because the 2024 regulatory action was a specific enforcement decision while the 2026 research is an academic audit with its own methodology and scope.

The ICO says cookie compliance has improved

The study also arrives as the ICO reports substantial progress across the wider UK internet.

In December 2025, the regulator said that 979 of the UK's top 1,000 websites met its cookie compliance checks at the time of their latest testing. The ICO said its programme had focused on whether non-essential advertising cookies were placed before users could make a choice, whether rejection was as easy as acceptance and whether cookies were stored without consent.

The regulator subsequently stated in April 2026 that 99% of the UK's top 1,000 websites met its compliance standards for cookie banners following its focused work with industry. It also published final guidance on storage and access technologies covering cookies, tracking pixels and device fingerprinting while taking account of changes introduced by the Data (Use and Access) Act.

The contrast with the Swansea findings is striking, although the two exercises are not directly equivalent. The ICO's programme concerns the UK's most visited websites across sectors while the Swansea study focuses specifically on UK-licensed gambling websites. Different samples and methodologies mean the results should not be treated as a direct statistical comparison.

Why privacy carries particular weight in gambling

Privacy concerns can take on an added dimension in the gambling sector because behavioural information may reveal more than ordinary browsing preferences.

Online gambling platforms can observe patterns relating to frequency, timing and engagement. Those signals can be valuable for legitimate operational purposes, including fraud prevention and responsible gambling interventions. At the same time, behavioural information can raise concerns if it is used for advertising or other commercial purposes without an appropriate legal basis or meaningful user choice.

Researchers behind the Swansea study highlighted this overlap between commercially valuable gambling behaviour and behaviours that may also be associated with gambling harm. The study did not establish an association between banner decisions and self-reported gambling harm severity in its experiment, which is an important limitation that should not be overlooked.

That finding reinforces the need for careful language around the issue. Privacy research should not be used to claim that particular operators are intentionally targeting vulnerable individuals unless evidence specifically establishes that conduct. The more defensible conclusion is that gambling data can be unusually sensitive and therefore requires clear governance, transparent consent practices and appropriate restrictions on downstream use.

Legal and compliance questions remain significant

For operators, the implications extend beyond the appearance of a cookie banner. Effective compliance requires technical systems to behave consistently with what users are told at the point of consent.

A banner may appear compliant while tracking scripts begin transmitting information before a choice is registered. Conversely, a website may process limited information for a legitimate operational purpose while still restricting advertising or analytics activity until consent is given.

This creates a practical challenge for compliance teams. They must assess the entire data flow rather than relying solely on the language shown to customers.

The UK's current regulatory environment also continues to evolve. The ICO's updated storage and access technologies guidance reflects changes in the law and seeks to provide greater clarity around tracking technologies. For gambling businesses, maintaining a clear record of what technologies are deployed, what data they process and what legal basis applies will remain central to risk management.

What the findings could mean for gambling operators

The Swansea research is likely to increase pressure on gambling companies to review cookie banners, consent management platforms and third-party tracking integrations.

The most immediate compliance question is whether non-essential tracking is technically prevented until a valid choice has been recorded. Operators may also need to review whether the reject option is genuinely accessible, whether default settings respect privacy choices and whether personal information is transmitted to third parties before consent.

The research could also encourage closer scrutiny of vendor relationships. Analytics and advertising providers can sit outside the operator's own corporate structure yet still receive information through website scripts and tags. Understanding exactly where information travels is therefore essential to effective data governance.

Conclusion

The latest research does not establish that every operator named in connection with the study has committed a proven legal offence. It does, however, present a substantial evidence base for examining how gambling websites handle consent, tracking and user data. With 624 UK-licensed sites audited and only 14% meeting the study's GDPR compliance criteria, the findings point to a sector-wide issue that deserves careful regulatory and corporate attention.

For consumers, the central issue is straightforward. A consent banner is meaningful only when a person can understand the choice and exercise it without unnecessary barriers. For operators, the responsibility is broader because compliance must exist not only on the screen but also inside the technical systems that process information after the page loads.

The gambling industry's privacy obligations will therefore increasingly depend on the substance behind consent rather than the appearance of compliance. As regulators continue to refine their guidance and researchers examine how digital design affects behaviour, gambling companies face a clear incentive to make privacy controls transparent, technically reliable and demonstrably aligned with the choices presented to customers.

FAQs

What did the Swansea study examine?
The study audited 624 UK-licensed gambling websites to examine consent banners, tracking practices and potential GDPR infringements. It also used an online experiment with 615 participants to assess how different consent banner designs influenced user choices.

How many gambling websites did the researchers identify as having potential GDPR issues?
The study reported that 86% of the websites appeared to breach at least one of the GDPR principles assessed by the researchers. The authors reported that only 14% were compliant under their criteria.

What are dark patterns in cookie banners?
Dark patterns are interface designs that can steer users toward particular choices. In the study, examples included visually emphasising acceptance, pre-selecting less privacy-friendly settings and placing rejection controls behind additional steps.

What percentage of websites processed personal data before consent?
The study reported that 67% of the audited websites processed personally identifiable information before obtaining consent under the criteria applied by the researchers.

Did every website in the study break the law?
No. The research identified apparent GDPR non-compliance based on its methodology and criteria. It should not be treated as a court judgment or individual regulatory ruling against every named operator.

Which gambling brands were mentioned in reporting about the findings?
Reporting referred to Ladbrokes, William Hill, Hollywoodbets, Admiral Casino and Dafabet in connection with different aspects of the researchers' testing. Those references do not by themselves establish legal liability.

Was Sky Bet part of the Swansea study's alleged breaches?
No. Sky Bet was discussed separately because the ICO reprimanded Bonne Terre Limited, trading as Sky Betting and Gaming, in 2024 over the unlawful use of advertising cookies without consent during a specified period in 2023.

What does the ICO say about cookie compliance in the UK?
The ICO reported major improvements among the UK's most visited websites. It said 979 of the top 1,000 websites met its cookie compliance checks in December 2025 and reported a 99% compliance rate in April 2026 following its ongoing work.

Why is privacy especially important for gambling websites?
Gambling websites can process detailed behavioural and transactional information. Some of these data can be useful for regulatory or responsible gambling purposes but may also carry heightened privacy risks if used for marketing or other purposes without an appropriate legal basis.

What should gambling operators review following the study?
Operators should review cookie banner design, consent management systems, pre-consent tracking, third-party analytics integrations and the technical controls that prevent non-essential data processing before a valid choice is recorded.

Share

A highly motivated, results-driven, enthusiastic and ambitious writer. I can offer you well researched and high-quality article writing on any topic for your website or blog and can as well re-write your existing web content.