Digital Shifts Redefine Betting Habits Across Britain as Fresh Data Emerges
Noah Schmitt · Sep 7, 2026

UK Gambling Websites Show High Rates of Cookie Consent Violations in University Audit

Researchers at Swansea University GREAT Centre examined 624 licensed UK gambling websites and identified GDPR compliance problems connected to cookie consent mechanisms and dark patterns in 86 percent of the sites reviewed. The audit focused on how these platforms handle user data through banners that request permission for tracking while the overall violation rate across general websites stands at 54 percent according to the same analysis.
Audit Scope and Key Findings
The study covered a wide selection of licensed operators and revealed that 24 percent of the sites provided no method for users to turn off tracking cookies, with Hollywood Bets and Admiral Casino listed among those examples. Two-thirds of the audited platforms collected personal information prior to obtaining consent and transmitted details to external marketing services, including Ladbrokes and William Hill. In addition 2 percent of sites offered no consent choice whatsoever, such as Dafabet. These patterns indicate systematic issues with how consent is presented and processed across the sector.
Data collection before user approval raises direct questions about adherence to GDPR rules that require clear affirmative action prior to processing personal details. Observers note the higher breach rate in gambling compared with other online categories points to industry-specific practices around marketing and third-party integrations that may require further regulatory attention.
Types of Violations Identified
Violations took several forms that researchers documented across the sample. Some platforms presented banners without reject options or made acceptance the only straightforward path while hiding decline buttons behind additional clicks. Others loaded tracking scripts immediately upon page visit regardless of user selection and forwarded data to advertisers before any choice was recorded. The audit also flagged instances where consent language remained vague or failed to specify data recipients which conflicts with transparency requirements under data protection regulations.
One section of the findings highlighted that nearly all breaches involved some element of dark patterns designed to steer users toward consent through interface design rather than neutral presentation. These included pre-ticked boxes, confusing wording, and unequal visual emphasis on accept versus reject choices. Researchers documented each instance with screenshots and technical logs to support the reported percentages.

Comparison With Broader Website Trends
The 86 percent figure stands notably above the 54 percent violation rate recorded across non-gambling websites in comparable checks. This gap suggests that licensed gambling operators may face unique pressures around data monetization and user acquisition that lead to shortcuts in consent flows. Figures from the audit indicate two-thirds of the gambling sites sent data to third parties before consent while general web studies typically show lower pre-consent sharing rates.
Those who've examined the results point out that the gambling sector's reliance on targeted advertising and affiliate networks could explain part of the difference yet the study itself stops short of attributing causes and instead presents the raw compliance data. The audit team cross-checked each site against current GDPR guidance on cookie banners issued by the Information Commissioner's Office.
Examples From Specific Operators
Hollywood Bets and Admiral Casino appeared in the 24 percent category where no disable option existed for tracking. Ladbrokes and William Hill fell into the group that collected and shared data prior to consent. Dafabet represented the 2 percent with no consent mechanism at all. The researchers selected these examples to illustrate the range of issues rather than to single out individual companies for enforcement action.
Each listed operator holds a UK license and operates multiple sites that the audit team visited during the review period. The findings do not indicate whether these practices have changed since the audit concluded or whether any operators have updated their banners in response.
Regulatory Context and Next Steps
UK data protection rules require websites to obtain valid consent before setting non-essential cookies and sharing data with third parties. The audit results arrive at a time when enforcement bodies continue to issue guidance on dark patterns and banner design. Operators found in breach may face requests for remediation or further investigation depending on how regulators prioritize the sector.
The Swansea University team released the aggregated statistics without naming every non-compliant site though they provided the percentages and representative examples. Follow-up work could involve deeper technical analysis of data flows or direct engagement with the licensed operators to verify current practices.
Conclusion
The audit supplies concrete numbers on GDPR compliance within the UK gambling sector and places those figures against a baseline from other websites. With 86 percent of the 624 sites showing at least one issue the study documents patterns around consent timing, tracking disablement, and third-party sharing that differ from general web standards. Future monitoring will determine whether these findings prompt adjustments in how licensed platforms manage cookie consent and data transfers.