8 Sep 2026

Swansea University Audit Reveals Extensive GDPR Breaches Across UK Gambling Websites

Audit report graphic showing cookie consent issues on gambling sites

Researchers at Swansea University's GREAT Centre completed a detailed audit of 624 licensed UK gambling websites and identified GDPR breaches related to cookie consent banners plus data collection practices on 86 percent of those platforms. The findings highlight several recurring problems, including the collection of user data before any consent was obtained on roughly two-thirds of the sites examined, with specific examples involving operators such as Ladbrokes and William Hill.

Further issues surfaced when 24 percent of the audited sites offered no mechanism for users to disable tracking entirely, while many others employed manipulative interface designs known as dark patterns that pre-selected options favoring more invasive privacy settings. These patterns appeared frequently enough to stand out as a systematic concern rather than isolated errors, and the overall violation rate exceeded the 54 percent recorded across general websites in comparable reviews.

Breakdown of Consent and Data Practices

The audit process involved systematic checks of each website's cookie banners, data prompts, and backend collection routines, and the results showed that a majority began gathering information such as IP addresses, browsing behavior, and device details before users had a chance to review or approve those actions. Because consent must precede any such collection under GDPR rules, this timing mismatch created direct compliance gaps on hundreds of platforms at once.

Operators that pre-ticked boxes or buried opt-out controls behind multiple clicks effectively steered users toward broader data sharing, and the study documented these tactics on a substantial portion of the sample. In cases where no disable option existed at all, visitors had no practical way to limit tracking, which compounded the initial consent failures already observed.

Scale and Patterns Across the Sector

With 624 sites representing a broad cross-section of licensed UK operators, the 86 percent breach figure translates to more than 500 individual platforms carrying at least one documented issue. The concentration of problems around cookie timing and dark patterns suggests that similar design choices may have been adopted industry-wide, rather than arising independently at each company.

Data privacy compliance statistics chart for online gambling

Comparative data placed the gambling sector's non-compliance well above the 54 percent baseline seen in wider web audits, and observers note that the difference may stem from the commercial incentives tied to detailed user profiling in betting environments. Yet the study itself stops at reporting the observed practices without assigning motives, leaving regulators to interpret the business context behind the technical findings.

Regulatory and Operational Context

UK gambling sites operate under both Gambling Commission licensing and GDPR enforcement, so the identified breaches carry potential consequences from the Information Commissioner's Office as well as existing license conditions. The audit report, referenced in coverage from The News International, supplies a quantitative snapshot that regulators can cross-reference against their own monitoring data.

Because the sample covered only licensed operators, the results reflect the state of compliant-facing platforms rather than unregulated offshore sites, and this distinction matters when assessing how widespread the practices truly are within the regulated market. Follow-up actions could involve formal notices, required banner redesigns, or deeper investigations into data-handling policies at the largest operators.

Conclusion

The Swansea University audit supplies concrete numbers on cookie consent failures and dark pattern usage across hundreds of UK gambling websites, with 86 percent showing at least one breach and two-thirds beginning data collection ahead of consent. These figures stand in contrast to the 54 percent general-web average and single out specific mechanisms such as absent opt-out controls and pre-selected invasive defaults. The documented patterns provide regulators and operators alike with a clear baseline for measuring future compliance efforts.