Study finds 86 per cent of gambling sites breach GDPR
A study by researchers at Swansea University's GREAT Centre has accused online bookmakers and casinos of widespread breaches of UK data protection law through their use of cookie consent banners, with 86% of licensed British gambling websites found to be flouting GDPR rules. The findings raise concerns about "data surveillance" of customers and highlight what critics describe as a failure by the Information Commissioner's Office (ICO) to enforce compliance in the gambling sector, despite the regulator's broader success in getting most major UK websites to follow cookie regulations.
Of the 624 gambling websites tested, 24% offered no option to disable tracking software, including operators such as Hollywood Bets and Admiral Casino, while two-thirds, including Ladbrokes and William Hill, began collecting user data before consent was given. A small proportion (2%), including Dafabet, offered no consent choice at all. Researchers also identified widespread use of "dark patterns" designed to nudge users towards accepting data sharing, such as visually emphasising the least privacy-friendly option (60% of sites) and hiding the reject option behind an extra step (47%). Legal experts, including Ravi Naik of AWO, said the findings pointed to systemic non-compliance and criticised the ICO's lack of meaningful enforcement action against the sector.
- 86% of UK gambling websites found breaching GDPR cookie consent rules
- Two-thirds of sites collected user data before consent was granted
- Critics say the ICO has failed to enforce compliance in gambling