Study finds 86 per cent of gambling sites breach GDPR
A study by researchers at Swansea University's GREAT Centre has accused online bookmakers and casinos of widespread breaches of UK data protection law through their use of cookie consent banners, with 86% of licensed British gambling websites found to be flouting GDPR rules. The findings raise concerns about "data surveillance" of customers and highlight what critics describe as a failure by the Information Commissioner's Office (ICO) to enforce compliance in the gambling sector, despite the regulator's broader success in getting most major UK websites to follow cookie regulations.
Of the 624 gambling websites tested, 24% offered no option to disable tracking software, including operators such as Hollywood Bets and Admiral Casino, while two-thirds, including Ladbrokes and William Hill, began collecting user data before consent was given. A small proportion (2%), including Dafabet, offered no consent choice at all. Researchers also identified widespread use of "dark patterns" designed to nudge users towards accepting data sharing, such as visually emphasising the least privacy-friendly option (60% of sites) and hiding the reject option behind an extra step (47%). Legal experts, including Ravi Naik of AWO, said the findings pointed to systemic non-compliance and criticised the ICO's lack of meaningful enforcement action against the sector.
- 86% of UK gambling websites found breaching GDPR cookie consent rules
- Two-thirds of sites collected user data before consent was granted
- Critics say the ICO has failed to enforce compliance in gambling
New here? Start with this
Online gambling firms in the UK are licensed to operate but must also follow separate data protection rules under the UK General Data Protection Regulation (GDPR). One key requirement is that websites must ask visitors for genuine consent before using cookies and tracking tools that follow their behaviour online, and must make it just as easy to refuse this tracking as to accept it. The Information Commissioner's Office (ICO) is the regulator responsible for enforcing these rules.
Researchers at Swansea University's GREAT Centre examined hundreds of licensed British gambling websites, including well-known bookmakers and casinos, to see whether their cookie consent banners actually complied with the law. Their study looked at issues such as whether sites collected data before users had made a choice, whether a "reject" option was offered at all, and whether design choices were used to steer people towards accepting more data collection than they might otherwise choose.
This matters because gambling companies hold sensitive information about people's spending and behaviour, and how that data is collected and used can affect both privacy and, in some cases, approaches to problem gambling. The findings also touch on wider questions about how effectively the ICO monitors and enforces data protection law within a specific, high-risk industry sector.
Both sides, in good faith
The strongest fair case each way — we don't pick a winner.
The case for
Privacy advocates and legal experts argue that the scale of non-compliance uncovered here, affecting the vast majority of licensed gambling sites, represents a serious and sustained breach of data protection rights that deserves urgent regulatory attention. They point out that gambling operators handle particularly sensitive behavioural data used to profile and target vulnerable customers, making early or non-consensual tracking and manipulative "dark patterns" especially harmful. From this perspective, the ICO's apparent inaction despite clear evidence amounts to a failure to protect consumers, and only firm enforcement, including fines, will change entrenched industry practice.
The case against
Others, including those familiar with regulatory practice and industry constraints, would note that cookie consent design is a notoriously grey area where technical shortcomings do not necessarily equate to deliberate wrongdoing, and that some data collection before explicit consent may be tied to legitimate purposes such as fraud prevention, age verification or responsible gambling safeguards rather than pure marketing surveillance. They might also argue that regulators must prioritise limited resources according to actual consumer harm, and that a single academic audit, however rigorous, should prompt engagement and proportionate correction with operators before being read as proof of systemic bad faith or regulatory neglect.
Business Cybersecurity Research Science Technology UK World
Read the full article at the source →
Originally published by The Guardian as “Online bookies accused of UK privacy breaches with use of cookie banners”.