Just 14% of UK Gambling Sites Are GDPR Compliant on Cookies, Study Finds
By Antonina Tupikova · Founder, iGaming Times3 min read
Researchers audited every one of the 624 gambling websites licensed in Britain and found dark patterns on 86% of consent banners, no reject option on 24%, and personal data being processed before consent on two-thirds. A second, randomised study then showed the most common banner design measurably pushes people into sharing data they did not want to share.
- The audit covered all 624 UK-licensed gambling websites and found that 86% of consent banners used at least one dark pattern, a design that nudges users towards accepting tracking
- Only 14%, or one in seven, of the sites audited were judged compliant with the General Data Protection Regulation
- Almost a quarter, 24%, offered no option to turn tracking off, and 67% processed personally identifiable data before consent was given
- A second study, a randomised experiment with 615 participants on a simulated gambling platform, found the most common banner design significantly increased acceptance of tracking and reduced the alignment between what users chose and what they said they wanted
- The paper is published open access in Computers in Human Behavior Reports and was preregistered, with the data and screenshots of every audited site posted to the Open Science Framework
An Audit of Every Licensed Site, Not a Sample
Researchers at Swansea University have published the first systematic audit of consent banners across the licensed British gambling market, and the compliance picture it describes is considerably worse than the internet at large. The paper, Consent banners, dark patterns, and GDPR infringements in online gambling, is by Jack McGarrigle, Jamie Torrance, Martyn Quigley and Simon Dymond, and appears in volume 23 of Computers in Human Behavior Reports under a Creative Commons licence.
The first of its two studies audited all 624 websites holding a British licence. It found that 86% of consent banners exhibited at least one dark pattern, that 24% offered no option to reject tracking at all, and that 67% processed personally identifiable data before any consent had been obtained. On the authors' assessment, only 14% of the sites were compliant with the General Data Protection Regulation. A previous study covering all types of website, not only gambling, put the equivalent non-compliance figure at 54%.
Reporting the findings, the Guardian broke down the design patterns the researchers recorded: visual emphasis on the least privacy-friendly option on 60% of sites, privacy-unfriendly settings pre-selected on 29%, and the reject option hidden behind a second layer on 47%. It named operators in each category, reporting that Hollywood Bets and Admiral Casino provided no option to turn tracking off, that Ladbrokes and William Hill were among the two-thirds harvesting data before consent, and that 2% of sites offered no consent choice at all, a group that included Dafabet.
Operators are permitted to process some data before consent for legitimate purposes, such as confirming that a customer is logging in from the United Kingdom. The researchers found data being sent to third-party analytics platforms used for marketing. Entain, which owns Ladbrokes, told the Guardian that any data collected before consent was not used for advertising or marketing. Evoke, which owns William Hill, declined to comment. Hollywood Bets and Admiral Casino did not respond to requests for comment.
The Second Study Tested Whether the Design Actually Changes Behaviour
The audit establishes prevalence. The experiment establishes effect. In the second study, 615 participants were randomly assigned to different consent banners inside a simulated gambling platform. The banner design most commonly found in the audit significantly increased acceptance of tracking, and produced significantly lower alignment between the choices participants made and the preferences they reported. The authors found no association between banner decisions and self-reported gambling harm severity.
That framing matters for how the findings are read. The researchers argue that data consent design is a consumer protection issue in gambling specifically, because of what they call the structural overlap between profitable behavioural patterns and harmful gambling behaviours. The goal of the data collection, they write, is "maintaining engagement and consumer losses".
Ravi Naik, legal director at the data protection specialist AWO, told the Guardian the report's findings "paint a picture of widespread and systemic non-compliance", and said the most striking element was "the light it casts on the failure of the Information Commissioner's Office to take meaningful enforcement action against the online gambling sector". AWO has previously acted for the campaign group Clean Up Gambling, whose complaint led to the ICO reprimanding SkyBet in 2024 for unlawfully sharing user data with advertising companies. SkyBet was not among the operators identified as breaching GDPR in this study.
An ICO spokesperson said the regulator was committed to "monitoring compliance across the UK's most visited websites and driving long-term adherence to lawful cookie practices", and would "take action where necessary to protect people's information rights". The ICO says its multi-year cookie project has brought 95% of the country's top 1,000 websites into compliance. The Gambling Commission has separately investigated a licensee over customer data held offshore.
The Gap Between 95% and 14% Is the Story
The ICO's own headline number and this study's headline number describe two different worlds. The regulator has concentrated its cookie enforcement on the most visited sites in the country, and by that measure it has been effective. Gambling sites are numerous, individually mid-sized, and collectively hold some of the most sensitive behavioural data in consumer services. A project scoped by traffic rank was always going to miss most of them. That is not a failure of will so much as a failure of targeting, but the practical result is a licensed sector where the compliant operator is the exception.
This Is a Second Regulator's Problem Landing on the Gambling Commission's Desk
Data protection is the ICO's remit, not the Gambling Commission's, and nothing in this paper changes that. But the Commission licenses these 624 sites, and it has spent the past two years building a case that operator data should be used to identify customers at financial risk rather than to market to them. A finding that two-thirds of licensees pass identifiable data to marketing analytics before consent sits directly across that argument. The Commission has shown it will act on how operators treat customers rather than waiting for another regulator, as it did in suspending two licences last week. Whether consent design is a social responsibility question or purely a privacy one is now a live choice.
The Methodology Is the Hard Part to Argue With
Industry responses to research of this kind usually start with the sample. There is no sample here. The audit covered the entire licensed population, the study was preregistered before data collection, and the screenshots of every audited site are published on the Open Science Framework alongside the analysis code. An operator that disputes its classification can point to its own screenshot. That degree of openness is rare in gambling research and it shifts the burden: the question is no longer whether the numbers are right, but what anybody intends to do about them.
Consent banners were designed as the mechanism that makes tracking lawful. On this evidence, across an entire licensed sector, they are mostly working as the mechanism that makes it look lawful.


