UK Gambling Operators Under Review Following Cookie Consent Audit

Jordan Müller · Sep 11, 2026

UK Gambling Operators Under Review Following Cookie Consent Audit

Audit report cover showing data privacy compliance statistics for UK gambling websites

Researchers from Swansea University’s GREAT Centre completed an audit of 624 licensed British gambling websites in September 2026, and the results showed that 86 percent had committed at least one GDPR breach connected to cookie consent banners. The study examined how operators handled user data collection through these banners, and it compared the outcomes against earlier findings from broader website reviews that reported a 54 percent violation rate.

Data collection before consent emerged as a central problem, with two-thirds of the sites, including major operators such as Ladbrokes and William Hill, transmitting user information to third-party platforms without first obtaining approval. Another 24 percent of the audited sites provided no mechanism for users to turn off tracking, which left visitors without basic control over their personal data. Researchers also documented widespread use of dark patterns, where privacy-invasive settings appeared pre-selected by default, and these design choices steered users toward accepting broader data sharing.

Audit Scope and Methodology

The audit focused exclusively on licensed British gambling platforms, and it applied consistent criteria to each site to measure compliance with GDPR requirements for cookie consent. Teams reviewed banner design, consent timing, data transmission practices, and the presence of options to reject tracking. Findings indicated that violations clustered around early data sharing and limited user choices, while the overall rate exceeded the 54 percent recorded in general website studies.

Observers noted that the gambling sector operates under additional licensing conditions from the UK Gambling Commission, yet the audit concentrated on data protection rules rather than betting regulations. The 624 sites represented a substantial portion of the licensed market, which allowed researchers to identify patterns across both large brands and smaller operators.

Key Issues Identified in the Findings

Two primary categories of non-compliance stood out during the review. First, many sites initiated data transfers to third parties before users interacted with consent banners, and this practice occurred even when banners appeared on the initial page load. Second, a significant share of platforms lacked any visible toggle or link to disable non-essential cookies, which meant users encountered only an accept option or no choice at all.

Close-up view of a cookie consent banner on a gambling website interface

Dark patterns appeared in various forms, such as pre-ticked boxes that enabled maximum data collection, and these elements remained consistent across multiple pages of individual sites. Researchers documented cases where rejecting cookies required several additional clicks compared with accepting them, and the imbalance affected how users navigated privacy settings. The audit report linked these design choices directly to the higher breach rate observed in the gambling sector.

Comparison With Earlier Website Studies

Previous reviews of general websites had placed the GDPR breach rate at 54 percent, yet the gambling-specific audit produced an 86 percent figure. This gap prompted further examination of sector-specific factors, including reliance on third-party analytics tools for marketing and user tracking. Data showed that gambling operators frequently integrated external platforms for advertising and performance monitoring, which increased the volume of data shared before consent.

Figures from the Audit of 624 UK gambling websites on cookie consent and GDPR compliance (2026) highlighted that the combination of pre-consent collection and limited rejection options appeared more frequently in this industry than in broader samples. Researchers attributed part of the difference to the commercial pressure on gambling sites to gather detailed user profiles for targeted promotions.

Response From Operators and Regulators

Following the release of the audit results, several operators began reviewing their consent mechanisms, although the study itself did not detail individual company statements. The UK Information Commissioner’s Office maintains oversight of GDPR enforcement, and the audit findings provided additional data for ongoing monitoring of online platforms. Licensed gambling sites must also satisfy requirements set by the Gambling Commission, which adds another layer of compliance expectations around data handling.

Experts observed that addressing the identified issues would require changes to banner design, data flow timing, and default settings across the audited sites. The report noted that 24 percent of operators offered no disable option, a figure that directly affects user autonomy under GDPR provisions.

Conclusion

The Swansea University audit established a clear record of cookie consent practices across hundreds of licensed British gambling websites, and the 86 percent breach rate underscored the scale of the identified problems. Specific issues around pre-consent data sharing, missing rejection options, and dark patterns formed the core of the findings, while the comparison to earlier 54 percent rates illustrated the sector’s distinct position. The results from September 2026 supply regulators and operators with detailed information on current compliance levels.