Researchers at Swansea University tested 624 British-licensed gambling websites and found that 86% appear to breach UK data protection law through the way they handle cookie consent, with two-thirds sending user data to third parties before any consent was given.
The audit, carried out by the university’s GREAT Centre and published on 6 September, examined the consent banners that appear when a user first lands on a licensed betting or casino site. It measured whether tracking started before consent, whether a genuine refusal option existed, and how the choices were presented.
67% of the sites transmitted data to third parties before the user had agreed to anything. 24% gave no option to turn tracking off. 2% presented no consent choice at all.
Design choices that push consent
The study also catalogued interface patterns that steer users toward accepting tracking. 60% gave visual emphasis to the privacy-unfriendly option, typically by making “accept all” more prominent than the alternative. 29% had privacy-unfriendly settings pre-selected by default. 47% placed the reject option behind a second layer, requiring an extra click to reach it.
Under the UK General Data Protection Regulation (UK GDPR) and the Privacy and Electronic Communications Regulations (PECR), non-essential cookies require prior consent that is freely given, specific and informed. Consent obtained through pre-ticked boxes or unequal choice architecture does not meet that standard, and setting cookies before the banner is answered fails it outright.
Sites named in the research as showing problems include Hollywood Bets, Admiral Casino, Dafabet, Ladbrokes and William Hill. Hollywood Bets sponsors Brentford FC and Dafabet sponsors Celtic FC. Sky Bet was not among the sites found in breach.
Operator responses
Entain, which owns Ladbrokes, said data collected before consent is not used for advertising or marketing purposes. Evoke, which owns William Hill, declined to comment. Hollywood Bets and Admiral Casino did not respond.
Ravi Naik, legal director at data protection firm AWO, said the results point to a sector-wide problem rather than isolated errors.
“The report’s findings paint a picture of widespread and systemic non-compliance.”
The researchers argued that the risk in gambling is different from other consumer sectors because of what the tracking data can be used for, citing the “structural overlap between profitable behavioural patterns and harmful gambling behaviours.” The same signals that identify a high-value customer, session length, deposit frequency, chasing behaviour, are the signals that identify a customer in difficulty.
The enforcement question
The Information Commissioner’s Office (ICO) reprimanded Sky Betting and Gaming in September 2024 after finding the operator set advertising cookies and shared data with adtech companies before users had a chance to accept or reject them. The regulator issued a reprimand rather than a fine.
The ICO says 95% of the UK’s 1,000 most-visited websites now comply with cookie rules following its compliance programme. That programme was aimed at the largest sites by traffic, which leaves most of the 624 licensed gambling domains in the Swansea sample outside its scope.
An ICO spokesperson said the regulator “will take action where necessary to protect people’s information rights.”
Two regulators have an interest here and neither owns the whole problem. The ICO enforces data protection but does not licence gambling operators. The Gambling Commission licences them and requires operators to identify customers at risk of harm, but does not police cookie consent. A site that profiles users through third-party trackers before consent sits in the gap between the two.
What operators face next
The study gives the ICO a named list and a measured baseline, which is the material a regulator needs to move from general guidance to specific enforcement. It also lands while the UK sector is already absorbing cost pressure, with the Treasury weighing a 40% slot machine duty at the October Budget.
For affiliates and marketing partners, the exposure runs further than the operator’s own domain. Pre-consent transmission to third parties implicates every recipient in the chain, including analytics providers, advertising exchanges and tracking partners that receive the data.
The ICO has signalled since the Sky Betting decision that it intends to widen its cookie compliance work beyond the top 1,000 sites. Whether the Swansea findings prompt formal action against named operators, or another round of correspondence and voluntary fixes, will show how far that intent extends into a sector where the data being collected has a documented link to consumer harm.
Source: Swansea University









