Some 86% of Gambling Commission-licensed gambling websites in the UK are breaching the General Data Protection Regulation (GDPR), according to a new audit from Swansea University’s Gambling Research, Education and Treatment (GREAT) Centre.
The researchers examined the cookie consent banners and network activity of all 624 casino and sports betting sites licensed by the Gambling Commission (UKGC), a full census of the regulated market rather than a sample. They found that a majority of operators were collecting and sharing personal data before users had given consent, and that many made it difficult, or in some cases impossible, to refuse tracking at all.
Data moving before consent is given
According to the audit, 67% of sites began gathering personally identifiable information before consent had been granted, sending unique user identifiers to third-party analytics and marketing services ahead of any choice being made. 24% of websites gave users no option to refuse tracking, and within that group, 2% showed no consent banner at all.
Only 29% of consent banners let users reject tracking as easily as they could accept it. On some sites, users needed as many as 15 clicks to decline tracking technologies, against a single click to accept.
Dark patterns tilt the click
The researchers attributed the imbalance to design choices they term dark patterns, layouts intended to steer visitors toward less privacy-friendly choices. 60% of sites made the accept button visually more prominent than the reject option. 47% hid the reject option behind an additional menu layer. 29% pre-selected settings that favoured data collection by default.
The GREAT Centre then ran a separate experiment with 615 UK online gamblers to test how banner design changes behaviour. Participants were shown a simulated betting site with one of six consent banner formats. The design most commonly used by gambling operators made users three to four times more likely to accept tracking than a neutral alternative offering a simple one-click choice.
Consent that doesn’t match what users want
Participants who accepted tracking rated their decision 4.4 out of 10 for reflecting their actual privacy preferences, compared with 7.9 among those who opted out, a gap the researchers said held regardless of a participant’s level of gambling risk. The result suggests that, for a large share of users, what operators record as consent does not match what the person actually wanted.
The GREAT Centre argues the data captured through these consent flows underpins personalised advertising and cross-site tracking across the gambling sector, alongside the UK’s £17.5bn online gambling market. The researchers also flagged that the same behavioural data used to identify commercially valuable customers can overlap with indicators associated with gambling-related harm, tying a data protection question directly to player safety.
Jack McGarrigle, the PhD researcher who led the study, said the results were consistent across the sector.
“We audited every licensed gambling site in the UK and the picture was stark. Most aren’t giving customers a fair choice about tracking. Some make it a single click to accept and up to fifteen to refuse. Our follow-up experiment showed this isn’t incidental; it works exactly as you’d expect, nudging people toward decisions they don’t actually agree with.”
McGarrigle carried out the research under the supervision of Professor Simon Dymond, Dr Martyn Quigley and Dr Jamie Torrance. The study is published in Computers in Human Behavior Reports.
The findings put consent banner design under compliance scrutiny. With 86% of the licensed market already flagged as breaching GDPR on the researchers’ own audit criteria, the open question is whether the Gambling Commission and the UK’s data protection enforcement bodies treat banner design as the next front in gambling oversight, alongside affordability checks and advertising rules, or leave operators to fix it on their own schedule.
Source: Swansea University









