purebetting.co.ukAll Guides

Swansea University Audit Uncovers GDPR Breaches Across Most Licensed UK Gambling Sites

Written by Drew Hartmann · Sep 7, 2026

Swansea University Audit Uncovers GDPR Breaches Across Most Licensed UK Gambling Sites

Researchers reviewing cookie consent mechanisms on multiple gambling websites during the Swansea University audit

Researchers at Swansea University’s GREAT Centre completed a detailed review of 624 licensed UK gambling websites in September 2026 and documented that 86 percent showed signs of breaching GDPR rules through their cookie consent banners and tracking setups. The audit examined how these sites handled user data collection and consent processes, revealing patterns that stand out against broader industry benchmarks.

Scope and Methodology of the Review

The team focused exclusively on operators holding UK licences, checking each site for compliance with data protection standards that require clear consent before personal information moves to third parties. They recorded instances where data flowed to marketing platforms prior to any user approval, noted the absence of straightforward rejection options, and catalogued visual designs that steered visitors toward accepting more tracking. This systematic approach allowed direct comparison with earlier studies that found roughly 54 percent non-compliance across general websites.

Key Compliance Shortfalls Identified

Two-thirds of the audited sites began collecting user data before presenting consent options, often routing that information straight to external marketing services. In addition, 24 percent of the platforms offered no visible way for visitors to turn off tracking, leaving users without practical control. Researchers also observed frequent use of dark patterns, including highlighted buttons that favoured privacy-invasive choices and rejection paths that required extra clicks or confusing navigation steps.

Comparison With Wider Web Practices

Those conducting the audit noted that the 86 percent figure sits well above the 54 percent non-compliance rate recorded in studies covering a broader range of websites. The gap suggests that the gambling sector has not kept pace with regulatory expectations even though the Information Commissioner’s Office has issued repeated guidance on cookie consent. Observers point out that the combination of pre-consent data transfers and limited opt-out tools creates a distinct profile of risk within this particular industry.

Close-up view of a typical dark pattern cookie banner used on gambling platforms

Regulatory Context and Ongoing Oversight

The findings arrive at a time when UK data protection authorities continue to monitor online services for GDPR adherence, with specific attention to sectors that handle large volumes of personal and financial information. The audit report references prior ICO statements that emphasise transparent consent mechanisms, yet the data from the 624 sites indicates that many operators have not fully implemented those expectations. Researchers compiled their observations into a study titled “Consent banners, dark patterns, and GDPR infringements in online gambling: Evidence from a systematic audit and online experiment,” which details the technical methods used to detect each type of breach.

One section of the work describes how third-party scripts activated immediately on page load for a majority of the tested domains, sending identifiers and browsing details before users could interact with any banner. Another section quantifies the proportion of sites that presented no decline button at all, forcing visitors either to accept defaults or leave the page entirely. These measurements provide concrete numbers that regulators can reference when assessing individual operator practices.

Implications for Licensed Operators

Operators named in the audit now face the task of aligning their consent flows with GDPR requirements, a process that may involve redesigning banner layouts, delaying third-party script execution, and adding clear rejection pathways. The study records that many sites already use complex tracking stacks for marketing and analytics, so adjustments will require coordination between technical teams and compliance staff. Because the review covered only licensed entities, the results highlight issues inside the regulated market rather than offshore platforms.

Conclusion

The Swansea University audit supplies a quantified snapshot of cookie and tracking practices among UK-licensed gambling sites as of September 2026. With 86 percent of the 624 examined domains showing potential GDPR shortfalls, including pre-consent data collection in two-thirds of cases and missing disable options in 24 percent, the sector stands apart from general web compliance averages. The documented presence of dark patterns further illustrates how interface design choices can affect user control over personal data. Regulators and operators alike now hold records that can guide future adjustments to consent mechanisms across the industry.