A new study reveals that nearly nine out of ten licensed UK gambling websites are breaching data privacy laws by collecting user data before consent is given and using manipulative cookie banners.
Researchers from Swansea University’s GREAT Centre examined 624 UK-licensed gambling websites, including major operators such as Ladbrokes and William Hill. Their findings indicate that 86% of these sites appear to violate the General Data Protection Regulation (GDPR), which sets strict rules on how companies collect, store, and process personal data.
A significant concern is that two-thirds of the gambling sites started harvesting users’ data before obtaining explicit consent. While some early data collection is permitted for legitimate purposes, like verifying a customer’s location within the UK, the study found that data was often sent prematurely to third-party marketing and analytics platforms. This practice raises questions about the transparency and legality of data handling by these operators.
Nearly a quarter (24%) of the tested websites did not provide users with the option to disable tracking cookies. This lack of choice restricts players’ control over their personal information and online privacy. Notable operators failing to offer opt-out options included Hollywood Bets, sponsor of Brentford FC, and Admiral Casino, linked to the high-street slot machine company.
The research also uncovered widespread use of so-called “dark patterns” in cookie consent banners. These design tactics nudge users toward accepting data sharing by visually emphasizing the least privacy-friendly options, pre-selecting consent by default, or hiding the reject button behind additional clicks. For example, 60% of sites highlighted the most invasive option visually, 29% pre-selected tracking consent, and 47% concealed the reject option behind a second layer.
Such manipulative interfaces do not necessarily breach GDPR on their own, but the study found that the same proportion of sites using dark patterns—86%—also committed at least one GDPR violation. This rate is considerably higher than the 54% non-compliance rate found in a previous study covering all types of websites, not just gambling.
Legal expert Ravi Naik, legal director at data protection firm AWO, commented that the findings “paint a picture of widespread and systemic non-compliance” within the gambling sector. This highlights a significant gap between regulatory expectations and actual practices among online bookmakers and casinos.
The UK’s data privacy regulator, the Information Commissioner’s Office (ICO), is engaged in a multi-year effort to enforce GDPR compliance across websites, including cookie banner regulations. While the ICO reports progress with 95% of the top 1,000 UK websites now compliant, gambling operators appear to lag behind in meeting these standards.
For players and bettors, these practices mean their online activity and personal data may be tracked extensively without clear permission. This raises concerns about privacy, targeted advertising, and potential misuse of sensitive information. Players should be aware of their rights to control data sharing and consider using browser settings or privacy tools to limit tracking.
This study adds to ongoing concerns about player protection in online gambling, alongside recent calls for stricter advertising rules and safer gambling measures in the UK. For further information on UK gambling regulation and player safety, see our UK section and Responsible Gambling coverage.
Related to this, a recent House of Lords report has urged the UK government to introduce a near-total ban on gambling advertising to protect public health, highlighting the sector’s regulatory challenges.
Source: Gambling | The Guardian.
- Study Finds UK Gambling Sites Breach Privacy Rules - September 18, 2026
- Tribal Leaders Frustrated by CFTC Meeting on Sports Event - September 18, 2026
- Global Rivers Face Severe Drying, Impacting Communities - September 18, 2026