Swansea University Researchers Document Extensive GDPR Violations Across UK Gambling Platforms
Written by Sofia Bauer · Sep 7, 2026

Swansea University Researchers Document Extensive GDPR Violations Across UK Gambling Platforms

Researchers at Swansea University conducted an audit of 624 licensed UK gambling websites and discovered that 86 percent of them breached GDPR requirements through their cookie consent banners, a figure notably higher than the 54 percent rate identified in a wider analysis of general websites, according to the published study results.
The violations centered on several specific practices that prevented users from exercising proper control over their personal data, including the collection of information before any consent was obtained on two-thirds of the audited sites, with prominent operators such as Ladbrokes and William Hill among those identified in the findings.
Key Issues Uncovered in the Audit Process
Twenty-four percent of the sites offered no mechanism for users to disable tracking cookies entirely, while 2 percent provided no consent option whatsoever, leaving visitors with no way to opt out of data collection at the point of entry, as detailed in the research documentation.
Dark patterns appeared frequently throughout the sample, with pre-selected invasive settings that steered users toward accepting all tracking by default rather than presenting neutral choices, a tactic that researchers noted undermined the spirit of informed consent under GDPR rules.
Scope and Methodology Behind the Findings
The audit examined a substantial portion of the licensed UK gambling market, focusing specifically on how cookie consent mechanisms handled user data in line with privacy regulations, and the results highlighted patterns that extended across both major and smaller operators without significant variation by site size.
Data collection prior to consent occurred on approximately 414 sites within the 624 total, illustrating how common the practice had become in an industry where user tracking supports targeted advertising and personalized features, yet the study stopped short of attributing motives and instead recorded the technical compliance gaps.
Those conducting the review compared their outcomes directly against a broader 2023 investigation of web cookies that found violations on just over half of examined domains, underscoring that the gambling sector deviated sharply from average online practices in this area.

Regulatory Context and Industry Response Patterns
GDPR mandates clear, affirmative consent for non-essential cookies, and the Swansea findings showed that many gambling platforms continued to process data through banners that failed to meet those standards, prompting discussions among data protection observers about enforcement priorities in the sector.
Examples such as Ladbrokes and William Hill appeared in the report because their banners initiated tracking before users interacted with consent options, a detail that aligns with the two-thirds statistic and demonstrates how even established brands encountered the same compliance shortfalls as lesser-known sites.
Observers note that the absence of disable options on 24 percent of platforms left users navigating through layered menus or external links to adjust preferences, which often resulted in incomplete control over data flows during typical browsing sessions on these gambling domains.
Comparison with Broader Web Trends
The 54 percent violation rate from the wider study provides a benchmark that places the gambling industry results in sharper relief, revealing an elevated incidence of issues that researchers traced to the technical design of consent interfaces rather than isolated errors.
Pre-selected settings favoring maximum data collection appeared consistently enough across the audited group to suggest a systemic approach, though the study presented these as observable patterns without speculating on design intent behind the banners.
Figures from the audit indicate that the 2 percent of sites lacking any consent mechanism represented a smaller but still measurable subset where users encountered no opportunity to refuse tracking from the outset, further compounding the overall compliance picture.
Implications for Data Handling in Licensed Gambling Operations
Licensed operators in the UK operate under additional oversight from bodies such as the Gambling Commission, which intersects with data protection requirements, and the Swansea University results supply concrete data points that regulators and site administrators can reference when reviewing banner implementations.
The research, which audited 624 UK gambling sites on cookie consent and GDPR compliance, emphasized measurable outcomes like pre-consent data gathering and limited opt-out functionality without extending into enforcement recommendations.
Those reviewing the findings have noted that the higher violation rate compared with general websites points to sector-specific challenges in balancing user tracking needs with regulatory consent standards, though the study itself focused on documentation rather than causation analysis.
Conclusion
The Swansea University audit stands as a detailed record of current cookie consent practices across hundreds of UK gambling websites, with the 86 percent violation rate, specific examples from major operators, and identified dark patterns providing a factual baseline for ongoing discussions around GDPR adherence in this domain.
By quantifying issues such as pre-consent collection affecting two-thirds of sites and the lack of disable options on nearly a quarter, the research offers measurable insights that distinguish the gambling sector from broader web trends while remaining grounded in the audited sample of 624 platforms.