All Guides

UK's Betting Market Transforms Under Mobile Growth and Fresh Regulatory Frameworks

Written by Greta Washington · Sep 8, 2026

UK Gambling Websites Show High Rates of Data Consent Violations in University Audit

Overview of online gambling websites and data privacy concerns in the UK market

Researchers at Swansea University’s GREAT Centre completed an audit of 624 licensed British gambling websites, and the findings point to widespread problems with how these platforms handle user data under GDPR rules, particularly through cookie consent mechanisms. The study documented that 86 percent of the sites appeared to breach regulations, a figure notably higher than the 54 percent violation rate observed across broader website audits conducted elsewhere.

Data collection often began before any consent was secured, with two-thirds of the platforms sending information to third-party marketing services right away, while 24 percent provided no way for users to turn off tracking at all. Dark patterns appeared frequently too, including pre-selected options that favored invasive privacy settings and reject buttons placed in hard-to-find locations.

Scope and Methods Behind the Audit

The systematic review covered a large sample of licensed operators active in the British market, and the team examined each site’s cookie banners along with their data flows in detail. Observers note that the audit combined technical checks with an online experiment component to measure how users interacted with different consent designs, which helped isolate patterns that might otherwise go unnoticed in standard reviews.

Evidence from the work shows consistent issues across multiple categories of gambling platforms, from betting exchanges to casino-style games, and the researchers tracked how quickly data moved to external domains even when banners claimed to offer choices. Those who’ve studied similar compliance efforts know that timing of data transfer often reveals whether consent truly precedes collection.

Key Violations Identified Across the Sample

Several recurring problems stood out in the results, and the breakdown highlights the scale of non-compliance. Two-thirds of sites initiated data collection before obtaining user approval, frequently routing that information to marketing partners without clear permission. Another 24 percent gave visitors no functional option to disable tracking, leaving people with limited control over their own information.

  • Pre-ticked boxes that automatically enabled the broadest data sharing settings appeared on many pages.
  • Reject buttons were hidden behind multiple clicks or placed in low-contrast areas that reduced visibility.
  • Consent banners sometimes loaded additional trackers immediately, bypassing the stated preference process.

These practices align with what the full paper describes as dark patterns, and the audit links them directly to GDPR consent requirements that demand clear, affirmative action from users before data processing begins.

Comparison With Earlier Website Studies

The 86 percent violation rate stands out when placed against the 54 percent figure from wider internet audits, and researchers point to the gambling sector’s heavy reliance on targeted advertising as one contributing factor. Gambling platforms often integrate multiple analytics and marketing services, which increases the chance that data leaves the site before consent is recorded.

Detailed view of cookie consent interfaces used on gambling platforms

Yet the audit also notes that some operators met the standards, showing that compliance remains achievable even within this regulated industry. The gap between the gambling-specific rate and the general average suggests sector-specific pressures may drive the difference, though the study stops short of attributing causes beyond the observed technical patterns.

Regulatory Context and Next Steps

UK data protection rules require explicit consent before personal data moves to third parties, and the findings indicate many gambling sites have not aligned their banner designs with those standards. The paper titled Consent banners, dark patterns, and GDPR infringements in online gambling: Evidence from a systematic audit and online experiment provides the full methodology and dataset for further review by regulators or compliance teams.

Those monitoring the sector expect the results to inform future enforcement priorities, particularly around banner design and data-sharing practices that affect large numbers of users daily. The audit supplies concrete examples that authorities can reference when assessing whether individual operators meet current legal thresholds.

Conclusion

The Swansea University audit supplies a clear snapshot of current consent practices across hundreds of licensed UK gambling sites, and the documented patterns offer regulators and operators a factual basis for examining where changes are needed. With 86 percent of the sample showing apparent violations, the data underscores the distance between existing banner implementations and GDPR expectations around timing, choice, and transparency. Further analysis of the linked paper can help clarify which technical fixes have already proven effective on the minority of sites that passed the review.