Online bookies accused of UK privacy breaches with use of cookie banners
A study reveals that nearly 9 out of 10 licensed British gambling websites are allegedly violating GDPR by mismanaging cookie consent, including harvesting data before user permission.
Intelligence analysis by Gemini 2.5 Flash

Research from the University of Swansea's GREAT Centre indicates widespread non-compliance with GDPR among UK online bookmakers and casinos, with 86% of sites appearing to flout data privacy rules. Many sites use 'dark patterns' to push users towards accepting tracking, and two-thirds reportedly collect data before consent is given, despite regulatory efforts by the Information Commis…
Imagine you go to a candy store, and before you even say what you want, they start putting candies in your bag and then try to make you buy more based on what they think you like. That's kind of what some online betting websites are doing with your computer's information. They're collecting details about you, like what you click on, without properly asking or letting you easily say no, which is against the rules about keeping your information private.
Analysis
The recent study by the University of Swansea's GREAT Centre casts a critical light on the online gambling industry's adherence to data privacy regulations in the UK. The findings suggest a systemic issue, with a vast majority of licensed British gambling websites seemingly in breach of the General Data Protection Regulation (GDPR). This widespread non-compliance, particularly concerning the handling of cookie banners and user consent, raises serious questions about consumer protection and the effectiveness of current regulatory oversight.
GDPR
The General Data Protection Regulation (GDPR) is a cornerstone of data privacy law in Europe, designed to give individuals greater control over their personal data. The study's assertion that 86% of gambling websites appear to be flouting these strict rules is alarming, especially given the sensitive nature of gambling data. Breaches include not offering an option to turn off tracking software, harvesting data before consent, and employing 'dark patterns' to manipulate user choices. These practices undermine the core principles of informed consent and data minimization that GDPR seeks to uphold, potentially exposing users to unwanted targeted advertising and data surveillance.
Information Commissioner’s Office
The Information Commissioner’s Office (ICO) is the UK's independent authority set up to uphold information rights in the public interest. The report's findings, particularly the high rate of non-compliance in the gambling sector, challenge the ICO's stated success in forcing 95% of the top 1,000 websites to comply with cookie regulations. Critics, such as Ravi Naik of AWO, argue that the ICO has failed to take meaningful enforcement action against the online gambling sector, despite previous concerns raised by groups like Clean Up Gambling. This suggests a potential gap in regulatory enforcement, allowing a significant industry to operate with apparent disregard for established privacy laws.
University of Swansea
The research conducted by the University of Swansea's GREAT Centre provides the empirical basis for these accusations. By testing 624 gambling websites, the study offers a comprehensive snapshot of the industry's practices. The researchers' methodology, which identified specific breaches like pre-consent data harvesting by major operators such as Ladbrokes and William Hill, lends credibility to the claims of systemic non-compliance. Their conclusion that the goal of collecting user data is often linked to "maintaining engagement and consumer losses" highlights the ethical dimension of data surveillance in an industry where profitable behavioral patterns can overlap with harmful gambling behaviors, underscoring the importance of robust data consent as a consumer protection issue.
Key points
- Nearly 9 out of 10 (86%) licensed British gambling websites appear to violate GDPR rules regarding cookie consent.
- A quarter of tested sites did not offer an option to turn off tracking software, and two-thirds harvested data before consent.
- Many operators use 'dark patterns' to nudge users into accepting privacy-unfriendly settings.
- The Information Commissioner's Office (ICO) is accused of failing to take meaningful enforcement action against the sector.
- Researchers suggest data collection aims to maintain engagement and consumer losses, linking it to harmful gambling behaviors.
Increased public awareness and regulatory pressure could force online gambling operators to adopt more transparent and compliant data practices, leading to stronger consumer privacy protections. This could foster greater trust in the industry and encourage a more ethical approach to digital marketing and user engagement.
If regulatory enforcement remains insufficient, the widespread non-compliance could persist, leading to continued data privacy breaches and erosion of consumer trust. This might result in more aggressive data surveillance tactics, potentially exacerbating issues related to problem gambling and exposing users to unwanted, targeted advertising.
Market signals
- ENT The study implicates Ladbrokes, owned by Entain, in widespread GDPR non-compliance, posing regulatory risk for the company.
AI-generated analysis of potential market relevance. Not financial advice.



