All Guides

Swansea University Audit Exposes GDPR Compliance Gaps Across UK Gambling Sites

Written by Olivia Günther · Sep 8, 2026

Swansea University Audit Exposes GDPR Compliance Gaps Across UK Gambling Sites

Researchers reviewing cookie consent banners on gambling websites during a systematic audit

Researchers at Swansea University’s GREAT Centre completed a systematic audit of 624 licensed British gambling websites and identified that 86% appeared to breach GDPR requirements, with the majority of problems centred on cookie consent banners; this figure stands notably higher than the 54% violation rate recorded in wider website examinations, and the findings come from a detailed paper titled “Consent banners, dark patterns, and GDPR infringements in online gambling: Evidence from a systematic audit and online experiment”.

The audit examined how these platforms handled user data collection through consent mechanisms, and it revealed several recurring patterns that triggered regulatory concerns; two-thirds of the sites gathered user information before securing proper consent, frequently routing that data to third-party marketing platforms, while 24% provided no mechanism at all for users to turn off tracking.

Breakdown of Consent Banner Problems

Consent banners on the audited sites often featured design choices that steered users toward accepting data collection, and these included pre-selected options that favoured privacy-invasive settings along with reject buttons positioned in ways that made them difficult to locate or use; such approaches fall under the category of dark patterns, which the study documented as widespread across the sample.

Observers note that the 86% violation rate emerged after a structured review process that checked each site against GDPR consent standards, and the researchers recorded instances where data transfers occurred immediately upon page load before any user interaction took place; this practice directly contravenes requirements that consent must be obtained prior to processing personal information.

Comparison With Broader Industry Data

Data from general website audits shows a 54% violation rate across various sectors, yet the gambling-specific findings reached 86%, and this gap highlights how licensed operators in this regulated market still encountered significant compliance shortfalls during the review period; the study links many of these issues to the technical setup of consent tools rather than intentional policy decisions.

Close-up view of a cookie consent interface showing pre-selected options and hidden reject buttons

Those who conducted the audit also examined how third-party scripts activated during the consent process, and they found that marketing platforms received data transmissions even when users had not yet interacted with the banner; this occurred because many sites loaded tracking code by default, bypassing the intended protective function of the consent step.

Dark Patterns in Practice

Dark patterns documented in the research included interfaces that highlighted an “accept all” button while placing the option to reject cookies behind additional clicks or in smaller text, and the study recorded cases where pre-ticked boxes assumed agreement to data sharing with multiple external partners; these design elements appeared across a substantial portion of the 624 sites reviewed.

The paper further details that 24% of sites offered no visible way to disable non-essential tracking, which left users without a straightforward method to limit data collection; researchers cross-checked these observations against GDPR articles that require clear, affirmative consent and equal ease of acceptance or refusal.

Evidence gathered during the audit shows that many platforms sent identifiers and behavioural data to external domains within seconds of a visitor arriving, and this happened irrespective of whether the consent banner had been acknowledged; the frequency of such transfers contributed directly to the overall violation count.

Regulatory Context and Next Steps

UK gambling operators operate under both gambling commission licensing and data protection rules, and the study findings indicate that cookie banner practices represent an area where alignment with GDPR standards requires further attention; the research team presented their methodology and results in the linked academic paper for wider scrutiny.

According to the published work, the audit covered a representative selection of licensed British sites, and the patterns identified suggest that similar issues may exist beyond the sampled group; the researchers recommend that operators review their consent implementations to ensure data collection occurs only after valid user agreement.

Conclusion

The Swansea University audit provides a clear snapshot of current consent practices on UK gambling websites, and it establishes that 86% of the examined platforms showed signs of GDPR non-compliance centred on banner design and data handling; the documented use of dark patterns, pre-consent data transfers, and absent rejection options forms the core of the reported issues, while the contrast with the 54% rate from general studies underscores the sector-specific findings. The full details remain available in the academic paper “Consent banners, dark patterns, and GDPR infringements in online gambling: Evidence from a systematic audit and online experiment” for those seeking the complete methodology and dataset references.