Britain's Betting Sector Shows Fresh Patterns in Player Habits and Regulatory Adjustments

Theo Neumann · Sep 8, 2026

UK Gambling Websites Show High Rates of Cookie Consent Shortcomings in New Audit

UK online gambling websites displayed on multiple screens with cookie consent banners visible Researchers at Swansea University’s GREAT Centre conducted a systematic audit of 624 licensed UK gambling websites and uncovered that 86 percent displayed at least one apparent GDPR violation tied to cookie consent banners. The examination focused on how these platforms handle user data collection through tracking technologies and revealed patterns that exceed the 54 percent violation rate observed across websites in general. The study documented specific practices that triggered the findings. Two-thirds of the sites began collecting user data and often routed it to third-party marketing platforms before securing any form of consent. Observers note that this sequence directly contravenes requirements under GDPR for obtaining permission prior to processing personal information.

Key Patterns Identified Across the Sample

Further breakdowns showed that 24 percent of the audited sites offered users no mechanism to disable tracking cookies at all. Examples include platforms such as Hollywood Bets and Admiral Casino where the consent interfaces lacked any reject or disable options. In 2 percent of cases sites provided no consent banner whatsoever as seen with Dafabet leaving visitors with no visible choice regarding data collection. Dark patterns appeared frequently throughout the sample. These design elements steer users toward accepting tracking through visual emphasis on accept buttons or repeated prompts that obscure refusal paths. The audit catalogued these tactics as part of the broader set of apparent violations. Data from the project links directly to the peer-reviewed paper titled Consent banners dark patterns and GDPR infringements in online gambling: Evidence from a systematic audit and online experiment available through ScienceDirect. The work combines the website review with experimental elements that test user responses to different banner configurations.

Comparison With Broader Web Landscape

The 86 percent figure stands notably above the baseline violation rate recorded for websites outside the gambling sector. Researchers compiled the gambling-specific sample from licensed operators only which means the results apply strictly to entities already subject to UK regulatory oversight. This distinction matters because licensed operators must also satisfy additional standards from bodies such as the Gambling Commission alongside data protection rules. And yet the overlap between gambling licensing and GDPR compliance creates a single point of accountability for these platforms. When cookie banners fail to meet consent standards the issue sits at the intersection of consumer protection and data privacy frameworks. Close-up view of cookie consent pop-up on a gambling website interface Those who examined the raw data found that many violations clustered around the timing of data transfers. Third-party scripts activated immediately upon page load in numerous instances sending identifiers to external domains before any user interaction occurred. This automatic handoff formed one of the most common apparent breaches recorded in the audit.

Regulatory Context and Next Steps

UK data protection authorities have previously issued guidance on consent mechanisms that emphasises clear affirmative action and equal ease of refusal. The Swansea findings supply a sector-specific snapshot that regulators can reference when prioritising enforcement actions. Because the sample covers hundreds of licensed sites the results offer a representative view rather than isolated case studies. People who operate gambling platforms must now decide how to adjust their consent flows in response to these documented patterns. Adjustments could involve redesigning banner layouts removing pre-consent data calls and ensuring every user receives functional reject options. The ball remains in the operators court to align practices with the standards already outlined in GDPR. The audit results emerged at a time when data protection remains a standing priority for both national and European regulators. As requirements continue to evolve through 2026 and beyond licensed operators face ongoing expectations to maintain compliant consent systems across all user touchpoints.

Conclusion

The Swansea University audit provides a clear factual record of cookie consent practices across 624 UK gambling websites. With 86 percent showing at least one apparent GDPR issue and specific examples of missing reject options pre-consent data collection and dark patterns the findings supply concrete data for further review. Observers and regulators alike can use these figures to track progress as platforms implement changes. The study stands as a reference point for understanding how consent mechanisms function within one regulated sector.