Swansea University Study Documents GDPR Breaches Across UK Gambling Websites
Written by Leon Franke · Sep 11, 2026

Swansea University Study Documents GDPR Breaches Across UK Gambling Websites

Researchers at Swansea University’s GREAT Centre completed a systematic audit of 624 licensed UK gambling websites and identified that 86 percent of them committed at least one breach of GDPR rules through their cookie consent banners. The findings, published in the journal Internet Interventions, show that two-thirds of the sites began collecting user data before obtaining consent and frequently transmitted that information to third-party marketing platforms.
Consent mechanisms on these platforms often lacked an option to reject tracking entirely, a shortcoming recorded on 24 percent of the audited sites including Hollywood Bets and Admiral Casino. The study also recorded widespread deployment of dark patterns designed to steer users toward accepting more invasive data settings rather than offering balanced choices.
Scope and Methodology of the Audit
The project examined every licensed gambling domain operating in the United Kingdom at the time of the review, creating a comprehensive dataset that allowed direct comparison with earlier research on general web populations. Earlier studies had reported a 54 percent violation rate across broader website samples, and the 86 percent figure recorded here therefore stands out as substantially higher.
Each site received evaluation against core GDPR requirements for cookie banners, including whether consent preceded data collection, whether rejection remained as easy as acceptance, and whether interface design introduced undue influence. The resulting report details both quantitative percentages and concrete examples drawn from the sample.
Key Patterns Identified in Consent Flows
Data collection before consent appeared in roughly two-thirds of the 624 sites, with many instances routing information to external marketing services immediately upon page load. Observers note that this sequence directly contravenes the requirement that consent must be obtained prior to processing personal data.
Twenty-four percent of the platforms provided no functional way to disable non-essential tracking, leaving visitors without a genuine choice. In several documented cases the only visible option advanced users toward acceptance while any rejection path remained hidden or non-functional.
Dark patterns took multiple forms across the sample. Some banners pre-selected the most permissive settings, others used repeated prompts that disappeared only after acceptance, and still others employed wording that framed refusal as a loss of site functionality. These techniques appeared consistently enough to qualify as a sector-wide characteristic rather than isolated exceptions.

Comparison With Broader Website Populations
The same research team placed its gambling-sector results alongside previously published audits covering thousands of general commercial and informational websites. The 32-percentage-point gap between the 86 percent rate and the 54 percent baseline indicates that structural differences in the gambling domain may contribute to elevated non-compliance.
One cited paper, “Consent banners, dark patterns, and GDPR infringements in online gambling: Evidence from a systematic audit and online experiment,” supplies the full methodological details and statistical tables supporting these comparisons. Readers can access the open-access article through ScienceDirect for additional figures and experimental follow-up data.
Regulatory Context and Sector Implications
UK data-protection rules require that cookie consent be freely given, specific, informed, and unambiguous. The audit results supply regulators with a quantified snapshot of current practice across an entire licensed industry. The Information Commissioner’s Office has previously issued guidance on consent mechanisms, and the Swansea findings provide fresh empirical material that can inform future enforcement priorities.
Because the study limited its scope to licensed operators, the reported percentages reflect activity within the regulated market rather than unlicensed or offshore sites. The authors note that the same audit protocol could be applied to other sectors for comparative purposes.
Conclusion
The Swansea University GREAT Centre audit establishes that 86 percent of 624 licensed UK gambling websites exhibited at least one GDPR violation in their cookie consent implementations, with pre-consent data collection, absent rejection options, and dark-pattern interfaces appearing at elevated rates compared with general web populations. The documented patterns supply concrete data points for ongoing regulatory oversight and for further academic examination of consent design across high-risk industries.