An audit of 624 gambling websites finds 86 per cent breaching data protection law at the cookie banner

Tech and AI

An audit of 624 gambling websites finds 86 per cent breaching data protection law at the cookie banner

By Staff Writer  |  7 September 2026

A windswept hawthorn bent over a limestone headland, with a white lighthouse on a rocky islet and a bay beyond under a bright sky

Nearly a quarter offered no way to refuse tracking at all, and two thirds began sending data to marketing platforms before the visitor had answered. The researchers frame consent design as a consumer protection issue, not a formality.

Researchers at Swansea University's Gambling Research, Education and Treatment Centre have audited the consent banners of 624 licensed British gambling websites and concluded that 86 per cent of them appear to have committed at least one breach of the UK General Data Protection Regulation. The paper, by Jack McGarrigle, Dr Jamie Torrance, Dr Martyn Quigley and Professor Simon Dymond, appeared in a peer reviewed journal in August 2026 under the title Consent banners, dark patterns, and GDPR infringements in online gambling, and its findings were reported on Sunday 6 September.

What the banners did

The cookie banner is the point at which a website asks a visitor which data it may collect. On 24 per cent of the sites audited there was no option to turn tracking software off at all, and on 2 per cent there was no consent choice of any kind. On two thirds of sites, data began flowing before the visitor had answered. Operators are permitted to collect some data before consent for legitimate purposes, such as confirming that a customer is connecting from the United Kingdom, but the researchers found the pre-consent data going to third party analytics platforms used for marketing.

Where a choice was offered, the design leant on the visitor. The least privacy friendly option was given visual prominence on 60 per cent of sites. Settings unfavourable to privacy were pre-selected on 29 per cent. On 47 per cent the option to reject was hidden behind a second layer of the banner. None of these patterns is a breach in itself, but the same proportion of sites that used them, 86 per cent, appeared to have broken the regulation in at least one respect.

A previous study across all kinds of website, not only gambling, put the breach rate at 54 per cent. The regulator says it has brought 95 per cent of the thousand most visited websites in the country into compliance on cookies and tracking.

Why the researchers think it matters more here

The centre's interest is not privacy for its own sake. Its argument is that the data harvested at the banner is what allows an operator to track a customer's behaviour and tailor inducements to it, and that the behaviour most profitable to the operator overlaps with the behaviour most harmful to the customer. The authors describe the purpose of the collection, in their words, as maintaining engagement and consumer losses.

The particular risk posed by data surveillance in online gambling, given the structural overlap between profitable behavioural patterns and harmful gambling behaviours, underscores the importance of data consent design as a consumer protection issue.

Jack McGarrigle, Dr Jamie Torrance, Dr Martyn Quigley and Professor Simon Dymond, the authors of the study, Swansea University

The Information Commissioner's Office, which has been running a multi year programme to bring websites into line on cookie consent, said it was committed to monitoring compliance across the most visited sites in the country and driving long term adherence to lawful cookie practices, and that it would take action where necessary to protect people's information rights. In 2024 it reprimanded one operator for sharing customers' data with advertising companies without a lawful basis; that operator was not among those the new study found in breach.

Two operators named in the report responded. The owner of one said any data collected before consent was not used for advertising or marketing. The owner of another declined to comment. Two others did not reply.

The point for anyone who runs a website

The findings are the researchers' and have not been tested by the regulator against any individual operator, so the 86 per cent is an audit figure and not a finding of liability. The mechanics, though, apply to any organisation with a consent banner: what fires before the visitor clicks, where it goes, and whether the reject button is as easy to find as the accept. Those three questions can be answered in a browser's developer tools in ten minutes, and this study is a reminder that other people are running exactly that test on sites that are not their own.