A new study from the University of Swansea’s GREAT Centre reveals that the vast majority of licensed British gambling platforms are flouting GDPR rules on cookie banners, with many harvesting personal data before users have given consent and employing deceptive design tricks to push them toward acceptance.
Tracking Opt‑Out Missing on Quarter of Sites
Researchers examined 624 gambling websites and found that nearly a quarter – 24% – offered no way to turn off tracking software. This means advertisers can follow users across the web and serve them targeted marketing without a clear opt‑out. Notable absentees included Hollywood Bets, the current Brentford FC sponsor, and Admiral Casino, owned by the high‑street slot machine firm of the same name. In addition, 2% of the sites provided no consent choice at all, Dafabet – sponsor of Celtic FC – being one example.
Data Harvested Before Consent Is Given
Two‑thirds of the operators began collecting visitors’ information before any consent was obtained. Well‑known names such as Ladbrokes and William Hill were among those identified. While firms are permitted to gather certain data for legitimate purposes – like confirming a user is located in the UK – the study showed that the information was routinely forwarded to third‑party analytics platforms used for marketing and advertising.
Dark Patterns Nudge Users Toward Acceptance
The report highlights widespread use of “dark patterns” – subtle design cues that steer people toward sharing more data than they intend. Sixty percent of sites gave visual emphasis to the least privacy‑friendly option, 29% pre‑selected privacy‑unfriendly settings by default, and 47% hid the reject button behind a second click. Although these tactics alone may not breach the law, the same 86% of sites that displayed them also committed at least one GDPR violation, a figure far higher than the 54% observed in a broader survey of all website types.
Regulator Response and Industry Reactions
Ravi Naik, legal director at data protection specialist AWO, said the findings “paint a picture of widespread and systemic non‑compliance”. He added: “It is sadly no surprise to see the findings in this report, yet the consequences of non‑compliance are no less damaging.” He also warned that the report “casts light on the failure of the Information Commissioner’s Office to take meaningful enforcement action against the online gambling sector”.
An ICO spokesperson responded that the regulator is “committed to monitoring compliance across the UK’s most visited websites and driving long‑term adherence to lawful cookie practices”, adding: “We will take action where necessary to protect people’s information rights.”
Entain, which owns Ladbrokes, stated that any data gathered prior to consent was not used for advertising or marketing. Hollywood Bets and Admiral Casino did not reply to requests for comment, while Evoke, the parent of William Hill, declined to comment.
Why it Matters
The investigation underscores a growing tension between the drive for personalised online experiences and the fundamental right to privacy, especially in an industry already linked to harmful behaviours. When gambling platforms sidestep consent mechanisms, they not only risk hefty fines under GDPR but also expose vulnerable users to relentless marketing that can exacerbate problem gambling. Strengthening enforcement and demanding transparent, user‑friendly cookie designs could set a precedent for how all sectors handle data, ensuring that technological innovation does not come at the expense of individual rights.