Swansea University Audit Highlights GDPR Issues in Cookie Banners Across UK Gambling Sites

Rosa Vogel · Sep 15, 2026

Swansea University Audit Highlights GDPR Issues in Cookie Banners Across UK Gambling Sites

Cookie consent banner on a typical UK gambling website interface

Researchers at Swansea University’s GREAT Centre conducted a detailed audit of 624 licensed British gambling websites in September 2026 and uncovered that 86 percent appeared to breach GDPR rules through their handling of cookie consent banners; the findings cover practices such as data collection prior to any user approval in roughly two-thirds of the examined sites along with the absence of clear options to turn off tracking tools on 24 percent of those platforms. The study also documented frequent deployment of dark patterns designed to steer users toward accepting tracking cookies while the overall violation rate stood notably higher than the 54 percent figure recorded in a separate review of general websites.

Scope and Methodology of the Examination

The audit focused exclusively on licensed operators within Britain and examined how each site presented its cookie consent mechanisms to visitors; researchers evaluated whether banners obtained valid consent before activating tracking scripts and whether they provided straightforward ways for users to reject non-essential cookies. Data collection before consent emerged as a recurring pattern across two-thirds of the sites while many failed to include balanced choices that allowed visitors to disable tracking software without extra steps or confusion. Observers note that these patterns persisted even though GDPR requires explicit and informed consent prior to processing personal data through cookies or similar technologies.

Prevalent Practices and Their Implications

Dark patterns surfaced throughout the reviewed platforms in forms that included highlighted accept buttons paired with less visible reject options or interfaces that required multiple clicks to adjust preferences; such designs appeared to influence user decisions toward permitting tracking in a majority of cases examined. The study identified these tactics on numerous sites operated by well-known companies including Ladbrokes, William Hill and Hollywood Bets where consent flows often defaulted to acceptance or obscured the path to full rejection. Figures from the audit indicate that these approaches contributed to the elevated violation rate when compared against broader web analyses that found lower percentages of similar issues.

Illustration of dark pattern design in online consent interfaces

Comparison with General Website Trends

Separate research into websites across various sectors revealed a 54 percent violation rate for cookie consent practices yet the gambling sector audit produced an 86 percent figure that exceeded that benchmark by a substantial margin; this difference suggests sector-specific factors at play in how operators structure their data collection interfaces. Researchers cross-referenced their results against established GDPR guidelines that mandate clear affirmative action from users before any non-essential tracking begins and noted that many gambling sites collected identifiers or behavioral data immediately upon page load. The gap between the two studies underscores how licensed gambling platforms handled consent mechanisms differently from the wider online environment during the same period.

Regulatory Context and Cited Examples

GDPR provisions require that consent banners offer genuine choice without deceptive elements and that no personal data processing occurs beforehand; the Swansea findings indicated departures from these standards on the majority of audited platforms. Reports referenced in coverage from The Guardian and additional outlets highlighted specific instances where major operators employed interface designs that limited user control over tracking preferences. Those patterns aligned with the broader statistics showing two-thirds of sites initiating data collection ahead of consent and nearly one-quarter omitting disable options entirely.

Conclusion

The audit results provide a factual snapshot of cookie consent operations on 624 licensed British gambling websites as of September 2026 with documented rates of apparent GDPR non-compliance reaching 86 percent alongside detailed breakdowns of pre-consent data gathering and limited rejection pathways. Researchers presented these observations through systematic review while contrasting them against lower violation levels found elsewhere on the web. The study supplies concrete data points that regulators and operators can reference when addressing consent banner configurations moving forward.