Swansea University Research Exposes Cookie Consent Failures Across UK Gambling Platforms

Casey Walter · Sep 6, 2026

Swansea University Research Exposes Cookie Consent Failures Across UK Gambling Platforms

Audit findings on gambling websites and data privacy compliance issues in the UK

Researchers at Swansea University's GREAT Centre conducted an audit of 624 licensed UK gambling websites, and the results show that 86 percent of these platforms commit at least one GDPR breach tied directly to cookie consent banners along with tracking practices. The study examined how these sites handle user data collection, consent mechanisms, and third-party sharing, revealing patterns that exceed the 54 percent violation rate identified in a separate broader web analysis. Data from the audit indicates systematic issues with transparency and user control options, particularly in how banners present choices for rejecting tracking.

Key Findings from the Audit Process

The examination focused on consent banner design and data transmission behaviors, where 24 percent of the audited sites provided no functional option to disable tracking at all. Sites such as Hollywood Bets and Admiral Casino appeared among those lacking basic rejection tools, which means users encountered banners that offered acceptance but left no clear path to opt out before data processing began. Observers note that this setup forces continued interaction without genuine choice, and the figures reveal that two-thirds of the platforms collected user information prior to obtaining any consent while routing that data to external marketing services. Ladbrokes and William Hill featured in examples where pre-consent transfers occurred, sending details onward without explicit approval.

Dark patterns emerged as another consistent element across many of the sites, with designs that highlighted privacy-invasive selections through color emphasis or required additional clicks to reach rejection buttons. These tactics, according to the researchers, complicate the process of declining tracking and often result in users defaulting to acceptance due to the added friction. The audit documented widespread use of such interfaces, which connect directly to the overall breach rate of 86 percent and highlight how interface choices influence compliance outcomes.

Comparison with Broader Industry Standards

When placed against the 54 percent breach rate from the larger web study, the gambling sector's 86 percent figure stands out for its concentration of issues. The Swansea team compared consent flows across categories and found that gambling platforms showed elevated instances of pre-consent data collection and incomplete opt-out pathways. This gap suggests sector-specific practices around marketing integrations may contribute to the higher numbers, although the report centers on factual audit metrics rather than causation claims. Experts have observed that the presence of third-party trackers activated before user input accounts for a significant portion of the documented problems.

Detailed breakdown of GDPR cookie violations on licensed gambling sites

One researcher who reviewed the dataset pointed out clusters of similar banner structures among the non-compliant sites, where visual priority given to accept buttons appeared repeatedly. The analysis covered a substantial sample size of 624 platforms, which provides a clear snapshot of current practices within the licensed UK market. Figures reveal that the combination of missing rejection options, early data transmission, and manipulative design elements creates multiple overlapping breaches rather than isolated incidents.

Regulatory Context and Site Examples

The audit results tie into existing GDPR requirements for clear consent and user control over personal data, with the documented cases showing direct conflicts in banner implementation. Sites named in the findings, including Hollywood Bets, Admiral Casino, Ladbrokes, and William Hill, illustrate specific instances of the identified problems without implying unique fault beyond the measured criteria. Data collection before consent and subsequent sharing with marketing platforms represent core areas where compliance fell short across two-thirds of the sample. Those who've studied the report note that these practices affect user data flows from the initial page load onward.

Additional patterns included banners that buried rejection paths behind multiple steps while keeping acceptance immediate, which aligns with the dark pattern descriptions in the study. The 24 percent without any disable function further compound the issue by eliminating even the possibility of opting out through the interface. Research indicates that such designs persist despite available technical solutions for compliant consent management, and the overall 86 percent rate reflects how these elements combine in practice.

Conclusion

The Swansea University audit delivers concrete data on GDPR-related cookie issues within the UK gambling sector, with 86 percent of 624 sites showing at least one breach area. Specific problems around absent opt-out choices, pre-consent tracking, and interface manipulation appear consistently in the results, exceeding rates seen in wider web examinations. The examples of individual platforms and the statistical comparisons provide a factual basis for understanding current compliance levels, while the documented patterns point to areas where banner and data handling processes intersect with regulatory standards.