Swansea University Audit Exposes Widespread GDPR Breaches Across UK Gambling Sites
Hugo Schmid · Sep 7, 2026

Swansea University Audit Exposes Widespread GDPR Breaches Across UK Gambling Sites

Researchers at Swansea University's GREAT Centre completed an audit of 624 licensed British gambling websites in September 2026, and the results showed that 86 percent committed at least one GDPR breach tied to cookie consent banners and data handling practices. The study focused exclusively on platforms operating under UK licenses, which allowed the team to isolate patterns specific to this regulated sector while comparing outcomes against earlier industry-wide benchmarks.
Audit Scope and Methodology
The GREAT Centre team examined every major category of licensed operator, from large bookmakers to smaller casino platforms, and they tracked how each site managed user data from the moment visitors arrived. Analysts checked consent mechanisms, data collection timing, and the presence of any pre-ticked options that could steer users toward sharing more information than intended. This approach produced a clear dataset that regulators and operators can now reference when assessing compliance levels.
Primary Violations Uncovered
Two-thirds of the audited sites began collecting user data before obtaining proper consent, a practice that directly contravenes GDPR requirements for explicit permission. Among the operators named in the findings were Ladbrokes and William Hill, both of which appeared on the list of platforms that gathered information ahead of any user agreement. In addition, 24 percent of sites offered no clear option for visitors to disable tracking entirely, leaving users without meaningful control over their personal details once they landed on the page.
Dark patterns surfaced across many of the non-compliant sites, including pre-selected settings that defaulted to invasive data sharing. These design choices made it harder for users to opt out, and they often appeared in prominent positions on cookie banners. Observers note that such patterns increase the likelihood of unintended data transfers to third-party advertisers or analytics providers.

Comparison to Broader Website Trends
The 86 percent breach rate stands notably higher than the 54 percent figure recorded in a wider study of websites across multiple sectors. Researchers cross-referenced their gambling-specific results with the general web audit, and the gap highlighted how heavily data-reliant gambling platforms may face unique compliance pressures. The difference suggests that cookie management standards in this industry have not kept pace with regulatory expectations applied elsewhere online.
Regulatory and Industry Context
UK data protection rules require clear, affirmative consent before any personal information moves to trackers or analytics tools. The GREAT Centre report documented repeated instances where gambling sites failed to meet this standard, and it flagged the use of layered consent flows that buried opt-out choices behind multiple clicks. Regulators now hold the detailed findings, which can support targeted enforcement actions or guidance updates aimed at licensed operators.
Those who have followed data privacy developments in gambling will recognize that cookie consent remains one of the most visible touchpoints between sites and users. The audit showed that even established brands continue to encounter difficulties translating legal requirements into functional website features, particularly when balancing commercial tracking needs against user rights.
Key Statistics at a Glance
- 86 percent of 624 audited sites recorded at least one GDPR breach
- Two-thirds began data collection before consent
- 24 percent lacked any disable-tracking option
- Pre-selected invasive settings appeared on a substantial portion of non-compliant pages
Conclusion
The Swansea University findings provide a concrete snapshot of current compliance levels within the licensed British gambling market. Operators now have specific data points they can use to review their own consent systems, while oversight bodies can reference the report when planning future checks. The study underscores that cookie banner design and data timing issues persist at scale, and it supplies regulators with a sector-specific benchmark that differs from general web trends. Further reviews may follow as both the industry and enforcement agencies respond to the documented patterns. The full study details remain available for public examination.