A recent study from Swansea University reveals a staggering 86% of UK-licensed online gambling websites are in violation of GDPR. The research highlights prevalent issues with cookie consent banners and data collection practices.
What Happened
Researchers from the Gambling Research, Education and Treatment (GREAT) Center at Swansea University conducted an audit of all 624 casino and sports betting websites licensed by the Gambling Commission in the UK. The findings, published in the journal Computers in Human Behavior Reports, indicate that a vast majority of these sites are non-compliant with data privacy regulations, specifically the General Data Protection Regulation (GDPR).
The study, led by doctoral student Jack McGarrigle and supervised by Professor Simon Dymond, Dr. Martyn Quigley, and Dr. Jamie Torrance, found significant breaches:
- Two-thirds (67%) of sites initiated the collection of personally identifiable data before users provided consent, sending unique user identifiers to third-party analytics and marketing platforms.
- Nearly a quarter (24%) offered no mechanism for users to refuse tracking whatsoever. This included 2% of sites that didn’t even display a consent banner.
- Only 29% of consent banners allowed users to reject tracking as easily as they could accept it. On some platforms, refusing tracking required up to 15 clicks.
- Most banners employed “dark patterns” – interface designs intentionally crafted to guide users towards the least private option. These tactics included visually emphasizing the accept button (60%), concealing the reject option behind a secondary layer (47%), and preselecting privacy-unfriendly settings (29%).
In a subsequent experimental phase, the research team examined the impact of these designs on user behavior. A sample of 615 UK online gamblers was presented with a simulated betting website featuring one of six different consent banners. The study revealed that the design most commonly used across the industry made participants three to four times more likely to accept tracking compared to a neutral, one-click alternative. Furthermore, participants who accepted tracking rated their choice as a significantly poorer reflection of their actual privacy preferences (4.4 out of 10, compared with 7.9 for those who rejected), suggesting that the design, rather than user intention, was the primary driver of the outcome. This effect was consistent across all levels of gambling risk among participants.
Key Details
- 86% of UK-licensed online gambling websites breach GDPR, according to a Swansea University study.
- 67% of sites collected personally identifiable data before obtaining user consent.
- 24% of sites provided no option for users to refuse tracking, with 2% lacking any consent banner.
- Only 29% of banners offered an equally easy option to reject tracking as to accept it.
- “Dark patterns” were prevalent, including visual emphasis on ‘accept’ (60%), hidden ‘reject’ options (47%), and preselected privacy-unfriendly settings (29%).
- Experimental results showed common banner designs made users 3-4 times more likely to accept tracking.
- Participants’ acceptance of tracking was often a poor reflection of their true privacy preferences.
Why It Matters
The researchers contend that the data collected through these non-compliant methods forms the foundation for personalized marketing and cross-web tracking of gambling customers. Critically, the characteristics used to identify commercially valuable players often overlap substantially with the behavioral markers associated with gambling harm. This suggests that the very practices breaching data privacy laws could also be contributing to and exploiting vulnerable individuals. The widespread non-compliance underscores a significant regulatory failure and raises serious concerns about consumer protection and responsible gambling practices within the UK online gambling industry. Jack McGarrigle emphasized the severity of the findings, stating, “Most aren’t giving customers a fair choice about tracking. Some make it a single click to accept a [sic].”