
Swansea University Audit Exposes Widespread GDPR Breaches in UK Gambling Websites

Researchers at Swansea University conducted a detailed audit of 624 licensed UK gambling websites and uncovered that 86 percent of them had committed at least one breach of GDPR rules tied to cookie consent banners along with broader data collection practices, and the findings were reported in September 2026 as regulators continued to scrutinize digital compliance across the sector.
The study examined how these platforms handled user data from the moment visitors arrived on their sites, and it revealed patterns that placed gambling operators behind many other industries when it came to meeting consent standards. Two-thirds of the audited sites began collecting user information before obtaining any form of consent, while 24 percent offered no clear way for users to turn off tracking mechanisms entirely.
Key Issues Identified in the Audit
Dark patterns appeared frequently throughout the sample, including pre-selected options that defaulted to invasive tracking settings and made it harder for users to opt out without extra clicks or navigation steps. Observers note these design choices often steer visitors toward sharing more data than they might intend, and the report documented how such tactics violated the requirement for clear, affirmative consent under GDPR.
Many sites failed to provide equal prominence to accept and reject buttons, which meant users encountered barriers when trying to limit data sharing. The audit also found inconsistencies in how cookie banners explained data use, leaving visitors without enough detail to make informed decisions before proceeding.
Brands Named in the Findings
Major operators including Ladbrokes and William Hill appeared among those flagged for compliance shortfalls, along with numerous other well-known platforms that together represent a significant portion of the UK market. The study did not single out any one company as uniquely problematic but instead presented the issues as widespread across the licensed gambling space.

According to the research, the gambling sector showed slower progress toward GDPR alignment compared with retail, news, and entertainment websites that had faced similar audits in previous years. This lag became evident when the team compared consent mechanisms side by side, and the results indicated that many gambling sites still relied on outdated banner designs that do not meet current regulatory expectations.
Scope and Methodology of the Research
The audit covered a broad cross-section of UK-licensed domains, ranging from large international betting groups to smaller specialist operators, and it focused specifically on cookie consent flows and initial data collection events. Researchers recorded each instance where data transfer began before consent, where opt-out paths were missing or obscured, and where interface elements nudged users toward broader data sharing.
Findings revealed that problems extended beyond simple banner text and often involved backend tracking scripts that activated regardless of user selection. Those who reviewed the data noted that such practices created ongoing privacy risks for anyone browsing or registering on the affected sites.
Regulatory Context in 2026
UK data protection authorities have increased enforcement activity around consent mechanisms since the start of the decade, and gambling operators now face additional pressure as the Information Commissioner's Office continues to issue guidance on dark patterns. The Swansea study arrives at a time when several sectors are updating their consent systems in response to recent fines and public scrutiny.
Although the report stops short of recommending specific penalties, it supplies regulators with a clear map of where licensed sites diverge from GDPR requirements. Industry observers expect the data to inform future compliance checks and possible corrective orders directed at the operators involved.
Conclusion
The Swansea University audit provides concrete evidence that a large majority of UK gambling websites still fall short on basic data protection standards, and the documented issues with consent timing, tracking controls, and interface design point to areas that operators will need to address to reach full compliance. As the regulatory environment evolves through late 2026, these findings offer a factual baseline for understanding where the sector stands today.