Swansea University Audit Exposes GDPR Issues Across UK Gambling Platforms
Taylor Krause · Sep 6, 2026

Swansea University Audit Exposes GDPR Issues Across UK Gambling Platforms

Researchers at Swansea University's GREAT Centre completed an audit of 624 licensed UK gambling websites that uncovered an 86 percent violation rate of GDPR rules tied to cookie consent banners and dark patterns, and the findings point to systematic problems in how these sites handle user data collection. The study examined practices ranging from data gathering before consent to the absence of any opt-out mechanisms for tracking, and it drew direct attention to major operators including Ladbrokes and William Hill among the two-thirds of sites that collected information prior to obtaining user approval.
Scope of the Examination
The audit focused exclusively on licensed platforms operating within the UK regulatory framework, and it applied consistent criteria to evaluate each site's consent mechanisms against GDPR standards. Observers note that the research team reviewed banner design, pre-selection defaults, and tracking options across desktop and mobile versions, while the methodology allowed direct comparison between gambling-specific sites and broader website categories that have undergone similar reviews in recent years.
Key Violations Identified
Two-thirds of the audited sites began collecting user data before any consent banner appeared, and this practice directly contravenes GDPR requirements that mandate clear affirmative action prior to processing personal information. An additional 24 percent of platforms offered no functional option to disable tracking cookies, which left users without meaningful control over their data once they entered the site. Pre-selected privacy-invasive options appeared frequently, and these defaults steered users toward maximum data sharing without requiring explicit confirmation at each step.
Dark patterns extended beyond simple consent flows, and the study documented cases where banners obscured rejection buttons or presented confusing language that made declining tracking more difficult than accepting it. Researchers documented these tactics across multiple operators, and the patterns emerged consistently enough to suggest industry-wide design choices rather than isolated errors.

Comparison With Broader Website Studies
The 86 percent violation rate stands notably higher than compliance figures reported in general website audits conducted across other sectors, and this contrast prompted the research team to examine whether gambling platforms face unique regulatory or commercial pressures that influence their design decisions. Data from the audit shows that non-gambling sites reviewed in parallel studies achieved markedly lower violation percentages, yet the Information Commissioner's Office has maintained claims of higher overall compliance across the wider digital economy.
Those who've examined the figures point out that the gambling sector's reliance on detailed user profiling for marketing and personalization may contribute to the elevated rate, and the study positions the findings as evidence that current enforcement mechanisms have not fully addressed consent practices in this specific domain. The report stops short of attributing intent, instead presenting the observed patterns as measurable outcomes from the 624-site sample.
Regulatory Context and Response
The Information Commissioner's Office oversees GDPR enforcement in the UK, and its public statements have emphasized improving compliance rates across industries, while the Swansea findings introduce new data specific to licensed gambling operators. Industry participants now face the task of aligning their consent systems with the documented shortcomings, and the audit provides a concrete benchmark against which future changes can be measured.
Updates to cookie banner designs have appeared on some platforms in the months following the initial audit release, and these adjustments include clearer rejection pathways along with removal of pre-checked tracking options. The study itself does not track subsequent modifications, yet it supplies the baseline data that regulators and operators can reference when assessing progress.
Conclusion
The Swansea University research supplies a detailed snapshot of consent practices on 624 licensed UK gambling websites, and the documented 86 percent violation rate highlights specific areas where GDPR requirements are not being met. The presence of dark patterns, pre-consent data collection, and absent opt-out mechanisms forms the core of the findings, while comparisons with other sectors underscore the distinct challenges within the gambling space. As operators and regulators review these results, the audit serves as a factual reference point for ongoing compliance efforts without prescribing particular remedies or timelines.