Swansea University Study Exposes GDPR Breaches Across British Gambling Websites
Written by Ines Beck · Sep 8, 2026

Swansea University Study Exposes GDPR Breaches Across British Gambling Websites

Researchers at Swansea University's GREAT Centre conducted an audit of 624 licensed British gambling websites, and the results showed that 86 percent of those sites committed at least one GDPR breach connected to cookie consent banners along with related data practices. The examination focused specifically on how these platforms handle user information during initial visits, and it uncovered patterns that set the gambling sector apart from broader web compliance trends.
Key Findings From the Audit Process
The audit process involved systematic checks on consent mechanisms across each site, and two-thirds of the platforms began collecting user data before obtaining proper consent. This practice appeared in well-known operators such as Ladbrokes and William Hill, where tracking started immediately upon page load in many cases. Observers note that such early collection violates core GDPR requirements because consent must precede any data processing activity.
Another 24 percent of the audited sites offered no clear option to disable tracking entirely, and this limitation left users without meaningful control over their information. Researchers documented instances where settings defaulted to maximum data sharing, and these configurations persisted even after users attempted to adjust preferences. The study compared these outcomes against general website standards, and it indicated that gambling platforms showed markedly lower compliance rates overall.
Dark Patterns in Consent Interfaces
Investigators identified manipulative design elements known as dark patterns on numerous platforms, and these included pre-selected invasive settings that steered users toward broader data collection. Such interfaces often presented options in ways that made refusal more cumbersome than acceptance, and the patterns appeared consistently across the sample. Data from the audit revealed that these tactics contributed directly to the high breach rate, and they highlighted gaps in how operators interpret regulatory guidelines.
Experts who reviewed the methodology confirmed that the sample covered a representative portion of licensed British operators, and the findings align with existing concerns about sector-specific data handling. The report emphasized that issues extended beyond isolated errors to systemic practices that affect user privacy at scale.
Broader Context of GDPR Requirements

GDPR establishes clear rules for cookie usage and data consent across the European Union and associated regions, and British law retains these standards following regulatory continuity measures. Consent banners must provide genuine choice without defaulting to acceptance, and they must allow users to reject non-essential tracking. The audit demonstrated that many gambling sites fell short on these points, and the discrepancies became evident through direct examination of live interfaces.
Those who analyzed the data found that poorer compliance in this sector compared with general websites points to unique operational pressures, yet the study itself stops at documenting the observed breaches without assigning causes. Figures from the project show the 86 percent breach rate stands notably higher than averages reported for other industries in similar reviews, and this gap underscores the need for targeted oversight in gambling.
Implications for Licensed Operators
Licensed operators now face potential regulatory scrutiny following the release of these findings, and the audit results have been shared with relevant authorities for further review. Sites that collected data prematurely or used restrictive consent designs may need to revise their banners and processing flows to align with legal standards. The study provides a factual baseline that regulators can reference when assessing ongoing compliance efforts across the sector.
According to the published summary, the audit represents one of the largest sector-specific examinations of its kind, and it offers concrete statistics on consent banner performance. People who manage gambling platforms have access to these details through public channels, and adjustments can follow directly from the identified issues.
Conclusion
The Swansea University audit supplies a detailed snapshot of current practices on British gambling websites, and it documents specific GDPR-related shortcomings in cookie handling and data collection. With 86 percent of sites showing at least one breach and clear examples involving major operators, the data presents a measurable picture of compliance levels in this area. Further monitoring and updates from regulatory bodies will determine how these findings translate into operational changes over time.