UK Gambling Platforms Under Review After University Audit Exposes Consent Banner Shortfalls

Sam Berger · Sep 8, 2026

UK Gambling Platforms Under Review After University Audit Exposes Consent Banner Shortfalls

UK gambling websites cookie consent audit findings illustration

Study Details and Scope

Researchers at Swansea University’s GREAT Centre conducted a systematic audit of 624 licensed British gambling websites, and the results highlight patterns of GDPR non-compliance centered on cookie consent mechanisms, while the broader web landscape shows lower violation rates according to comparable reviews.

Data collection occurred across multiple platforms, and the team examined how each site handled user tracking requests before any interaction took place; findings indicate that practices such as immediate data transmission to third parties occurred on a majority of the sampled domains.

Key Violation Patterns Identified

Two-thirds of the audited sites began gathering user information prior to securing explicit consent, and this data often flowed directly to external marketing services without user knowledge or approval, whereas 24 percent offered no functional way for visitors to turn off tracking entirely.

Dark patterns appeared frequently throughout the sample, including pre-ticked boxes that favored extensive data sharing along with obscured reject buttons that required extra navigation steps; these design choices made privacy-protective options less visible compared to acceptance pathways.

The overall violation rate reached 86 percent among the gambling sites, a figure that exceeds the 54 percent rate documented in wider website audits conducted across different sectors.

Technical and Regulatory Context

GDPR requires clear affirmative action for consent, yet many gambling platforms relied on banners that collected identifiers through scripts loaded on page load, and this approach bypassed the need for prior agreement in numerous cases.

Observers note that the gambling industry’s reliance on targeted advertising creates pressure to maximize data flows early in user sessions, while the audit reveals how banner implementations often fail to meet the regulation’s transparency standards.

Dark patterns in online gambling cookie banners example

Additional checks showed that some sites pre-selected the most invasive privacy settings by default, and reject options sat hidden behind multiple clicks or required scrolling through lengthy policy text before becoming available.

Comparison With Broader Website Trends

When placed against the 54 percent violation rate found in general web studies, the gambling sector’s 86 percent rate stands out as notably higher, and this gap suggests sector-specific factors influence how consent tools get implemented.

The research team documented these differences through direct comparison of banner behaviors across both gambling and non-gambling domains, which allowed patterns unique to licensed betting platforms to emerge clearly from the dataset.

Research Publication and Further Analysis

The full study appears under the title Consent banners, dark patterns, and GDPR infringements in online gambling: Evidence from a systematic audit and online experiment, and it combines the audit results with controlled testing of user responses to different banner designs.

Experiment participants encountered variations of the observed consent flows, and outcomes showed measurable differences in how quickly users granted permissions when dark patterns were present versus when clear reject options appeared prominently.

Implications for Licensed Operators

Licensed British gambling websites operate under dual oversight from both data protection and gambling regulators, and the audit findings provide concrete examples of where current banner setups diverge from GDPR requirements.

Site operators may need to adjust script loading sequences and banner configurations to align with consent rules, while the documented use of pre-selected options and hidden reject paths offers specific areas for technical review.

Conclusion

The Swansea University audit supplies detailed evidence of consent banner practices across hundreds of licensed domains, and the resulting statistics on pre-consent data collection, missing disable options, and dark pattern prevalence offer a clear baseline for understanding current compliance levels in the sector. Future monitoring can build on these measurements to track whether adjustments occur following the publication of these results.