Reported by 1 source

The short version

  • An academic study found that 86% of tested UK gambling websites violated GDPR rules regarding cookie banners and data collection.
  • Many operators used design tactics to nudge users toward accepting tracking, while others harvested data before explicit consent was provided.
  • Critics argue the findings highlight a failure by the Information Commissioner’s Office to enforce privacy standards effectively in this sector.

A significant gap exists between regulatory expectations and actual practices within the United Kingdom’s online gambling industry, according to new research. A study conducted by researchers at the University of Swansea’s GREAT Centre suggests that nearly nine out of ten licensed British gambling websites are failing to adhere to the General Data Protection Regulation. These strict rules govern how organizations collect, store, and process personal information, yet the findings indicate systemic non-compliance among major operators in the sector.

The investigation focused on the cookie banners that appear when users first visit a website, which are intended to allow individuals to choose what data they share. The researchers tested 624 gambling websites and discovered that nearly a quarter did not provide an option to disable tracking software. This technology allows advertisers to follow users across the web and deliver targeted marketing based on their browsing habits. Notable operators identified in this category included Hollywood Bets, a sponsor of Brentford FC, and Admiral Casino.

News Journal

Perhaps more concerning is the finding that two-thirds of the operators began collecting user data before obtaining explicit consent. While companies are permitted to gather certain information for legitimate purposes, such as verifying a customer’s location within the UK, the study revealed that this data was frequently transmitted to third-party analytics platforms used for marketing. Well-known brands including Ladbrokes and William Hill were among those found to engage in this practice.

The study also highlighted the prevalence of “dark patterns” designed to manipulate user choices. These design tactics nudge individuals toward accepting data sharing rather than protecting their privacy. For instance, 60% of the sites visually emphasized the least privacy-friendly option, while 29% pre-selected settings that allowed for extensive tracking. Additionally, nearly half of the websites hid the reject button behind a secondary menu layer, making it more difficult for users to opt out.

Although these design patterns do not automatically constitute legal breaches, the correlation with GDPR violations is strong. The same 86% of websites that employed such manipulative designs were found to have committed at least one breach of data protection laws. This rate is significantly higher than the 54% violation rate observed in a previous study that examined a broader range of internet websites, suggesting that the gambling sector lags behind other industries in compliance.

Legal experts view these findings as evidence of a deeper regulatory failure. Ravi Naik, legal director at data protection specialist AWO, described the situation as widespread and systemic non-compliance. He noted that while the results were not surprising, they underscore the damaging consequences of inadequate enforcement. AWO has previously represented campaign groups raising concerns about gambling firms’ privacy practices, including a 2024 case where SkyBet was reprimanded for unlawfully sharing user data with advertising companies.

The researchers emphasized that the primary motive behind this extensive data collection is to maintain user engagement and increase consumer losses. They warned that the overlap between profitable behavioral patterns and harmful gambling behaviors makes data consent design a critical consumer protection issue. By surveilling users, operators can tailor inducements to specific times or behaviors, potentially exacerbating problem gambling.

In response to the criticism, the Information Commissioner’s Office stated its commitment to monitoring compliance across the UK’s most visited websites. The regulator claimed to have forced 95% of the top 1,000 websites in the country to comply with cookie and tracking regulations as part of a multi-year project. However, the study suggests that big operators in the gambling industry remain outliers in this effort.

Several companies mentioned in the report declined to comment or did not return requests for clarification. Evoke, the owner of William Hill, offered no statement, while Hollywood Bets and Admiral Casino remained silent. Entain, which owns Ladbrokes, asserted that any data collected prior to consent was not used for advertising or marketing purposes. As the ICO continues its enforcement efforts, the disparity between general web compliance and gambling sector practices remains a focal point for privacy advocates.

The implications of these findings extend beyond individual privacy concerns to broader questions about corporate accountability and regulatory efficacy. With such a high percentage of operators flouting established rules, there is growing pressure on the Information Commissioner’s Office to take more meaningful action against the online gambling sector. Until then, users may remain vulnerable to unchecked data surveillance under the guise of standard web interactions.

Sources behind this briefing

Go to the original reporting