Swansea University Audit Reveals Widespread GDPR Violations Across UK Gambling Websites
Erik Wagner · Sep 8, 2026

Swansea University Audit Reveals Widespread GDPR Violations Across UK Gambling Websites

Researchers at Swansea University’s GREAT Centre completed an audit of 624 licensed UK gambling websites, and the findings show that 86 percent of those sites committed at least one GDPR violation tied to cookie consent banners and data handling practices, according to the published report.
The study examined how these platforms manage user data through consent mechanisms, and it compared results against broader website audits that recorded a 54 percent violation rate overall. Data from the gambling sector audit indicates significantly higher non-compliance levels than the average seen across other industries.
Key Findings from the Cookie Consent Audit
Two-thirds of the audited sites collected user data before obtaining consent, and many of those platforms shared the information with third-party marketers right away. In addition, 24 percent of the websites provided no clear option for users to disable tracking entirely, which left visitors with limited control over their personal information.
Dark patterns appeared frequently across the sample, including pre-selected options that favored invasive data collection and designs that forced users through extra clicks to reject cookies. Observers note these tactics often steer people toward accepting defaults that maximize data sharing rather than protecting privacy choices.
Comparison to Broader Website Compliance Data
The 86 percent violation rate in the gambling sector stands well above the 54 percent figure recorded in wider studies of UK websites, and researchers highlighted this gap as evidence of weaker adherence in this particular industry. The Information Commissioner’s Office has previously stated that overall compliance levels remain high across the web, yet the gambling-specific results suggest a different pattern in practice.
Those conducting the audit documented how consent banners on gambling sites frequently failed to meet GDPR standards for clear, affirmative consent. Many banners used confusing language or layered options that made rejection more difficult than acceptance, which researchers linked directly to the elevated violation count.

Industry Context and Regulatory Implications
Licensed UK gambling operators must follow both gambling regulations and data protection rules, and the audit shows that a large majority fell short on the data side. The findings come at a time when regulators continue to review how online platforms handle personal information, with particular attention on sectors that process sensitive user data at scale.
Study authors examined only licensed sites, which means the sample already operates under oversight from the UK Gambling Commission and the ICO. Despite these requirements, the data revealed consistent shortfalls in how consent flows and data sharing occur before users make active choices.
Further analysis from the GREAT Centre report points to repeated use of interface designs that prioritize data collection over user control, and these patterns contributed to most of the recorded violations. The audit did not name individual operators but instead presented aggregate statistics that illustrate sector-wide trends.
Next Steps for Compliance
Regulators and operators now have access to these specific figures, which detail exactly where consent mechanisms break down on gambling platforms. The study provides a clear benchmark that can guide future checks and updates to cookie practices across the licensed market.
Those reviewing the results note that bringing gambling sites into line with GDPR cookie rules will require changes to banner design, data collection timing, and third-party sharing protocols. The report stops short of recommending penalties but supplies the evidence base that enforcement bodies can draw upon.
Timeline and Publication Details
The audit findings were released ahead of September 2026 discussions on data protection enforcement priorities, and the timing allows regulators to incorporate the numbers into ongoing reviews of online compliance. The single source link for the study appears in coverage from multiple outlets reporting on the GREAT Centre work.
Conclusion
The Swansea University audit of 624 licensed UK gambling websites establishes that 86 percent showed at least one GDPR violation related to cookie consent and data practices, with two-thirds collecting data before consent and 24 percent offering no tracking opt-out. These figures exceed the 54 percent violation rate seen in wider website studies, and the documented use of dark patterns provides concrete examples of where current implementations fall short. The report supplies regulators and operators with measurable data on the scale of the issue across the sector.