Swansea University Audit Exposes Data Protection Shortfalls Across UK Gambling Websites
Ulrich Berger · Sep 8, 2026

Swansea University Audit Exposes Data Protection Shortfalls Across UK Gambling Websites

Researchers at Swansea University's GREAT Centre examined 624 licensed UK gambling websites and identified that 86 percent had committed at least one breach of GDPR and data protection rules, with problems centering on cookie consent banners together with manipulative interface designs known as dark patterns.
Audit Scope and Methodology
The project reviewed a broad sample of active, licensed platforms operating within the United Kingdom market, checking each site against current data protection standards enforced under GDPR, and the results showed widespread shortcomings in how user consent is obtained and managed before any data collection begins.
Two-thirds of the audited sites began gathering user information prior to receiving explicit consent, with much of that data routed directly to third-party marketing platforms without the knowledge or approval of visitors, creating clear violations of established privacy frameworks that require affirmative agreement first.
Key Violations Documented
Another 24 percent of the websites offered visitors no mechanism at all to disable tracking cookies or related technologies, leaving users without any practical way to limit data sharing once they arrived on the page, while many others pre-selected the most invasive tracking options by default and required extra steps to opt out.
These design choices fall under the category of dark patterns, interface techniques that steer users toward choices they might otherwise avoid, and the audit found such patterns embedded in cookie banners across the majority of non-compliant sites, often through confusing language, hidden toggles, or layered menus that obscured the full extent of data use.

Comparison With General Web Standards
The 86 percent breach rate recorded among gambling sites stands notably higher than the 54 percent violation rate observed across websites in general during comparable studies, highlighting sector-specific challenges in meeting consent and transparency requirements that apply equally to all online operators handling personal data.
According to coverage of the findings, the audit focused exclusively on licensed operators, meaning the results reflect practices within the regulated portion of the market rather than unlicensed or offshore platforms that fall outside UK oversight.
Regulatory Context and Next Steps
UK data protection rules require clear, informed consent before personal information is collected or shared, and the patterns identified in the audit suggest many gambling operators have yet to align their consent flows with these obligations despite ongoing enforcement activity by the Information Commissioner's Office.
Observers note that the prevalence of pre-checked boxes and limited opt-out options creates friction for users who wish to maintain control over their data, while the automatic transmission of information to third parties before consent further compounds the issue by expanding the scope of potential data exposure beyond the original site.
Conclusion
The Swansea University study provides a detailed snapshot of current compliance levels within the licensed UK gambling sector, showing that the majority of audited sites still fall short of GDPR standards in areas related to cookie management and user choice, and the gap relative to broader web averages underscores the need for targeted improvements in how these platforms handle consent mechanisms going forward.