NEWSAR
Multi-perspective news intelligence
SRCThe Guardian - World News
LANGEN
LEANCenter-Left
WORDS701
ENT12
SUN · 2026-09-06 · 07:00 GMTBRIEF NSR-2026-0906-109661
News/Online bookies accused of UK privacy breaches with use of co…
NSR-2026-0906-109661News Report·EN·Legal & Judicial

Online bookies accused of UK privacy breaches with use of cookie banners

A study by the University of Swansea found that 86% of licensed British gambling websites likely violate GDPR privacy regulations. Researchers discovered that nearly nine out of ten sites harvest user data before consent is given, with two-thirds sending this data to third-party marketing platforms.

Rob DaviesThe Guardian - World NewsFiled 2026-09-06 · 07:00 GMTLean · Center-LeftRead · 3 min
Online bookies accused of UK privacy breaches with use of cookie banners
The Guardian - World NewsFIG 01
Reading time
3min
Word count
701words
Sources cited
2cited
Entities identified
12entities
Quality score
100%
§ 01

Briefing Summary

AI-generated
NEWSAR · AI

A study by the University of Swansea found that 86% of licensed British gambling websites likely violate GDPR privacy regulations. Researchers discovered that nearly nine out of ten sites harvest user data before consent is given, with two-thirds sending this data to third-party marketing platforms. Many sites also employ "dark patterns" to encourage data sharing, such as visually emphasizing the least privacy-friendly options. The study identified specific operators like Hollywood Bets, Admiral Casino, Ladbrokes, William Hill, and Dafabet as non-compliant. The Information Commissioner's Office stated it is monitoring compliance and will take action to protect information rights.

Confidence 0.90Sources 2Claims 5Entities 12
§ 02

Article analysis

Model · rule-based
Framing
Legal & Judicial
Technology
Tone
Mixed Tone
AI-assessed
CalmNeutralAlarmist
Factuality
0.90 / 1.00
Factual
LowHigh
Sources cited
2
Limited
FewMany
§ 03

Key claims

5 extracted
01

86% of websites appear to have committed at least one breach of GDPR, a proportion significantly higher than the 54% found in wider internet analysis.

statisticUniversity of Swansea's GREAT Centre study
Confidence
1.00
02

The vast majority of bookies and online casinos use “dark patterns” to nudge people towards accepting data sharing.

statisticUniversity of Swansea's GREAT Centre study
Confidence
1.00
03

Two-thirds of operators began harvesting users’ data before they had given their consent.

statisticUniversity of Swansea's GREAT Centre study
Confidence
1.00
04

24% of gambling websites tested did not offer the option to turn off tracking software.

statisticUniversity of Swansea's GREAT Centre study
Confidence
1.00
05

Nearly nine out of 10 (86%) licensed British gambling websites appear to be flouting GDPR rules on cookie banners.

statisticUniversity of Swansea's GREAT Centre study
Confidence
1.00
§ 04

Full report

3 min read · 701 words
Online bookmakers and casinos have been accused of widespread non-compliance of information privacy requirements, including “data surveillance” of customers, according to a study.Nearly nine out of 10 (86%) licensed British gambling websites appear to be flouting the General Data Protection Regulation (GDPR), the strict rules governing how organisations can collect, store and process personal data, according to the research.The findings relate to the “cookie” banners that appear on a website when a user first navigates to it, asking which information they are willing to share.Britain’s data privacy regulator, the Information Commissioner’s Office, is in the midst of a multi-year project to force websites to comply with GDPR rules governing the banners. It claims to have forced 95% of the top 1,000 websites in the country to comply with the cookie and tracking regulations.But a study by researchers at the University of Swansea’s GREAT Centre found that big operators in the gambling industry appear to lag far behind.Nearly a quarter (24%) of 624 gambling websites tested did not offer the option to turn off tracking software, which allows advertisers to follow users around the web and target them with marketing tailored to their interests.Operators that did not provide an option to turn off tracking included the Brentford FC sponsor Hollywood Bets, and Admiral Casino, owned by the high-street slot machine firm of the same name.Two-thirds of operators began harvesting users’ data before they had given their consent for it to be collected, the study found. They included well-known operators such as Ladbrokes and William Hill. Operators are allowed to do this for legitimate reasons, such as ensuring a customer is logging on from the UK, but researchers found that data was sent to third-party analytics platforms used for marketing.Of the websites studied, 2% offered no consent choice at all, including Dafabet, the sponsor of Celtic FC.Researchers also found that the vast majority of bookies and online casinos use “dark patterns” to nudge people towards accepting data sharing. These nudges include visual emphasis of the least privacy-friendly option (60%), default pre-selection of privacy-unfriendly settings (29%), and the reject option being hidden behind a second layer (47%).Such patterns do not necessarily constitute breaches in themselves. But the same proportion of websites that feature them, 86%, appear to have committed at least one breach of GDPR, the study found.This proportion is significantly higher than has been reflected in analysis of the wider internet. A previous study that examined all types of website, not just gambling, placed the figure at 54%.Ravi Naik, legal director at the data protection specialist AWO, said the report’s findings “paint a picture of widespread and systemic non-compliance”.He added: “It is sadly no surprise to see the findings in this report, yet the consequences of non-compliance are no less damaging.“The most striking thing to arise from this report is the light it casts on the failure of the Information Commissioner’s Office to take meaningful enforcement action against the online gambling sector.”AWO has previously acted for the campaign group Clean Up Gambling, which raised concerns with the ICO about gambling firms’ compliance.In 2024, SkyBet was reprimanded by the ICO for unlawfully sharing users’ data with advertising companies, after the campaign raised concerns, through AWO, about an operator that treated a customer’s gambling during early-morning hours as a sign of harm and as a cue to send personalised inducements at those times.SkyBet was not among those claimed to have breached GDPR in the University of Swansea report.The study’s authors said the goal of collecting users’ data was “maintaining engagement and consumer losses”.“The particular risk posed by data surveillance in online gambling, given the structural overlap between profitable behavioural patterns and harmful gambling behaviours, underscores the importance of data consent design as a consumer protection issue.”An ICO spokesperson said the data regulator was committed to “monitoring compliance across the UK’s most visited websites and driving long-term adherence to lawful cookie practices”.They added: “We will take action where necessary to protect people’s information rights.”Evoke, the owner of William Hill, declined to comment. Entain, the owner of Ladbrokes, said any data it collected prior to consent being given was not used for advertising or marketing. Hollywood Bets and Admiral Casino did not return a request for comment.
§ 05

Entities

12 identified
§ 06

Keywords & salience

10 terms
cookie banners
1.00
gdpr
1.00
privacy breaches
0.90
data surveillance
0.80
online bookmakers
0.70
gambling websites
0.70
data protection
0.60
tracking software
0.50
dark patterns
0.50
information commissioner's office
0.40
§ 07

Topic connections

Interactive graph
Network visualization showing 5 related topics
View Full Graph
Person Organization Location Event|Click node to navigate|Edge numbers = shared articles