8 Sep 2026
Swansea University Audit Reveals Extensive Cookie Consent Failures Across UK Gambling Sites

Researchers at Swansea University’s GREAT Centre examined 624 licensed UK gambling websites and identified that 86 percent had committed at least one GDPR breach tied to cookie consent practices, with the audit exposing patterns of non-compliance that set the sector apart from broader UK online standards.
The study documented specific failures including 24 percent of sites providing no mechanism for users to disable tracking cookies, while two-thirds began collecting personal data before securing any form of consent and frequently routed that information to third-party marketing platforms without authorization.
Scope and Methodology of the Audit
Conducted as a systematic review of active licensed operators, the project focused on cookie consent banners and their alignment with GDPR requirements for transparency and user control, revealing that gambling platforms often employed design choices that complicated or discouraged opt-outs.
Observers noted that these practices appeared across a majority of the sampled sites, with widespread reliance on pre-selected privacy-invasive defaults and interfaces that made rejection processes noticeably more cumbersome than acceptance steps.
Key Compliance Shortfalls Identified
Data from the audit showed that nearly one-quarter of the 624 sites offered users no functional way to turn off tracking, a direct violation of consent rules that require equal ease in granting or withholding permission.
Two-thirds of the platforms initiated data transfers to external marketing services prior to obtaining consent, which researchers flagged as a core breach because GDPR mandates affirmative agreement before any processing occurs.
Additional issues surfaced around dark patterns, where settings defaulted to maximum data collection and rejection buttons were either hidden, required multiple clicks, or led to confusing secondary screens that still permitted tracking.
Industry Context and Sector Comparison
The findings placed gambling operators significantly behind other categories of UK websites in meeting regulatory benchmarks, as similar audits in retail, news, and financial services sectors have typically reported lower breach rates and more straightforward consent mechanisms.
Those who reviewed the results pointed out that the combination of pre-consent data sharing and difficult opt-out flows created an environment where users effectively lost control over their information from the first interaction.

Regulatory bodies have previously issued guidance emphasizing clear, balanced consent interfaces, yet the Swansea data indicates that many licensed gambling sites continue to fall short of those expectations even as enforcement attention grows.
Technical and Operational Implications
Because the breaches involve both timing of data collection and third-party transfers, operators now face potential investigations that could require retroactive consent audits and system redesigns to bring banners into line with GDPR standards.
The audit also highlighted how these practices affect user trust and data accuracy, since individuals who encounter barriers to rejection may simply abandon sites or provide incomplete information that distorts downstream analytics.
Regulatory Landscape in Late 2026
As of September 2026, the Information Commissioner’s Office continues to prioritize cookie compliance across high-risk sectors, and the Swansea findings supply fresh evidence that gambling platforms require targeted scrutiny to close the gap with other industries.
License holders who have not yet addressed these issues may encounter increased demands for documentation and remedial action, particularly where data has already been shared without valid consent.
Conclusion
The Swansea University audit supplies a clear snapshot of current practices across hundreds of licensed sites and underscores the need for gambling operators to align cookie consent systems with GDPR obligations that other UK sectors have more consistently adopted.
With 86 percent of examined websites showing at least one breach and recurring patterns around pre-consent collection and dark patterns, the data points to concrete areas where technical and design adjustments can restore compliance.