Swansea University Audit Exposes Cookie Consent Failures Across UK Gambling Websites
Sofia Keller · Sep 7, 2026

Swansea University Audit Exposes Cookie Consent Failures Across UK Gambling Websites

Researchers at Swansea University conducted a detailed examination of 624 licensed British gambling websites and identified that 86 percent of them violated GDPR rules through problems with cookie consent banners, and this figure stands well above the 54 percent average recorded in wider website analyses conducted elsewhere. The study focused specifically on how these platforms handle user data collection and consent mechanisms, revealing patterns that affect data privacy across the sector. Operators such as Ladbrokes and William Hill appeared among those collecting information prior to securing proper approval, while many others transmitted details to external third-party services without clear user permission.
Scope and Methodology of the Audit
The audit covered a substantial portion of the licensed market in Britain, and it systematically checked each site for compliance with rules on cookie banners that require explicit consent before any tracking begins. Teams reviewed banner designs, data flows, and user options to determine whether consent occurred before personal information moved onward. Findings indicated that roughly two-thirds of the operators began gathering user data in advance of obtaining approval, and this practice extended to sending that information directly to third-party platforms for further processing. Such actions breach core GDPR principles that mandate affirmative consent at the outset rather than afterward.
Key Violations Identified
Among the most common issues, 24 percent of the sites provided no mechanism at all for users to turn off tracking functions entirely, leaving visitors with limited or no control over their data once they arrived. Dark patterns appeared frequently as well, including pre-selected boxes that favored extensive data sharing and interfaces that made it difficult or confusing to reject tracking altogether. These design choices steered users toward acceptance without presenting balanced alternatives, and the overall violation rate exceeded broader industry benchmarks by a significant margin. The study documented these elements across multiple operators rather than isolating them to a few outliers.

Comparison With Broader Website Studies
Data from the Swansea review placed the 86 percent breach rate in context against the 54 percent average seen in general website audits, and this gap highlights particular challenges within the gambling sector where high volumes of user data move through advertising and analytics networks. Observers note that the combination of pre-consent collection and third-party transfers creates additional exposure points, and the absence of rejection options in nearly a quarter of cases compounds the problem further. Researchers compiled these statistics through direct inspection of live sites rather than relying on self-reported information from the companies involved.
Regulatory Context and Sector Response
British gambling platforms operate under licensing rules that already incorporate data protection requirements, yet the audit results suggest enforcement gaps remain in the area of cookie management. The study did not single out individual companies for penalties but instead presented aggregate findings that regulators could use for targeted follow-up. Those who examined the data observed that many banners failed basic tests for clarity and user agency, and the patterns repeated across both major and smaller operators alike. External reporting on the audit appeared in outlets such as this coverage, which summarized the core statistics without additional commentary.
Technical Details on Dark Patterns and Data Flows
Pre-selection of invasive settings occurred when banners loaded with tracking cookies already active, and users had to navigate multiple clicks to reach any opt-out controls. In several instances, the rejection path led to error messages or redirected users back to the accept option, and these friction points qualified as dark patterns under current interpretations of consent law. Data transmission to third parties often happened within seconds of page load, before any banner interaction took place, which directly contravenes the requirement that consent precede any processing. The audit recorded these sequences across the 624 sites using automated and manual verification methods to ensure accuracy.
Conclusion
The Swansea University findings establish a clear baseline for the current state of cookie compliance among licensed British gambling websites, and they provide regulators with concrete metrics for future monitoring. The 86 percent breach rate, driven by early data collection, missing opt-out tools, and dark pattern designs, exceeds general website averages adn points to sector-specific issues that may require updated guidance or enforcement actions. As of September 2026, industry participants continue to operate under the same GDPR framework examined in the study, which means the documented practices remain relevant for ongoing compliance efforts.