Nearly nine in 10 licensed British gambling websites appear to breach general data protection regulation (GDPR) rules, according to a study by Swansea University’s GREAT Centre.

The study examined 624 gambling websites and focused on cookie banners, which ask users whether they consent to having their data collected and shared, The Guardian reported.

Nearly a quarter, or 24%, of the sites did not provide an option to disable tracking software used to monitor users and deliver targeted advertising. These included Hollywood Bets, a sponsor of Brentford FC, and Admiral Casino.

Two-thirds of the websites began collecting user data before consent was given. While operators can collect certain information for legitimate purposes, such as verifying that customers are accessing their services from the UK, researchers found that data was also sent to third-party analytics platforms used for marketing.

A further 2% of the websites offered no consent choice at all. These included Dafabet, a sponsor of Celtic FC.

The researchers also found widespread use of “dark patterns” designed to encourage users to accept data sharing. These included highlighting the least privacy-friendly option on 60% of sites, pre-selecting privacy-unfriendly settings on 29%, and placing the option to reject cookies behind a second layer on 47%.

Overall, 86% of the gambling websites studied appeared to have committed at least one GDPR breach. This compares with 54% in a previous study covering websites across the wider internet.

Ravi Naik, Legal Director at data protection specialist AWO, described the findings as evidence of “widespread and systemic non-compliance”.

“It is sadly no surprise to see the findings in this report, yet the consequences of non-compliance are no less damaging,” he said. “The most striking thing to arise from this report is the light it casts on the failure of the Information Commissioner’s Office to take meaningful enforcement action against the online gambling sector.”

The ICO is conducting a multi-year project to improve compliance with GDPR rules on cookies and tracking. The regulator said it had brought 95% of the UK’s top 1,000 websites into compliance with the requirements.

An ICO spokesperson said the regulator remained committed to monitoring compliance and taking action where necessary to protect people’s information rights.

The study’s authors said data collection in online gambling was aimed at “maintaining engagement and consumer losses”. They said the overlap between profitable customer behaviour and harmful gambling behaviour made data surveillance a consumer protection concern.

Original article: https://www.yogonet.com/international/news/2026/09/07/126264-86-of-uk-gambling-sites-appear-to-breach-gdpr-according-to-study