Online bookies accused of UK privacy breaches with use of cookie banners

by | Sep 9, 2026 | Technology

Online bookies accused of UK privacy breaches with use of cookie banners

Researchers at Swansea University’s GREAT Centre completed an analysis of data privacy practices across the online gambling industry, revealing significant gaps in compliance with GDPR regulations. The study examined 624 gambling websites and compared their practices against established data protection standards that govern how companies collect, store, and use personal information.

The research focused particularly on cookie banners—the consent notifications that appear when users first visit a website—and the tracking technologies they control. Nearly one-quarter of the operators tested did not provide users with a straightforward option to disable tracking software, which enables advertisers to monitor browsing behavior and deliver targeted marketing. Notable operators identified as lacking adequate opt-out mechanisms included Hollywood Bets and Admiral Casino.

Two-thirds of the gambling websites analyzed began collecting user data before obtaining explicit consent from visitors, according to the findings. While some data collection prior to consent may be permitted for legitimate purposes such as verifying a user’s location, researchers determined that many operators were transmitting this information to third-party analytics firms for marketing applications. Major operators including Ladbrokes and William Hill were cited in this context. Additionally, 2% of the websites examined offered no consent options whatsoever, including Dafabet.

The study identified widespread use of “dark patterns”—design techniques intended to influence user behavior toward less privacy-protective choices. These included visual emphasis of data-sharing options (found on 60% of sites), pre-selected privacy-unfriendly settings (29%), and hidden rejection options requiring additional navigation steps (47%). The researchers noted that 86% of all websites examined appeared to violate at least one GDPR requirement, substantially exceeding non-compliance rates observed across other website categories.

The Information Commissioner’s Office, Britain’s data privacy regulator, indicated it maintains an ongoing enforcement initiative targeting the nation’s most-visited websites. A spokesperson stated the agency would pursue corrective action as warranted to safeguard data protection rights. Several operators contacted for comment either declined to respond or provided statements regarding their data handling practices.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI