The gambling websites GDPR breach rate stands at 86% across all 624 casino and sports betting sites licensed by the Gambling Commission, according to a peer-reviewed study published in Computers in Human Behavior Reports by Jack McGarrigle and colleagues at the University of Swansea’s GREAT Centre.
That figure is considerably worse than the broader internet. A previous study covering all website types placed the equivalent non-compliance rate at 54%. The gap should embarrass an industry that already operates under intense public scrutiny.
The Scale of the Gambling Websites GDPR Breach Problem
The Swansea team audited the cookie consent banners and network traffic of the full licensed population, not a sample. Nearly a quarter of operators, 24%, offered users no way to turn off tracking software at all. Among them were Hollywood Bets, the Brentford FC shirt sponsor, and Admiral Casino.
Two-thirds of operators began harvesting data before users had given consent. The study named Ladbrokes and William Hill among those. Operators can collect limited data before consent for legitimate purposes, such as verifying a user’s location, but researchers found that data was being routed to third-party analytics platforms used for marketing.
A further 2% offered no consent choice whatsoever, including Dafabet, the Celtic FC sponsor.
The study also found that dark-pattern design is near-universal across the sector. According to Phys.org’s report on the research, those manipulative consent banners increase tracking acceptance three- to fourfold compared with neutral designs, and the choices users make under them poorly reflect their actual privacy preferences.
The specific dark patterns recorded include: visual emphasis on the least privacy-protective option (60% of sites), default pre-selection of privacy-unfriendly settings (29%), and the reject option hidden behind a second layer (47%). The dark patterns alone do not constitute GDPR breaches, but 86% of sites deploying them also committed at least one substantive violation.
The ICO’s Record Under the Microscope
The Information Commissioner’s Office (ICO) has spent years pursuing cookie compliance across the wider web. Its January 2025 announcement outlined a plan to bring the top 1,000 UK websites into line, and by that point it had already assessed the top 200 and written to 134 of them with concerns.
A December 2025 update from the ICO claimed 979 of those top 1,000 sites now met its compliance checks. The regulator framed this as a success. The Swansea findings suggest the gambling sector, heavily trafficked and high-risk, was left largely untouched by that effort.
Ravi Naik, legal director at data protection specialist AWO, said the report’s findings ‘paint a picture of widespread and systemic non-compliance.’ He added: ‘It is sadly no surprise to see the findings in this report, yet the consequences of non-compliance are no less damaging. The most striking thing to arise from this report is the light it casts on the failure of the Information Commissioner’s Office to take meaningful enforcement action against the online gambling sector.’
I think Naik has it right. The ICO’s 97.9% compliance headline for the top 1,000 websites is a respectable number, but if it was achieved by concentrating on news publishers and retail sites while an entire regulated industry ran surveillance-grade data collection on people with gambling disorders, the headline flatters the regulator.
AWO has form here. The firm represented Clean Up Gambling in the complaint that led to the ICO’s reprimand of Sky Betting and Gaming. According to the AWO case summary, Sky Bet unlawfully deployed third-party surveillance tools via tracking pixels, with the violation running from 10 January 2023 to 3 March 2023. SkyBet does not appear among those cited for breaches in the Swansea study.
Entain, owner of Ladbrokes, said any data collected before consent was not used for advertising or marketing. Evoke, owner of William Hill, declined to comment. Hollywood Bets and Admiral Casino did not respond to requests for comment.
The ICO said it was committed to ‘monitoring compliance across the UK’s most visited websites and driving long-term adherence to lawful cookie practices’ and would ‘take action where necessary to protect people’s information rights.’
The Gambling Commission’s next licence review cycle is the obvious forcing mechanism. Whether the ICO chooses to act before then, or waits for another campaign group to drag a single operator through a two-year complaint process, is the question the gambling industry will be watching closely.


