Online bookmakers and casinos operating in the UK have been accused of widespread non-compliance with information privacy requirements, including what researchers describe as "data surveillance" of customers, according to a recent study.
The research, conducted by academics at the University of Swansea’s GREAT Centre, suggests that nearly nine out of 10 (86%) licensed British gambling websites appear to be flouting the General Data Protection Regulation (GDPR). GDPR sets strict rules for how organisations can collect, store, and process personal data.
The findings specifically relate to the "cookie" banners that greet users upon their first visit to a website, which are designed to ask users about their willingness to share information.
The Information Commissioner’s Office (ICO), Britain’s data privacy regulator, is currently undertaking a multi-year project aimed at ensuring websites comply with GDPR rules concerning these banners. The ICO claims to have compelled 95% of the country's top 1,000 websites to adhere to cookie and tracking regulations.
However, the Swansea study indicates that major operators within the gambling industry are significantly lagging behind this broader compliance trend.
The researchers examined 624 gambling websites and found that nearly a quarter (24%) did not provide users with the option to disable tracking software. This software is typically used by advertisers to monitor users' online activity and deliver targeted marketing. Among the operators identified for not offering this opt-out were Hollywood Bets, a sponsor of Brentford FC, and Admiral Casino, owned by the high-street slot machine firm of the same name.
Further analysis revealed that two-thirds of the operators tested began collecting users’ data before explicit consent had been given. This group included well-known names such as Ladbrokes and William Hill. While operators are permitted to harvest some data for legitimate operational reasons, such as confirming a customer is logging on from within the UK, the study found that data was being transmitted to third-party analytics platforms primarily used for marketing purposes.
In a smaller number of cases, 2% of the websites surveyed offered no consent choice at all, including Dafabet, a sponsor of Celtic FC.
The study also highlighted the widespread use of "dark patterns" by the vast majority of bookies and online casinos. These design elements are used to subtly nudge individuals towards accepting data sharing. Examples of these patterns included the visual emphasis of the least privacy-friendly option (found on 60% of sites), the default pre-selection of privacy-unfriendly settings (29%), and the placement of the "reject" option behind a secondary layer of interaction (47%).
While the presence of such dark patterns does not, in itself, necessarily constitute a breach of regulations, the study found that 86% of websites employing these patterns appeared to have committed at least one GDPR breach.
This proportion of non-compliance within the gambling sector is notably higher than figures observed in broader internet analysis. A previous study that encompassed all types of websites, not exclusively gambling platforms, reported a non-compliance rate of 54%.
Ravi Naik, legal director at AWO, a specialist firm in data protection, commented that the report’s findings "paint a picture of widespread and systemic non-compliance." He added: "It is sadly no surprise to see the findings in this report, yet the consequences of non-compliance are no less damaging."
Mr Naik also criticised the regulator, stating: "The most striking thing to arise from this report is the light it casts on the failure of the Information Commissioner’s Office to take meaningful enforcement action against the online gambling sector."
AWO has previously represented the campaign group Clean Up Gambling, which has raised concerns with the ICO regarding the compliance of gambling firms. In 2024, the ICO reprimanded SkyBet for unlawfully sharing users’ data with advertising companies. This action followed concerns, channelled through AWO, about an operator that allegedly interpreted a customer's early-morning gambling behaviour as a sign of harm, prompting the delivery of personalised inducements during those hours. SkyBet was not among the operators identified in the University of Swansea report as having breached GDPR.
The authors of the study articulated that the primary objective behind collecting users’ data in this manner was "maintaining engagement and consumer losses." They emphasised: "The particular risk posed by data surveillance in online gambling, given the structural overlap between profitable behavioural patterns and harmful gambling behaviours, underscores the importance of data consent design as a consumer protection issue."
In response to the report, an ICO spokesperson affirmed the data regulator’s commitment to "monitoring compliance across the UK’s most visited websites and driving long-term adherence to lawful cookie practices." The spokesperson added that the ICO "will take action where necessary to protect people’s information rights."
Evoke, the owner of William Hill, declined to comment on the study's findings. Entain, which owns Ladbrokes, stated that any data it collected prior to consent being given was not used for advertising or marketing purposes. Hollywood Bets and Admiral Casino did not respond to requests for comment.