Swansea University's GREAT Centre audited 624 licensed UK gambling sites and found GDPR breaches on 86% of them. By comparison, 54% of general websites violate the regulation.
The main issue is cookie banners. A quarter of sites gave users no way to disable tracking, including Hollywood Bets, sponsor of Brentford FC, and Admiral Casino. Two thirds began collecting data before consent was granted: beyond geolocation checks, which are legitimate, information was passed to third-party marketing platforms. Another 2% offered no choice at all, among them Dafabet, sponsor of Celtic FC.
The study recorded widespread use of dark patterns. 60% of sites visually highlighted the most invasive option, 29% pre-selected settings in favour of data collection, and 47% hid the cookie refusal button behind a second menu layer.
Ravi Naik, a lawyer at specialist firm AWO, called the findings evidence of "large-scale systematic disregard for the rules." He pointed to inaction by the Information Commissioner's Office, which has run a multi-year project to bring sites into GDPR compliance. The ICO claims to have brought 95% of the thousand largest British sites into line, but the gambling data contradicts that figure.
The researchers stress that data collection in online gambling is aimed at retaining players and increasing their losses. Because profitable customer behaviour overlaps with signs of problem gambling, user tracking becomes a consumer protection issue, not just a privacy one.