Online bookmakers and casinos have been accused of widespread non-compliance of information privacy requirements, including “data surveillance” of customers, according to a study.
Nearly nine out of 10 (86%) licensed British gambling websites appear to be flouting the general data protection regulation (GDPR), the strict rules governing how organisations can collect, store and process personal data, according to the research.
The findings relate to the “cookie” banners that appear on a website when a user first navigates to it, asking which information they are willing to share.
Britain’s data privacy regulator, the Information Commissioner’s Office, is in the midst of a multi-year project to force websites to comply with GDPR rules governing the banners. It claims to have forced 95% of the top 1,000 websites in the country to comply with the cookie and tracking regulations.
But a study by researchers at the University of Swansea’s GREAT Centre found that big operators in the gambling industry appear to lag far behind.
Nearly a quarter (24%) of 624 gambling websites tested did not offer the option to turn off tracking software, which allows advertisers to follow users around the web and target them with marketing tailored to their interests.
Operators that did not provide an option to turn off tracking included the Brentford FC sponsor Hollywood Bets, and Admiral Casino, owned by the high-street slot machine firm of the same name.
Two-thirds of operators began harvesting users’ data before they had given their consent for it to be collected, the study found. They included well-known operators such as Ladbrokes and William Hill. Operators are allowed to do this for legitimate reasons, such as ensuring a customer is logging on from the UK, but researchers found that data was sent to third-party analytics platforms used for marketing.
Of the websites studied, 2% offered no consent choice at all, including Dafabet, the sponsor of Celtic FC.
Researchers also found that the vast majority of bookies and online casinos use “dark patterns” to nudge people towards accepting data sharing. These nudges include visual emphasis of the least privacy-friendly option (60%), default pre-selection of privacy-unfriendly settings (29%), and the reject option being hidden behind a second layer (47%).
Such patterns do not necessarily constitute breaches in themselves. But the same proportion of websites that feature them, 86%, appear to have committed at least one breach of GDPR, the study found.
This proportion is significantly higher than has been reflected in analysis of the wider internet. A previous study that examined all types of website, not just gambling, placed the figure at 54%.
Ravi Naik, legal director at the data protection specialist AWO, said the report’s findings “paint a picture of widespread and systemic non-compliance”.
He added: “It is sadly no surprise to see the findings in this report, yet the consequences of non-compliance are no less damaging.
“The most striking thing to arise from this report is the light it casts on the failure of the Information Commissioner’s Office to take meaningful enforcement action against the online gambling sector.”
AWO has previously acted for the campaign group Clean Up Gambling, which raised concerns with the ICO about gambling firms’ compliance.
In 2024, SkyBet was reprimanded by the ICO for unlawfully sharing users’ data with advertising companies, after the campaign raised concerns, through AWO, about an operator that treated a customer’s gambling during early-morning hours as a sign of harm and as a cue to send personalised inducements at those times.
SkyBet was not among those claimed to have breached GDPR in the University of Swansea report.
The study’s authors said the goal of collecting users’ data was “maintaining engagement and consumer losses”.
“The particular risk posed by data surveillance in online gambling, given the structural overlap between profitable behavioural patterns and harmful gambling behaviours, underscores the importance of data consent design as a consumer protection issue.”
An ICO spokesperson said the data regulator was committed to “monitoring compliance across the UK’s most visited websites and driving long-term adherence to lawful cookie practices”.
They added: “We will take action where necessary to protect people’s information rights.”
Evoke, the owner of William Hill, declined to comment. Entain, the owner of Ladbrokes, said any data it collected prior to consent being given was not used for advertising or marketing. Hollywood Bets and Admiral Casino did not return a request for comment.

4 hours ago
8

















































