A Swansea University audit of every Gambling Commission-licensed casino and sports-betting website found that 86% appeared to breach UK data-protection rules. The researchers examined 624 sites’ banners and network traffic, finding that 67% began collecting personally identifiable information before consent, while 24% gave visitors no way to refuse tracking.
The study, published in Computers in Human Behavior Reports, was led by PhD researcher Jack McGarrigle at Swansea’s Gambling Research, Education and Treatment Centre. It examined whether gambling websites’ consent mechanisms met GDPR requirements, which cover the processing and protection of personal data.
Data gathered before consent was transmitted as unique user identifiers to third-party analytics and marketing services, the researchers found. Although data can be collected before consent for certain legitimate purposes, including checking whether a customer is in the UK, the study found the pre-consent transfers went to marketing-related analytics platforms.
The audit also identified barriers to declining tracking. Only 29% of banners let users reject tracking as easily as they could accept it; some required up to 15 clicks to opt out. Two per cent of sites showed no consent banner at all.
Most sites used so-called dark patterns that directed visitors towards data-sharing choices. Sixty per cent visually highlighted the accept option, 47% placed the reject choice behind an additional menu layer and 29% pre-selected settings favouring data collection. Such design practices do not necessarily amount to GDPR breaches on their own, The Guardian reported, but the study found widespread non-compliance alongside them.
A separate experiment involving 615 UK online gamblers tested six simulated banner formats. The format most commonly used by operators made participants three to four times more likely to accept tracking than a neutral banner with a one-click choice. Those who accepted rated the decision’s fit with their actual privacy preferences at 4.4 out of 10, against 7.9 among those who opted out; the effect did not vary by gambling-risk level.
The authors argued that the data supports personalised marketing and cross-site tracking, and that indicators used to identify commercially valuable customers can overlap with markers of gambling-related harm. Ravi Naik, legal director at AWO, called the findings evidence of “widespread and systemic non-compliance”.
GDPR took effect in the UK on May 25, 2018. The Gambling Commission says consent is one potential lawful basis for processing personal data, alongside bases such as legal obligations and legitimate interests, but operators must still meet transparency requirements and protect customers’ data. The Information Commissioner’s Office said it would monitor compliance with lawful cookie practices and take action where necessary; it said it had brought 95% of the UK’s top 1,000 websites into compliance with cookie and tracking rules.