A new academic study has put the privacy practices of UK online gambling websites under renewed scrutiny after researchers audited 624 licensed sites and found widespread use of so-called dark patterns in cookie-consent banners.
Researchers from Swansea University’s GREAT Centre reported that 86% of the consent banners they examined contained at least one dark pattern designed in a way that could steer users towards accepting tracking. The study, published in Computers in Human Behavior Reports on 25 August 2026, also found that only 14% of the audited sites met all of the GDPR requirements assessed by the researchers.
What the researchers found
The audit covered 624 UK-licensed gambling websites. According to the paper, 24% of the sites offered no option to reject tracking, while 67% processed personally identifiable data before consent had been obtained. The researchers also identified design practices such as visually emphasising privacy-unfriendly choices, pre-selecting tracking options and placing rejection controls behind additional clicks.
The study did not say that every use of a dark pattern is automatically unlawful. Instead, it separated manipulative interface design from specific GDPR compliance tests. Its broader conclusion was that consent design in online gambling can materially influence whether users agree to data collection and whether their choices reflect their stated privacy preferences.
Why this matters for the gambling sector
Online gambling operators rely heavily on account, behavioural and marketing data. That makes consent design especially sensitive because the same behavioural information used for analytics and personalisation can also reveal patterns associated with intensive or harmful gambling.
The researchers argued that privacy should therefore be treated as a consumer-protection issue rather than simply a technical compliance matter. In a second part of the study, 615 participants were shown different consent-banner designs in a simulated gambling environment. The most common banner design identified in the audit increased acceptance of tracking and reduced the alignment between users’ choices and their stated preferences.
ICO says it will act where necessary
The findings received fresh attention in the UK on 6 September after reporting by The Guardian. The newspaper quoted the Information Commissioner’s Office as saying it is monitoring compliance across heavily visited UK websites and will take action where necessary to protect information rights.
The ICO has previously taken enforcement action against gambling companies over unlawful use of personal data for advertising. The new study is not itself an enforcement decision and does not mean that the ICO has ruled that every site identified by the researchers breached the law.
For licensed operators, the practical implication is that cookie banners, tracking scripts and consent-management platforms are likely to remain a compliance focus. Gambling businesses may need to ensure that non-essential tracking does not begin before valid consent, that rejecting tracking is genuinely available and that interface design does not steer users towards a privacy-intrusive choice.
What happens next
The study’s authors call for stronger enforcement and stricter standards for consent-banner design. Whether the research leads to new ICO investigations or industry-wide guidance remains to be seen, but the findings add privacy and data governance to the growing list of compliance pressures facing UK gambling operators.
Sources
- Swansea University research record: https://cronfa.swan.ac.uk/Record/cronfa72625
- The Guardian, 6 September 2026: https://www.theguardian.com/technology/2026/sep/06/online-bookies-privacy-breaches-cookies-tracking
We check licensing, terms, payments, and available player-protection tools. Commercial relationships do not change our evidence standards.




Comments
Keep comments constructive. Every comment is reviewed before publication.