A large-scale study of British-licensed betting and casino websites has found widespread use of “dark patterns” and tracking technologies that may collect personal data before users have meaningfully agreed to share it.

Britain’s online gambling industry is facing renewed scrutiny over its handling of customer data after researchers found that a large majority of licensed betting and casino websites appear to use cookie banners in ways that could conflict with UK privacy rules.
A study of 624 UK-licensed gambling websites found that only about 14% appeared fully compliant with applicable consent requirements, while 86% displayed at least one potentially problematic design or data-processing practice. Researchers identified widespread use of so-called “dark patterns”—interface techniques designed to steer users toward accepting tracking rather than making a genuinely neutral choice.
The research, conducted by academics associated with Swansea University’s GREAT Centre and published in Computers in Human Behavior Reports, raises particular concerns because gambling companies can collect highly detailed information about customers’ behaviour.
That information may include when people gamble, which games or sports they prefer, how frequently they return to a website, their device information and how they respond to promotions.
In an industry where behavioural patterns can potentially reveal vulnerability as well as commercial value, researchers argue that privacy is not merely a technical compliance issue.
It can also become a matter of consumer protection.
Data collected before consent
One of the most striking findings concerned what happened before users had even made a decision on a cookie banner.
The study found that approximately 67% of the gambling websites examined processed personally identifiable information before users had given consent. Researchers said data were in some cases transmitted to third-party analytics services commonly associated with advertising and marketing.
That distinction matters under UK privacy rules.
Websites are generally permitted to deploy technologies that are strictly necessary to provide a service—for example, security mechanisms or technologies required to verify that a customer is accessing a service legitimately.
But non-essential cookies and tracking systems normally require valid consent before they are placed or used.
The Information Commissioner’s Office states that organisations must give users clear information about non-essential tracking and obtain appropriate consent before using it. Consent must involve a genuine positive action rather than simply assuming agreement because someone continued browsing.
The researchers found that the practices of some gambling sites appeared to fall short of that standard.
Well-known operators including Ladbrokes and William Hill were among websites found to transmit information before consent had been given, according to the research reported by the Guardian.
Entain, which owns Ladbrokes, said information collected before consent was not used for advertising or marketing purposes. Evoke, the owner of William Hill, declined to comment to the Guardian.
The illusion of choice
The research also examined how consent banners themselves were designed.
In theory, a cookie banner is supposed to allow users to make an informed choice.
In practice, that choice can be heavily influenced by design.
Researchers found that 24% of the websites examined offered no straightforward option to reject tracking, while 2% provided no meaningful consent choice at all.
Some of the websites were found to place visual emphasis on the option that permitted the greatest level of data collection.
About 60% used visual prominence to favour the least privacy-protective choice, while 29% reportedly had privacy-unfriendly settings selected by default.
In 47% of cases, the option to reject tracking was concealed behind an additional menu or second layer.
Such techniques are commonly described as dark patterns.
They can include brightly coloured “accept” buttons paired with less visible rejection options, additional clicks required to refuse tracking, confusing language or default settings that favour data collection.
Dark patterns are not automatically unlawful in every circumstance.
But where their design interferes with a person’s ability to give freely informed consent, they can create serious regulatory problems.
The ICO’s guidance emphasises that consent must be freely given, specific and informed, and that users should have an easy means of enabling or disabling non-essential tracking technologies.
Why gambling data are different
Privacy concerns surrounding online gambling carry an additional dimension because of the extraordinary amount of behavioural information that can be generated by a regular customer.
A typical website might know that a person enjoys football.
A betting operator could potentially know far more: which leagues they follow, how much they stake, what time of night they gamble, whether losses cause them to increase their bets and which promotional messages are most likely to bring them back.
The study’s authors argue that such information can create a powerful surveillance system around individual customers.
Their concern is particularly acute because patterns that are commercially valuable to gambling companies may overlap with behaviours associated with gambling harm.
The researchers wrote that the industry’s model creates a significant consumer-protection risk because the behavioural patterns most profitable to operators can sometimes resemble patterns associated with harmful gambling.
That makes the question of consent significantly more important than it might appear from a simple cookie pop-up.
A customer may believe they are merely accepting routine website functionality while potentially allowing companies or third-party platforms to construct sophisticated behavioural profiles.
From advertising to personalised inducements
Personalisation is now central to the economics of digital gambling.
Online operators compete intensely for customer attention and use analytics to identify which promotions, bonuses or betting opportunities are most likely to attract particular users.
That can produce an increasingly individualised gambling environment.
Someone interested primarily in football may receive football promotions. A customer who frequently places bets late at night might receive offers designed to encourage engagement during those hours.
In principle, personalisation can make digital services more relevant.
In gambling, however, regulators face the additional question of whether data-driven marketing could exploit vulnerable behaviour.
The issue has already surfaced in previous enforcement action.
In 2024 the ICO reprimanded Sky Betting & Gaming after finding that the company had unlawfully processed customer data through advertising cookies without valid consent. The regulator concluded that personal information had been shared with advertising technology companies before appropriate consent was obtained.
SkyBet was not among the operators identified as breaching GDPR in the new Swansea research, according to the Guardian.
The earlier case nonetheless demonstrated why regulators view gambling-related tracking with particular caution.
A gap in enforcement?
The latest findings also raise questions for the Information Commissioner’s Office itself.
The ICO has spent several years pushing major websites toward more compliant cookie-banner designs and says its campaign has produced substantial improvements.
In April 2026, the regulator said 99% of the UK’s top 1,000 websites were meeting its cookie-banner compliance standards following focused enforcement work.
That makes the gambling-sector findings especially striking.
If only around one in seven licensed gambling websites in the Swansea study appeared compliant, it suggests that progress across some of Britain’s largest websites may not be reflected evenly across particular industries.
Ravi Naik, legal director at data-protection law firm AWO, described the findings as evidence of widespread and systemic non-compliance and criticised what he regarded as insufficient enforcement against gambling companies.
The ICO said it remained committed to monitoring compliance among major websites and would take action where necessary to protect information rights.
Gambling regulation meets privacy regulation
The controversy exposes an important regulatory overlap.
British betting companies are already subject to extensive rules governing licensing, responsible gambling, advertising and customer protection through the Gambling Commission.
But the collection of customer information also places them within the scope of data-protection and electronic-communications law.
Cookies and similar technologies are primarily governed by the Privacy and Electronic Communications Regulations, or PECR, while the UK GDPR becomes relevant when those technologies involve processing personal data.
In April 2026 the ICO published updated guidance covering not only traditional cookies but also technologies such as tracking pixels, device fingerprinting, scripts and other mechanisms used to recognise or monitor users online.
The technological distinction is increasingly important.
Modern online tracking no longer depends solely on the small text files traditionally associated with cookies.
Companies can potentially identify users through combinations of device characteristics, browser configurations and other signals.
Regulation is therefore shifting toward the broader concept of online tracking technologies, rather than cookies alone.
Consent cannot simply be decorative
The deeper issue raised by the study is whether consent banners actually function as genuine privacy controls.
Consumers encounter so many pop-ups that accepting them can become almost automatic.
The visual architecture of a banner can make that tendency even stronger.
If one button is large, colourful and instantaneous while refusal requires several steps through complicated menus, a website may technically present a choice while substantially influencing the outcome.
The Swansea researchers tested this issue experimentally with more than 600 participants.
They found that the most commonly used banner design identified in the audit significantly increased acceptance of tracking and produced poorer alignment between what users actually preferred and the choices they ultimately made.
That finding goes to the heart of modern privacy regulation.
Consent is supposed to express an individual’s preference.
If interface design systematically causes people to make decisions that conflict with those preferences, the consent mechanism begins to lose its purpose.
A highly valuable stream of behavioural intelligence
For gambling companies, customer data have considerable commercial value.
Sportsbooks and casinos increasingly operate like sophisticated technology businesses, using algorithms, analytics and customer segmentation alongside traditional betting products.
Every interaction can potentially contribute to a data profile.
The result is an industry capable of knowing not simply what a person bets on, but potentially how their gambling behaviour changes over time.
That information could be used positively—for example, to identify potential gambling harm and intervene.
But it can also be used commercially to maximise engagement.
That dual purpose creates a fundamental regulatory tension.
The same behavioural data that could help protect a vulnerable customer can potentially be used to encourage that customer to continue gambling.
This is why researchers describe privacy and responsible-gambling policy as increasingly interconnected.
What happens next
The new study does not establish that every operator it identified will necessarily face enforcement action.
Whether a specific practice constitutes a breach depends on the precise technology involved, the information processed, the purpose for which it is collected and whether an applicable legal exemption exists.
Individual companies may also dispute researchers’ interpretations of particular tracking technologies.
But the scale of the findings makes the broader issue difficult to dismiss.
An industry in which hundreds of websites appear to steer consumers toward tracking—and in many cases begin processing data before those users have made a choice—will inevitably attract regulatory attention.
The potential consequences go beyond cookie banners.
As gambling becomes increasingly digital, regulators will have to determine how operators can use behavioural analytics without turning responsible-gambling systems into sophisticated marketing infrastructures.
For customers, meanwhile, the familiar pop-up asking them to “accept cookies” may be far more consequential than it appears.
Behind that simple button can sit an extensive ecosystem of analytics platforms, advertising technologies and behavioural profiling tools.
The Swansea research suggests that on many British gambling websites, the question may no longer be simply whether consumers are giving consent.
It is whether the digital environment has been designed so that refusing consent is genuinely as easy—and as meaningful—as giving it.




