Swansea University's GREAT Centre Audit Exposes Cookie Consent Failures on UK Gambling Sites
Written by Klara Simon · Sep 8, 2026

Swansea University's GREAT Centre Audit Exposes Cookie Consent Failures on UK Gambling Sites

Researchers at Swansea University's GREAT Centre completed an audit of 624 licensed British gambling websites in 2026 and determined that 86 percent of them had committed at least one GDPR breach connected to cookie consent banners, a figure that exceeds the 54 percent violation rate identified in broader website studies conducted across other sectors.
The audit examined how these platforms handled user data collection through tracking cookies and consent mechanisms, revealing patterns that regulators have flagged in previous compliance checks while focusing specifically on the gambling industry this time around.
Scope and Methodology of the 2026 Study
Teams from the GREAT Centre selected sites that hold licenses from the UK Gambling Commission and assessed each one against GDPR requirements for cookie banners, which must give users clear choices before any tracking begins. The review covered banners for functionality, consent options, and data transmission practices, with analysts documenting whether sites provided equal ease of rejecting tracking as accepting it.
Data collection occurred over several months leading into September 2026, allowing researchers to capture current practices after updates to enforcement guidance from the Information Commissioner's Office. Observers note that the sample size of 624 represents a substantial portion of the active licensed market in Britain at the time.
Primary Issues Identified in Cookie Consent Practices
Twenty-four percent of the audited sites offered no option to disable tracking cookies at all, leaving users without a functional way to refuse data collection while still accessing the platform. Two-thirds of the sites began gathering user data before any consent banner appeared or before users interacted with it, often routing that information directly to third-party advertising and analytics platforms.
Researchers documented widespread deployment of dark patterns, defined in the study as interface designs that steer users toward accepting invasive tracking settings through pre-selected checkboxes or misleading button wording. These practices appeared across multiple site categories, including sports betting and casino platforms, and persisted even on sites that displayed consent banners at first glance.

Comparison with Broader Industry Benchmarks
The 86 percent breach rate stands notably higher than the 54 percent found in general website audits, according to figures cited in the GREAT Centre report. Analysts attribute part of this gap to the high volume of third-party integrations common in online gambling environments, where data flows to advertisers and tracking services occur at greater frequency than on typical retail or news sites.
Yet the study also points out that many violations involved straightforward omissions, such as missing reject buttons or unclear language, rather than solely complex technical setups. People who've examined similar audits in other regulated sectors often discover that licensing requirements do not automatically translate into stronger privacy compliance without targeted oversight.
Regulatory Context and Next Steps
The UK Gambling Commission maintains rules on fair advertising and player protection, while GDPR enforcement falls primarily under the Information Commissioner's Office. The GREAT Centre audit supplies evidence that regulators can reference when reviewing individual operator compliance records, though the report itself stops short of naming specific companies or recommending penalties.
Those who've studied data protection trends note that cookie consent remains an area of active enforcement across Europe, with recent guidance emphasizing granular choices and equal prominence for accept and reject options. The Swansea findings align with ongoing discussions about how gambling operators should adapt their data practices to meet both sector-specific and general privacy standards.
Conclusion
The 2026 audit by Swansea University's GREAT Centre provides a detailed snapshot of cookie consent practices across hundreds of licensed British gambling websites, documenting an 86 percent rate of at least one GDPR-related issue and highlighting particular problems with pre-consent data collection and manipulative interface designs. The results offer regulators and operators concrete data points for assessing current compliance levels and identifying areas where banner configurations fall short of legal requirements.