Study Finds Widespread Privacy Breaches and Data Surveillance Across UK Gambling Websites

Update: 6 September 2026, 7:36:55 PM

A study conducted by researchers at Swansea University’s GREAT Centre has accused the online gambling industry of systemic non-compliance with privacy regulations. The research indicates that nearly nine out of 10 licensed British gambling websites—approximately 86%—appear to be flouting the General Data Protection Regulation (GDPR), which governs the collection, storage, and processing of personal data.

The report highlights a practice described as “data surveillance,” where operators prioritize maintaining engagement and consumer losses through the aggressive collection of user information. Researchers found that two-thirds of the operators studied began harvesting data before users had provided explicit consent. While companies are permitted to collect data for specific legitimate purposes, such as verifying a user’s location, the study observed that information was frequently funneled to third-party analytics platforms for marketing purposes.

Several major industry players were identified in the research. For instance, 2% of the websites analyzed offered no mechanism for users to withhold consent, including Dafabet, which sponsors Celtic FC. Other operators that failed to provide an option to disable tracking included Hollywood Bets, a sponsor of Brentford FC, and Admiral Casino. Furthermore, well-known brands such as Ladbrokes and William Hill were noted for collecting data prior to receiving user approval.

The study also identified the widespread use of “dark patterns” designed to manipulate users into accepting data sharing. These tactics include visually emphasizing privacy-invasive options (60%), pre-selecting settings that favor data collection (29%), and burying the “reject” option behind secondary menus (47%). While these design choices are not inherently illegal, the researchers noted that the 86% of sites utilizing them also appeared to commit at least one GDPR breach, a figure significantly higher than the 54% breach rate found in studies of the broader internet.

Legal experts have characterized these findings as evidence of systemic failure. Ravi Naik, legal director at the data protection firm AWO, stated that the report highlights the failure of the Information Commissioner’s Office (ICO) to implement meaningful enforcement against the online gambling sector. AWO has previously worked with the campaign group Clean Up Gambling to raise compliance concerns with regulators.

In 2024, the ICO issued a reprimand to SkyBet for unlawfully sharing customer data with advertising firms. This action followed concerns that the operator was using data regarding a customer’s early-morning gambling habits to send personalized inducements. Notably, SkyBet was not among the companies cited for GDPR breaches in the Swansea University report.

Industry responses to the findings have been mixed. Evoke, the owner of William Hill, declined to comment on the study. Entain, which owns Ladbrokes, asserted that any data collected before consent was obtained was not utilized for advertising or marketing purposes. Hollywood Bets and Admiral Casino did not respond to requests for comment. The study’s authors concluded that the design of data consent is a critical consumer protection issue, particularly given the structural overlap between profitable behavioral patterns and harmful gambling habits. The report also notes that default pre-selection of privacy-unfriendly settings (29%), and the reject option being hidden behind a second layer (47%), these nudges include visual emphasis of the least privacy-friendly option (60%). The report also notes that not just gambling, placed the figure at 54%, a previous study that examined all types of website. The report also notes that you can contact Rob using one of the following methods, if you have something to share about this story. The report also notes that app has a tool to send tips about stories. The report also notes that messages are end to end encrypted and concealed within the routine activity that every Guardian mobile app performs. The report also notes that let alone what is being said, this prevents an observer from knowing that you are communicating with us at all. The report also notes that download it (iOS / Android ) and go to the menu, if you don’t already have app. The report also notes that to send a message to Rob Davies please choose the ‘Business’ team.

More News

Comments

Your email address will not be published.