
A raft of bookmakers licensed by the United Kingdom Gambling Commission (UKGC) have been accused of flouting general data protection regulations (GDPR), according to a fresh study published.
Researchers at Swansea University’s Gambling Research, Education and Treatment (GREAT) Centre alleged in their findings that many of the UK operators didn’t comply with privacy requirements.
Among the key concerns raised was the use of cookie banners where users’ data was already being harvested before they had given their consent for it to be collected.
Tracking user preferences through cookies has become more commonplace nowadays. UK betting sites have typically used such information in the past to try to improve the wagering experience for players. However, Swansea University presented a more disturbing picture of how gambling operators were more negligent in implementing cookies.
In their report, researchers suggested that nearly a quarter (24%) of 624 gambling websites examined didn’t offer an option to turn off tracking software. These cookie banners, as Swansea University attested, exhibited “dark patterns” which nudged users to accept data sharing.
Indeed, of the banners tested, 86% displayed at least one dark pattern, while there were other GDPR infringements found. Over two-thirds of sites (67%) supposedly processed personable identifiable data before obtaining consent, while only 14% of sites were GDPR compliant.
Although UK operators are permitted to gather user data, researchers discovered the data was then sent to third-party platforms for marketing purposes.
Gambling operator interest in consumer data isn’t exactly a new phenomenon. In the modern age, the scope of consumer data has expanded significantly. However, Swansea University sought to investigate how data practices are managed, so as to ensure consumer rights are upheld.
Within their audit, researchers discovered that 2% of gambling operators didn’t have a consent banner present on the site. Interestingly, almost half of users (47%) were asked to click beyond the first layer of a cookie banner to find a reject option.
In some cases, it supposedly took up to 15 clicks to reject cookies on some sites, further frustrating users into accepting rather than gathering their freely stated preferences as intended by GDPR. Swansea University also reserved space to survey UK gamblers, detailing betting risk.
A Problem Gambling Severity Index (PGSI) was incorporated. Of the 615 participants, 85% gambled daily or almost daily, while just 9% placed a bet less than once a month. Meanwhile, 18% of gamblers fell into the high-risk category, which would suggest the banners did have an impact.
Currently, Britain’s data privacy regulator, the Information Commissioner’s Office (ICO), is beavering away on a project forcing websites to be more GDPR compliant with the banners displayed.
Ravi Naik, legal director at the data protection specialist firm AWO, admitted he wasn’t taken aback by the report’s findings, suggesting that privacy in the gambling sector is a systemic issue.
He said:
“It is sadly no surprise to see the findings in this report, yet the consequences of non-compliance are no less damaging.
“The most striking thing to arise from this report is the light it casts on the failure of the Information Commissioner's Office to take meaningful action against the online gambling sector.”
Swansea University maintained that the collation of users’ data was to “maintain engagement and customer losses”. Whether the ICO will amp up its efforts to stymie alleged rogue practises remains to be seen.

+18 | Please gamble responsibly | Commercial content | T&Cs apply GambleAware.com