sözaltı news World
World
EN AZ
Online bookies accused of UK privacy breaches with use of cookie banners

Online bookies accused of UK privacy breaches with use of cookie banners

theguardian.com 06.09.2026 09:00 7 views
Most gambling websites nudge users towards accepting tracking data and harvest it before consent is given, study showsOnline bookmakers and casinos have been accused of widespread non-compliance of information privacy re

Online bookmakers and casinos have been accused of widespread non-compliance of information privacy requirements, including “data surveillance” of customers, according to a study. Nearly nine out of 10 (86%) licensed British gambling websites appear to be flouting the general data protection regulation (GDPR), the strict rules governing how organisations can collect, store and process personal data, according to the research. The findings relate to the “cookie” banners that appear on a website when a user first navigates to it, asking which information they are willing to share.

Britain’s data privacy regulator, the Information Commissioner’s Office, is in the midst of a multi-year project to force websites to comply with GDPR rules governing the banners. It claims to have forced 95% of the top 1,000 websites in the country to comply with the cookie and tracking regulations. But a study by researchers at the University of Swansea’s GREAT Centre found that big operators in the gambling industry appear to lag far behind.

Nearly a quarter (24%) of 624 gambling websites tested did not offer the option to turn off tracking software, which allows advertisers to follow users around the web and target them with marketing tailored to their interests. Operators that did not provide an option to turn off tracking included the Brentford FC sponsor Hollywood Bets, and Admiral Casino, owned by the high-street slot machine firm of the same name. Two-thirds of operators began harvesting users’ data before they had given their consent for it to be collected, the study found.

They included well-known operators such as Ladbrokes and William Hill. Operators are allowed to do this for legitimate reasons, such as ensuring a customer is logging on from the UK, but researchers found that data was sent to third-party analytics platforms used for marketing. Of the websites studied, 2% offered no consent choice at all, including Dafabet, the sponsor of Celtic FC.

Researchers also found that the vast majority of bookies and online casinos use “dark patterns” to nudge people towards accepting data sharing. These nudges include visual emphasis of the least privacy-friendly option (60%), default pre-selection of privacy-unfriendly settings (29%), and the reject option being hidden behind a second layer (47%). Such patterns do not necessarily constitute breaches in themselves.

But the same proportion of websites that feature them, 86%, appear to have committed at least one breach of GDPR, the study found. This proportion is significantly higher than has been reflected in analysis of the wider internet. A previous study that examined all types of website, not just gambling, placed the figure at 54%.

Extract — continue reading at the source.

Read full story