UK gambling websites breach GDPR by misusing cookie banners
A new study has found that the majority of licensed British gambling websites are collecting tracking data from users before obtaining the required consent, a practice that breaches the European Union’s General Data Protection Regulation (GDPR). The research, which examined a sample of online bookmakers and casino operators, identified systematic “data surveillance” tactics that nudge visitors toward accepting tracking cookies and other identifiers without clear, informed permission.
The analysis shows that 86 percent of the sites surveyed appear to be non‑compliant with GDPR’s strict rules on the collection, storage and processing of personal information. investigators observed that many platforms embed consent banners in a manner that discourages users from rejecting tracking, and in several cases harvest behavioural data prior to any affirmative opt‑in. The findings raise concerns about the adequacy of current oversight mechanisms, as the gambling sector is subject to both industry‑specific licensing requirements and broader data‑privacy legislation.
Regulatory bodies have been urged to scrutinise the practices uncovered by the study and to enforce corrective measures where violations are confirmed. Failure to comply with GDPR can result in substantial fines, and continued non‑compliance may prompt further investigations into the data‑handling policies of online gambling operators, reinforcing the need for transparent consent procedures to protect consumer privacy.