Cookie Consent by Free Privacy Policy Generator

UK gambling websites accused of widespread GDPR breaches

86% of licensed British gambling websites appear to be flouting GDPR requirements in how they handle tracking cookies and user consent, according to a new study reported by The Guardian. The research found that most gambling sites nudge users towards accepting tracking data through manipulative design patterns in cookie banners, and many harvest tracking data before consent is given. The findings describe this as "data surveillance" of customers and highlight that the scale of non-compliance suggests systemic issues across the sector rather than isolated lapses. The research raises questions about whether the Information Commissioner's Office has sufficient resources to enforce privacy rules consistently across high-risk sectors.

Why this matters for UK organisations

Cookie consent is not a technical problem, it is a governance and design problem. GDPR requires that consent is freely given, specific, informed and unambiguous, and that tracking does not begin before consent is obtained. The gambling sector handles sensitive personal data, financial information and behavioural patterns that can be used to profile vulnerable individuals, which makes privacy compliance particularly important. The fact that such a high proportion of UK-licensed operators appear to be non-compliant suggests that many organisations are still treating cookie banners as a compliance checkbox rather than a meaningful privacy control, and that enforcement action may be inconsistent or under-resourced. This is not unique to gambling; similar issues exist across e-commerce, media, retail and other sectors that rely on behavioural tracking for advertising and analytics.

What to review

Review whether your website's cookie consent mechanisms meet GDPR requirements, whether tracking starts before consent is given, and whether your consent banners use design patterns that genuinely allow users to refuse tracking as easily as they can accept it. Audit what tracking technologies are deployed, what data they collect, who that data is shared with, and whether your privacy notices accurately reflect current practice. If your organisation handles sensitive data or operates in a regulated sector, the risk of enforcement action and reputational harm from non-compliance is higher. Ensure that privacy compliance is owned by someone with the authority to challenge design and commercial decisions, and that cookie consent is reviewed regularly as part of your data protection governance.

Source: The Guardian

News and blog posts
OpenAI's AI agents autonomously compromised a defunct German website in May...
86% of licensed British gambling websites appear to be flouting GDPR...
The G7 has published a call to action urging governments to launch national...
Today's brief covers four areas where familiar security disciplines need...