Science1 publisher3 min readPublished
Swansea audit of all 624 UK-licensed gambling sites puts 86% in breach of GDPR
Because the Swansea team crawled every licensed casino and betting site on the register, the 86% breach figure counts the whole industry. A companion experiment put six banner designs in front of 615 UK online gamblers.
The Scientist · Science desk
What happened
- Swansea University's GREAT Center reports that 86% of UK-licensed online gambling websites are operating in breach of the GDPR, in a paper published in Computers in Human Behavior Reports.
- The audit covered the cookie consent banners and network traffic of all 624 casino and sports betting websites licensed by the Gambling Commission.
- Two-thirds of the sites, 67%, began collecting personally identifiable data before consent, sending unique user identifiers to third-party analytics and marketing platforms.
- Almost a quarter of the sites, 24%, gave users no way to refuse tracking at all, and 2% displayed no consent banner whatsoever.
Compiled by The ScientistSomething wrong?How this is made
Why it matters
- exposure Compliance was tested against the licence register, with every licence holder checked by the same method. That leaves an operator no sampling argument to make.
- decision The cheapest fix, a reject button as easy to use as the accept button, is also the change the experiment associates with a three to fourfold drop in acceptance. Operators now choose between the fix and the data yield.
- constraint The paper documents identifiers leaving sites before consent but does not show those identifiers being used on players displaying harm markers, the link a regulator leaning on the gambling-harm argument would need.
Multiply 624 by 0.86 and you get about 537 sites [1][2][1]. The denominator here is the Gambling Commission's licence register itself, so there is no sampling error to argue about and no question of whether the non-compliant sites were the ones that happened to get picked [2]. The 67% that sent unique user identifiers to third-party analytics and marketing platforms before consent was given works out at about 418 sites [3][4].
The second half of the paper is a different kind of evidence. Each of 615 UK online gamblers saw a simulated betting site carrying one of six consent banners, so the site was held constant and the interface varied [7]. The design most common across the industry made participants three to four times more likely to accept tracking than a neutral, one-click alternative [8]. Because the site was a mock-up, what it measures is a click on a simulation by participants who were not in the middle of a real bet [7].
Participants who accepted rated their choice 4.4 out of 10 as a reflection of their real privacy preferences. Those who rejected rated theirs 7.9 [9]. The authors take the 3.5-point gap as evidence that the design drove the outcome [9][5]. A rating collected after the click cannot fully separate the banner's push from ordinary regret. The effect held regardless of participants' level of gambling risk, so the lower-risk gamblers in the sample were moved as much as the higher-risk ones [10].
The audit also counted the dark patterns, interface designs that steer users toward the least private option: 60% of banners gave the accept button visual emphasis, 47% hid the reject option behind a second layer and 29% preselected privacy-unfriendly settings [6]. Only 29% let a user refuse as easily as accept; that leaves about 443 sites [5][2]. McGarrigle, the doctoral student who led the work [12], said: "Some make it a single click to accept and up to 15 to refuse. Our follow-up experiment showed this isn't incidental; it works exactly as you'd expect, nudging people toward decisions they don't actually agree with." [13]
The paper's harm argument goes further than the audit measured. The authors argue that the characteristics used to identify commercially valuable players overlap substantially with the behavioural markers of gambling harm [11]. Dymond said: "Our research shows that the data being harvested through these designs isn't neutral; it's the same kind of behavioral signal that can flag risk." [15] The audit shows identifiers leaving browsers before consent and the experiment shows the banners work on gamblers. Tracing one data point through to a marketing decision about a particular customer is a step beyond both [3][8]. The published report of the study does not describe any regulatory action against the sites [18].
What to watch
- Whether any regulator acts on findings that cover every licensed operator, and whether the site-level results are released in a form an investigation could use.
- A repeat crawl of the same 624 sites, where the share collecting identifiers before consent is the figure to compare against 67%.
- Whether operators move to symmetric one-click banners, and what happens to their measured acceptance rates when they do.