Leadership1 distinct publisher3 min readPublished
The ICO counts cookie compliance among the country's most visited websites, while Swansea researchers tested 624 licensed gambling sites against a different measure, and the enforcement record in that sector runs to a single reprimand.
The Board Room · Leadership desk

Compiled by The Board RoomSomething wrong?How this is made
Both percentages can be true at once, and that is the more useful finding. One counts websites selected by traffic rank inside the regulator's own multi-year project and judged against its own criteria [4]. The other counts 624 licensed gambling sites against a threshold test of at least one apparent GDPR breach [1][2]. The pairing tells you how the ICO project defines its universe: its spokesperson described the work as "monitoring compliance across the UK's most visited websites" [12], which is a selection rule built on audience size rather than licence category or product risk.
Applied to the 624 sites, the percentages become countable populations. About 537 sites carry at least one apparent breach [1], roughly 150 offer no way to switch tracking off [2], around 416 begin collecting before consent [3], and about 12 present no consent choice at all [4]. Against the earlier study that looked at all types of website and found 54% non-compliance [11], gambling runs 32 percentage points higher, close to 1.6 times the rate [5].
A banner audit is not an adjudication, and the report itself concedes ground on that: dark patterns such as visual emphasis of the least private option, pre-selected settings and a reject button behind a second layer [8] do not in themselves constitute breaches [9], and the study's language is that sites "appear" to be flouting the rules [1]. Two of the remaining findings are about consent mechanics rather than design choices: no option to disable tracking at all [5], and no consent choice presented at all [7]. A third is about data flow: transmission to third-party analytics platforms used for marketing before consent was given [6]. All three sit squarely in the categories the cookie project exists to police.
The enforcement history in the sector, as reported, is thin and reactive. In 2024 the ICO reprimanded SkyBet for unlawfully sharing user data with advertising companies, after Clean Up Gambling raised concerns through the firm AWO; SkyBet was not among the operators the Swansea report places in breach [13]. Ravi Naik, AWO's legal director, said the most striking thing about the new findings is the light they cast on the ICO's failure to take meaningful enforcement action against online gambling [10]. Complaint-led enforcement needs a documented complaint, and the study now supplies one covering 624 sites [2].
Coverage by traffic rank is a defensible allocation for a regulator with finite staff, because it protects the most users per hour worked. The cost of that choice lands where the audience is smaller and the per-user stake is higher, which is the case the study's authors make when they describe the purpose of the data collection as "maintaining engagement and consumer losses" and point to the overlap between profitable behavioural patterns and harmful gambling [14]. That trade-off identifies who absorbs the cost, not whether the ICO chose wrongly.
The board-deck version writes itself: 86% of the sector is in the same position [1], the ICO has said only that it will act where necessary [12], and Evoke, which owns William Hill, declined to comment on the findings [15]. It is incomplete because regulators do not grade on a curve, and because the operators the study names by name, among them Hollywood Bets and Admiral Casino on the tracking finding [5] and Dafabet on the absence of any consent choice [7], are the cheapest cases for anyone to bring. The decision available this quarter is banner configuration; the decision that follows next year belongs to whoever reads the file first.
Ranked by verification strength, evidence, and original report placement.
Nearly nine out of 10 (86%) licensed British gambling websites appear to be flouting the GDPR, according to research by the University of Swansea's GREAT Centre; the same proportion appears to have committed at least one breach of GDPR.
The findings relate to the cookie banners that appear when a user first navigates to a website, asking which information they are willing to share.
The Information Commissioner's Office is in the midst of a multi-year project to force websites to comply with GDPR rules governing cookie banners, and claims to have forced 95% of the top 1,000 websites in the country to comply with the cookie and tracking regulations.
24% of the 624 gambling websites tested did not offer the option to turn off tracking software; operators without that option included Hollywood Bets, the Brentford FC sponsor, and Admiral Casino.
2% of the websites studied offered no consent choice at all, including Dafabet, the sponsor of Celtic FC.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 6, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
build
The ICO fines what you cannot prove: Article 32 makes encryption and erasure an engineering liability1 distinct publisher
product
Brazil fined ByteDance for data it took from users who never logged in1 distinct publisher
product
Reform UK bets EU adequacy survives scrapping the ICO's multi-million-pound fines1 distinct publisher
security
NIST's multi-cloud tally: one resilience win against 23 new problems1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One newsroom relaying one unpublished paper
Every number here — the 86%, the 624 sites, the three dark-pattern counts — reaches readers through the Guardian's reading of a Swansea paper that is neither linked nor dated in the story, and the test used to call a site in breach is never spelled out. What holds the floor up is that the interested parties are all on the record: the ICO defends its programme, Entain denies the marketing use, and Evoke's refusal to comment alongside two non-responses is reported rather than glossed.
Behaviour observed on live sites, not surveyed
The researchers loaded 624 licensed gambling sites and watched what the banners actually did, which is why the pre-consent traffic to third-party analytics is the sturdiest item in the set: it is a network observation, not a self-report. Set against it is the ICO's 95% figure, which covers a different population, the country's 1,000 busiest sites, and comes from the body being criticised.
A hedge that hardens on the way to the headline
The study's verb is that sites 'appear to' breach, and the reporting keeps that qualifier in the body while the round number travels without it. Two of the behaviours pooled into the 86% would need a regulator's finding to become violations: pre-consent requests that may be UK geolocation checks, and dark patterns the authors themselves say are not breaches on their own. No such finding exists in the sector beyond a 2024 reprimand of an operator the study did not flag.
Both the charge and the defence come from involved parties
The sharpest line belongs to AWO's Ravi Naik, whose firm carried the Clean Up Gambling complaint that produced the ICO's only gambling reprimand, a connection the Guardian discloses rather than buries. The researchers sit in a centre that studies gambling harm and frame data collection as a consumer protection problem; the ICO is answering a direct charge about its own record; the operators either issue a narrow denial or say nothing. Readers get the positions, and each position has something riding on it.
Descriptive counts firm, legal conclusion soft
The arithmetic checks out and the banner behaviour is the kind of thing a second researcher could reproduce in an afternoon, so the descriptive findings are safe to repeat. Confidence falls at the point where non-compliance becomes a legal characterisation: 'apparent breach' is the researchers' judgement, untested by the ICO, and the regulator's counter-figure covers websites that may barely overlap with the 624 tested.