Skip to main content
Licensed & Regulated
Expert Reviews
Responsible Gambling
18+
Regulatoryglobal

86% of UK Gambling Sites Face GDPR Compliance Issues, Swansea Study Finds

A Swansea University study reports that 86% of British gambling websites appear to breach GDPR rules, putting the UK gaming sector under fresh regulatory scrutiny. The research raises critical concerns over data protection practices across licensed operators in the UK.

Published
September 8, 2026
Read time
4 min
Sources
1 cited
31Casino editorial news image for regulatory: 86% of UK Gambling Sites Face GDPR Compliance Issues, Swansea Study Finds
AI-generated illustration

Article overview

This report reads a live market development through the lenses that matter most on 31Casino: regulation, operator conduct, and the likely effect on ordinary players trying to understand what changed.

Focus

Regulatory coverage with global market context.

Reporting basis

1 cited sources across 1 source domains.

Updated reading

Sources reviewed through Sep 8, 2026.

Reader takeaway

Gambling news matters most when it does more than repeat a headline. The useful question is what the development changes for market clarity, compliance, and player trust.

yogonet.com

Lead brief

A Swansea University study reports that 86% of British gambling websites appear to breach GDPR rules, putting the UK gaming sector under fresh regulatory scrutiny. The research raises critical concerns over data protection practices across licensed operators in the UK.

Coverage frame

This piece sits inside the wider 31Casino news desk, where single developments are read against regulation, market structure, and reader relevance.

Primary source base

yogonet.com
Quick Summary
  • A Swansea University study found 86% of UK-licensed gambling sites may violate GDPR requirements.
  • The research examined 624 online gambling platforms, focusing on cookie consent practices.
  • Almost a quarter of sites reportedly failed to use cookie banners altogether.
  • The findings highlight ongoing regulatory and compliance challenges within the UK gambling sector.

What Happened

A team at Swansea University’s GREAT Centre conducted an extensive review of 624 gambling websites operating under UK licenses. The study, reported by The Guardian, centred on how these sites manage user data consent, particularly through cookie banners displayed upon visiting. The findings reveal that nearly nine in ten of these gambling platforms appear non-compliant with essential GDPR standards, casting doubt on industry-wide data protection practices.

Of special concern, approximately 24% of the sites reviewed did not display cookie banners at all, meaning users visiting these platforms may have their data collected without clear consent. Such banners are a central tenet of GDPR, designed to give users a meaningful choice over tracking and data sharing.

Why It Matters

The findings expose a fundamental disconnect between regulatory requirements and day-to-day data collection practices in the UK gambling market, which is among the world’s most closely scrutinised online gaming environments. For operators, the risk extends beyond regulatory censure to potential financial penalties and reputational damage.

The General Data Protection Regulation (GDPR), in force since May 2018, requires organisations that process personal data of EU and UK citizens to implement clear, lawful consent mechanisms for data collection. Cookie banners have become the industry standard for obtaining and managing this consent. The Swansea study suggests that the vast majority of UK gambling sites are falling short in delivering genuine consent options.

💡

86% — the proportion of UK-licensed gambling platforms examined that showed apparent failures to meet GDPR compliance standards, according to Swansea University researchers.

This is particularly significant in light of persistent public concern over data privacy and the potential for misuse of player information, especially in a sector where personal data is both sensitive and highly valuable. The apparent scale of non-compliance identified in the report may prompt renewed focus from the Information Commissioner’s Office (ICO) and the UK Gambling Commission (UKGC), both of which are responsible for enforcing privacy and operational standards.

Industry Context

Online gambling operators in the UK are subject to a dual compliance regime: they must meet the requirements of the UK Gambling Commission for their gaming activity and adhere to comprehensive data protection laws under GDPR. In recent years, the UKGC has sharpened its scrutiny of operators, particularly concerning social responsibility, marketing, and customer data practices.

However, the cookie consent gap identified in the Swansea research aligns with broader European findings. Studies across other markets have revealed that many digital businesses, from retailers to news sites, still fall short of full GDPR compliance, often due to unclear consent mechanisms or opaque data-sharing practices.

For gambling sites, the stakes are high. Operators handle vast amounts of personal and behavioral data, including financial transactions, player habits, and communication logs. Failure to properly obtain and document user consent can lead to enforcement action, including fines or, in extreme cases, licence suspension.

Regulatory Background

UK gambling operators are bound by the UK GDPR, which mirrors the EU’s GDPR following Brexit. This regulation places responsibility on businesses to inform users about how their data will be used, to gain affirmative opt-in consent before storing or sharing non-essential cookies, and to allow users to subsequently withdraw consent easily.

The UK Gambling Commission, while primarily mandated to tackle gambling-related harm and crime, also monitors whether its licensees uphold their legal obligations under privacy legislation. Past enforcement actions have targeted failures in anti-money laundering, customer verification, and advertising, but data protection is increasingly coming under the regulatory spotlight as digital operations proliferate.

What Happens Next

The Swansea University report is expected to trigger further investigation by both the ICO and UKGC. Operators cited as non-compliant could face warnings or formal enforcement action, including requirements to amend cookie consent processes or demonstrate robust GDPR policies. Given continued regulatory focus on player protection and compliance, UK licensees will likely review and update their data privacy practices as a matter of urgency to avoid substantial penalties.

Sources


This article is for informational purposes only. 31Casino does not provide gambling services or recommendations. If you're concerned about your gambling, visit our Responsible Gambling page for support resources.

Source appendix

Research trail for this article

The reporting below is grounded in publicly accessible material reviewed for this story. Source pages are listed individually so readers can trace the original record.