Nearly 9 in 10 Gambling Sites Are Breaking Cookie Law. Your Website Might Be Too.

This week the Guardian reported on a study from Swansea University's GREAT Centre that examined 624 licensed British gambling websites. The finding: about 86% appear to have committed at least one breach of the GDPR through the way they handle cookie consent. Britain's regulator, the Information Commissioner's Office, is several years into a project to force websites to fix exactly this. It is a striking number - but the detail that should worry everyone else is buried further down: an earlier study of the wider web, across all industries, put the same figure at 54%.
In other words, gambling sites are the extreme. They are not the exception. More than half of all websites carry the same problem.
The cookie banner has quietly become the violation
For years the cookie banner was treated as a box to tick: add a banner, and you are compliant. The Swansea research shows how wrong that assumption is. The problem was rarely a missing banner. It was banners engineered to manufacture consent rather than collect it, and tracking that started before consent was ever given.
Across the 624 gambling sites, the researchers found:
Around two-thirds began harvesting user data before consent was given. Some pre-consent processing is lawful (confirming a visitor is in the UK, for example), but the study found data being sent to third-party analytics platforms used for marketing - which is not.
Nearly a quarter (24%) offered no way to turn tracking off at all.
2% offered no consent choice whatsoever.
The vast majority used "dark patterns" to nudge people into accepting: visual emphasis on the least private option (60%), privacy-unfriendly settings pre-selected by default (29%), and the reject option hidden behind a second layer (47%).
Under the GDPR and the ePrivacy rules, consent must be freely given, specific, and as easy to refuse as it is to accept. A banner built to nudge, hide, and default people into tracking does not collect valid consent. To a regulator, that is the same as having no consent at all - which makes every non-essential tracker firing on the page unlawful. As one data-protection specialist quoted in the Guardian put it, the findings "paint a picture of widespread and systemic non-compliance."
This is not a gambling problem. It is a web problem.
It is tempting to read the headline as a story about bookmakers behaving badly. It is not. Gambling was simply the vertical this study put under the microscope - and the 54% baseline across all websites tells you the same failures are sitting on ordinary sites right now.
We scan websites across retail, beauty, e-commerce, SaaS, and consumer brands every day, and we see the identical patterns: a household-name children's brand firing 86 trackers before any consent with no banner at all, global retailers loading advertising pixels the moment the page opens, "reject" buttons that close the banner but change nothing behind the scenes. The gambling numbers are worse, but the mechanism is universal, and the reason is the same everywhere.
Almost nobody tests what their cookie banner actually does. They test whether it exists.
Why "we have a banner" tells you nothing
A cookie banner is a promise rendered in a user interface. Whether it keeps that promise is a question about behavior, and behavior is invisible unless you measure it. Three failures hide in plain sight on sites whose owners believe they are compliant:
Trackers fire before consent. The banner is still on screen asking permission while analytics and advertising requests have already gone out. The consent was theater.
Reject does not actually reject. Clicking "reject all" dismisses the banner, but the tracking scripts keep running. Regulators treat this as no consent at all.
Dark patterns invalidate the consent that is given. If the interface was designed to steer the choice, any acceptance it produced does not legally count.
None of these show up in a policy review. None of them throw an error. The only way to catch them is to load the live site, interact with the banner the way a real user - or a regulator - would, and watch what the site actually does. That is exactly what the ICO's project involves, and exactly what plaintiffs' scanners look for.
How Complyy tests it
Complyy checks cookie consent the way it is actually experienced, not the way it is documented. For every site we monitor, we:
Confirm a consent banner is present with a genuine, accessible reject option - not just an "accept" button.
Measure whether tracking fires before consent by loading the page fresh and recording every request to advertising and analytics networks before any choice is made.
Click "reject" and verify it works - we exercise the reject flow, then re-inspect the network traffic to confirm the non-essential trackers actually stopped, rather than the banner simply disappearing.
Detect dark patterns - pre-ticked boxes, a reject option buried behind a second layer, or visual weighting that steers the choice.
Every finding comes with timestamped, verifiable evidence - screenshots and network logs captured at the moment of the test - so you can see exactly where your banner is failing and prove, later, that you fixed it. It is the same external, behavior-based examination a regulator would run, done continuously instead of once.
The window is closing
The significance of the Swansea study is not the 86% figure. It is that a regulator has moved from writing guidance to actively measuring compliance - the ICO says it has already brought 95% of the UK's top 1,000 websites into line - and is now under public pressure to enforce further. Cookie-banner enforcement is no longer theoretical, and the tools that surface these violations, automated scanners that load a site and watch what it does, are available to regulators, plaintiffs, and journalists alike.
The only real advantage left is to run those checks on yourself first. A banner that exists is not the same as a banner that complies. The difference is measurable today, and it is far cheaper to find it before someone else does.