Back to News

86% of Gambling Sites Breach GDPR With Cookie Banners - Is Your Business Website Next?

86% of Gambling Sites Breach GDPR With Cookie Banners - Is Your Business Website Next?

On 6 September 2026, researchers at Swansea University published findings that ought to make every UK business owner look again at the little box that appears in the corner of their own website. Testing 624 licensed British gambling websites, the university’s GREAT Centre found that 86% appear to breach GDPR through the way they ask - or fail to ask - for cookie consent, and through the data they collect before anyone has agreed to anything. The story has been framed as a gambling story, and the operators named in it are household betting brands. But the mechanism being described is not specific to gambling in any way. It is a consent banner, a tag manager, and a set of defaults that nobody has audited since the day the site went live.

That is the part that should concern a UK SME reading this on 7 September 2026. The study’s comparison point is the more uncomfortable number: a previous piece of research covering websites of all types, not just gambling, found a GDPR non-compliance rate of 54%. The gambling sector is worse than average - substantially worse - but the average itself means that more than half of the websites on the internet are getting this wrong. If you run a business website with Google Analytics, a Meta pixel, a live chat widget, a heatmap tool and a booking system, the statistical odds are not on your side, and they never have been.

What has changed is the enforcement climate. The Information Commissioner’s Office is partway through a multi-year project targeting cookie banner compliance specifically, and claims to have brought 95% of the UK’s top 1,000 websites into line. In 2024 it formally reprimanded SkyBet for unlawfully sharing user data with advertising companies after a complaint was raised through the campaign group Clean Up Gambling. The regulator is working downwards through the traffic rankings and acting on complaints when they arrive. A consent banner that was “good enough” in 2019 is now a documented, evidenced, publicly testable compliance failure that any competitor, disgruntled customer or researcher can screenshot in thirty seconds.

86%
Of 624 licensed British gambling sites appear to breach GDPR
624
Licensed gambling websites tested by Swansea University
66%
Began harvesting user data before consent was given
54%
Non-compliance rate found across websites of all types

What the Swansea researchers actually found

The study, carried out by the GREAT Centre at Swansea University, took the population of 624 gambling websites licensed to operate in Britain and tested each one for how it handles cookie consent and what data it collects. That population choice matters: these are not fly-by-night offshore operations outside the reach of UK law. They are licensed operators, regulated by the Gambling Commission, with legal departments, compliance functions and the resources to get this right. The finding that 86% appear to breach GDPR is therefore not a story about cowboys. It is a story about what happens when a legal requirement is delegated to a marketing tag and then forgotten.

The failures fall into three distinct categories, and it is worth separating them because they carry different levels of legal risk and require different fixes. The first is the absence of choice. Nearly a quarter of the sites tested - 24% - offered no way at all to turn off the tracking software that allows advertisers to follow users around the web. The banner may have appeared, the word “cookies” may have been used, but there was no functioning mechanism to decline. A smaller group, 2% of sites, offered no consent choice whatsoever - among them Dafabet, the shirt sponsor of Celtic FC. A banner that cannot be refused is not a consent mechanism; it is a notification, and under UK GDPR and PECR a notification does not create a lawful basis for non-essential cookies.

The second category is collection before consent, and it is the most widespread. Two-thirds of operators began harvesting user data before the user had given consent, including well-known brands such as Ladbrokes and William Hill. In some cases that data was passed straight to third-party analytics and marketing platforms. This is the failure mode that trips up the most well-intentioned organisations, because it is almost never a deliberate decision. It is a tag firing on page load because that is what tags do unless something stops them. The banner asks the question politely while the network tab shows the answer has already been sent.

The third category is dark patterns - interface design deliberately weighted to produce the answer the operator wants. The researchers found visual emphasis on the least privacy-friendly option on 60% of sites (the “Accept all” button rendered large, coloured and prominent while “Reject” is small, grey or rendered as plain text). They found pre-selected privacy-unfriendly defaults on 29% - toggles switched on before the user has touched anything. And they found the reject option hidden behind a second click on 47%, buried inside a “Manage preferences” sub-panel that the user must actively seek out. Each of these is a documented, named technique. None of them is compatible with the requirement that consent be freely given, specific, informed and as easy to withdraw as it is to give.

Ravi Naik, legal director at the data protection specialist AWO, said the findings “paint a picture of widespread and systemic non-compliance”, and was critical of what he characterised as the ICO’s lack of meaningful enforcement action specifically against online gambling. That criticism cuts both ways for a business reading this. It is true that enforcement in this area has been light relative to the scale of the problem. It is also true that regulators respond to public research findings, press coverage and complaints - and this study has now supplied all three.

Why this is a general business risk, not a gambling story

Nothing in the Swansea findings is specific to betting. The 86% figure comes from a sector that happens to have been tested; the 54% baseline across all website types is the number that applies to everyone else. If your site loads Google Analytics, an advertising pixel, a chat widget or a session-recording tool before the visitor has clicked anything, you have the same collection-before-consent problem as Ladbrokes and William Hill. If your banner shows a bright “Accept all” button and hides “Reject” behind “Manage preferences”, you have the same dark pattern problem as the 47%. The difference between you and a named operator in a national newspaper is traffic rank and the attention of a researcher - not the underlying compliance posture.

How British cookie consent law reached this point

The rules that the Swansea study measured against are not new, and none of them arrived without warning. The chronology below matters because it removes the most common defence a business reaches for when a compliance gap is pointed out - that the requirement was unclear, or recent, or unenforced. It has been clear for eight years, clarified repeatedly since, and actively worked by the regulator for the past three.

25 May 2018 - GDPR takes effect
The General Data Protection Regulation becomes applicable across the EU and, via the Data Protection Act 2018, in the UK. Consent must be freely given, specific, informed and unambiguous, expressed through a clear affirmative action. Silence, pre-ticked boxes and inactivity are explicitly ruled out. Alongside it, the Privacy and Electronic Communications Regulations (PECR) continue to require consent before non-essential cookies and similar technologies are placed on a user’s device.
July 2019 - The ICO updates its cookie guidance
The Information Commissioner’s Office publishes updated guidance on cookies and similar technologies, and brings its own website into line at the same time. The guidance is unambiguous on the points the Swansea study found breached: implied consent is not consent, cookie walls are problematic, and non-essential cookies must not be set before the user has agreed. Analytics cookies are confirmed as non-essential, notwithstanding how routinely they are treated otherwise.
May 2020 - European guidance closes the loopholes
Updated consent guidelines confirm that continuing to scroll, or simply continuing to browse, does not constitute valid consent, and that access to a service cannot be made conditional on accepting non-essential cookies. The practical effect is to invalidate an entire generation of banner designs built on the assumption that carrying on using the site counts as agreement.
November 2023 - The ICO writes to the UK’s biggest websites
The regulator moves from guidance to direct intervention, contacting the operators of the country’s most-visited websites and giving them a deadline to fix non-compliant cookie banners. The specific complaint is the one the Swansea researchers measured: it must be as easy to reject non-essential cookies as it is to accept them. Emphasis, click count and default state are all in scope.
2024 - The programme widens beyond the top 100
Having reported substantial compliance improvements among the largest sites, the ICO commits to extending the same review methodology down through the traffic rankings, ultimately targeting the top 1,000 UK websites. The message to everyone below that line is explicit: the standard is the same regardless of where you sit in the rankings, and the review is working downwards.
2024 - SkyBet formally reprimanded
The ICO issues a formal reprimand to SkyBet for unlawfully sharing user data with advertising companies, after a complaint was raised through the campaign group Clean Up Gambling. The case establishes two things a UK business should note: the regulator does act on cookie and adtech data-sharing failures, and the trigger was a complaint from a third party rather than a proactive audit.
2025–2026 - The ICO reports 95% compliance in the top 1,000
The regulator states that its cookie compliance project has brought 95% of the UK’s top 1,000 websites into line. The figure is a genuine achievement and a warning at the same time: the remediation effort has been concentrated at the top of the traffic distribution, which means the compliance gap now sits almost entirely with the small and medium-sized organisations nobody has contacted yet.
6 September 2026 - The Swansea findings are published
Swansea University’s GREAT Centre reports that 86% of 624 licensed British gambling websites appear to breach GDPR, with two-thirds collecting data before consent, 24% offering no way to disable advertising trackers, and dark patterns present across the majority of banners. AWO’s Ravi Naik describes the picture as “widespread and systemic non-compliance”.
7 September 2026 - The read-across for everyone else
A named, quantified, sector-wide study is now on the public record, alongside an existing 54% non-compliance baseline for websites generally. For any UK organisation, the useful response is not to read it as a gambling story but to run the same tests against its own site - open the developer tools, load the homepage in a clean browser profile, and see what fires before the banner is answered.

The failure modes, ranked by how common they are

Grouping the study’s findings by prevalence gives a rough priority order for anyone auditing their own site. The bars below combine the gambling-sector figures with the wider-internet baseline, so the fourth bar is the one to read as “the average website” rather than “the average bookmaker”.

Gambling sites appearing to breach GDPR overall
86%
Collecting user data before consent was given
66%
Visual emphasis on the least privacy-friendly option
60%
All website types - non-compliance baseline
54%
Reject option hidden behind a second click
47%
Pre-selected privacy-unfriendly defaults
29%
No way at all to switch off advertising trackers
24%

Read the bars from the bottom up and they describe an escalating scale of difficulty rather than an escalating scale of severity. The 24% at the bottom - no way to turn off advertising trackers - is the most serious legal failure but the rarest, and it is usually a symptom of a consent platform that was installed in “notice only” mode and never switched to a mode that actually gates anything. The 29% with pre-selected defaults is a configuration setting, often a single toggle inside the consent management platform, sitting on the wrong value because the wrong value was the default when the account was created.

The middle band is design. 47% hiding rejection behind a second click and 60% visually emphasising acceptance are both deliberate choices made by somebody - usually a marketing team optimising for opt-in rates, occasionally a template author who has never read the guidance. These are the ones that generate the most argument internally, because the business case for the dark pattern is real and immediate (higher consent rates mean better analytics coverage and better ad attribution) while the compliance case is abstract until a complaint arrives.

The 66% collecting data before consent is the technical failure, and it is the one that most often surprises the organisation running the site. A business can have a perfectly designed banner with a balanced Accept and Reject, no pre-ticked boxes and no dark patterns - and still be firing Google Analytics, a Meta pixel and a heatmap script on page load because those scripts were hard-coded into the template three years before the consent platform was bought. The banner and the tags are two separate systems, and unless somebody explicitly wired the first to gate the second, they simply run in parallel and ignore each other.

Why 86% is the number that survives scrutiny

An eighty-six per cent failure rate invites a reasonable question: is the bar simply set too high? It is a fair challenge and it deserves a direct answer. The requirements the researchers tested against are not aspirational best practice, and they are not a maximalist reading of the law. They are the four things the ICO has said in guidance, in direct correspondence with website operators, and in its published enforcement outcomes: do not set non-essential cookies before consent; make rejection as easy as acceptance; do not pre-tick the boxes; and make the choice real, meaning that declining actually stops the tracking. A site can fail all four while displaying a banner that looks entirely professional. That is precisely why the failure rate is so high - the banner is doing the job it was bought to do, which is to look like compliance, and nobody has tested whether it is compliance.

86%
Of 624 licensed British gambling websites appear to breach GDPR on cookie consent and data collection - against a 54% baseline for websites of all types

The second reason the figure holds up is that these tests are observable from outside. A researcher does not need access to your servers, your privacy notice, your records of processing activity or your data protection impact assessments to establish that a tracking cookie was written before the banner was answered. They need a browser with a clean profile and the network tab open. The entire methodology can be replicated by a journalist, a competitor, a customer with a grievance, or an automated scanner running against a list of domains. Compare that to most areas of data protection compliance, where a breach is invisible until something goes wrong internally. Cookie consent is the one part of GDPR that is continuously and publicly auditable, at zero cost, by anybody who cares to look.

That external observability is what turns this from a paperwork risk into a practical one. The SkyBet reprimand in 2024 did not begin with an ICO audit - it began with a complaint raised through Clean Up Gambling. The regulator’s capacity to proactively review the whole UK web is obviously finite; that is why its own project has been organised around the top 1,000 sites by traffic. But its capacity to respond to a well-evidenced complaint about a small business is not constrained in the same way, because the evidence arrives pre-assembled. For an SME, the realistic risk pathway is not a random audit. It is somebody with a screenshot and ten minutes.

Where UK SME websites most often fail

The grid below maps the study’s findings onto the specific failure points we see most frequently on small and medium-sized business websites. The badge reflects how likely the item is to be a live problem right now on a typical UK SME site that has not had a consent audit, not how severe the legal consequence would be.

Cookie consent failure points on a typical UK SME website
Analytics or advertising tags firing before the banner is answered High
“Reject all” requires more clicks than “Accept all” High
No record kept of who consented, to what, and when High
Third-party embeds (maps, video, chat, fonts) outside the consent gate High
Cookie policy lists categories that no longer match the tags in use Medium
Non-essential toggles pre-set to “on” in the preference panel Medium
No route for a visitor to change or withdraw consent after the first visit Medium
Strictly necessary cookies correctly identified and exempted Low

Read the high band together and a pattern emerges: every one of those four items is a wiring problem rather than a policy problem. The organisation has bought a consent tool, written a cookie policy and added a banner - the artefacts of compliance are all present. What is missing is the connection between the banner and the things it is supposed to control. Tags fire because nothing gates them. Embeds load because an iframe from a video platform or a mapping service does not consult your consent manager unless you make it. Consent records are absent because logging was never switched on, and without them the organisation cannot demonstrate compliance even where it has achieved it - which under Article 7 is itself a failing.

The medium band is drift. A cookie policy is accurate on the day it is written and decays from then on, because tags accumulate. Marketing adds a pixel for a campaign; the campaign ends; the pixel stays. A developer adds a session-recording tool to debug a checkout problem and never removes it. Two years later the policy describes a site that no longer exists. The single most useful discipline here is not a bigger policy document but a scheduled re-scan: a quarterly check of what is actually loading, compared against what the policy says loads.

The one item in the low band - correctly identifying strictly necessary cookies - is where most organisations genuinely do fine, largely because platforms handle it. Session cookies, load balancing, basket contents, security tokens and authentication state are all exempt from the consent requirement, and content management systems generally get this right out of the box. The mistake to avoid is the reverse one: assuming that because a cookie is useful to you, it is necessary. Analytics is the classic case. It is valuable, it is first-party, it feels harmless - and it is unambiguously non-essential under the ICO’s guidance, which means it needs consent like everything else.

What a proper consent audit and rebuild costs

The figures below are indicative first-year costs for a UK organisation putting this right properly: auditing what actually loads, wiring the consent gate to the tags, rebuilding the banner so acceptance and rejection are genuinely equivalent, enabling consent logging, and updating the cookie policy to describe reality. They assume an existing website on a mainstream platform and exclude any wider site redesign.

Business size Typical exposure Proportionate response Indicative first-year cost
1–10 staff Brochure or small e-commerce site on WordPress, Shopify or a website builder; a free consent plugin installed at launch and untouched since; Google Analytics and possibly a Meta pixel hard-coded into the theme; no consent logging; cookie policy copied from a template Full scan of what loads before and after consent; move analytics and advertising tags behind a consent gate; rebuild the banner with equal-weight Accept and Reject on the first layer; enable consent logging; rewrite the cookie policy against the actual tag list; add a persistent link to change preferences £750 – £2,200
11–50 staff Marketing site plus one or more connected systems - CRM forms, booking engine, live chat, embedded video, a heatmap or session-recording tool; tags managed partly in a tag manager and partly in the template; more than one agency has touched the site over the years The above, plus consolidation of all tags into a single managed layer with documented consent categories; review of third-party embeds and iframes; data processing agreements checked against the tools actually in use; a documented quarterly re-scan; briefing for the marketing team on why opt-in rate is not the only metric £2,500 – £7,000
51–150 staff Multiple sites or subdomains, possibly multiple markets; an advertising stack with attribution dependencies; regulated or contractual obligations to evidence data protection controls; an existing Cyber Essentials certification and a named data protection lead The above across the full estate, plus a consent management platform configured for cross-domain consistency; server-side tagging reviewed for the same before-consent failure; consent records retained and reportable; documented evidence pack for the accountability principle; annual review scheduled with the data protection lead £7,000 – £18,000
150+ staff Complex estate with legacy microsites nobody owns; adtech integrations passing identifiers to multiple partners; international traffic engaging both UK GDPR and EU GDPR; genuine commercial dependency on measurement and attribution The above, plus a mapped inventory of every domain and every processor receiving data; contractual review of adtech partners; a tested process for handling consent-related complaints and subject access requests; continuous automated scanning with alerting when a new tag appears outside the gate £18,000 – £45,000

Two things are worth noting about those bands. The first is that the bottom band - under two thousand pounds for a small business - is not a large number against the risk it removes, and a substantial part of that work is one-off rather than recurring. The second is that the cost driver in the upper bands is almost never the banner. It is the inventory: establishing what is actually on the site, which third parties receive data, and under what agreement. Organisations consistently underestimate that step because they assume a list already exists somewhere. On the great majority of estates we look at, it does not.

Two postures, and the difference between them

Almost every organisation caught by a study like this one was in the first column below. Very few were negligent; most had bought a tool, ticked the box and moved on. The gap between the columns is not spending, and it is not legal expertise. It is whether anybody has ever tested the thing rather than installed it.

Reactive posture

What most UK SME websites look like today

  • A consent banner installed at launch, using whichever plugin was free or default, never reconfigured since
  • Analytics and advertising tags hard-coded in the template, firing on page load regardless of what the banner says
  • “Accept all” styled as the primary button; “Reject” behind a “Manage preferences” link, if present at all
  • No consent log, so the organisation cannot demonstrate compliance even for the visitors it handled correctly
  • Cookie policy written once, describing a tag list that has since changed several times
  • Third-party embeds - maps, video, chat, hosted fonts - loading outside the consent gate entirely
  • Nobody owns the question; it sits between marketing, the web agency and whoever handles IT
  • Compliance status is unknown until a complaint, a customer question or a press story forces the check

Proactive posture

Where Cloudswitched web development takes you

  • Every non-essential tag gated by the consent layer, verified by loading the site in a clean profile and watching the network
  • Accept and Reject presented with equal visual weight, on the first layer, in a single click each
  • No pre-selected non-essential toggles anywhere in the preference panel
  • Consent decisions logged with timestamp and scope, so the accountability principle can actually be evidenced
  • A persistent, findable route for visitors to change or withdraw consent on any later visit
  • Third-party embeds placeholdered until consent is given, with a clear explanation of what loading them means
  • A quarterly re-scan that catches new tags before they become a finding, with a named owner for the result
  • Cookie policy generated from the real tag inventory and updated when the inventory changes, not annually by memory

The item that carries the most weight in that second column is the least glamorous one: the quarterly re-scan. Consent compliance is not a state you reach, it is a state you maintain, because the thing being regulated - what loads in a visitor’s browser - changes every time somebody adds a campaign pixel or embeds a video. A site that was fully compliant in March can be firing an ungated tracker in June without a single line of the consent configuration having changed. That is exactly how sixty-six per cent of a regulated, resourced, professionally managed sector ended up collecting data before consent.

41
Typical UK SME website readiness against the four tests the ICO actually applies - Cloudswitched indicative score out of 100

Forty-one is a poor score and a very recoverable one, and the split behind it is consistent. Organisations score well on the visible artefacts - a banner exists, a cookie policy exists, someone can point at both - and badly on everything that requires the artefacts to be connected to the site’s actual behaviour. The heaviest single deduction is almost always tags firing before consent, because it fails the most fundamental requirement and because it is present on the majority of sites we scan. The second heaviest is the absence of consent records, which is invisible to the visitor but is the first thing a regulator asks for.

What makes the number recoverable is that most of the deductions come from a small number of fixable causes. Gating the tags is a configuration change, not a redevelopment. Rebalancing the banner is a design change measured in hours. Switching on consent logging is usually a checkbox inside a tool the organisation is already paying for. The work that takes real time is the inventory - establishing what is loading and who receives the data - and that is a one-off cost with a long tail of benefit, because it is also the answer to the next data protection question anyone asks you.

The fifteen-minute test you can run on your own site today

Open a private or incognito window, launch your browser’s developer tools, and switch to the Application (or Storage) tab with the Network tab alongside it. Load your homepage and do not touch the banner. Now look at the cookies that have already been written and the requests that have already gone out. If you see anything from an analytics, advertising or session-recording domain before you have clicked anything, you have the collection-before-consent problem that two-thirds of the gambling sites in the Swansea study had. Then answer two more questions: can you decline in exactly one click from the first screen, and are Accept and Reject styled with the same prominence? Three questions, fifteen minutes, and you will know whether you are in the 54% or outside it - and you will have the specific evidence needed to get the fix budgeted.

At a glance

Detail What the research found
Who conducted the study Researchers at the GREAT Centre, Swansea University
Sample 624 gambling websites licensed to operate in Britain
Headline finding 86% appear to breach GDPR through cookie consent handling and data collection
Comparison baseline 54% non-compliance across a previous study covering websites of all types
No way to disable advertising trackers 24% of sites tested
No consent choice offered at all 2% of sites, including Dafabet, shirt sponsor of Celtic FC
Data collected before consent Two-thirds of operators, including Ladbrokes and William Hill; some data passed to third-party analytics and marketing platforms
Visual emphasis on the least privacy-friendly option 60% of sites
Reject option behind a second click 47% of sites
Pre-selected privacy-unfriendly defaults 29% of sites
Expert assessment Ravi Naik, legal director at AWO: the findings “paint a picture of widespread and systemic non-compliance”
Regulator position The ICO is running a multi-year cookie compliance project and says it has brought 95% of the UK’s top 1,000 websites into line
Precedent for enforcement In 2024 the ICO formally reprimanded SkyBet for unlawfully sharing user data with advertising companies, following a complaint raised via Clean Up Gambling
Applicable UK law UK GDPR (consent must be freely given, specific, informed and unambiguous) alongside PECR (consent required before non-essential cookies are placed)
Software flaw or patch required None - this is a configuration, design and governance failure, not a technical vulnerability

The pattern this fits into

The Swansea findings belong to a run of stories we have covered this year in which the failure is never the technology itself but the gap between what an organisation believes a control does and what it actually does. Our reporting on ASCII smuggling walking millions of phishing messages past Microsoft 365 filters described exactly that shape: rules that existed, looked correct and had stopped matching, with nobody monitoring whether they still fired. A consent banner that displays but gates nothing is the same failure wearing different clothes - the artefact is present, the function is absent, and the only way to find out is to test it rather than look at it.

The regulatory thread runs the same way. The debate around proposed UK AI kill-switch legislation is a live example of how quickly a compliance expectation can move from guidance to statutory obligation, and how badly organisations fare when they have treated the guidance phase as optional. And the first UK conviction for operating an SMS Blaster showed a regulator and a court acting decisively once a well-evidenced case landed in front of them - which is precisely the dynamic the SkyBet reprimand demonstrates for cookie and adtech data-sharing failures.

On the supplier side, the questions raised in our coverage of accountability for UK business broadband faults and of continuity risk in the Gamma and Epiris buyout apply directly here. Who owns your consent configuration? The web agency that built the site four years ago, the marketing agency that manages the tag manager, or the person who installed the plugin? On most SME estates the honest answer is nobody, and an unowned control is an unmaintained control. If there is a single operating principle running through all of these stories, it is that the most expensive things in an IT estate are the assumptions nobody has written down - and they only ever bill you after something has already passed through them.

Do you actually know what your website loads before the banner is answered?

Cloudswitched audits business websites against the four tests the ICO applies - nothing non-essential before consent, rejection as easy as acceptance, no pre-ticked defaults, and a choice that genuinely stops the tracking - then rebuilds the consent layer so the banner controls the tags instead of sitting alongside them.

Talk to us about Web Development

Frequently asked questions

We are not a gambling company. Does this study actually apply to us?
The sector is incidental. The researchers tested 624 licensed gambling sites because that is a well-defined, regulated population, but the tests they applied are the standard UK GDPR and PECR requirements that govern every website serving UK visitors. The more relevant number for an ordinary business is the comparison figure quoted in the study: a previous piece of research across websites of all types found a 54% non-compliance rate. The gambling sector is worse than average at 86%, but the average is still more than half. Unless your site has had a consent audit and the results were acted on, you have no evidence you are in the compliant minority.
We use Google Analytics but we do not advertise. Do we still need consent?
Yes. This is the single most common misunderstanding we encounter. The ICO’s position is clear that analytics cookies are not strictly necessary, and PECR requires consent before any non-essential cookie or similar technology is placed on a user’s device. “Strictly necessary” means necessary to deliver the service the user has explicitly requested - session management, basket contents, load balancing, security and authentication. It does not mean useful to the business, first-party, anonymised, or industry standard. An analytics tag that fires on page load before the visitor has answered the banner is the exact failure mode found on two-thirds of the sites in the Swansea study.
Our banner has an “Accept all” button and a “Manage preferences” link. Is that compliant?
Almost certainly not, and this is the design the ICO wrote to the UK’s largest websites about in 2023. The requirement is that rejecting non-essential cookies must be as easy as accepting them. If accepting takes one click on a prominent button and rejecting takes a click into a preference panel, then toggles, then a save - the two are not equivalent. The Swansea researchers found this specific pattern on 47% of sites, alongside 60% giving visual emphasis to the least privacy-friendly option. The fix is straightforward: put a “Reject all” button on the first layer, styled with the same weight as “Accept all”.
What is the realistic penalty if we get this wrong?
For most UK SMEs the realistic outcome is not a headline fine. It is a complaint, an information notice, a reprimand and a deadline to fix it - which is what happened to SkyBet in 2024 after a complaint was raised through Clean Up Gambling. That sequence still carries real cost: the remediation work under time pressure, the internal disruption, the disclosure obligations if you have contracts or tenders that ask about regulatory action, and the reputational effect of a published reprimand. The larger practical risk for many businesses is commercial rather than regulatory - enterprise procurement and public sector tenders increasingly ask directly about consent handling, and a failed check can cost a contract long before a regulator ever notices.
Our site was built by an agency who installed a cookie plugin. Are we covered?
A plugin gives you a banner, not compliance. In our experience the most common configuration on an SME site is a consent tool operating in what is effectively notice-only mode - it displays, it records a click, and it does not actually block anything, because blocking requires the tags to be wired through it and that wiring is a separate piece of work nobody scoped. The Swansea study found 24% of sites offered no functioning way to turn off advertising trackers at all, and many of those will have had a perfectly professional-looking banner. As the data controller, the legal responsibility is yours regardless of who built the site, so the only safe answer is to test it rather than assume.
What exactly is a “dark pattern” in this context?
It is an interface design deliberately weighted to steer the user toward the choice the operator prefers rather than the one the user would otherwise make. The Swansea researchers measured three specific varieties: visual emphasis on the least privacy-friendly option, found on 60% of sites, where Accept is large and coloured while Reject is small, grey or plain text; pre-selected privacy-unfriendly defaults, found on 29%, where non-essential toggles are already switched on; and hidden rejection, found on 47%, where declining requires a second click into a sub-panel. All three undermine the requirement that consent be freely given, and all three are now well-documented enough that they are difficult to defend as accidental.
Do we need to keep records of consent? Nobody has ever asked us for them.
Yes. The accountability principle requires you to be able to demonstrate compliance, and for consent that means being able to show who consented, what they consented to, when, and how the request was worded at the time. Without a log you cannot evidence compliance even for the visitors you handled perfectly - which puts you in the same position as an organisation that handled them badly. Most consent management platforms can record this; on a large number of the sites we audit, the capability exists and has simply never been switched on. It is usually a configuration change rather than a purchase, and it is the first thing a regulator asks for when a complaint arrives.
Will rejecting cookies wreck our marketing data?
It will reduce your measured traffic, and it is better to plan for that than to discover it. The honest framing is that a compliant banner reveals your real consent rate rather than manufacturing one - the numbers you were reporting before were partly an artefact of a design that made refusal difficult. There are legitimate routes to useful measurement within the rules: consent-mode modelling offered by the major analytics platforms, server-side aggregate metrics that do not rely on device storage, and genuinely first-party measurement of outcomes rather than individuals. What is not available is the previous approach of treating a hidden Reject button as a measurement strategy, and the trend across the sector is one direction only.
What about embedded YouTube videos, Google Maps and live chat widgets?
These are the most frequently missed items on any consent audit, because they do not look like tracking - they look like content. A third-party iframe or script generally sets its own cookies and receives the visitor’s IP address and page context the moment it loads, entirely independently of your consent banner, unless you have explicitly deferred it. The correct pattern is to replace the embed with a placeholder that loads the real thing only after consent, with a short line explaining what accepting means. It is a small amount of front-end work and it closes a gap that otherwise makes the rest of your consent configuration academic.
How often should we re-check, once we have fixed it?
Quarterly is a sensible default for most SMEs, and after any significant marketing or development change regardless of the calendar. The reason is drift: what loads in a visitor’s browser changes every time someone adds a campaign pixel, embeds a new tool or ships a template update, and none of those changes touch the consent configuration itself. A site that passed in March can be firing an ungated tracker in June with nobody having done anything wrong on purpose. Attach the check to a named owner rather than a policy document - the failure mode across the whole of the Swansea sample is not ignorance of the rules, it is an absence of anybody whose job it was to look.

Get your consent layer built to do the job it appears to do

Cloudswitched web development covers the whole chain - a full inventory of what your site loads and who receives it, tags moved behind a working consent gate, a banner where rejection is genuinely one click, consent logging switched on and evidenced, third-party embeds placeholdered, and a scheduled re-scan with a named owner so new tags never quietly appear outside the gate.

Talk to us about Web Development
Tags:Web DevelopmentCyber EssentialsSEOIT Support
CloudSwitched

London-based managed IT services provider offering support, cloud solutions and cybersecurity for SMEs.

CloudSwitched Service

Web Development

Custom websites, web apps and e-commerce solutions built for results

Learn More

Technology Stack

Powered by industry-leading technologies including SolarWinds, Cloudflare, BitDefender, AWS, Microsoft Azure, and Cisco Meraki to deliver secure, scalable, and reliable IT solutions.

SolarWinds
Cloudflare
BitDefender
AWS
Hono
Opus
Office 365
Microsoft
Cisco Meraki
Microsoft Azure

Latest Articles

13
  • Internet & Connectivity

Bandwidth Planning for Growing UK Businesses: A Practical Guide to Sizing Your Internet Connection in 2026

13 Sep, 2026

Almost every UK business sizes its internet connection exactly once. Someone signs a lease, an installer quotes what is available at the postcode, a number is...

Read more
12
  • Database Reporting

Data Warehouse vs Reporting Database: A UK Business Guide to Choosing the Right Architecture for Business Intelligence in 2026

12 Sep, 2026

Most UK businesses do not choose a data warehouse architecture deliberately. They arrive at one by accident, usually at the point where a monthly management...

Read more
11
  • AI

AI Feature Prototyping: A UK Business Guide to Validating AI Product Ideas Before Committing Engineering Budget in 2026

11 Sep, 2026

Almost every expensive AI failure in a UK business starts the same way: somebody demonstrated something impressive in a chat window, everybody in the room...

Read more

Enquiry Received!

Thank you for getting in touch. A member of our team will review your enquiry and get back to you within 24 hours.