On 6 September 2026, researchers at Swansea University published findings that ought to make every UK business owner look again at the little box that appears in the corner of their own website. Testing 624 licensed British gambling websites, the university’s GREAT Centre found that 86% appear to breach GDPR through the way they ask - or fail to ask - for cookie consent, and through the data they collect before anyone has agreed to anything. The story has been framed as a gambling story, and the operators named in it are household betting brands. But the mechanism being described is not specific to gambling in any way. It is a consent banner, a tag manager, and a set of defaults that nobody has audited since the day the site went live.
That is the part that should concern a UK SME reading this on 7 September 2026. The study’s comparison point is the more uncomfortable number: a previous piece of research covering websites of all types, not just gambling, found a GDPR non-compliance rate of 54%. The gambling sector is worse than average - substantially worse - but the average itself means that more than half of the websites on the internet are getting this wrong. If you run a business website with Google Analytics, a Meta pixel, a live chat widget, a heatmap tool and a booking system, the statistical odds are not on your side, and they never have been.
What has changed is the enforcement climate. The Information Commissioner’s Office is partway through a multi-year project targeting cookie banner compliance specifically, and claims to have brought 95% of the UK’s top 1,000 websites into line. In 2024 it formally reprimanded SkyBet for unlawfully sharing user data with advertising companies after a complaint was raised through the campaign group Clean Up Gambling. The regulator is working downwards through the traffic rankings and acting on complaints when they arrive. A consent banner that was “good enough” in 2019 is now a documented, evidenced, publicly testable compliance failure that any competitor, disgruntled customer or researcher can screenshot in thirty seconds.
What the Swansea researchers actually found
The study, carried out by the GREAT Centre at Swansea University, took the population of 624 gambling websites licensed to operate in Britain and tested each one for how it handles cookie consent and what data it collects. That population choice matters: these are not fly-by-night offshore operations outside the reach of UK law. They are licensed operators, regulated by the Gambling Commission, with legal departments, compliance functions and the resources to get this right. The finding that 86% appear to breach GDPR is therefore not a story about cowboys. It is a story about what happens when a legal requirement is delegated to a marketing tag and then forgotten.
The failures fall into three distinct categories, and it is worth separating them because they carry different levels of legal risk and require different fixes. The first is the absence of choice. Nearly a quarter of the sites tested - 24% - offered no way at all to turn off the tracking software that allows advertisers to follow users around the web. The banner may have appeared, the word “cookies” may have been used, but there was no functioning mechanism to decline. A smaller group, 2% of sites, offered no consent choice whatsoever - among them Dafabet, the shirt sponsor of Celtic FC. A banner that cannot be refused is not a consent mechanism; it is a notification, and under UK GDPR and PECR a notification does not create a lawful basis for non-essential cookies.
The second category is collection before consent, and it is the most widespread. Two-thirds of operators began harvesting user data before the user had given consent, including well-known brands such as Ladbrokes and William Hill. In some cases that data was passed straight to third-party analytics and marketing platforms. This is the failure mode that trips up the most well-intentioned organisations, because it is almost never a deliberate decision. It is a tag firing on page load because that is what tags do unless something stops them. The banner asks the question politely while the network tab shows the answer has already been sent.
The third category is dark patterns - interface design deliberately weighted to produce the answer the operator wants. The researchers found visual emphasis on the least privacy-friendly option on 60% of sites (the “Accept all” button rendered large, coloured and prominent while “Reject” is small, grey or rendered as plain text). They found pre-selected privacy-unfriendly defaults on 29% - toggles switched on before the user has touched anything. And they found the reject option hidden behind a second click on 47%, buried inside a “Manage preferences” sub-panel that the user must actively seek out. Each of these is a documented, named technique. None of them is compatible with the requirement that consent be freely given, specific, informed and as easy to withdraw as it is to give.
Ravi Naik, legal director at the data protection specialist AWO, said the findings “paint a picture of widespread and systemic non-compliance”, and was critical of what he characterised as the ICO’s lack of meaningful enforcement action specifically against online gambling. That criticism cuts both ways for a business reading this. It is true that enforcement in this area has been light relative to the scale of the problem. It is also true that regulators respond to public research findings, press coverage and complaints - and this study has now supplied all three.
Nothing in the Swansea findings is specific to betting. The 86% figure comes from a sector that happens to have been tested; the 54% baseline across all website types is the number that applies to everyone else. If your site loads Google Analytics, an advertising pixel, a chat widget or a session-recording tool before the visitor has clicked anything, you have the same collection-before-consent problem as Ladbrokes and William Hill. If your banner shows a bright “Accept all” button and hides “Reject” behind “Manage preferences”, you have the same dark pattern problem as the 47%. The difference between you and a named operator in a national newspaper is traffic rank and the attention of a researcher - not the underlying compliance posture.
How British cookie consent law reached this point
The rules that the Swansea study measured against are not new, and none of them arrived without warning. The chronology below matters because it removes the most common defence a business reaches for when a compliance gap is pointed out - that the requirement was unclear, or recent, or unenforced. It has been clear for eight years, clarified repeatedly since, and actively worked by the regulator for the past three.
The failure modes, ranked by how common they are
Grouping the study’s findings by prevalence gives a rough priority order for anyone auditing their own site. The bars below combine the gambling-sector figures with the wider-internet baseline, so the fourth bar is the one to read as “the average website” rather than “the average bookmaker”.
Read the bars from the bottom up and they describe an escalating scale of difficulty rather than an escalating scale of severity. The 24% at the bottom - no way to turn off advertising trackers - is the most serious legal failure but the rarest, and it is usually a symptom of a consent platform that was installed in “notice only” mode and never switched to a mode that actually gates anything. The 29% with pre-selected defaults is a configuration setting, often a single toggle inside the consent management platform, sitting on the wrong value because the wrong value was the default when the account was created.
The middle band is design. 47% hiding rejection behind a second click and 60% visually emphasising acceptance are both deliberate choices made by somebody - usually a marketing team optimising for opt-in rates, occasionally a template author who has never read the guidance. These are the ones that generate the most argument internally, because the business case for the dark pattern is real and immediate (higher consent rates mean better analytics coverage and better ad attribution) while the compliance case is abstract until a complaint arrives.
The 66% collecting data before consent is the technical failure, and it is the one that most often surprises the organisation running the site. A business can have a perfectly designed banner with a balanced Accept and Reject, no pre-ticked boxes and no dark patterns - and still be firing Google Analytics, a Meta pixel and a heatmap script on page load because those scripts were hard-coded into the template three years before the consent platform was bought. The banner and the tags are two separate systems, and unless somebody explicitly wired the first to gate the second, they simply run in parallel and ignore each other.
Why 86% is the number that survives scrutiny
An eighty-six per cent failure rate invites a reasonable question: is the bar simply set too high? It is a fair challenge and it deserves a direct answer. The requirements the researchers tested against are not aspirational best practice, and they are not a maximalist reading of the law. They are the four things the ICO has said in guidance, in direct correspondence with website operators, and in its published enforcement outcomes: do not set non-essential cookies before consent; make rejection as easy as acceptance; do not pre-tick the boxes; and make the choice real, meaning that declining actually stops the tracking. A site can fail all four while displaying a banner that looks entirely professional. That is precisely why the failure rate is so high - the banner is doing the job it was bought to do, which is to look like compliance, and nobody has tested whether it is compliance.
The second reason the figure holds up is that these tests are observable from outside. A researcher does not need access to your servers, your privacy notice, your records of processing activity or your data protection impact assessments to establish that a tracking cookie was written before the banner was answered. They need a browser with a clean profile and the network tab open. The entire methodology can be replicated by a journalist, a competitor, a customer with a grievance, or an automated scanner running against a list of domains. Compare that to most areas of data protection compliance, where a breach is invisible until something goes wrong internally. Cookie consent is the one part of GDPR that is continuously and publicly auditable, at zero cost, by anybody who cares to look.
That external observability is what turns this from a paperwork risk into a practical one. The SkyBet reprimand in 2024 did not begin with an ICO audit - it began with a complaint raised through Clean Up Gambling. The regulator’s capacity to proactively review the whole UK web is obviously finite; that is why its own project has been organised around the top 1,000 sites by traffic. But its capacity to respond to a well-evidenced complaint about a small business is not constrained in the same way, because the evidence arrives pre-assembled. For an SME, the realistic risk pathway is not a random audit. It is somebody with a screenshot and ten minutes.
Where UK SME websites most often fail
The grid below maps the study’s findings onto the specific failure points we see most frequently on small and medium-sized business websites. The badge reflects how likely the item is to be a live problem right now on a typical UK SME site that has not had a consent audit, not how severe the legal consequence would be.
Read the high band together and a pattern emerges: every one of those four items is a wiring problem rather than a policy problem. The organisation has bought a consent tool, written a cookie policy and added a banner - the artefacts of compliance are all present. What is missing is the connection between the banner and the things it is supposed to control. Tags fire because nothing gates them. Embeds load because an iframe from a video platform or a mapping service does not consult your consent manager unless you make it. Consent records are absent because logging was never switched on, and without them the organisation cannot demonstrate compliance even where it has achieved it - which under Article 7 is itself a failing.
The medium band is drift. A cookie policy is accurate on the day it is written and decays from then on, because tags accumulate. Marketing adds a pixel for a campaign; the campaign ends; the pixel stays. A developer adds a session-recording tool to debug a checkout problem and never removes it. Two years later the policy describes a site that no longer exists. The single most useful discipline here is not a bigger policy document but a scheduled re-scan: a quarterly check of what is actually loading, compared against what the policy says loads.
The one item in the low band - correctly identifying strictly necessary cookies - is where most organisations genuinely do fine, largely because platforms handle it. Session cookies, load balancing, basket contents, security tokens and authentication state are all exempt from the consent requirement, and content management systems generally get this right out of the box. The mistake to avoid is the reverse one: assuming that because a cookie is useful to you, it is necessary. Analytics is the classic case. It is valuable, it is first-party, it feels harmless - and it is unambiguously non-essential under the ICO’s guidance, which means it needs consent like everything else.
What a proper consent audit and rebuild costs
The figures below are indicative first-year costs for a UK organisation putting this right properly: auditing what actually loads, wiring the consent gate to the tags, rebuilding the banner so acceptance and rejection are genuinely equivalent, enabling consent logging, and updating the cookie policy to describe reality. They assume an existing website on a mainstream platform and exclude any wider site redesign.
| Business size | Typical exposure | Proportionate response | Indicative first-year cost |
|---|---|---|---|
| 1–10 staff | Brochure or small e-commerce site on WordPress, Shopify or a website builder; a free consent plugin installed at launch and untouched since; Google Analytics and possibly a Meta pixel hard-coded into the theme; no consent logging; cookie policy copied from a template | Full scan of what loads before and after consent; move analytics and advertising tags behind a consent gate; rebuild the banner with equal-weight Accept and Reject on the first layer; enable consent logging; rewrite the cookie policy against the actual tag list; add a persistent link to change preferences | £750 – £2,200 |
| 11–50 staff | Marketing site plus one or more connected systems - CRM forms, booking engine, live chat, embedded video, a heatmap or session-recording tool; tags managed partly in a tag manager and partly in the template; more than one agency has touched the site over the years | The above, plus consolidation of all tags into a single managed layer with documented consent categories; review of third-party embeds and iframes; data processing agreements checked against the tools actually in use; a documented quarterly re-scan; briefing for the marketing team on why opt-in rate is not the only metric | £2,500 – £7,000 |
| 51–150 staff | Multiple sites or subdomains, possibly multiple markets; an advertising stack with attribution dependencies; regulated or contractual obligations to evidence data protection controls; an existing Cyber Essentials certification and a named data protection lead | The above across the full estate, plus a consent management platform configured for cross-domain consistency; server-side tagging reviewed for the same before-consent failure; consent records retained and reportable; documented evidence pack for the accountability principle; annual review scheduled with the data protection lead | £7,000 – £18,000 |
| 150+ staff | Complex estate with legacy microsites nobody owns; adtech integrations passing identifiers to multiple partners; international traffic engaging both UK GDPR and EU GDPR; genuine commercial dependency on measurement and attribution | The above, plus a mapped inventory of every domain and every processor receiving data; contractual review of adtech partners; a tested process for handling consent-related complaints and subject access requests; continuous automated scanning with alerting when a new tag appears outside the gate | £18,000 – £45,000 |
Two things are worth noting about those bands. The first is that the bottom band - under two thousand pounds for a small business - is not a large number against the risk it removes, and a substantial part of that work is one-off rather than recurring. The second is that the cost driver in the upper bands is almost never the banner. It is the inventory: establishing what is actually on the site, which third parties receive data, and under what agreement. Organisations consistently underestimate that step because they assume a list already exists somewhere. On the great majority of estates we look at, it does not.
Two postures, and the difference between them
Almost every organisation caught by a study like this one was in the first column below. Very few were negligent; most had bought a tool, ticked the box and moved on. The gap between the columns is not spending, and it is not legal expertise. It is whether anybody has ever tested the thing rather than installed it.
Reactive posture
What most UK SME websites look like today
- A consent banner installed at launch, using whichever plugin was free or default, never reconfigured since
- Analytics and advertising tags hard-coded in the template, firing on page load regardless of what the banner says
- “Accept all” styled as the primary button; “Reject” behind a “Manage preferences” link, if present at all
- No consent log, so the organisation cannot demonstrate compliance even for the visitors it handled correctly
- Cookie policy written once, describing a tag list that has since changed several times
- Third-party embeds - maps, video, chat, hosted fonts - loading outside the consent gate entirely
- Nobody owns the question; it sits between marketing, the web agency and whoever handles IT
- Compliance status is unknown until a complaint, a customer question or a press story forces the check
Proactive posture
Where Cloudswitched web development takes you
- Every non-essential tag gated by the consent layer, verified by loading the site in a clean profile and watching the network
- Accept and Reject presented with equal visual weight, on the first layer, in a single click each
- No pre-selected non-essential toggles anywhere in the preference panel
- Consent decisions logged with timestamp and scope, so the accountability principle can actually be evidenced
- A persistent, findable route for visitors to change or withdraw consent on any later visit
- Third-party embeds placeholdered until consent is given, with a clear explanation of what loading them means
- A quarterly re-scan that catches new tags before they become a finding, with a named owner for the result
- Cookie policy generated from the real tag inventory and updated when the inventory changes, not annually by memory
The item that carries the most weight in that second column is the least glamorous one: the quarterly re-scan. Consent compliance is not a state you reach, it is a state you maintain, because the thing being regulated - what loads in a visitor’s browser - changes every time somebody adds a campaign pixel or embeds a video. A site that was fully compliant in March can be firing an ungated tracker in June without a single line of the consent configuration having changed. That is exactly how sixty-six per cent of a regulated, resourced, professionally managed sector ended up collecting data before consent.
Forty-one is a poor score and a very recoverable one, and the split behind it is consistent. Organisations score well on the visible artefacts - a banner exists, a cookie policy exists, someone can point at both - and badly on everything that requires the artefacts to be connected to the site’s actual behaviour. The heaviest single deduction is almost always tags firing before consent, because it fails the most fundamental requirement and because it is present on the majority of sites we scan. The second heaviest is the absence of consent records, which is invisible to the visitor but is the first thing a regulator asks for.
What makes the number recoverable is that most of the deductions come from a small number of fixable causes. Gating the tags is a configuration change, not a redevelopment. Rebalancing the banner is a design change measured in hours. Switching on consent logging is usually a checkbox inside a tool the organisation is already paying for. The work that takes real time is the inventory - establishing what is loading and who receives the data - and that is a one-off cost with a long tail of benefit, because it is also the answer to the next data protection question anyone asks you.
Open a private or incognito window, launch your browser’s developer tools, and switch to the Application (or Storage) tab with the Network tab alongside it. Load your homepage and do not touch the banner. Now look at the cookies that have already been written and the requests that have already gone out. If you see anything from an analytics, advertising or session-recording domain before you have clicked anything, you have the collection-before-consent problem that two-thirds of the gambling sites in the Swansea study had. Then answer two more questions: can you decline in exactly one click from the first screen, and are Accept and Reject styled with the same prominence? Three questions, fifteen minutes, and you will know whether you are in the 54% or outside it - and you will have the specific evidence needed to get the fix budgeted.
At a glance
| Detail | What the research found |
|---|---|
| Who conducted the study | Researchers at the GREAT Centre, Swansea University |
| Sample | 624 gambling websites licensed to operate in Britain |
| Headline finding | 86% appear to breach GDPR through cookie consent handling and data collection |
| Comparison baseline | 54% non-compliance across a previous study covering websites of all types |
| No way to disable advertising trackers | 24% of sites tested |
| No consent choice offered at all | 2% of sites, including Dafabet, shirt sponsor of Celtic FC |
| Data collected before consent | Two-thirds of operators, including Ladbrokes and William Hill; some data passed to third-party analytics and marketing platforms |
| Visual emphasis on the least privacy-friendly option | 60% of sites |
| Reject option behind a second click | 47% of sites |
| Pre-selected privacy-unfriendly defaults | 29% of sites |
| Expert assessment | Ravi Naik, legal director at AWO: the findings “paint a picture of widespread and systemic non-compliance” |
| Regulator position | The ICO is running a multi-year cookie compliance project and says it has brought 95% of the UK’s top 1,000 websites into line |
| Precedent for enforcement | In 2024 the ICO formally reprimanded SkyBet for unlawfully sharing user data with advertising companies, following a complaint raised via Clean Up Gambling |
| Applicable UK law | UK GDPR (consent must be freely given, specific, informed and unambiguous) alongside PECR (consent required before non-essential cookies are placed) |
| Software flaw or patch required | None - this is a configuration, design and governance failure, not a technical vulnerability |
The pattern this fits into
The Swansea findings belong to a run of stories we have covered this year in which the failure is never the technology itself but the gap between what an organisation believes a control does and what it actually does. Our reporting on ASCII smuggling walking millions of phishing messages past Microsoft 365 filters described exactly that shape: rules that existed, looked correct and had stopped matching, with nobody monitoring whether they still fired. A consent banner that displays but gates nothing is the same failure wearing different clothes - the artefact is present, the function is absent, and the only way to find out is to test it rather than look at it.
The regulatory thread runs the same way. The debate around proposed UK AI kill-switch legislation is a live example of how quickly a compliance expectation can move from guidance to statutory obligation, and how badly organisations fare when they have treated the guidance phase as optional. And the first UK conviction for operating an SMS Blaster showed a regulator and a court acting decisively once a well-evidenced case landed in front of them - which is precisely the dynamic the SkyBet reprimand demonstrates for cookie and adtech data-sharing failures.
On the supplier side, the questions raised in our coverage of accountability for UK business broadband faults and of continuity risk in the Gamma and Epiris buyout apply directly here. Who owns your consent configuration? The web agency that built the site four years ago, the marketing agency that manages the tag manager, or the person who installed the plugin? On most SME estates the honest answer is nobody, and an unowned control is an unmaintained control. If there is a single operating principle running through all of these stories, it is that the most expensive things in an IT estate are the assumptions nobody has written down - and they only ever bill you after something has already passed through them.
Do you actually know what your website loads before the banner is answered?
Cloudswitched audits business websites against the four tests the ICO applies - nothing non-essential before consent, rejection as easy as acceptance, no pre-ticked defaults, and a choice that genuinely stops the tracking - then rebuilds the consent layer so the banner controls the tags instead of sitting alongside them.
Talk to us about Web DevelopmentFrequently asked questions
Get your consent layer built to do the job it appears to do
Cloudswitched web development covers the whole chain - a full inventory of what your site loads and who receives it, tags moved behind a working consent gate, a banner where rejection is genuinely one click, consent logging switched on and evidenced, third-party embeds placeholdered, and a scheduled re-scan with a named owner so new tags never quietly appear outside the gate.
Talk to us about Web Development


