67% of UK Gambling Sites Track You Before You Consent. Stop Them Before Your Next Bet

Two-thirds of UK gambling sites process user data before consent, while many also use deceptive cookie banners designed to push users toward accepting tracking.
We receive compensation from the products and services mentioned in this story, but the opinions are the author's own. Compensation may impact where offers appear. We have not included all available products or offers. Learn more about how we make money and our editorial policies.

You open a gambling website and see a cookie banner asking you to accept or reject data collection and tracking. But what if the website has already started harvesting your data before you even get the chance to make a choice?

A new study of 624 UK-licensed gambling websites found that approximately two-thirds sent information to Google Analytics 4 before visitors had given consent.[1]

And that’s just the beginning. Many gambling websites also use dark patterns to nudge you toward accepting cookie tracking, including hiding the reject option behind additional layers and pre-selecting privacy-unfriendly settings.

The consequences can go beyond simply seeing more targeted ads. This data can be used to understand your gambling habits and target you with personalized inducements, potentially exploiting people who are already experiencing gambling harm.

In this article
How UK gambling sites collect your data without consent
How your gambling data can put you at risk
What can you do to protect yourself
Bottom line

A new report by Swansea University’s GREAT Centre has found that 67% of the 624 online gambling websites tested process behavioral information even before obtaining user consent.

Researchers detected traffic sent to Google Analytics 4 endpoints, which can record website activity, including page views, clicks, and other interactions. GA4 can also assign an identifier that recognizes the same browser or device across multiple sessions.

Under the UK GDPR, companies need a valid legal basis to process personal data. The UK’s Privacy and Electronic Communications Regulations also generally require consent before websites use nonessential analytics or advertising cookies. The researchers therefore treated GA4 requests sent before consent as evidence of potential noncompliance.

In addition to not obtaining consent, the report also highlighted several violations in the types of consent banners used on these gambling websites.

  • No banners: 2% of these websites have no banners at all.
  • Binary banners: Only 5% of the websites offer a simple accept-reject banner, which is perhaps the most user-friendly.
  • Accept/settings banners: As many as 47% of websites show the accept/settings type of banner. Accepting tracking is as easy as a single click; however, rejecting it often involves multiple layers, taking as many as 15 clicks on some websites.
  • No options: 22% of websites simply inform users that their personal data is being collected and do not offer any option to reject such data collection, which the researchers classified as noncompliant.
  • Category banner: Only 24% of these websites offer a category banner, which allows users to either accept, reject, or manage their cookies with a single click.

Even the websites that do offer some sort of consent banner have several dark patterns that attempt to promote privacy-invasive cookie options.

The same report found that at least 86% of the websites had one dark pattern, and 60% placed visual emphasis on the least privacy-friendly option.

For instance, 99% of the websites that offer an accept-settings banner had the accept option visually emphasized.

Furthermore, 47% of them hid the reject option behind a second layer, while 29% had privacy-unfriendly options pre-selected for the user. It would be fairly easy for a visitor to simply accept these selected options without verifying what they mean for their privacy.

Overall, only 14% of the websites met all the study’s compliance criteria.

How your gambling data can put you at risk

Such extensive data collection not only helps advertisers build an online profile of you and target you with ads, but also helps the betting industry in ways you might not be aware of. For example, Scaleo, another ad-tech company, describes real-time triggers. If a player spends over a certain amount in a specific time, operators can send pop-up notifications nudging them to deposit more.

A powerful example of how this data can be used was seen in the RTM v. Bonne Terre Limited 2025 case. Evidence disclosed in the case showed how Sky Betting and Gaming profiled a customer experiencing gambling harm. Its systems reportedly treated gambling during early-morning hours as both a potential risk signal and an opportunity to deliver personalized marketing. The High Court initially ruled in the customer’s favor, but the Court of Appeal overturned that decision in April 2026, holding that consent must be assessed objectively.

Consumer data can also be used to track users across the web through tracking cookies, which means that people who have shown an interest in or recently visited a gambling website could be targeted with personalized gambling advertisements on third-party websites, such as social media.

The extent of this third-party tracking was highlighted by researcher Wolfie Christl. During 37 visits to three Sky Betting and Gaming websites, his investigation recorded 2,154 network requests to 83 third-party hosts operated by at least 44 companies.

During these requests, they found that Signal, which was owned by TransUnion, held up to 186 different profile attributes on one individual. Those attributes included predictions about the customer’s future value, win-back potential, share of gambling spending, and responsiveness to promotions. SBG was later reprimanded by the Information Commissioner’s Office.

In addition to cookie and tracking data, gambling platforms are also legally required to verify a user’s identity through KYC and anti-money laundering checks. This means they already have personally identifiable information like your name, email address, address, and more.

This data, along with tracking details, forms a rich source of personalized user information. Worse still, if it falls into the hands of a malicious threat actor through a data breach, for instance, it could lead to highly targeted phishing emails, which could snowball into identity theft or financial fraud.

What can you do to protect yourself

You may not be able to stop every tracking request, but these steps can limit how much information gambling websites and their partners collect:

  1. Use the reject option: While around 47% of websites hide their reject option behind a second layer, such as Settings, Manage Cookies, or More Options, you shouldn’t just click Accept All to access the website in haste. Stop, find, and choose the reject option, even if it takes a minute or two. It might be a hassle, but it’s worth doing.
  2. Do not trust pre-checked data forms: Don’t just click past pre-checked data collection options, as 29% of websites already have privacy-unfriendly options selected. Unselect anything that invades your privacy and reject such data collection.
  3. Use tracking protection tools: Ad blockers such as uBlock Origin or Privacy Badger can restrict many of these ad trackers. Additionally, you could use browser protection tools such as Firefox’s Enhanced Tracking Protection and Safari’s Intelligent Tracking Prevention.
  4. Know your GDPR rights: It’s important you’re aware of the protection you’ve been granted under GDPR rules. You have the right to withdraw consent at all times, not just during the first website visit. You can also submit a Subject Access Request (SAR) to see what data a company holds.
  5. Use an identity theft protection service: Considering the nature of the data available to such gambling platforms, it makes sense to get an identity theft protection service. These tools can scan known databases and the dark web to find any of your leaked information. They can also offer professional identity restoration services to help you restore your identity.

Bottom line

Around 67% sent information to GA4 endpoints before visitors had provided consent. Even those that do often hide the reject option behind obscure menus, sometimes requiring as many as 15 clicks to get through. That said, you can stay safe by taking a few preventive measures.

Don’t click on 'Accept All Cookies' while visiting a website. Find time to locate the reject option, even if it takes a minute or two. Additionally, use tracking protection or browser protection tools, along with an identity theft protection service.

Author Details
Krishi Chowdhary specializes in digital privacy, cybersecurity, and consumer technology. He has written extensively on online privacy tools and broader cybersecurity topics, including online scams, data breaches, age verification, and emerging digital threats. Krishi believes technology reporting should empower readers, not confuse them, and is committed to making even the most technical subjects easy to understand without compromising on accuracy or depth. His work has appeared in leading technology publications, including CNET, ExpressVPN, and TechRadar, where he has covered topics ranging from cybersecurity incidents and privacy product announcements to artificial intelligence and major technology news

Citations

[1] Consent banners, dark patterns, and GDPR infringements in online gambling: Evidence from a systematic audit and online experiment