Search
Choose a style
Dark
Light
Time to read: 3 min

UK gambling sites using advertising cookies could be breaching GDPR

Credit: Shutterstock/ GraphicsN

Research by Swansea University School of Psychology claims 86% of online bookies have formed ‘dark patterns’ in collecting user data.

The majority of licensed British gambling websites could be breaching data protection laws in their online marketing, new research has revealed.

Nearly nine out of 10 (86%) of betting operators have formed a dark pattern in how they collect data through third-party cookies, according to the study by Swansea University School of Psychology.

This primarily relates to the cookie consent pop-up box that appears when a user first navigates to a website. The consent box usually asks users to either accept, reject or manage the information they are willing to share.

Advertisers use third-party cookies to track a user’s browsing behaviour across different sites and use that information to serve targeted ads.

Of the 624 UK gambling websites analysed in the study, only a quarter (24%) offered the option to reject cookies and manage settings. And of those that did, in nearly half (44%) of banners, the ‘reject’ or ‘manage cookies’ options were smaller, shaded in lower contrast and more difficult to find than the ‘accept’ button.

Overall, a significant number of online bookies and casinos used at least “one dark pattern in their banner design” to nudge users towards accepting cookies with 60% putting a visual emphasis on ‘accepting’ data sharing; 29% pre-selecting privacy unfriendly settings as a default; and 47% hiding the ‘reject’ option behind a second or third layer.

Just over a fifth (22%) of sites examined offered no option. These banners informed users their personal data was being collected but offered no option to exercise their data privacy rights, which is in breach of the UK’s General Data Protection Regulation (GDPR).

While 2% of sites had no cookie consent box at all, which is also in breach of GDPR.

The study also found that two-thirds (67%) of online gambling sites processed users’ personal data prior to obtaining content.

Only 14% of firms were deemed fully GDPR compliant.

Just last year there were calls for wider regulators to investigate the advertising algorithms and data tracking of operators, fuelled by a High Court ruling by Justice Collins Rice that Sky Betting and Gaming (Sky Bet) had violated UK data protection laws.

The High Court had arbitrated a former problem gambler’s case against Sky Bet for advertising to him without obtaining valid consent. Sky Bet was accused of using third-party cookies to create an extensive profile of the problem gambler to target him with personalised ads.

Following an investigation, the Information Commissioner’s Office (ICO) found Sky Betting and Gaming was processing personal data through the use of certain cookies in a way that was not lawful, transparent or fair.

While Skybetting and Gaming have since made changes to allow users to reject tracking cookies, the ICO said at the time it had already reviewed the UK’s 100 websites and found more than half were using advertising cookies in a way that did not comply with the law.

Stephen Bonner, deputy commissioner, at ICO, said then: “Our enforcement action against Sky Betting and Gaming is a warning that there will be consequences if organisations breach the law, and people are denied the choice over targeted advertising.

“We are preparing to scrutinise the next 100 most frequented websites, so I urge all organisations to assess their cookie banners now to make sure consent can be freely given before a letter arrives from the regulator.”

Subscribe to our newsletter