Study Finds Majority of UK Online Gambling Sites Breach Data‑Protection Rules
A new study released by the Gambling Research, Education and Treatment (GREAT) Centre at Swansea University reveals that 86% of UK‑licensed online gambling platforms are failing to meet the standards set by the EU General Data Protection Regulation (GDPR), marking a widespread compliance shortfall across the sector.
The research, which appears in the peer‑reviewed journal *Computers*, examined a representative sample of gambling websites operating under UK licences. By cross‑checking the sites' privacy policies, data‑handling practices and user‑consent mechanisms against GDPR requirements, the authors concluded that only a small minority of operators adhered fully to the regulation.
GDPR, which came into force across the European Economic Area in 2018, imposes strict obligations on organisations that collect, store or process personal data. Key provisions include the need for clear consent, the right of individuals to access and delete their data, and mandatory breach notification within 72 hours. For online gambling firms, which routinely handle sensitive financial and behavioural information, compliance is not merely a legal formality but a cornerstone of consumer trust.
The study’s findings raise concerns for the millions of UK residents who gamble online. Inadequate data protection can expose users to identity theft, unauthorised marketing, and broader privacy infringements. Consumer groups have long warned that the gambling industry’s rapid digital expansion outpaces its ability to safeguard personal information, and the new evidence lends weight to those warnings.
Regulators are likely to take note. The UK Gambling Commission, which oversees licensing and compliance, has previously highlighted data security as a priority area. While the Commission can levy fines and impose remedial conditions, enforcement actions have historically focused on gambling‑related harms rather than data‑privacy breaches. The GREAT Centre’s report may prompt a shift toward more rigorous scrutiny of privacy practices.
Industry bodies have responded with a mixture of caution and commitment. Some operators have pledged to review their data‑handling procedures and upgrade privacy notices, citing the study as a catalyst for improvement. Others argue that the regulatory landscape is already complex and that aligning with GDPR across diverse jurisdictions presents practical challenges.
Looking ahead, the authors recommend a coordinated approach that includes regular independent audits, clearer guidance from the Gambling Commission, and stronger penalties for non‑compliance. As the digital gambling market continues to grow, ensuring that personal data is protected will remain a critical test of both industry responsibility and regulatory effectiveness.
Comments (0)
Be the first to comment.
Join the discussion