Online casinos and bookmakers have long dismissed the cookie banner as a technicality: a small window the user closes before registering. Yet new research from Swansea University reveals that a far more serious issue lies behind that window. What is now called into question is the entire data collection infrastructure on which attribution, retargeting, CRM segmentation, and personalized offers depend.
Researchers at the GREAT Centre examined 624 websites of UK-licensed gambling operators. At least one potential breach of GDPR and cookie consent requirements was identified on 86% of them. Around 66% of sites began collecting or transmitting data before the user gave consent, 24% offered no proper way to disable tracking, and on 2% of sites there was no choice at all.
- What is GDPR? The General Data Protection Regulation is an EU regulation governing the processing of personal data of individuals. It came into force in 2018 and requires organizations to obtain explicit consent for data collection, ensure data protection, and respect the rights of data subjects. GDPR applies to all companies handling the data of EU residents, regardless of their location, and provides for substantial fines for violations.
The findings were published in the journal Technology in Society and received wide coverage in The Guardian.
A legal caveat is important here: the study does not replace a regulator's investigation or a court ruling. The phrase "signs of a violation" is more accurate than claiming that 86% of operators have already been found in breach. Even with that caveat, however, the scale of the sample points not to a handful of poorly configured banners, but to an industry-wide pattern.
On 3S.INFO, we break down why the cookie banner has ceased to be a mere formality before registration. The core problem is the conflict between the drive to improve attribution, personalization, player LTV, and the obligation to obtain valid consent, protect vulnerable users, and avoid turning responsible gambling data into a retention marketing tool.
The Cookie Banner: A Cog in the Marketing Funnel
On many sites, tracking consent is designed not as a neutral choice, but as a managed conversion.
- What is a cookie banner? It is a pop-up notification on a website that informs visitors about the use of cookies and similar tracking technologies, for example, for analytics, advertising, personalization, and third-party services. Typically, the banner allows users to accept, reject, or customize optional cookies, while strictly necessary cookies may operate without separate consent. In the EU, this mechanism helps a site obtain prior, informed, and unambiguous user consent in line with GDPR and ePrivacy requirements.
According to the study, 60% of sites visually emphasized the option that involved sharing more data. On 29%, the less private settings were selected by default, and on 47%, the reject button was placed on a second layer of the interface. To accept all cookies, a single click was enough. To reject them, users sometimes had to open the settings, switch off categories, and save their choice separately.
Such practices are commonly called dark patterns: interface techniques that nudge users toward an action favorable to the platform. Not every dark pattern is automatically a legal violation. However, it casts doubt on the central condition of legitimate consent: whether it was freely given, informed, and unambiguous.
According to the UK's Information Commissioner's Office, consent must be given through a positive action, and turning off optional cookies must be easy. Simply continuing to browse a site does not constitute consent. Users must understand exactly what they are permitting and for what purposes. The ICO specifically points out that non-essential tracking cannot be disguised behind a generic reference to the privacy policy or enabled without a clear choice.
For a product team, the crux of the problem is that consent rate has long since become almost as much of a marketing metric as registration or first deposit. The more users hit Accept All, the richer the attribution, the larger the retargeting audiences, and the more accurate the behavioral models.
This sets up a conflict of interest: the company is formally obliged to offer a free choice, yet it has a commercial stake in the user choosing the maximum level of tracking.
What Does Gambling Marketing Actually See?
The word "cookies" often creates the impression that we are talking about a few harmless files in a browser. In reality, they may be just the first link in a long chain.
That chain includes advertising identifiers, pixels, SDKs, device fingerprinting, web analytics systems, affiliate postbacks, customer data platforms, CRM, and ad accounts. Together, they help connect the source of a visit with registration, deposit, gaming sessions, and subsequent customer behavior.
Based on this data, an operator can determine which products interest a player, when they usually return, which bonuses they respond to, how often they top up their account, and how sensitive they are to specific communications. The player is then placed into a segment: new depositing customer, slots enthusiast, sports bettor, VIP candidate, inactive user, or a customer likely to churn.
Not all such data is collected solely on the basis of consent. For example, certain processing may be necessary for authorization, information security, geolocation checks, fraud prevention, KYC compliance, or responsible gambling requirements.
But the operator having a lawful reason to determine a user's country does not automatically grant the right to transmit their behavior to an advertising platform. Technically necessary processing and commercial tracking must be separated by purpose, legal basis, and data recipients.
This is precisely where the cookie banner ceases to be a design element. It becomes a switch that must genuinely control the entire MarTech chain.
Where Privacy Meets Responsible Gambling
Gambling differs from most other digital industries in that data is used not only to lift conversion, but also to detect harm.
UK rules require operators to identify customers who may be experiencing problems, engage with them, and evaluate the outcome of the measures taken. This calls for analyzing deposit frequency, session duration, rising stakes, night-time activity, attempts to recoup losses, and other behavioral changes. The UK Gambling Commission explicitly describes the identify – interact – evaluate model.
The paradox is that the very same signals can carry commercial value.
More frequent deposits may signal growing risk, yet they also mean rising revenue. Returning right after a loss can indicate chasing losses, yet from a retention standpoint it looks like a high likelihood of repeat play. A long session warrants scrutiny from a player protection angle, but from a product perspective it means high engagement.
That is why the critical question becomes not only what data is collected, but also which system has been granted access to it and what action that system triggered.
If a risk marker blocks bonuses and prompts the safer gambling team to make contact, the system is performing a protective function. If the same marker, or its commercial equivalent, triggers a personalized cashback, push notification, or win-back campaign, the effect is the opposite.
The core privacy risk here lies in the blurring of processing purposes. Data collected to protect a player must not quietly morph into fuel for boosting their LTV.
Sky Betting & Gaming: Two Different Stories About One Data Stack
A telling warning came in the form of an ICO investigation into Sky Betting & Gaming.
The regulator found that between January 10 and March 3, 2023, the site processed personal data through advertising cookies and passed it to advertising technology companies immediately after the page loaded, before the user could accept or reject cookies. The ICO issued the operator a formal enforcement notice. At the same time, the regulator specifically noted that it found no evidence of deliberate use of the data to target vulnerable players. The ICO's decision was published in September 2024.
That caveat matters. A breach of the consent mechanism does not prove deliberate exploitation of a problem gambler. It shows how serious the consequences of a misconfigured tag manager, consent management platform, or advertising pixel can be.
A separate legal dispute against the companies operating Sky Betting & Gaming made the picture even more complex. In January 2025, the High Court sided with a former player who claimed his data had been used for profiling and personalized marketing without valid consent. However, in April 2026, the Court of Appeal overturned that ruling, stating that consent should be assessed objectively, by a clear positive action on the user's part, rather than by attempting to reconstruct their inner state at the moment of the click.
The full text of the RTM v Bonne Terre Limited ruling has been published by the UK court system.
For operators, this is an important clarification: having a gambling problem does not by itself invalidate a person's expressed consent. But the ruling does not waive the requirements for transparency, freedom of choice, fairness, and specific processing purposes. Nor does it permit activating advertising cookies before consent is obtained or hiding the reject option behind a manipulative interface.
In other words, the Court of Appeal removed a practically unworkable requirement to assess each customer's subjective capacity to give consent. But it did not hand the industry a carte blanche for any tracking after a formal click on Accept.
Regulators' Next Target Will Be the Data Stack, Not the Banner
Until recently, privacy and responsible gambling were seen as adjacent but separate domains.
The privacy team kept an eye on GDPR, PECR, consent, and data deletion requests. The safer gambling team tuned risk models and customer interactions. Marketing owned segments and campaigns. IT handled integrations. The affiliate department plugged in trackers and managed attribution.
The problem is that data moves between these systems faster than responsibility moves between departments.
The next stage of enforcement will therefore likely go beyond the look of the banners. Regulators may start asking tougher questions:
- Which events are sent to third parties before consent?
- Which sources were used to build a particular CRM segment?
- Are vulnerability signals being used to select a bonus?
- Can the marketing system see the responsible gambling score?
- Is advertising switched off immediately after self-exclusion or the emergence of strong harm indicators?
- Can the chain from a data source to a specific offer be reconstructed?
An audit like this no longer stops at the website page. It reaches into the CDP, CRM, tag manager, affiliate platform, data warehouse, ad accounts, and personalization algorithms.
The same action can capture the attention of two regulators simultaneously. The ICO will weigh the lawfulness, transparency, and fairness of data processing. The Gambling Commission will examine whether the operator protected the customer and whether its systems amplified the risk of harm.
What Will Change for CRM and Retention
For CRM teams, the core task will be to separate data by purpose.
Service messages, mandatory notifications, security-related communications, and responsible gambling messages cannot be lumped together with promotional mailings just because they are sent through the same platform. Every audience, variable, and automated trigger must have an explainable purpose.
Segments whose names conceal the real logic are especially risky. Labels like "highly engaged," "high propensity," "reactivation opportunity," or "valuable churn risk" can group together people with vastly different behavior. Among them may well be players whose activity already shows signs of harm.
It is not enough for an operator to say that an algorithm built the segment. The company must understand which signals the model used and why a particular offer was shown to a given person.
This does not spell the end of personalization. But its quality will have to be measured not only by uplift, conversion, and incremental GGR. Additional criteria are emerging: data provenance, the existence of a permitted purpose, the explainability of the segment, and the absence of conflicts with player-protection controls.
What This Means for Affiliates and MarTech
The affiliate chain adds yet another layer of complexity.
A user may come from a review site via a tracking link, land on the operator's page, register, make a deposit, and then end up in an ad network's audience. Several companies are involved in this process, each of which may set identifiers, receive postback events, or enrich the data.
Consent obtained on one site does not necessarily cover processing by another participant in the chain. Much depends on what exactly was explained to the user, who determines the purposes of processing, and what data is transferred.
Server-side tracking, too, cannot be treated as a universal fix for privacy issues. It reduces reliance on browser cookies and ad blockers, but it does not waive the requirements for a legal basis, transparency, and purpose limitation. If data leaves the server without the user's knowledge, it may be even harder to justify such an architecture to a regulator.
For operators, this means affiliate due diligence has to reach beyond creatives and traffic sources. They will need to grasp how a partner builds its audience, which profiling technologies it deploys, what consent language it shows, and whom it hands identifiers to.
MarTech providers, in turn, will have to prove not merely that their platform is secure, but that it can honor user choice at every level of integration.
Privacy Is Becoming a Constraint on Personalization
For years, the industry treated personalization as an unconditional advantage. The more an operator knows about a customer, the sharper the bonus, the higher the retention, and the lower the spend on ineffective communications.
Now, the value of a segment will depend not only on its conversion rate. What matters increasingly is the provenance of the data and the permissibility of the inference the operator has drawn about a person.
It is one thing to know that a player prefers live casino. It is far harder to justify using a model that predicts the emotional moment at which they are most likely to make another deposit. It is acceptable to analyze visit frequency to detect risk. It is far more dangerous to use a sharp spike in that frequency as a trigger for a promo.
Technical capability and lawful right are not the same thing. The formula "we can predict this" no longer means "we are entitled to use that prediction for marketing."
What Operators Should Check Right Now
The first practical step is not a legal review of the privacy policy, but a technical audit of how data actually flows:
- which cookies, pixels, and SDKs activate before the user makes a choice;
- whether accepting and rejecting optional tracking are equally easy;
- whether rejection truly blocks data transmission;
- which events analytics and advertising platforms receive;
- on what basis each CRM segment was created;
- whether risk markers can be used by marketing models;
- how quickly a self-excluded or restricted customer disappears from ad audiences;
- what data affiliates and other partners receive;
- how long identifiers and behavioral signals are retained;
- whether the operator can prove the provenance of a specific marketing attribute.
Particular attention should be paid to legacy integrations. A tracking code may have been installed years ago by a different agency or employee, then outlived changes to the CRM, the website, and the consent platform. It may no longer appear on the architecture diagram, yet it keeps sending data.
Consent Is Becoming Part of the License to Be Trusted
The new study does not prove that British operators systematically exploit vulnerable players through data. It shows something else: a significant portion of the industry still cannot conclusively demonstrate proper control even at the very first stage, the moment consent is obtained.
If data starts being collected before a person has made a choice, the entire downstream chain falls under suspicion. A retargeting audience, an attribution report, a CRM segment, and a personalized bonus may all be technically effective, yet built on a flawed foundation.
Privacy may therefore indeed become the new front line in gambling regulation. Not instead of responsible gambling, but alongside it, and increasingly within it.
For an operator, consent is no longer a formal button before registration. It is the ability to explain the entire data lifecycle: what was collected, why, on what legal basis, to whom it was passed, how long it was retained, and why a particular offer was shown to a particular player.
It is this explainability, not the volume of data in the CDP, that is gradually becoming the real license to personalize.