UK Air Traffic Control Disruption: Why...
Recent disruption across UK airports has shown how quickly the failure of a critical system can have far-reaching consequences. While...
Read MoreCookie banners have become so familiar that most people barely notice them anymore. Visit a website, click “Accept All” and continue. For organisations, this familiarity can create its own risk. Once a consent management platform has been installed and a cookie banner appears on the website, there can be an assumption that compliance has been dealt with.
New research into UK-licensed gambling websites provides a timely reason for organisations in every sector to challenge that assumption. A peer-reviewed study led by researchers at Swansea University’s Gambling Research, Education and Treatment Centre examined the consent banners used across 624 UK-licensed gambling websites.
The researchers reported that only 14% of the sites they assessed met the GDPR-related compliance criteria used in their study. They also found that 86% of consent banners contained at least one form of what researchers describe as a “dark pattern”, 24% of sites provided no option to reject tracking, and 67% processed personally identifiable information before consent had been obtained.
These are findings from academic research rather than determinations made by the Information Commissioner’s Office or a court. They should therefore not be interpreted as establishing legal liability on the part of any individual operator.
Nevertheless, the scale of the findings raises a much broader question: how many organisations have a cookie banner on their website without knowing what actually happens behind it?
The study, published in Computers in Human Behaviour Reports, examined the design and operation of consent banners across 624 gambling websites licensed in the UK. The researchers looked not only at whether a banner appeared, but also at how choices were presented and what happened technically before a user had made them.
According to the study, 86% of the banners assessed contained at least one dark pattern. The researchers also reported that 24% of sites offered no option to reject tracking and that 67% processed personally identifiable information before users had provided consent.
The researchers then conducted a separate randomised experiment involving 615 participants using simulated gambling sites. They found that the most common banner design identified during the website audit significantly increased acceptance of tracking and resulted in poorer alignment between the choices users made and the preferences they had expressed.
That finding is particularly interesting from a governance perspective. A consent mechanism can technically present somebody with a choice while still being designed in a way that makes one outcome considerably more likely than another.
The question for organisations should therefore not simply be, “Did the user click a button?” It should also be, “Did we give them a genuine and understandable choice?”
Cookie compliance is frequently described simply as a GDPR requirement, but the legal position in the UK is more nuanced.
The principal rules governing the storage of information on, or access to information from, a user’s device are contained in the Privacy and Electronic Communications Regulations 2003, or PECR. Where consent is required under PECR, that consent must meet the standard established by UK data protection law. Where cookies or similar technologies also involve the processing of personal information, the UK GDPR will apply to that associated processing.
In simple terms, organisations need to understand both what is being placed on or accessed from the user’s device and what subsequently happens to any personal information collected through that technology.
The rules also extend beyond traditional browser cookies. The ICO’s current guidance covers technologies including tracking pixels, device fingerprinting, local storage, scripts, tags and other mechanisms capable of storing or accessing information on people’s devices.
A website may therefore present what appears to be a compliant cookie banner while tracking occurs through technologies that the organisation has not adequately considered.
There is another important change UK organisations need to be aware of.
The Data (Use and Access) Act 2025 amended the UK rules to create additional circumstances in which storage and access technologies can be used without consent. The ICO’s final guidance, published in April 2026, reflects those changes.
In addition to existing exceptions for activities such as strictly necessary technologies, organisations may now be able to use certain technologies without consent for limited statistical purposes, such as producing aggregate information about how visitors use a service in order to improve it.
However, this is not a general exemption for analytics or tracking. The ICO makes clear that the statistical-purpose exception does not extend to identifying or tracking individual visitors, profiling them, connecting visitor identities to activity for advertising purposes, monitoring people across websites, or retaining individual-level information beyond what is needed to create aggregate statistics.
Advertising presents an even clearer position. The ICO states that storage and access technologies used for online advertising require consent, including technologies used for associated tracking and profiling.
This makes understanding the purpose of each technology essential. Calling something an “analytics cookie” does not automatically determine whether consent is required. What matters is what the technology actually does.
One of the biggest practical lessons from the research is that the existence of a cookie banner tells an organisation remarkably little about whether its website is compliant.
A banner is only the visible front end of a much larger technical process. Behind it may sit advertising platforms, analytics providers, social media pixels, tag-management systems, embedded videos, customer-engagement software, session-recording tools, affiliate marketing technologies and other third-party services.
Some may begin communicating with external platforms almost as soon as a visitor arrives.
That creates a significant governance problem if the organisation believes tracking starts only after somebody presses “Accept”.
The ICO’s guidance is clear that, where consent is required, organisations cannot set non-essential technologies before the necessary consent has been obtained. Users must also be given clear information and meaningful control over non-essential technologies.
A beautifully designed banner therefore achieves very little if the website has already transmitted information elsewhere before the user gets the opportunity to make a choice. Compliance needs to be tested technically, not simply reviewed visually.
The term “dark pattern” is commonly used to describe an interface design that steers, pressures, confuses or manipulates a user towards a particular decision.
Regulators increasingly refer to the broader concept of online choice architecture, recognising that seemingly small design decisions can have a significant influence over how people behave online. The Competition and Markets Authority describes online choice architecture as the environment in which people make choices online and has warned that some design practices can influence people towards decisions they might not otherwise have made.
In the context of cookie consent, that could include making an “Accept All” button highly prominent while hiding rejection behind several menus, using confusing wording, turning non-essential options on by default, or designing the journey so that refusing tracking requires considerably more effort than accepting it.
The issue is not that every difference in colour, size or position automatically constitutes unlawful manipulation. The question is whether the overall design gives people a genuine opportunity to understand and exercise their choice.
The ICO’s own privacy-by-design guidance warns organisations to avoid harmful design practices when presenting privacy choices and says interfaces should not mislead people or create inappropriate pressure.
Good interface design should make compliance easier. It should not be used to find the most effective way of persuading somebody to surrender their privacy.
Consent under UK data protection law must be freely given, specific, informed and unambiguous. It should involve a genuine positive choice.
The ICO says valid consent should give people meaningful, ongoing control over how their information is used. Consent requests should be clear, prominent, separate from unrelated terms and easy to understand.
That principle has significant implications for cookie banners. An organisation may naturally prefer users to accept advertising or analytics technologies because those systems provide valuable marketing information. But commercial preference does not change the standard of consent.
If rejecting tracking is unnecessarily difficult, confusing or substantially more burdensome than accepting it, organisations should question whether the resulting consent genuinely represents the user’s choice.
This is not merely theoretical regulatory guidance. The ICO has already undertaken significant work examining how major UK websites present cookie choices. Its position has been that users should be given meaningful control over whether they are tracked for personalised advertising.
By April 2026, the regulator reported that 99% of the UK’s top 1,000 websites met its cookie-banner compliance standards following targeted work with industry.
The Swansea research provides an interesting contrast, although the two figures should not be directly compared because the populations, methodologies and compliance assessments are different. What both demonstrate is that cookie-banner design is firmly within regulatory attention.
Another common mistake is treating consent as a single moment in time. A person presses “Accept”, the organisation records the choice and compliance is considered complete.
In reality, consent needs to correspond with what the organisation subsequently does.
If the technologies on a website change, additional advertising providers are introduced, new tracking purposes appear, or information starts being shared with different organisations, an old consent may no longer adequately cover the new processing.
The ICO advises organisations to understand whether technologies are first-party or third-party, identify their purposes, understand what information is shared, determine how long they operate for, distinguish between necessary and non-essential technologies, document their use and establish an appropriate review period.
This means cookie governance needs an owner.
Websites naturally change over time. Marketing teams introduce new plugins, developers deploy analytics tools, advertising agencies add tracking pixels, social media integrations are enabled, websites are rebuilt and third-party services change what their software does.
None of these changes needs to be malicious to create a compliance problem. The risk comes when nobody steps back and asks whether the organisation’s privacy controls still accurately reflect the technology operating on the website.
This is where cookie compliance becomes a leadership and governance issue rather than simply a website-development task.
Marketing teams may select technologies because they provide useful conversion data. Developers may deploy the scripts. A third-party agency may operate the website. Legal or compliance teams may write the privacy and cookie notices. The Data Protection Officer may periodically review the documentation.
But who is responsible for confirming that all of those elements match?
If the website says advertising technologies are disabled until consent but a tag fires immediately when the page loads, the privacy notice does not change that technical reality.
Similarly, relying on a third-party consent management platform does not automatically transfer responsibility for the organisation’s compliance to that supplier.
Organisations need sufficient oversight to understand what their websites are doing with people’s information. The ICO’s rules expressly apply to technologies that organisations incorporate from third parties, including advertising networks and other external services.
The fact that a supplier provided the script does not make the resulting processing somebody else’s problem.
Although the underlying compliance lessons apply to all organisations, the context of gambling helps explain why this particular research has attracted attention.
Online gambling services can generate extensive behavioural information. A platform may potentially know when somebody gambles, how frequently they gamble, what products they use, how long sessions last, what devices they use, how they respond to promotions and whether their behaviour changes over time.
Not all of that information is necessarily collected through advertising cookies, and the existence of data does not itself establish that it is being processed unlawfully.
However, the combination of behavioural tracking and personalised marketing understandably raises significant privacy questions when it occurs in sectors where some customers may also be vulnerable.
This is not an entirely new regulatory concern.
In 2024, the ICO issued a reprimand to Bonne Terre Limited, trading as Sky Betting and Gaming, after finding that certain advertising cookies had processed people’s personal information and shared it with advertising technology companies before users had been given the opportunity to accept or reject those cookies.
The ICO said its investigation found no evidence that the company had deliberately misused information to target vulnerable gamblers.
The distinction is important. Regulators do not need to establish deliberately harmful intent before poor data governance becomes a compliance problem. A system can create unlawful or inappropriate processing because it was configured incorrectly, inadequately monitored or designed without sufficient consideration of the applicable privacy rules.
The gambling sector has recently been involved in another important UK data protection development.
In April 2026, the Court of Appeal considered RTM v Bonne Terre Limited and another, a case involving consent to cookies, personal-data processing and direct marketing in the context of a person who had experienced problem gambling.
The Court of Appeal rejected an approach under which the validity of consent depended on analysing an individual’s subjective state of mind. Instead, it held that consent is assessed objectively by considering the outward indication of the person’s wishes against the statutory requirements for freely given, specific, informed and unambiguous consent.
The case is legally distinct from the Swansea University research, but it reinforces why organisations should be careful when discussing consent.
It is not accurate simply to say that any interface capable of influencing behaviour automatically makes consent invalid. Nor is it safe to assume that a clicked “Accept” button automatically proves valid consent regardless of the surrounding circumstances.
What matters is whether the mechanism satisfies the applicable legal requirements.
Good governance therefore means designing a consent process that an organisation would be comfortable explaining to a regulator, rather than merely designing one that maximises acceptance rates.
There is another reason businesses should revisit cookie governance now.
The Data (Use and Access) Act 2025 significantly strengthened the ICO’s enforcement powers under PECR. Historically, PECR penalties were considerably lower than the maximum penalties available under the UK GDPR.
The new regime brings those powers much closer together. The ICO can now issue certain PECR penalties of up to £17.5 million or 4% of worldwide annual turnover, depending on the applicable provisions and circumstances.
The Act also strengthened other regulatory powers, including the ability to obtain technical reports.
That matters because cookie compliance has sometimes been treated as a relatively minor issue. A banner might be seen as something to tidy up when the website is next redesigned.
That attitude is becoming increasingly difficult to justify. The regulatory framework, enforcement capability and sophistication of technical scrutiny are all moving in the opposite direction.
One practical consequence is that organisations should not rely exclusively on screenshots or policy reviews when auditing cookie compliance. Someone needs to test what actually happens.
Before consent is given:
These are technical questions.
An organisation can have an excellent privacy notice and still fail them.
The broader governance lesson from the Swansea research is not confined to gambling. Every organisation with a website should be able to explain how its tracking technologies are governed.
There should be a current inventory. Purposes should be documented. Technologies requiring consent should not activate before that consent is obtained. The banner should provide genuine control. Privacy information should reflect what happens technically. Third-party technologies should be understood. Changes to the website should trigger an appropriate review.
And somebody should periodically test whether the whole process still works as intended.
The ICO itself recommends documenting cookie use and establishing appropriate review periods rather than treating implementation as a one-off exercise.
That turns cookie compliance from a banner into a control.
The Swansea University study focuses on online gambling, but the technology it examines is not specific to gambling.
Cookie banners, analytics tools, advertising pixels, third-party scripts and consent management platforms appear across almost every part of the modern internet.
That makes the findings relevant to retailers, professional services firms, financial organisations, charities, manufacturers, public bodies, media companies and almost any organisation maintaining a public-facing website.
The important question is not whether a website has a cookie banner.
It is whether that banner accurately controls what happens behind it.
For boards and senior leaders, that means gaining assurance that cookie compliance has not simply been delegated somewhere between marketing, IT, a web developer and a third-party agency, with nobody ultimately responsible.
For privacy teams, it means testing the technology rather than relying entirely on documentation.
For website and marketing teams, it means recognising that the most commercially effective design is not necessarily the most appropriate if it undermines genuine user choice.
And for organisations generally, it means remembering the purpose of consent.
Consent should record a decision made by the individual. It should not be a hurdle designed to produce the decision the organisation wanted in the first place.
AJC helps organisations strengthen their data protection and privacy governance, including reviewing consent processes, website tracking technologies and the controls behind them. If you would like support assessing your organisation’s cookie compliance and identifying any gaps, contact us on 020 7101 4861 or email us at info@ajollyconsulting.co.uk if you think we can help.
Sources:
https://www.sciencedirect.com/science/article/pii/S2451958826003441
https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/consent/
https://ico.org.uk/about-the-ico/what-we-do/our-work-on-online-tracking/
https://www.judiciary.uk/judgments/rtm-v-bonne-terre-limited-and-another/
https://www.sciencedirect.com/science/article/pii/S2451958826003441
Image accreditation: Allison Saeng (May 2026) from Unsplash.com+. Last accessed on 15th September. Available at: https://unsplash.com/photos/smartphone-displaying-football-bets-with-casino-chips-and-coins-iPtZgZSRMHA
Recent disruption across UK airports has shown how quickly the failure of a critical system can have far-reaching consequences. While...
Read MoreProtecting patient data is not just about securing systems and technology. This article looks at how human behaviour, organisational processes...
Read MoreA recent €825 million GDPR fine against Uber has put automated decision making firmly in the spotlight. This article looks...
Read More