:

UK BETTING SITES BREACH PRIVACY RULES WITH COOKIE TACTICS

SECURITY DESK1 MIN READ
SUN, SEP 6, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A study found that 86% of licensed British gambling websites violate GDPR privacy requirements, using deceptive cookie banners to track users before obtaining consent.

Online bookmakers and casinos are harvesting customer data through aggressive tracking practices that circumvent UK privacy protections. The research reveals websites employ dark patterns in cookie banners that nudge users toward accepting surveillance, with many collecting data before explicit consent is given. GDPR regulations require organizations to obtain clear permission before tracking personal information. The widespread non-compliance suggests systematic "data surveillance" across the gambling industry. The findings raise questions about enforcement by UK regulators. Gambling websites operating under British licenses are subject to strict data protection standards, yet the majority appear to prioritize data collection over legal requirements. Licensed operators could face enforcement action if authorities act on the study's conclusions. The investigation highlights a broader pattern of websites using misleading interface design to obscure privacy choices from users, a practice known as "dark patterns" or "dark UX."

■ SOURCES

The Guardian — Technology

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Berlin's government is intensively reviewing 5.79TB of state data released by ransomware group Rhysida after refusing to pay a ransom demand. The leaked files reportedly contain sensitive information on national defense and threat response plans.

15H AGOIndustry Desk

Cybercriminals are exploiting thousands of compromised small-business websites to distribute ClickFix malware payloads stored in smart contracts on the BNB Smart Chain, amplifying the reach of a known threat.

18H AGOAI Desk

Quad9 provides an open DNS recursive service that prioritizes user privacy and security at no cost. The service blocks malware and phishing domains while maintaining minimal data collection.

21H AGOSecurity Desk

A government website running Ruby on Rails was exploited within hours of a critical vulnerability patch becoming public. The rapid attack demonstrates how quickly threat actors weaponize disclosed security flaws.

21H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.