The websites were observed between April and June 2025, more than a year before publication. Operators may have since changed consent platforms, removed third-party trackers or redesigned banners. Any reporting about individual brands should therefore give them an opportunity to describe remedial work completed after the audit.
The paper does not establish that the ICO or UKGC has ruled against every website classified as non-compliant. The ICO enforces data-protection and electronic-communications rules, while gambling licensing and consumer-protection obligations fall within the UKGC’s remit.
Compliance teams can nevertheless use the findings to support renewed technical testing across their operations. Reviews should cover pre-consent network requests, tag-manager settings, affiliate pixels, rejection paths, consent records and vendor data flows. Testing should be repeated after website releases, campaign launches and changes to third-party tools, rather than relying on the banner’s visible appearance alone.