HURRY! THIS BLOG POST MAY NOT BE HERE TOMORROW!! - Understanding Dark Patterns and India's Regulatory Response
INTRODUCTION
In
today's digital age, the internet has become an indispensable part of everyday
life.
Whether
it is ordering food after a long day, purchasing groceries with a few taps on a
smartphone, or shopping for clothes and electronics from the comfort of home, we
increasingly rely on online platforms for convenience, speed, offers and
choice.
You
might have encountered some of these scenarios that I illustrate below.
While
browsing an e-commerce platform for a new shirt or pair of shoes, you may have come
across messages such as "Only 1 item left in stock!" "27
people are viewing this product right now!" or a countdown timer
warning that a discount will expire within minutes. Concerned that you might
miss out on a good deal, you quickly complete the purchase. Later, you may access
the site again, and the same messages persist, and it would make you wonder
whether the urgency was genuine at all.
Or
perhaps you may be ordering dinner through a food delivery application or
purchasing groceries through a convenience platform. You proceed to checkout
expecting to pay the price displayed earlier, only to discover that an
additional charge, donation, insurance fee, or service has somehow found its
way into your basket without your conscious approval. Many consumers simply
accept the extra cost rather than spend time figuring out how to remove it.
These
experiences are examples of what are commonly known as “Dark Patterns”,
and it relies on behavioural biases and moments of inattention.
It
is, in its essence, it is a scenario whereby user interface designs are curated
and crafted to steer, pressure, or manipulate consumers into making decisions
that would ultimately benefit the platform.
THE
FINE LINE BETWEEN MARKETING AND MANIPULATION
Of
course, it can always be argued that it is a harmless design choice and is not
inherently malicious nor fundamentally different from techniques that
businesses have employed for decades. Traditionally, businesses have relied on
techniques such as positioning essential goods at the back of the store to
increase customer exposure to other products, and salespersons routinely invoke
scarcity, popularity and urgency to encourage purchases. In this sense, digital
platforms have merely translated established principles of behavioural
economics into the online environment.
When
viewed from this perspective, what some describe as manipulation may merely be
an evolution of traditional marketing in a digital environment, whereby
businesses seek to present information in a manner that is engaging and commercially
effective.
Marketing,
by its very nature, seeks to influence consumer behaviour. A business is well entitled
to advertise its products, highlight their benefits, emphasise genuine
discounts and present information in a manner that encourages purchases, but the
law has been consistent that businesses can do so as long as consumers are provided
with accurate information and the representations made by the business are accurate.
Dark
patterns, however, operate differently. Their objective is not merely to
persuade consumers to make a purchase, but to shape the decision-making process
itself. Rather than helping consumers make informed choices, they exploit
cognitive biases, information asymmetries and behavioural vulnerabilities to
secure outcomes that consumers may not have chosen if the information had been
presented fairly.
A
genuine limited-time offer differs fundamentally from an artificial countdown
timer that resets upon refresh; similarly, a transparent service fee is not
equivalent to a charge that quietly appears at the final stage of checkout.
While businesses are entitled to persuade consumers, they cannot do so at the
cost of informed consent and meaningful choice.
The
distinction, therefore, lies not in the presence of influence, but in the
manner in which that influence is exercised.
The
growing regulatory scrutiny of dark patterns, therefore, reflects an attempt not
to prohibit effective marketing, but to ensure that commercial success is
achieved through transparency and fair dealing rather than deception and
behavioural manipulation.
The
prevalence of such practices has not gone unnoticed by regulators. As dark
patterns became increasingly embedded within digital commerce, concerns began
to emerge regarding their impact on consumer autonomy, informed consent, and
fair market practices.
In
this context, the Guidelines
for Prevention and Regulation of Dark Patterns, 2023, were issued by the
Central Consumer Protection Authority ("CCPA").
DARK PATTERNS
Framed
under Section 18 of the Consumer Protection Act, 2019, the CCPA notified the
Guidelines that sought to identify and prohibit a range of deceptive online
practices, including false urgency, basket sneaking, confirm shaming, subscription traps, and interface interference, amongst others, which I shall
explain in detail below.
The
guideline defines dark pattern to be, “any practices or deceptive design
pattern using user interface or user experience interactions on any platform
that is designed to mislead or trick users to do something they originally did
not intend or want to do, by subverting or impairing the consumer autonomy,
decision making or choice, amounting to misleading advertisement or unfair
trade practice or violation of consumer rights.”
Further,
it states that, “no person, including any platform, shall engage in any dark
pattern practice,” and it is applicable to;
- All platforms, systematically offering goods or services in India;
- Advertisers; and
- Sellers
Annexure I to the Guidelines identifies thirteen specific practices that may constitute dark patterns:
1. False Urgency
As
the name suggests, it is simply creating a false sense of scarcity or urgency
to induce consumers into making immediate decisions.
An
online marketplace displays a message stating "Only 1 item left in
stock" or "Offer ends in 5 minutes", despite having
substantial inventory or repeatedly resetting the time, which would constitute an
example of False Urgency.
Consumers
often perceive scarce goods as more valuable and are therefore more likely to
make impulsive decisions without adequately comparing alternatives. While
genuine stock limitations and time-bound offers are legitimate marketing tools,
the practice becomes problematic when the urgency itself is fabricated.
Although proving that a claim of scarcity by a retailer or an advertiser was artificial so as to induce the consumer to buy immediately rather than it being a genuine instance where stock was limited is, of course, easier in theory
2. Basket Sneaking
"Basket Sneaking" refers to a scenario when a platform adds products, services or charges to a consumer's shopping basket during the purchasing process without their clear knowledge or consent, resulting in the consumer paying more than they originally intended.
Rather
than persuading consumers to purchase additional products, it relies on
inattention and default settings to increase transaction value. The practice
effectively shifts the burden onto the consumer to identify and remove unwanted
additions, thereby capitalising on predictable human oversight.
A
ticket-booking platform automatically adds a donation or premium service to the
checkout page through a pre-selected option would be an illustration of basket
sneaking.
However, it would be pertinent to note that ‘necessary fees’, which are a requirement for the completion of the order, such as delivery charges, gift wrapping, additional taxes on the product charged by the government or any other charges which are explicitly disclosed to the consumer at the time of purchase, shall not constitute the practice of Basket Sneaking,
3. Confirm Shaming
Confirm
shaming is a scenario whereby a platform frames one option in a way that makes
the user feel guilty or foolish for rejecting an offer.
An
example could be when a platform for booking flight tickets uses the phrase “I
will stay unsecured”, when a user does not include insurance in their cart or
any other such phrase which is designed to steer consumers towards a
commercially beneficial choice rather than facilitate a genuine and informed
decision.
Rather
than presenting choices neutrally, this practice frames one option as
irresponsible, foolish or undesirable and thus, the consumer may act not
because the product is valuable, but to avoid the negative emotional
association deliberately created by the platform.
4. Forced Action
Forced
action refers to a scenario where a platform compels a consumer to undertake
an additional step such as purchasing another product, subscribing to a
separate service or disclosing personal information as a precondition for
accessing the product or service they originally intended to obtain.
In
such cases, the consumer's ability to make a free and independent choice is
undermined by making the desired transaction contingent upon compliance with
unrelated requirements.
For example, forcing a user to share personal information linked with Aadhar or credit card, even when such details are not necessary for making the intended purchase or forcing a user to share details of his contacts or social networks in order to access products or services purchased or intended to be purchased by the user.
5. Subscription Trap
This
refers to a practice wherein, subscribing to a service is made simple and
seamless, while cancelling the subscription or opting out is made unnecessarily
complex, time-consuming or burdensome.
A
common example is when a streaming platform that permits users to subscribe
with a single click but requires them to navigate multiple webpages, contact
customer support, or send emails in order to cancel the subscription.
This
is designed keeping in mind. the tendency of consumers to postpone inconvenient
tasks. It is not uncommon to observe that minor procedural hurdles discourage
users from cancelling recurring subscriptions, thereby increasing retention
rates.
However, in this circumstance, continued revenue is derived not from a consumer's conscious decision to remain subscribed, but from the friction deliberately introduced into the cancellation process.
6. Interface Interference
This
refers to the deliberate design of a user interface in a manner that gives
undue prominence to one option while concealing, diminishing or making it more
difficult to access alternative choices. By manipulating visual cues such as
colour, size, placement or wording, platforms steer users towards a particular
decision without overtly restricting their freedom to choose.
A common example is a website displaying a large, brightly coloured ‘Accept’ button while relegating the ‘Decline’ option to small, faint text or placing it in a less visible location.
7. Bait and Switch
This is when consumers are enticed with a particular product, offer or outcome, only to substitute it with a different or less favourable alternative after the consumer has committed to the transaction.
An
illustration of this could be an instance whereby a user clicks on a button
advertising a "Free Trial", only to be redirected to a page requiring
immediate payment or enrolment in a paid subscription plan instead.
It
relies on the idea that once a consumer has invested time and effort in
pursuing an offer, they are often more inclined to continue with the
transaction, even if the original terms have changed. By capitalising on this
behavioural tendency, platforms encourage consumers to accept outcomes they may
have rejected had the true nature of the offer been disclosed at the outset.
The practice is therefore objectionable not because alternatives are offered,
but because consumers are induced to act on representations that ultimately
prove to be misleading.
8. Drip Pricing
Drip
Pricing is a practice wherein a product or service is advertised at an
attractive initial price while disclosing additional mandatory fees, charges or
other price components only at a later stage when checking out. As a result,
the final amount payable is significantly higher than the price that initially
attracted the consumer.
A
common example is an airline ticket advertised for ₹2,999, where mandatory convenience fees, service charges and
other unavoidable costs are progressively added during checkout, increasing the
final price to ₹4,200.
Drip pricing exploits the behavioural phenomenon known as anchoring, whereby consumers place disproportionate weight on the first price they encounter. Having already invested time in selecting the product and progressing through the purchase, many consumers are inclined to complete the transaction despite the incremental increase in cost. Beyond influencing individual purchasing decisions, drip pricing undermines market transparency by making meaningful price comparisons between competing products or services more difficult.
9. Disguised Advertisement
This
is the practice of presenting promotional content in a manner that conceals its
commercial nature, making it appear to be independent or unbiased content.
Advertisements may be disguised as user reviews, news articles, editorial
content or other forms of organic content, thereby misleading consumers into
engaging with them under the mistaken belief that they are not promotional in
nature.
A
common example is an influencer or content creator publishing a glowing product
review without disclosing that it is a paid promotion, or a website displaying
a sponsored article that closely resembles an independent news report without
any clear indication that it is an advertisement.
Disguised
advertisements are in direct violation of one of the core principles of consumer
protection: transparency. By blurring the distinction between independent
content and commercial promotion, businesses can influence purchasing decisions
without consumers recognising that they are being marketed to.
For
this reason, the CCPA Guidelines also treat disguised advertisements as a form
of misleading advertisement, reinforcing the obligation on sellers and
advertisers to clearly disclose the promotional nature of their content.
10. Nagging
As
the name suggests, this is when entities repeatedly interrupt or prompt users
with persistent requests, notifications or pop-ups to encourage them to
complete a transaction, share personal information or take another action that
benefits the platform. These repeated interactions continue even when the user
has indicated disinterest or has not expressly consented to receiving them.
Common
examples include websites repeatedly prompting users to download their mobile
application, platforms persistently requesting access to personal information
under the guise of security, or websites repeatedly asking users to enable
notifications or accept cookies without providing a clear and accessible option
to decline.
Nagging exploits the psychological tendency known as decision fatigue. Repeated prompts and interruptions can wear down a user's resistance, increasing the likelihood that they will eventually comply simply to remove the inconvenience rather than because they genuinely wish to do so.
11. Trick Question
Trick
Question refers to the use of ambiguous, misleading or unnecessarily complex
language to confuse users and influence the choices they make. By employing
techniques such as double negatives, vague wording or misleading answer
options, platforms increase the likelihood that consumers will inadvertently
select an option they did not intend.
A common example is a subscription prompt asking, " A checkbox stating: "Uncheck this box if you do not wish not to receive promotional emails." rather than providing clear and straightforward "Yes" or "No" choices. The inconsistent wording can easily mislead users into making the opposite selection from what they intended.
12. SaaS Billing
This
is a case of misuse of recurring billing mechanisms in Software-as-a-Service
(SaaS) platforms to generate revenue through opaque or deceptive subscription
practices.
To
better understand this practice, let us take the example of a platform such as
Notion, Canva, or Adobe Creative Cloud offering a free trial that automatically
converts into a paid subscription unless cancelled before a specified date.
While these subscription models are entirely legitimate concerns arise as users are not provided with adequate reminders before renewal or where cancellation is significantly more cumbersome than enrolment like subscription trapping or where recurring charges continue without clear and informed consent.
13. Rogue Malaware
Rogue
Malware refers to deceptive software or online practices that falsely convince
users that their device has been infected with a virus or other security
threat, thereby inducing them to download malicious software or make
unnecessary payments for fraudulent security services. Instead of protecting
the user, the software itself installs malware or otherwise compromises the
user's device.
The
aforesaid thirteen practices identified by the CCPA have all at some point of
time influenced consumer behaviour and unfortunately, not through the intrinsic
merits of a product or service, but rather by exploiting cognitive biases,
information asymmetries or behavioural vulnerabilities.
The guidelines therefore mark a significant evolution in Indian consumer protection law and recognise that consumer harm in the digital age may arise not only from false representations or defective products, but also from the architecture of digital interfaces themselves.
Now,
the question that stands before us is: What happens if a platform engages in
these practices?
FROM REGULATION TO REALITY
It
is worth examining whether this regulatory framework has translated into
meaningful enforcement, or whether it remains largely aspirational. The short
answer is that the CCPA has, to its credit, demonstrated a willingness to act
and in some instances, its interventions have produced tangible changes in
platform behaviour.
Following
the issuance of the Guidelines for Prevention and Regulation
of Dark Patterns, 2023,
the CCPA in May 2025 convened
a stakeholder consultation meeting with leading e-commerce entities
including Amazon, Flipkart, Swiggy, Zomato, BigBasket, Uber, Ola, MakeMyTrip,
EaseMyTrip, Meta, WhatsApp, Paytm and several others. The objective was to
sensitise platforms to the regulatory concerns surrounding dark patterns and
encourage voluntary compliance before coercive enforcement became necessary.
Subsequently,
On June 2025, the CCPA thereafter issued an advisory directing all e-commerce
platforms to conduct comprehensive self-audits within three months to identify
and eliminate dark patterns from their digital interfaces.
Platforms
were further encouraged to furnish self-declarations confirming compliance with
the Guidelines, while the Department of Consumer Affairs simultaneously
constituted a Joint Working Group comprising representatives from government
ministries, regulators and consumer organisations to monitor violations,
recommend corrective measures and strengthen consumer awareness.
Following
the advisory, twenty-six
leading e-commerce platforms voluntarily submitted declarations stating
that they had completed internal or third-party audits and that their platforms
were free from dark patterns.
ENFORCEMENT
PHYSICS WALLAH
Earlier
last month, the first major enforcement action was
initiated suo motu against PhysicsWallah Limited and McAfee Software
India Private Limited for indulging in Dark Pattern practices.
Physics
Wallah was found to have engaged in the practices of Basket Sneaking, Confirm
Shaming, and Forced Action.
With
respect to Basket Sneaking, the platform automatically included a ₹10 donation to the PW Foundation in the total payable amount
by keeping the option pre-selected during checkout. Consumers were required to
actively opt out if they did not wish to contribute, resulting in additional
charges being imposed without their explicit consent.
The
CCPA also found that PhysicsWallah employed Confirm Shaming by displaying
emotionally persuasive messages relating to children's education, healthcare
and marriages when consumers attempted to deselect the donation. Rather than
presenting a neutral choice, the interface sought to induce guilt and moral
pressure, thereby influencing users to retain the donation.
The
Authority also identified Forced Action in the manner in which the platform
offered its so called "free" courses. Although the courses were
advertised as being freely accessible, users could only access the content
after furnishing personal information such as their mobile number and email
address.
Upon
examination, the CCPA found that the educational content remained identical
across all user accounts, indicating that the mandatory collection of personal
data served no functional purpose in providing access to the courses.
Therefore,
the CCPA further imposed a penalty of ₹5,00,000/- (Rupees Five Lakh only) for the
aforesaid violations.
McAffee
In
the same order, McAfee was fined ₹1,00,000/- (Rupees One Lakh only) for
employing confirm shaming, interface interference, trick questions and forced
action in its interface especially with regard to the renewal page.
The
renewal interface employed Confirm Shaming by framing the decision not to renew
in a manner that suggested consumers were acting irresponsibly, thereby using
emotional pressure instead of neutral language.
Simultaneously,
Interface Interference was evident in the visual design of the page, where the
renewal option was made significantly more prominent than the option to
decline, subtly steering users towards continued subscription.
The
Authority also found the use of Trick Questions, as consumers were presented
with confusing and emotionally loaded language instead of a clear and neutral
choice regarding renewal.
Finally,
the absence of an equally visible and straightforward opt-out mechanism
amounted to Forced Action, as users were effectively compelled to navigate a
less accessible path in order to decline renewal.
SPICEJET
2
weeks ago, on 14.07.2026, the CCPA struck its sword on Spicejet and imposed a
penalty of ₹1,00,000/- (Rupees One Lakh only) after
finding that the airline's online booking platform employed Forced Action, Interface
Interference, and Trick Question during the booking process.
With
respect to Forced Action, the CCPA observed that consumers booking flight
tickets were automatically enrolled in the SpiceClub Loyalty Programme through
a pre-ticked checkbox.
The
Authority further found that the platform employed Interface Interference by
presenting the airline's preferred options as the default selections. The
visual prominence afforded to the pre-selected checkboxes subtly steered
consumers towards joining the loyalty programme and consenting to promotional
communications, thereby influencing their decision-making through interface
design rather than informed choice.
While
the CCPA had previously notified and ordered the airline to rectify the issue, they
merely substituted one pre-ticked checkbox with another to obtain consent for
promotional messages via SMS, WhatsApp and email, effectively continuing the
impugned practice in a different form.
The
CCPA also held that SpiceJet's consent mechanism amounted to a Trick Question.
The booking interface employed confusing and negatively worded consent
language, making it difficult for consumers to clearly understand whether they
were opting in or opting out of promotional communications.
Thus,
it is fair to say that the CCPA has transitioned from merely prescribing
standards to actively enforcing them. Through its recent enforcement actions,
the Authority has demonstrated that the guidelines are not intended to remain
advisory in nature but constitute enforceable standards governing digital
consumer interactions.
By
initiating proceedings against prominent digital platforms across diverse
sectors, including edtech, software subscriptions and aviation, the CCPA has
sent an unequivocal message that indulging in such practices will invite
regulatory scrutiny irrespective of the industry involved.
These
enforcement actions are likely to serve as deternece and encourage businesses to
proactively reassess their user interfaces, strengthen internal compliance
mechanisms and embed transparency and consumer autonomy into the design of
their digital platforms.
EXPANDING REGULATORY LANDSCAPE
The
challenge posed by dark patterns extends beyond e-commerce marketplaces and
quick-commerce platforms. Increasingly, digital interfaces are also the primary
means through which consumers access financial products and services.
Banking
applications, lending platforms, insurance products and investment services are
now marketed, distributed and purchased through online channels, creating
opportunities for the same manipulative techniques to influence financial
decision-making.
The
efforts of the CCPA to Recognising this risk, the Reserve Bank of India
("RBI") has now taken a decisive step.
Last
month, on 15 June 2026, the RBI issued the Reserve Bank of India (Commercial Banks –
Responsible Business Conduct) Second Amendment Directions, 2026,
introducing an explicit prohibition on the use of dark patterns by regulated
entities across websites, mobile applications and other sales channels.
The
amendment forms part of a broader regulatory effort aimed at curbing
mis-selling within the financial sector. Alongside banning dark patterns, the
RBI has strengthened requirements relating to informed customer consent,
transparent disclosures, product suitability assessments and the prohibition of
compulsory bundling of financial products. Significantly, where mis-selling is
established, regulated entities may be required to refund the entire amount
involved and cancel the impugned sale.
Further,
Banks are now required to obtain explicit and informed customer consent, ensure
that products are suitable for the customer's needs and risk profile, make
clear and transparent disclosures regarding product features, costs and risks,
and periodically audit their digital interfaces to identify and eliminate
deceptive design practices.
he
Directions further provide robust remedial measures by requiring banks, where
mis-selling is established, to refund the entire amount involved, cancel the
impugned sale and compensate customers in accordance with their board-approved
policies.
However,
it is set to be effective from 01.01.2027.
CONCLUSION
The
regulation of dark patterns is undoubtedly a welcome development in India's
digital consumer protection framework. That said, one need not agree with every
aspect of the regulatory approach or every practice classified as a dark
pattern.
Businesses
have always relied on marketing, behavioural insights and persuasive design to
attract customers, and drawing the line between legitimate persuasion and
unlawful manipulation will inevitably remain a matter of debate.
Overregulation
also carries the risk of stifling innovation and constraining businesses from
designing intuitive and commercially effective user experiences.
Nevertheless,
the larger objective behind the CCPA Guidelines and the subsequent enforcement
actions cannot be ignored. At their core, these measures seek to protect the
average consumer from being misled, pressured or unknowingly nudged into
decisions they did not intend to make. In an increasingly digital economy,
where even minor interface changes can significantly influence consumer
behaviour, ensuring transparency, informed consent and genuine choice is both
necessary and desirable.
For
consumers, these developments also bring an important takeaway.
Dear
Reader, if you encounter practices such as hidden charges, pre-selected
add-ons, misleading countdown timers, confusing cancellation processes, forced
subscriptions or any other dark pattern you are not without recourse.
These
practices constitute unfair trade practices under the Consumer Protection Act,
2019, and complaints can be made to the Central Consumer Protection Authority
(CCPA) through the National Consumer Helpline or through the Department of
Consumer Affairs' E- Jagriti App.
very insightful
ReplyDeleteAs it is too long I just gone through main points only.
ReplyDeleteI wish you all success in this venture.
Ednad Krishnamohana Bhat & Jayalakshmi
Loved the narration and analysis! Very comprehensive piece on the subject matter.
ReplyDeleteReally well written!!!! Love how you’ve made a topic like this so approachable for people without a legal background
ReplyDelete