Published on: 21st August 2026
Authored by: Ishika Garg
Maharishi Markandeshwar (deemed to be) University
Abstract
As online shopping, food delivery, and digital subscriptions become integral to daily life in India, digital marketplaces increasingly employ deceptive user interface designs known as “dark patterns.”[1] These intentionally crafted designs manipulate consumer choice, exploit behavioral vulnerabilities, and impair free decision-making.[1] While India has introduced foundational legal protections through the Consumer Protection Act, 2019,[2] the Consumer Protection (E-Commerce) Rules, 2020,[3] and the Central Consumer Protection Authority’s (CCPA) Guidelines for Prevention and Regulation of Dark Patterns, 2023,[4] enforcement gaps remain.[1] Drawing upon comparative frameworks from the European Union, the United States, the United Kingdom, and Australia, this article evaluates the efficacy of India’s legal architecture, highlighting enforcement challenges posed by AI personalization, cross-border platforms, and the absence of standalone statutory monetary penalties.[1][5][6][7][8]
Introduction
Online shopping has become a part of everyday life in India.[1] Whether people are buying clothes, booking hotel rooms, ordering food, or subscribing to streaming platforms, digital marketplaces offer convenience and speed.[1] However, many websites and mobile applications are designed in ways that influence users to make decisions they may not have intended to make.[1] For example, a countdown timer may create false pressure to buy immediately, a paid add-on may already be selected in the shopping cart, or the option to refuse an offer may be hidden in small or faded text.[1] These are not accidental design mistakes but carefully planned techniques known as dark patterns.[1]
Dark patterns are interface designs that manipulate consumers into making choices that benefit businesses rather than consumers.[1] These practices reduce the consumer’s ability to make free and informed decisions.[1] With India’s rapidly growing digital economy and millions of first-time online shoppers, the use of such deceptive practices has become a major concern.[1] Many users, particularly those with limited digital literacy, may not even realise they have been misled until after completing a transaction.[1]
To address these concerns, India has introduced several legal measures, including the Consumer Protection Act, 2019,[2] the Consumer Protection (E-Commerce) Rules, 2020,[3] and the Guidelines for Prevention and Regulation of Dark Patterns, 2023,[4] issued by the Central Consumer Protection Authority (CCPA).[1] These laws seek to ensure transparency, protect consumer rights, and prevent unfair trade practices.[1] However, an important question remains: Are these laws sufficient to protect consumers from manipulative digital practices, or do significant enforcement gaps still exist?[1] This article examines the concept of dark patterns, the Indian legal framework, and whether consumers are truly protected in today’s digital marketplace.[1]
Understanding Dark Patterns
The term “dark patterns” was first introduced by user-experience designer Harry Brignull in 2010 to describe website and application designs that trick users into taking actions they did not intend.[1] Over time, the concept gained global recognition, leading governments and regulators to take notice of its harmful effects.[1]
In India, the Central Consumer Protection Authority (CCPA) defines a dark pattern as any deceptive user interface design that misleads or tricks consumers into doing something they did not originally intend by impairing or subverting their decision-making or choice.[4] Such practices may amount to an unfair trade practice or a misleading advertisement under consumer protection law.[2][4]
It is important to distinguish between persuasive design and dark patterns.[1] Businesses often use attractive layouts, personalised recommendations, or discounts to encourage purchases.[1] Such practices are generally acceptable as long as they are transparent and truthful.[1] A dark pattern, however, goes a step further by hiding important information, creating artificial pressure, or manipulating users into making decisions that they might not have made if all relevant information had been presented clearly.[1]
Many businesses use dark patterns because they are effective.[1] These techniques rely on behavioural psychology and exploit common human tendencies such as fear of missing out (FOMO), loss aversion, social proof, and decision fatigue.[1] Consumers under time pressure or faced with confusing choices are more likely to make impulsive decisions that increase the company’s profits.[1]
Common Types of Dark Patterns
The CCPA Guidelines, 2023 identify thirteen recognised dark patterns:[4]
• False Urgency: Businesses create artificial pressure by displaying messages such as “Only two items left” or countdown timers suggesting that an offer will expire within minutes, which may not reflect actual stock levels.[1][4]
• Basket Sneaking: Additional products, insurance plans, donations, or paid services are automatically added to the consumer’s shopping cart without clear consent.[1][4]
• Confirm Shaming: Consumers are made to feel guilty for declining an offer (e.g., replacing “No Thanks” with “No, I don’t want to save money”).[1][4]
• Hidden Costs and Drip Pricing: Mandatory charges such as platform fees, convenience fees, or taxes are revealed only at the final stage of payment.[1][4]
• Subscription Traps: Enabling easy sign-ups while making cancellation unnecessarily complex through multiple steps, phone calls, or confirmation screens.[1][4]
• Interface Interference: Important options (such as declining services) are hidden in small or faded fonts, while the platform’s preferred option is prominently highlighted.[1][4]
• Nagging: Repeated pop-up notifications interrupt browsing to encourage subscriptions, purchases, or data sharing.[1][4]
• Trick Questions: Using confusing phrasing or double negatives to lead consumers into unintentional selections.[1][4]
• False Scarcity and Fake Reviews: Displaying false claims regarding limited inventory or using fake customer reviews to fabricate popularity.[1][4]
• Privacy Zuckering: Tricking consumers into sharing more personal information than necessary through confusing privacy settings or consent prompts.[1][4]
• Disguised Ads, Bait and Switch, Forced Action, SaaS Billing, and Ranking Manipulation: Additional prohibited practices specified under the 2023 Guidelines.[4]
The list provided in the CCPA Guidelines, 2023 is explicitly illustrative, allowing regulators to address emerging forms of digital manipulation as technology continues to evolve.[4]
Real-Life Examples in the Indian Market
Dark patterns are increasingly visible across various digital platforms used by Indian consumers.[1] Although many of these practices have attracted public criticism, they should not be treated as findings of legal liability unless determined by a competent authority.[1]
Large e-commerce platforms such as Amazon and Flipkart have often been criticised for using countdown timers during sales, highlighting limited stock availability, and offering pre-selected protection plans or warranties during checkout.[1] While these features may improve sales, they also raise concerns about whether consumers are making fully informed decisions.[1]
Similarly, online travel booking platforms frequently display messages such as “Only two rooms left at this price” or “Booked five times in the last hour.”[1] Such notifications may encourage consumers to make hurried bookings without comparing prices or considering alternative options.[1]
Food delivery applications have also faced criticism for automatically suggesting tips for delivery partners, adding platform fees, or encouraging donations during the payment process.[1] Although these charges may be legitimate, consumers may overlook them if they are not displayed clearly.[1]
Subscription-based services, including OTT platforms, fitness applications, and software providers, have also been questioned for making subscription cancellation much more difficult than the sign-up process.[1] While users can often subscribe with a single click, cancelling the service may require navigating several pages or contacting customer support.[1]
These examples demonstrate that dark patterns are not confined to one industry.[1] They have become a widespread feature of digital commerce and reinforce the need for effective legal regulation and stronger consumer awareness.[1]
Why Dark Patterns Harm Consumers
Dark patterns affect consumers across financial, psychological, and privacy domains, weakening the fundamental consumer law principle of free and informed choice.[1]
• Financial Loss: Hidden costs, pre-selected add-ons, and recurring subscription charges cause consumers to pay significantly more than original advertised prices.[1]
• Privacy Risks: Confusing privacy settings and pre-selected consent boxes induce users to disclose excess personal data.[1] This presents acute concerns under the Digital Personal Data Protection Act, 2023, which requires explicit, voluntary, and informed consent.[9]
• Impairment of Consumer Autonomy: Artificial urgency and hidden details subvert independent decision-making, invalidating genuine informed consent.[1]
• Psychological Exploitation & Fatigue: Repetitive notifications and countdown timers induce decision fatigue, forcing compliance out of convenience.[1]
• Erosion of Market Trust: Misleading interfaces damage overall consumer trust in the digital marketplace, indirectly harming transparent businesses.[1]
International Position
European Union:
The EU enforces rigorous standards through the General Data Protection Regulation (GDPR), requiring freely given, specific, informed, and unambiguous consent.[5] Furthermore, the Digital Services Act (DSA) explicitly bans online platforms from designing interfaces that deceive, manipulate, or impair user autonomy, regulating platform design itself.[5]
United States:
The Federal Trade Commission (FTC) regulates dark patterns under Section 5 of the FTC Act as unfair or deceptive acts or practices.[6] Significant enforcement actions include proceedings against Amazon (for deceptive Prime subscription enrollment and cancellation barriers) and Epic Games (settled for US$520 million regarding unwanted in-game purchases and child privacy violations).[6][10][11]
United Kingdom:
The Digital Markets, Competition and Consumers Act 2024 grants the Competition and Markets Authority (CMA) direct statutory authority to penalize manipulative online design, fake reviews, and pressure selling.[7]
Australia:
Enforces prohibitions on misleading and deceptive conduct under the Australian Consumer Law, with the Australian Competition and Consumer Commission (ACCC) prioritizing digital interface manipulation.[8]
Lessons for India:
Comparative frameworks demonstrate that India must pair explicit design standards with stringent financial penalties and proactive enforcement to establish true deterrence.[1]
Legal Framework in India
1. Consumer Protection Act, 2019:
Establishes core consumer rights—including the right to be informed, the right to choose, and the right to seek redressal.[2] It prohibits unfair trade practices and misleading advertisements.[2] Section 10 establishes the Central Consumer Protection Authority (CCPA) with statutory powers to investigate violations, direct recalls, and penalize misleading practices.[2]
2. Consumer Protection (E-Commerce) Rules, 2020:
Mandates transparency across e-commerce platforms, requiring explicit price displays, clear vendor identification, transparent fee structures, and structured grievance redressal mechanisms.[3]
3. CCPA Guidelines for Prevention and Regulation of Dark Patterns, 2023:
Issued under Section 18 of the Consumer Protection Act, 2019, these Guidelines apply to all online platforms, marketplaces, advertisers, and sellers offering goods or services to Indian consumers (including foreign entities).[4] Violations qualify as unfair trade practices under the 2019 Act.[2][4] In June 2025, the CCPA issued directives requiring major e-commerce platforms to perform mandatory self-audits and remove identified dark patterns.[1]
Statutory Limitation: The 2023 Guidelines do not prescribe distinct, dedicated monetary penalties for dark pattern infractions, relying instead on general enforcement provisions under the Consumer Protection Act, 2019.[1][2][4]
Landmark Cases and Regulatory Actions
• Google Play Store Billing Investigation: The Competition Commission of India (CCI) penalised Google for anti-competitive billing defaults, demonstrating how platform architecture dictates user choice.[1]
• WhatsApp Privacy Policy Dispute (2021): Examined by the CCI and the Delhi High Court regarding manufactured consent and take-it-or-leave-it digital updates.[1]
• CCPA Enforcement Directives: Broadened proactive scrutiny through mandatory self-audit directives issued to major e-commerce platforms.[1]
• US FTC Enforcement Benchmarks: Action against Amazon Prime’s cancellation flow and Epic Games’ US$520 million settlement illustrate global precedents treating interface design as actionable consumer harm.[6][10][11]
Challenges in Enforcement
• Rapid Technological Evolution: Fast-paced interface developments outpace administrative updates.[1]
• AI Personalization & Dynamic Layouts: Algorithmic interfaces personalize dark patterns individually, complicating evidentiary tracking.[1]
• Cross-Border Jurisdiction: Enforcing compliance against foreign-headquartered digital entities requires international regulatory coordination.[1]
• Digital Literacy & Awareness Gaps: Low consumer recognition of interface manipulation leads to severe underreporting.[1]
• Institutional Technical Constraints: Monitoring extensive digital marketplaces requires specialized forensic tools and increased technical personnel within the CCPA.[1]
• Evidentiary Intent Standards: Proving deliberate design manipulation versus benign user-experience choices often requires internal design records and A/B test logs.[1]
Conclusion
Dark patterns represent a critical regulatory challenge in the digital economy.[1] India has established a foundation through the Consumer Protection Act, 2019,[2] E-Commerce Rules, 2020,[3] and the CCPA Dark Patterns Guidelines, 2023.[4] However, answering whether Indian consumers are truly protected reveals that protection is currently only partial.[1] Moving forward, closing enforcement gaps will require introducing dedicated statutory monetary penalties, building technical forensic capacity within regulatory bodies, monitoring AI-driven personalization, and maintaining active international cooperation.[1]
References
[1] Ishika Garg, Dark Patterns Under Consumer Protection Law: Are Indian Consumers Really Protected? (2026 manuscript text).
[2] Consumer Protection Act, No. 35 of 2019, §§ 2(47), 10, 18 (India).
[3] Consumer Protection (E-Commerce) Rules, 2020, Ministry of Consumer Affairs, Food and Public Distribution (India).
[4] Central Consumer Protection Authority, Guidelines for Prevention and Regulation of Dark Patterns, 2023, Notification F. No. CCPA-1/2023 (Nov. 30, 2023).
[5] Regulation (EU) 2016/679 (General Data Protection Regulation); Regulation (EU) 2022/2065 (Digital Services Act), art. 25.
[6] Federal Trade Commission Act, 15 U.S.C. § 45(a) (Section 5).
[7] Digital Markets, Competition and Consumers Act 2024, c. 13 (UK).
[8] Competition and Consumer Act 2010, Schedule 2 (Australian Consumer Law).
[9] Digital Personal Data Protection Act, No. 22 of 2023 (India).[cite: 6]
[10] FTC v. Amazon.com, Inc., No. 2:23-cv-00938 (W.D. Wash. 2023).[cite: 6]
[11] FTC v. Epic Games, Inc., No. 5:22-cv-00518 (E.D.N.C. 2022).[cite: 6]




