Designed to Deceive: From Soft Regulation to Active Enforcement Against Dark Patterns

Published On: 14th August 2026

Authored By: Prisha Chaudhry
O.P. Jindal Global University, Sonipat

INTRODUCTION

Every time a checkout page nudges a shopper toward an option they never chose or a subscription button buries “cancel” three clicks deep, a design decision has quietly overidden a legal one. These manipulative interface choices known as dark patterns sit at an uncomfortable intersection of consumer protection law, data privacy and behavioural design. For years they were treated as a product management problem rather than a legal one. That assumption no longer holds in India.

Since November 2023, when the Central Consumer Protection Authority (CCPA) notified the Guidelines for Prevention and Regulation of Dark Patterns[1], India has steadily built a regulatory architecture around this problem. What sets the last eighteen months apart is not the existence of rules but the willingness to enforce them. Between June 2025 and June 2026 India moved from advisory language asking platforms to audit their own practices to reasoned orders imposing financial penalties on named entities[2]. That shift is genuinely significant and also incomplete, enforcement has begun but its architecture is not yet built to match the scale of the busineses it targets.

UNDERSTANDING DARK PATTERNS

Dark patterns are interface choices deliberately engineered to steer users toward outcomes that serve the platforms comercial interest rather than the users actual intent. They exploit predictable cognitive shortcuts urgency , social pressure decision fatigue ratherthan persuading through fair argument or fairpricing.

Businesses use them because they work. A donation box pre ticked at checkout, a countdown timer that resets on refresh or a decline button dressed up in guilt all measurably increase conversion at the cost of informed consent. India’s 2023 Guidelines list thirteen such practices[3]. The ones that come up most often in enforcement are false urgency (manufacturing artificial scarcity) basket sneaking (adding charges at checkout nobody asked for), subscription traps (making cancellation for harder than signing up ever was), confirm shaming(language that guilts a user out of opting out) and interface interference (giving one choice more visual weight than the other). Each replaces genuine consumer choice with design manipulation which is exactly the harm consumer protection law was writtenTo stop.[4]

INDIAS LEGAL FRAMEWORK

The regulatory foundation predates the 2023 Guidelines. Section 2(47) of the Consumer Protection Act 2019 (CPA) defines “unfair trade practice” broadly enough to capture deceptive digital design and Section 18 gives the CCPA set up under Section 10 power to issue guidelines preventing such practices[5]. The Consumer Protection (E Commerce) Rules 2020 supplied an earlier still operative layer: Rule 4 (9) requires consumer consent to be secured through clear, affirmative action, ruling out default or pre ticked options.[6]

The CCPA notified the Guidelines for Prevention and Regulation of Dark Paterrns on 30 November 2023[7] and India became one of the first jurisdictions anywhere to treat dark patterns as a distinct regulatory category rather than folding them into general advertising or privacy law. The Guidelines apply broadly covering ecommerce entities, advertisers, sellers and service providers and Annexure 1 lists the thirteen specified practices discussed above[8]. Enforcement stayed sparse for roughly eighteen months after notification with isolated suo motu notices such as one against IndiGo Airlines in June 2024 over confirm shaming language, the exception rather than the rule[9].

RECENT LEGAL DEVELOPMENTS: FROM ADVISORY TO ORDER

The turning point came on 5 June 2025. After a high level stakeholder meeting convened by the Department of Consumer Afairs the CCPA issued a formal Advisory directing every ecommerce platform to audit its own practices within 90 days, flag any dark patterns found and file declarations confirming compliance[10]. The Advisory ran through 31 December 2026 and was framed as interpretive of the 2023 Guidelines rather than a standalone instrument, letting the CCPA argue it carried the same statutory backing as the Guidelines themselves even though it set out no penalty structure of its own[11].

That audit mandate changed the compliance conversation inside Indian digital businesses. Compliance was no longer a background risk flagged during a periodic review and it became a filing obligation with a public deadline. The results exposed the limits of letting platforms mark their own homework, by early 2026, only 23 major platforms had filed declarations at all[12], some months after the window had closed and independent audits by LocalCircles found that most, Amazon included, still showed the very practices their declarations claimed to have removed[13]. The CCPA responded with clarification notices to fifteen platforms in late November 2025 for continuing to fall short despite what their declarations said[14].

The june 2026 orders began closing that gap. On 1 June 2026, in Case No. CCPA-2/94/2025 – CCPA, the CCPA held PhysicsWallah Limited liable for basket sneaking (a Rs.10 Donation pre selected at checkout), confirm shaming and forced dat collection tied to courses marketed as free, imposing a Rs. 5 lakh penalty and noting that a large share of the platform’s users are students, including minors[15]. A parallel order the same week penalised McAfee Software India Private Limited Rs.1 lakh over a subscription renewal interface offering users a choice between “Renew Now” and “Accept Risk”, language the CCPA found manufactured unjustified fear while giving disproportionate visual weight to renewal[16].

What matters about both orders is less their size than their reasoning. The PhysicsWallah order set out for the first time with real depth that liability for dark patterns turns on the cumulative effect of an interface’s design choices on consumer autonomy rather than the financial harm caused[17] and that Rule 4(9) demands affirmative , informed consent not mere technical disclosure[18]. The framework is also spreading across sectors: in April 2026 the IRDAI directed every regulated entity selling insurance through digital platforms to comply with the 2023 Guidelines after a LocalCircles survey found 80 percent of respondents had trouble canceling their policies[19]. Dark patterns regulation in India is no longer confined to ecommerce checkout pages, it is becoming a general expectation for consumer facing digital interfaces across regulated industries.

CRITICAL ANALYSIS

India has not fuly transitioned from soft regulation to active enforcement so much as it has begun to. The PhysicsWallah and McAfee orders are real adjudicated findings with reasoned analysis behind them, not mere advisories and that counts as a meaningful institutional development[20]. But the penalties, Rs. 5 lakh and Rs. 1 lakh are trivial next to the revenues of the platforms concerned. A fine a business can absorb as an immaterial line item does not function as a deterrent at best, it is the cost of occasionally getting caught. Until the penalty regime is recalibrated, whether through a statutory amendment linking penalties to turnover or more aggressive use of existing powers to order broader corrective disclosures, enforcement risks staying symbolically important while remaining practically marginal[21].

The audit and declaration model raises a related concern. Asking platforms to certify their own compliance with no standardised methodology no independent verification and no credible penalty for a false declaration, invites exactly the outcome that followed : widespread non compliance dressed up as compliance[22]. The LocalCircles findings on Amazon make the point well, since Amazon had filed a declaration, the paperwork existed, the conduct had not changed[23]. A regulator relying on voluntary self policing is in effect asking the regulated to grade their own exam.

There is also a coordination gap worth flagging. The Digital Personal Data Protection Act 2023 sets its own consentstandard requiring consent to be free, specific, informed and unambiguous overlapping heavily with what the CCPA is worried about when it talks about manipulated consent[24]. The DPDP Act remains only partially operational, though and nothing currently links the Data Protection Board to CCPA enforcement in any structured way, leaving a single flawed interface capable of trigering paralel proceedings under two regimes that do not talk to each other. Set against mid 2025 when the Advisory carried no enforcement teeth at all, two reasoned penalty orders by June 2026 still mark genuine progress. But progress is not sufficiency and the deterrent value stays limited until penalties are scaled to match the businesses being regulated.

THE BUSINESS AND COMPLIANCE PERSPECTIVE

For in house legal teams and compliance officers, dark patterns review can no longer sit exclusively with product or deign teams. The PhysicsWallah order shows that the CCPA will look past a platform’s stated intent (its donation mechanism was framed as charitable) and examine the actual consent architecture placed in front of the user[25]. Legal and compliance functions need to sit inside product design review from the start rather than auditing interfaces after launch.

Three practical implications follow. Checkout and cancellation flows deserve the scrutiny once reserved for contractual terms since the CCPA treats interface asymmetry making “accept” easier to find than “decline” as substantively equivalent to a coercive contract term[26]. Declarations filed with the regulator are not a formality either, given the CCPA’s willingness to send clarification notices to platforms whose filings do not match their actual interfaces[27]. Design teams need internal guidance translating the thirteen specified dark patterns into concrete rules since a phrase like “interface interference” is legally meaningful but not obviously actionable without translation. Businesses across sectors should also expect regulators, following IRDAI’s lead to adopt the CCPA’s framework independently exposing a single non compliant pattern to more than one authority at once[28].

COMPARATIVE PERSPECTIVE: THE EU AND THE UNITED STATES

India’s approach is worth reading against two more mature regulatory traditions. The European Union addresses dark patterns mainly through the GDPR and the Digital Services Act[29]. The European Data Protection Board’s guidelines link deceptive design to consent violations[30] and the Court of Justice’s Planet49 decision established that consent boxes checked in advance for the user are invalid[31]. The EU’s approach is built around consent and anchored in privacy law, reinforced by a penalty structure that scales with turnover, supplying exactly the deterrent scale India’s framework currently lacks.

The United States relies instead on the federal trade commission’s general section 5 authority over unfair or deceptive practices[32], supplemented by targeted actions such as FTC’s case against Amazon over its prime cancellation flow[33]. The American model is more fragmented and litigation driven than the European one, but the FTC settlements have historically carried far larger consequences than anything India has ordered so far[34].

India’s framework borrows the EU’s instinct to define dark patterns explicitly and the American instinct to proceed case by case but has neither the EU’s penalty scale nor the depth of case law the US has built up. That hybrid position allows for flexibility but will only mature once it develops either the penalty architecture of one or the precdential depth of the other.

FUTURE OUTLOOK

 The trajectory points toward three developments in the near term: further sectoral extension, following IRDAI’s example[35], into banking, travel and edtech, given how much concern the CCPA has shown for platforms with vulnerable or younger users, renewed pressure for self declaration to be replaced or supplemented by independent audit requirements, given the gap already opened up between filed declarations and actual conduct[36] and hardest of all, AI driven personalisation which is likely to produce a new generation of dark patterns, urgency messages generated on the fly, persuasion tailored to the individual user, that the current list of thirteen practices was never drafted to anticipate.

CONCLUSION

India’s dark patterns framework has travelled further in three years than most comparable regimes managed in a decade: a defined taxonomy in 2023, an advisory experiment in self regulation in 2025 and reasoned enforcement orders by 2026[37]. That is a genuine achievement and deserves to be recognised as one. But the PhysicsWallah and the McAfee orders are a beginning not a culmination. A regulatory regime is only as credible as its worst case consequence for a well resourced repeat offender and on that measure India’s penalty architecture still asks very little of the platform it targets[38]. What gets written next will not come from new guidelines but from whether the CCPA makes non compliance genuinely costly and whether businesses start treating consumer trust as a design principle rather than a litigation risk managed after the fact.

REFERENCES

[1] Central Consumer Protection Authority, Guidelines for Prevention and Regulation of Dark Patterns (30 November 2023).

[2] Press Information Bureau, Ministry of Consumer Affairs, Food & Public Distribution, ‘CCPA Acts Against Dark Patterns on Digital Platforms’ (3 June 2026).

[3] Guidelines for Prevention and Regulation of Dark Patterns (n 1) annex 1.

[4] Consumer Protection Act 2019, s 2(47).

[5] Consumer Protection Act 2019, ss 10, 18.

[6] Consumer Protection (E-Commerce) Rules 2020, r 4(9).

[7] Central Consumer Protection Authority, Guidelines for Prevention and Regulation of Dark Patterns (30 November 2023).

[8] Guidelines for Prevention and Regulation of Dark Patterns (n 7) annex 1.

[9] Central Consumer Protection Authority, Notice to IndiGo Airlines (19 June 2024).

[10] Central Consumer Protection Authority, Advisory in terms of the Consumer Protection Act, 2019 on Self-Audit by E-Commerce Platforms for Detecting Dark Patterns, CCPA-1/1/2023-CCPA (5 June 2025).

[11] ibid.

[12] Ministry of Consumer Affairs, Government of India, Platform Self-Declaration Filings under the CCPA Advisory dated 5 June 2025 (data as of February 2026).

[13] LocalCircles, Dark Pattern Compliance Audit of E-Commerce and Quick-Commerce Platforms (January 2026).

[14] Central Consumer Protection Authority, Clarification Notices to Fifteen Digital Platforms (24–28 November 2025).

[15] Central Consumer Protection Authority v PhysicsWallah Ltd, Case No CCPA-2/94/2025-CCPA, Order dated 1 June 2026.

[16] Central Consumer Protection Authority, Order against McAfee Software India Pvt Ltd (1 June 2026).

[17] Central Consumer Protection Authority v PhysicsWallah Ltd (n 15).

[18] Consumer Protection (E-Commerce) Rules 2020, r 4(9); Central Consumer Protection Authority v PhysicsWallah Ltd (n 15).

[19] Insurance Regulatory and Development Authority of India, Press Release directing compliance with CCPA Dark Patterns Guidelines by Insurance E-Platforms (April 2026); LocalCircles, Representation on Dark Patterns in Insurance Platforms (18 March 2026).

[20] Central Consumer Protection Authority v PhysicsWallah Ltd (n 15); Central Consumer Protection Authority, Order against McAfee Software India Pvt Ltd (n 16).

[21] Central Consumer Protection Authority v PhysicsWallah Ltd (n 15); Central Consumer Protection Authority, Order against McAfee Software India Pvt Ltd (n 16).

[22] Central Consumer Protection Authority, Advisory in terms of the Consumer Protection Act, 2019 on Self-Audit by E-Commerce Platforms for Detecting Dark Patterns, CCPA-1/1/2023-CCPA (5 June 2025).

[23] LocalCircles, Dark Pattern Compliance Audit of E-Commerce and Quick-Commerce Platforms (n 13).

[24] Digital Personal Data Protection Act 2023.

[25] Central Consumer Protection Authority v PhysicsWallah Ltd (n 15).

[26] Consumer Protection (E-Commerce) Rules 2020, r 4(9); Central Consumer Protection Authority v PhysicsWallah Ltd (n 15).

[27] Central Consumer Protection Authority, Clarification Notices to Fifteen Digital Platforms (n 14).

[28] Insurance Regulatory and Development Authority of India, Press Release directing compliance with CCPA Dark Patterns Guidelines by Insurance E-Platforms (n 19).

[29] Regulation (EU) 2016/679 (General Data Protection Regulation) [2016] OJ L119/1; Regulation (EU) 2022/2065 (Digital Services Act) [2022] OJ L277/1.

[30] European Data Protection Board, Guidelines 03/2022 on Deceptive Design Patterns in Social Media Platform Interfaces (14 February 2023).

[31] Bundesverband der Verbraucherzentralen und Verbraucherverbände – Verbraucherzentrale Bundesverband eV v Planet49 GmbH (Case C-673/17) EU:C:2019:801.

[32] Federal Trade Commission Act 1914, 15 USC § 45.

[33] Federal Trade Commission, Amazon.com, Inc. (Prime Cancellation Complaint) (2023).

[34] Central Consumer Protection Authority v PhysicsWallah Ltd (n 15); Central Consumer Protection Authority, Order against McAfee Software India Pvt Ltd (n 16).

[35] Insurance Regulatory and Development Authority of India, Press Release directing compliance with CCPA Dark Patterns Guidelines by Insurance E-Platforms (April 2026).

[36] LocalCircles, Dark Pattern Compliance Audit of E-Commerce and Quick-Commerce Platforms (n 13).

[37] Central Consumer Protection Authority, Advisory in terms of the Consumer Protection Act, 2019 on Self-Audit by E-Commerce Platforms for Detecting Dark Patterns (n 10); Central Consumer Protection Authority v PhysicsWallah Ltd (n 15); Central Consumer Protection Authority, Order against McAfee Software India Pvt Ltd (n 16).

[38] Central Consumer Protection Authority v PhysicsWallah Ltd (n 15); Central Consumer Protection Authority, Order against McAfee Software India Pvt Ltd (n 16).

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top