
This article is written by Vrinda Bhardwaj of O.P Jindal Global University, an intern under Legal Vidhiya
Abstract
The digital economy has greatly transformed consumer interactions, moving them from physical marketplaces to intricate digital interfaces. While this transition offers a lot of convenience but it has also gotten “dark patterns” into the picture which are like deceptive user interface designs intended to manipulate users into making choices that weaken their autonomy and often leads to financial or data-related harm. This article explores the conceptual framework of dark patterns, the psychological triggers they exploit and the emerging legal response in India. By analysing the “Guidelines for Prevention and Regulation of Dark Patterns, 2023” issued by the Central Consumer Protection Authority (CCPA), alongside broader provisions of the Consumer Protection Act, 2019, and the Digital Personal Data Protection Act, 2023, this paper argues for a better enforcement mechanism to protect digital sovereignty.
Keywords
Dark Patterns, Consumer Protection, Digital Sovereignty, Indian Jurisprudence, CCPA Guidelines, Deceptive Design, User Autonomy, Data Privacy.
Introduction
Currently the smartphone has become the primary gateway to the global economy. From ordering groceries to managing financial portfolios, these apps dominate daily life to a very great extent. However, the architecture of these digital spaces is rarely neutral. User Interface (UI) and User Experience (UX) design, while intended to facilitate navigation, are increasingly being weaponized through “dark patterns.” These are design choices crafted with the deliberate intention of tricking or misleading users into performing actions they did not intend to take such as signing up for recurring subscriptions, sharing excessive personal data or purchasing unwanted insurance.
The term “dark patterns” was first coined by Harry Brignull in 2010 but the practice has existed in various forms long before the digital age. In the physical world, bait-and-switch tactics or hidden fees were the norm but in the digital realm, these tactics have become sophisticated, data-driven, and basically present everywhere. For the Indian consumer, who is often navigating a rapidly digitising economy with varying levels of digital literacy, these patterns pose a significant threat to financial security and privacy. Recognising this, Indian regulators have recently taken pioneering steps to define and prohibit these practices, aligning Indian consumer law with global standards like the GDPR in Europe and the FTC’s enforcement actions in the United States.
The Psychological Foundations of Deceptive Design
To understand why dark patterns are so effective, one must look at behavioral economics and cognitive psychology. Human beings do not always make rational decisions infact, we rely on “heuristics” or mental shortcuts to navigate complex environments. Dark patterns exploit these shortcuts. For example, the “scarcity bias” makes us value items more if we think they are running out. Applications use “false urgency” timers to trigger this bias, forcing a purchase decision before the user can fully evaluate the terms.
Another common psychological trigger is “default bias.” Most users tend to stick with pre-selected options because changing them requires additional cognitive effort. Tech companies exploit this by pre-ticking boxes for newsletters, data sharing, or even “optional” insurance. By the time the user realises they have agreed to something, the transaction is often complete. This systematic exploitation of human psychology is what makes dark patterns a form of “cognitive hacking,” which goes beyond traditional marketing and enters the realm of coercion.
The Indian Regulatory Framework
Until recently, the Indian legal system lacked a specific definition for dark patterns, relying instead on the broad provisions of the Consumer Protection Act, 2019. Under Section 2(47) of this Act, “unfair trade practices” are prohibited, covering a wide range of deceptive activities. However, as the digital economy matured, it became clear that a more granular approach was needed to handle the specificities of app design.
The CCPA Guidelines of 2023
In late 2023, the Central Consumer Protection Authority (CCPA) issued the “Guidelines for Prevention and Regulation of Dark Patterns.” These guidelines are significant because they transition dark patterns from a vague ethical concern to a specific legal violation. The guidelines apply to all platforms, including e-commerce entities, sellers, and advertisers, ensuring a level playing field across the Indian internet.
The guidelines provide a comprehensive list of prohibited practices. One of the most prevalent is “Basket Sneaking.” This occurs when a platform adds additional items such as a small donation, a service fee, or a protection plan to the user’s cart without their explicit consent. Under the new guidelines, this is a clear violation of consumer rights. Another critical area is “Subscription Traps,” where a company makes it nearly impossible for a user to cancel a recurring payment. This is often achieved by hiding the cancellation button or requiring the user to call a support line that never picks up.
The guidelines also tackle “Confirmshaming.” This is the use of emotive language to make a user feel guilty for opting out of a service. For example, a pop-up might offer a discount with two buttons: “Yes, I love saving money” and “No, I prefer to pay full price.” By framing the rejection in a negative light, the platform manipulates the user’s emotional state to drive a specific outcome. This is a direct violation of the principle of “meaningful consent” which forms the bedrock of Indian consumer law.
Data Privacy and the Digital Personal Data Protection Act (DPDPA)
The intersection of dark patterns and data privacy is addressed through the Digital Personal Data Protection Act, 2023. Many dark patterns are designed to trick users into giving “consent” for data processing. For instance, “confirmshaming” might be used to make a user feel guilty for choosing a private browsing option. The DPDPA mandates that consent must be “free, specific, informed, unconditional, and unambiguous.” If a design pattern uses trickery to obtain data, that consent is legally void. This creates a dual-layer of protection for Indian citizens and the CCPA protects their wallets, and the DPDPA protects their personal information.
Judicial Trends and Precedents in Indian Jurisprudence
Indian courts have historically been protective of consumers, even before the specific dark pattern guidelines were enacted. In various cases, the Supreme Court of India has emphasized that the “right to choose” is a fundamental aspect of consumer rights. While there are fewer cases specifically using the term “dark patterns” in the past, the underlying principles of transparency and fairness have been upheld consistently.
For example, in cases involving the aviation sector, the CCPA has previously cracked down on “pre-ticked” insurance boxes, citing them as a violation of the Consumer Protection Act. Similarly, the judiciary has taken a dim view of hidden charges in hotel bookings which is a practice known as “drip pricing.” These precedents provide the foundation for the strict enforcement of the 2023 Guidelines.
The concept of “Unfair Trade Practices” has been expanded through judicial interpretation to include any digital design that obfuscates terms or hides costs. In the case of Vodafone International Holdings B.V. v. Union of India, the Court highlighted the importance of clear disclosure in commercial transactions. While that case focused on taxation, the principle of “substance over form” is directly applicable to dark patterns and the court looks at the actual impact on the user rather than the technical design justifications provided by the company.
The Role of the Advertising Standards Council of India (ASCI)
Before the CCPA guidelines were notified, the ASCI had already begun drafting guidelines for “Dark Patterns in Advertising.” Their focus was primarily on “Drip Pricing” and “Bait and Switch” tactics. ASCI’s intervention was crucial because it signaled to the industry that self-regulation was no longer sufficient. The current legal landscape in India is now a hybrid of self-regulatory standards and hard law enforcement by the CCPA.
Global Comparisons: Learning from the EU and USA
India’s move to regulate dark patterns does not happen in a vacuum. Globally, there is a growing consensus that “deceptive design” must be checked. The European Union’s Digital Services Act (DSA) and the General Data Protection Regulation (GDPR) provide some of the strictest protections in the world. The EU approach focuses heavily on “privacy by design,” ensuring that the most private setting is always the default.
In USA, the Federal Trade Commission (FTC) has been active in suing companies that use dark patterns. In a famous case against Epic Games, the FTC secured a multi-million dollar settlement over the use of “dark patterns” that tricked players into making unwanted purchases. India’s guidelines mirror many of these global standards but are tailored to the unique challenges of the Indian market, such as the high prevalence of mobile-first users who may not have access to large-screen interfaces where disclosures are easier to read.
The Impact on Small and Medium Enterprises (SMEs)
While large tech companies are the primary targets of these regulations, SMEs in India must also adapt. Many small app developers use third-party “growth hacking” kits that include dark patterns by default. Under the 2023 Guidelines, being unaware that a third-party tool is using deceptive design is not a valid defense. Indian startups must now prioritise “Ethical UX” to avoid heavy penalties and reputational damage. This shift, while challenging in the short term, will ultimately lead to a more sustainable digital ecosystem where users feel safe and valued.
Specific Dark Patterns prohibited in India
1. False Urgency
This involves creating a false sense of scarcity to pressure a purchase. Common examples include “Only 1 item left in stock!” or “Sale ends in 10 minutes!” when neither is true. In India, this is now explicitly prohibited if the urgency is fabricated.
2. Basket Sneaking
As discussed, this is the addition of items or services to a user’s cart without consent. A common Indian context is the automatic addition of “COVID-19 relief donations” or “conveyance fees” that are only visible on the final payment screen.
3. Subscription Traps (Roach Motel)
This makes it easy to get into a situation but hard to get out. The “Cancel Subscription” button might be hidden in a maze of menus, or require the user to print a physical form and mail it. Indian guidelines mandate that cancellation must be as easy as signing up.
4. Drip Pricing
This is the practice of showing a low initial price and then adding multiple fees throughout the checkout process, such that the final price is significantly higher. This is often seen in travel and hospitality apps in India.
5. Interface Interference
This involves design that makes certain actions harder than others. For example, making the “Accept All Cookies” button large an green while making the “Reject All” button small, grey, and hidden behind a “Settings” link.
Challenges in Enforcement and Technical Detection
Despite the robust legal framework, enforcement remains a significant hurdle. Dark patterns are often subtle and can be changed with a few lines of code. Unlike a physical product that can be seised, a deceptive UI can be “A/B tested” and altered in real-time to evade detection. Furthermore, the CCPA must balance regulation with innovation. Excessive policing of UI could stifle creative design that actually helps users.
To overcome these challenges, the CCPA is looking toward “RegTech” (Regulatory Technology). This involves using automated tools to scan apps for known dark patterns. Additionally, public awareness is key. The “Jago Grahak Jago” campaign must be updated to include digital literacy, teaching users how to spot and report “subscription traps” or “false urgency” tactics.
The Road Ahead: Ethical UX as a Competitive Advantage
As consumers become more aware of dark patterns, they are likely to gravitate toward platforms that respect their autonomy. Ethical UX is not just a legal requirement but it is a brand-building exercise. Companies that prioritize transparency will build long-term loyalty, which is far more valuable than the short-term gains from a “subscription trap.”
The future of Indian jurisprudence in this area will likely involve more granular rules for AI-driven interfaces. As generative AI begins to power chatbots and personalized recommendations, the potential for manipulation grows exponentially. The law must evolve from static guidelines to a dynamic oversight framework that can keep pace with the speed of digital innovation.
Conclusion
The regulation of deceptive dark patterns marks a pivotal moment in Indian digital jurisprudence. By moving beyond the broad definitions of the Consumer Protection Act and providing specific, actionable guidelines, India has positioned itself as a leader in digital consumer rights. However, the battle against deceptive design is an ongoing one. As technology evolves with the rise of AI-driven interfaces and voice-activated assistants then new forms of dark patterns will inevitably emerge.
The path forward requires a multi-stakeholder approach. Businesses must adopt “Fairness by Design” principles, regulators must stay technically adept, and consumers must remain vigilant. Protecting the digital sovereignty of the Indian citizen is not just a legal requirement but a prerequisite for a trustworthy and inclusive digital future. The 2023 Guidelines are the first step in a long journey toward an ethical internet.
References
- GLANVILLE WILLIAMS, LEARNING THE LAW 69 (Sweet & Maxwell 2014)2.
- DD BASU, CONSTITUTION OF INDIA 201 (2010)3.
- ALAN REDFERN ET. AL., REDFERN AND HUNTER ON INTERNATIONAL ARBITRATION 211-215 (Kluwer Arbitration 2009)4.
- Vodafone International Holdings B.V. v. Union of India and Anr., (2012) 341 ITR 1 (SC)5.
- Ador Samia Pvt. Ltd. v. Peekay Holdings Ltd., (1998) 8 SCC 5726.
- Guru Nanak Foundation v. Rattan Singh and Sons, AIR 1981 SC 20757.
- Consumer Protection Act, 2019, No. 35, Acts of Parliament, 2019 (India).
- Digital Personal Data Protection Act, 2023, No. 22, Acts of Parliament, 2023 (India).
- Banking Regulation Act, 1949, § 3, No. 10, Acts of Parliament, 1949 (India)8.
- Guidelines for Prevention and Regulation of Dark Patterns, 2023, Central Consumer Protection Authority (India).
- Maharashtra Labour Welfare Fund Act, 1953, § 5, No. 40, Acts of Maharashtra State Legislature, 1953 (India)9.
- INDIA CONST. art. 21.
- INDIA CONST. art. 1, § 9, cl. 210.
- INDIA CONST. art. 269, amended by The Constitution (Eightieth Amendment) Act, 200011.
- David E. Graham, Cyber Threats and the Law of War, 4 J. NAT’L SEC. L. & POL’Y 87, 91 (2010)12.
- Emre Öktem, Turkey: Successor or Continuing State of the Ottoman Empire?, 24 LEIDEN J. INT’L L. 561 (2011)13.
- CENTRAL CONSUMER PROTECTION AUTHORITY, https://consumeraffairs.nic.in (last visited Jan. 16, 2026).
- BEN & JERRY’S HOMEMADE ICE CREAM, http://www.benjerry.com (last visited Oct. 6, 2008)14.
- THE LEGAL BLUEBOOK, https://www.legalbluebook.com/default.aspx15.
Disclaimer: The materials provided herein are intended solely for informational purposes. Accessing or using the site or materials does not establish an attorney-client relationship. The information presented on this site is not to be construed as legal or professional advice, and it should not be relied upon for such purposes or used as a substitute for advice from a licensed attorney in your state. Additionally, the viewpoint presented by the author is personal.