Assessing India’s Evolving Regulatory Framework on Dark Patterns

 

Dark patterns are increasingly embedded in everyday digital interactions, often steering consumers towards choices they may not otherwise make. India’s regulatory response has evolved from general consumer protection and e-commerce rules to the CCPA’s 2023 Dark Patterns Guidelines, the 2025 self-audit initiative, and the 2026 amendments introducing annual self-audits and compliance certificates. This piece examines that evolution, its emerging enforcement architecture and argues for a more preventive, risk-based approach to digital choice architecture.

 

CONSIDER PLACING AN ONLINE ORDER, booking a movie ticket, or ordering food, and then having a small charitable donation automatically added to your cart without your knowledge or express consent, or when you decide not to buy a travel add-on. A warning has been given saying that “No, I will be taking the risk”. The same platform also informs users that there is a temporary sale at a discounted price or that there are “only a few items left” in stock. These unfair trade practices, which are intentionally designed to sway consumer decisions, are known as “dark patterns.”

In 2010, UX designer Harry Brignull coined the phrase “dark pattern.” In a nutshell, these are deceptive UI design strategies (i.e., how websites and apps are visually presenting choices and interactions to the users) that cause users to perform actions they did not intend to perform. Examples include hiding the cost of some items, making it difficult to cancel a subscription, and automatically adding items to a cart without consent. Even though these practices are common, they usually violate consumer law principles.

The Central Consumer Protection Authority (CCPA) issued the Guidelines for Prevention and Regulation of Dark Patterns, 2023 (“2023 Guidelines”) identifying 13 specified dark patterns and treating such practices within the framework of misleading advertisements, unfair trade practices and consumer rights. In June 2025, the CCPA further advised e-commerce platforms to conduct self-audits to identify and eliminate dark patterns. And more recently, the Consumer Protection (E-Commerce) (Amendment) Rules, 2026 (“2026 Rules”), notified on 09 September 2026, have further moved the issue into the e-commerce compliance framework by mandating e-commerce entities to comply with the 2023 Guidelines, undertake yearly self-audits and prominently display a certificate of compliance. These amendments will come into force on 1 January 2027.

Whether we are working, shopping, or utilizing services, our ability to navigate the digital world depends on the user interface and user experience. Addressing dark patterns is crucial to protecting consumer rights because platforms have more influence over our choices.

Evolution of the regulations for dark patterns in India

In India, there is no single dedicated legislation on Dark Patterns. It has developed incrementally across consumer protection, e-commerce, and data protection law.

The Information Technology Act, 2000, which is India’s first digital law, laid down the principles of electronic transactions and information technology. It did not encapsulate manipulative interface design or deceptive consent practices.

The Consumer Protection Act, 2019 (“CPA 2019”), which replaced the Consumer Protection Act, 1986, addresses the changing consumer landscape, specifically through the lens of the rise of e-commerce and online platforms. This Act reinforced the legislation against unfair trade practices and established an authority i.e, the Central Consumer Protection Authority (“CCPA”), with powers to protect, promote and enforce consumer rights, investigate unfair trade practices and take measures against practices prejudicial to consumer interests. Yet, the law did not fully address the concern that revolves around the dark pattern practices.

Following this, the Consumer Protection (E-Commerce) Rules, 2020 required explicit, affirmative consumer consent and prohibited tactics like pre-ticked checkboxes, which are often associated with dark patterns. The Rules provided an important statutory basis for addressing certain forms of manipulative digital commerce even before dark patterns were expressly identified by the CCPA.

A further layer emerged with the Digital Personal Data Protection Act, 2023. Section 6 provides that consent must be free, specific, informed, unconditional and unambiguous, given through clear affirmative action, and limited to personal data necessary for the specified purpose. The relationship between data-protection consent and dark patterns: a design that formally obtains a “click” may nevertheless raise questions about whether the resulting consent satisfies the statutory requirements of voluntariness, informed choice and affirmative action.

In late November of that year, the CCPA issued the 2023 Guidelines in compliance with Section 18 of the CPA 2019. The CCPA Guidelines list 13 types of dark patterns, as detailed in Annexure 1 of the Guidelines. These regulations are generally applicable to advertisers, sellers, and the platforms that systematically offer goods or services in India.

In June 2025, the CCPA issued an advisory to all e-commerce platforms to comply within three months by conducting a self-audit to identify any troubling or dark patterns, and urged them to make a self-declaration in light of the audit findings. However, the advisory did not address whether the self-audits can be conducted by the platform’s technical team or whether a third-party expert is required. This created ambiguity and implementation problems.

The most recent development is the Consumer Protection (E-Commerce) (Amendment) Rules, 2026, notified on 09 September, 2026. The amended Rules expressly strengthen the e-commerce framework in relation to dark patterns, among other matters, and require e-commerce entities to comply with the 2023 Dark Patterns Guidelines, undertake yearly self-audits, and prominently display a certificate of compliance. The amendments come into force on 1 January 2027.

Therefore, dark pattern regulation is increasingly moving from identifying prohibited interface practices to an ongoing compliance framework. However, whether these formal compliance obligations can translate into effective prevention and accountability depends substantially on their implementation and enforcement.

Enforcement in action

The CCPA’s interventions provide an indication of how the emerging framework has operated in practice. In BookMyShow’s checkout flow, the platform was pre-ticking an extra ₹1 donation to its “BookASmile” charity for every ticket. The CCPA deemed this “basket sneaking” (a prohibited dark pattern) and issued a notice. BookMyShow then changed its UI to give an opt-in choice for donations. Likewise, IndiGo Airlines used guilt-laden wording, “No, I will take the risk,” to shame users away from skipping add-on purchases. After a complaint and a follow-up CCPA intervention, IndiGo neutralised the prompt (“No, I will not add to the trip”) and clarified the one-click “Skip” on seat selection. In both cases, the companies only corrected course after CCPA intervention, as the official press noted, CCPA “issued notices to IndiGo and BookMyShow [and] after intervention, both companies took corrective measures.”

The CCPA’s approach subsequently moved beyond corrective directions towards the imposition of monetary penalties. In June 2026, the CCPA imposed a ₹5 lakh penalty on PhysicsWallah and a ₹1 lakh penalty on McAfee for dark-pattern practices and directed both entities to discontinue practices that affected informed consumer choice. The PhysicsWallah case involved, among other practices, an automatically selected ₹10 donation and emotional messaging associated with retaining the donation, while the McAfee case concerned practices involving fear-based messaging and the absence of a neutral choice. In July 2026, the CCPA imposed a further ₹1 lakh penalty on SpiceJet for deceptive interface practices, including automatic enrolment into its loyalty programme through a pre-ticked checkbox and default consent to promotional communications. In each case, the CCPA relied upon the CPA, the E-Commerce Rules and the 2023 Guidelines.

Most recently, Rapido, a ride-hailing service, was most recently fined ₹10 lakh by the Central Consumer Protection Authority (CCPA) for utilizing misleading dark patterns in its app interface. On the other hand, Namma Yatri took corrective measures and collaborated with authorities, which resulted in the termination of its proceedings without a financial penalty. Rapido was reprimanded by the CCPA for engaging in unfair trade practices, including “interface interference” and “confirm shaming,” by using misleading prompts that forced customers to pay greater prices and tips under the false pretense that drivers would otherwise decline their rides.

These interventions are significant because they demonstrate that the Indian framework has moved beyond merely identifying dark patterns as a regulatory concern. The CCPA has begun using the existing consumer-protection architecture to investigate and penalise concrete instances of manipulative interface design.

At the same time, the relatively limited number of reported enforcement actions means that it remains too early to conclude that India has established a fully preventive enforcement model.

Policy gaps and weaknesses

Despite good intentions, there are gaps that blunt India’s anti-dark-pattern regime:

The 2023 Guidelines identify manipulative practices within the existing consumer-protection framework, and the CCPA has since imposed penalties in individual cases. However, the Guidelines do not create a standalone statutory offence with a separate calibrated penalty structure for dark-pattern violations. This creates uncertainty regarding the precise legal consequences attached to different forms and degrees of dark-pattern conduct. 

The June 2025 Advisory required e-commerce platforms to conduct self-audits within three months and encouraged them to provide self-declarations based on the results of those audits. Further, the subsequent 2026 Rules have moved by requiring platforms to undertake yearly self-audits and prominently display a certificate of compliance, with the amendments coming into force from 1 January 2027. However, the framework still leaves questions concerning the methodology, independence and verification of such audits. The regulatory architecture places responsibility on platforms to identify their own problematic design practices, without establishing a general requirement for independent third-party assessment. This raises questions about whether self-certification alone can provide sufficient assurance where the commercial incentives of a platform may conflict with the objective of identifying manipulative design.

The rules offer no roadmap or support for startups and small sellers. The Advisory offers no roadmap for smaller platforms, startups, or sector regulators. Unlike large platforms, smaller firms may not know where to begin with a dark-pattern audit. Smaller players might risk non-compliance without tailored guidance or capacity-building, which would undermine the goals of fairness and inclusive justice in the digital marketplace.

Dark patterns are not static. The “specified 13 dark patterns” is a start, but what is the process to update or expand it? Without channels for updating the rules, regulators may constantly be chasing yesterday’s tricks. This lag undermines consumer dignity: users deserve that interface fairness is upheld not only today’s tricks but tomorrow’s innovations.

The joint working group

To bolster capacity, the Department of Consumer Affairs constituted a Joint Working Group (“JWG”), comprising members from concerned Ministries, regulators, Voluntary Consumer Organisations and National Law Universities. Its mandate is to examine and take measures, identifying Dark Patterns violations on e-commerce platforms and, at regular intervals, further the information to the Department of Consumer Affairs. The JWG will suggest appropriate awareness programmes for creating awareness amongst the consumers. This is a welcome step for inter-agency collaboration. But its design has limits: industry players, UX experts, or technologists are absent from the composition. The JWG might risk missing practical insights into platform design. The JWG has no enforcement power; it can only suggest fixes. The group might remain a consultative platform rather than a driver of change.

Recommendations

India should supplement mandatory self-audits with a risk-based system of independent review. Because large platforms / entities present material consumer-facing risks. They could be required to undergo periodic independent audits, especially in the cases where there are repeated complaints or previous findings of non-compliance. Mere assessment of the visual interface is not enough but the underlying choice architecture, defaults, consent mechanisms and relevant user journeys. This would complement the annual self-audit requirement introduced through the 2026 Rules.

To motivate startups and smaller e-commerce entities, and support business equality, the Government should develop standardised compliance toolkits, model audit checklists and practical guidance. 

Developing a publicly accessible AI system could help consolidate information concerning dark-pattern advisories, enforcement orders, recurring violations and compliance guidance. Such system could improve transparency and allow consumers, researchers and businesses to understand how the regulatory framework is being applied. 

A multi-perspective approach involving industry, UX and product-design professionals, technologists, behavioural researchers, consumer organisations and digital-rights groups should be followed for future amendments to the Guidelines and related regulatory measures. 

An accessible mechanism should be provided by the e-commerce platforms for reporting suspected dark patterns with appropriate escalation pathways where complaints are unresolved. The mechanism should be designed to capture sufficient information about the relevant interface and transaction without imposing excessive burdens on consumers. This not only helps supplementing regulatory monitoring by providing authorities with information, but also helps identify recurring or newly emerging practices across platforms.

A contemporary regulatory practice for prevention should be encouraged, particularly in higher-risk contexts, where platforms should conduct pre-launch testing of interface changes to determine whether they disproportionately steer users towards outcomes they would not otherwise choose. Such exercise could help in examining factors such as default settings, choice symmetry, cancellation pathways, disclosure prominence and the ease of refusing an option.

Nota Bene

Beyond the need for efficient statutory enforcement, the scheme of dark patterns confronts us to deal with deeper questions of law and design. They are not just marketing tactics but deliberate exploitations of behavioural economics (scarcity bias, loss aversion, default bias) that systematically tilt choice against the user. In legal-philosophical understanding, this rusts the very idea of informed consent, which is a foundational principle in contract law, consumer protection, and modern data protection regimes. Seeing through the lens of digital constitutionalism, manipulative design becomes more than a consumer rights issue; it is a dignity issue, undermining autonomy and hollowing out the freedom to make a meaningful “no.”

Yet regulation here is fraught: the standardisation problem (how to distinguish legitimate persuasion from manipulation), the proof of harm dilemma (micro-harms diffused across millions of users rarely fit cleanly into damages models), and the emerging challenge of algorithmic dark patterns that personalise manipulation, create an enforcement nightmare. Their harms are not evenly distributed: vulnerable groups like children, the elderly, and the digitally less literate are often the easiest targets, making the issue not only one of consumer protection but also of equality and justice in the digital sphere. 

These tensions remind us that the task ahead is about re-imagining digital governance as an architecture that secures autonomy, dignity, and fair choice by design.