The emergence of ‘dark patterns’ in digital business has led to significant legal scrutiny in India, particularly by the Central Consumer Protection Authority (CCPA). These dark patterns refer to manipulative design strategies in digital environments that influence consumer decision-making by making certain actions more accessible or appealing than others. Typical examples include pre-selected options for donations or memberships, hidden cancellation processes, and misleading price displays that only become apparent at checkout.
The Regulatory Framework
In response to these practices, the CCPA issued the Guidelines for Prevention and Regulation of Dark Patterns, 2023, under Section 18 of the Consumer Protection Act, 2019. These guidelines target platforms offering goods or services online in India, alongside their advertisers and sellers. The guidelines broadly define dark patterns as deceptive design practices that undermine consumer autonomy or impair decision-making, thereby constituting misleading advertisements, unfair trade practices, or violations of consumer rights.
Prohibited Patterns and Enforcement
The CCPA guidelines identify 13 prohibited patterns, including false urgency, basket sneaking, confirm shaming, forced action, subscription traps, interface interference, and drip pricing. The journey from advisory to enforcement has been swift. In June 2025, the CCPA advised online platforms to self-audit their interfaces to eliminate dark patterns and publish compliance declarations. By November 2025, 26 platforms complied. However, self-regulation has shown limited impact, prompting the CCPA to initiate actions against seven platforms, issuing monetary penalties and corrective directions totaling approximately ₹20 lakh.
Patterns of Concern
The CCPA’s enforcement actions have highlighted four main patterns of concern:
- Default Selections and Basket Sneaking: Automatic additions like Zepto’s paid memberships or PhysicsWallah’s pre-selected donations were penalized. A pre-selected option without explicit consumer consent does not count as consent.
- Drip Pricing: Platforms like Zepto and FirstCry were noted for displaying initial prices that increased unexpectedly at checkout, which is considered misleading.
- Confirm Shaming and Visual Hierarchy: McAfee and IndiGo were reprimanded for using emotionally charged language to influence decisions, prompting changes to more neutral messaging.
- False Urgency: Platforms like Anuj Jindal’s coaching service used unsubstantiated urgency tactics, which the CCPA identified as deceiving consumers.
Assessment of Penalties
While the guidelines lack a specific penalty grid, the CCPA aligns its monetary directives with the Consumer Protection Act, allowing penalties up to ₹10 lakh for first-time violations and up to ₹50 lakh for subsequent breaches. Penalties tend to vary based on factors such as the nature and number of patterns used, duration and scale, consumer impact, and the platform’s market position.
Voluntary Remediation
Corrective actions can affect outcomes but do not eliminate liability. For instance, IndiGo and BookMyShow resolved issues through interface changes without financial penalties. However, the CCPA clarifies that remediation does not absolve past violations, as seen in the cases of Zepto and PharmEasy, where changes were considered reactive.
Building a Defensible Program
A robust compliance program should focus on the entire consumer journey, encompassing all stages from acquisition to grievance resolution. Key principles include ensuring optional payments are unselected by default, transparent pricing before commitment, substantiated scarcity claims, and balanced opt-in and opt-out flows.
Conclusion
The penalties imposed so far may not be substantial enough to change corporate behavior on a large scale, but they signify a firm regulatory approach. The CCPA’s transition from advisory to enforcement within 18 months underscores the importance of proactive interface design reviews by compliance teams to prevent regulatory intervention.
For digital businesses in India, the message is clear: ensure that consumer interfaces preserve informed and genuine choices, as the regulatory landscape now closely monitors the consumer journey. Businesses must decide whether to conduct internal reviews or risk regulatory scrutiny.
About the authors: Naresh Pareek is a Partner, Abhishek Nair is an Associate, and Shravan Kalluri is a Consultant at Lex Consult.
Disclaimer: The views expressed in this article are those of the authors and do not necessarily reflect the position of Bar & Bench.
