

The price shown on a product page rises at checkout. A donation is already selected. Declining an add-on requires the consumer to announce that they will “take the risk." A subscription cancellation is buried three screens deep, behind a prompt asking whether you are “sure you want to miss out.” These may feel like minor irritants. Collectively, they represent a pattern (generally referred as ‘dark patterns’), and increasingly, a legal problem.
Dark patterns are digital choice environments arranged so that one outcome is easier, more prominent or more urgent than another. What was once treated as a user-experience problem has, in India’s expanding e-commerce market, become a consumer-protection concern. As digital transactions increase, so does the sophistication of the consumer journey, where pre-selected defaults, delayed price disclosures, emotionally charged language and repeated prompts combine to steer decisions before the consumer has had the opportunity to make one. The influence is often cumulative: each individual screen may appear superficially defensible, but the journey as a whole can compromise the very autonomy it purports to preserve.
That said, not every nudge is unlawful. A platform may legitimately highlight a popular plan, flag a genuine security risk or recommend a relevant add-on. The threshold question is not whether the interface influences the consumer, but whether it fairly assists a decision or instead misleads, coerces or exploits predictable inattention so that the consumer takes a step they did not intend to take. The Central Consumer Protection Authority’s (CCPA) recent enforcement orders offer the first sustained indication of where that line is being drawn.
The CCPA issued the Guidelines for Prevention and Regulation of Dark Patterns, 2023 (CCPA Guidelines) under Section 18 of the Consumer Protection Act, 2019 (CPA). They apply to platforms systematically offering goods or services in India, as well as to advertisers and sellers operating on such platforms. The Guidelines define dark patterns broadly as any deceptive design practice on a platform that subverts consumer autonomy or impairs decision-making, amounting to a misleading advertisement, unfair trade practice or violation of consumer rights.
The CCPA Guidelines identify 13 prohibited patterns, including false urgency, basket sneaking, confirm shaming, forced action, subscription traps, interface interference and drip pricing.
The trajectory from policy to penalty has been relatively swift. In June 2025, the CCPA issued an advisory directing online platforms to conduct self-audits within 3 months, remove dark patterns from their interfaces and consider publishing self-declarations of compliance. By November 2025, 26 leading platforms had submitted such declarations. The enforcement record, however, suggests that self-regulation has had a limited effect. Since the advisory, the CCPA has initiated action and issued monetary penalties against 7 platforms and corrective directions against two others, collecting approximately ₹20 lakh in aggregate penalties. These are not large sums, but they establish precedent, and the orders themselves reveal a regulator developing a coherent enforcement approach around four recurring patterns of concern.
Default selections and basket sneaking: The most frequently enforced pattern involves pre-selected additions to the consumer’s cart. Zepto’s automatic addition of a paid membership, PhysicsWallah’s pre-selected ₹10 donation to its PW Foundation, PharmEasy’s automatic PLUS membership and BookMyShow’s pre-ticked BookASmile contribution were each treated as basket sneaking. SpiceJet’s pre-ticked enrolment in its loyalty programme and default consent to promotional communications were characterised as forced action and interface interference. The common thread is that a pre-selected default, without a specific affirmative action by the consumer, does not constitute consent.
Drip pricing: Zepto displayed a lower price on the product page before adding handling charges and membership fees at checkout. FirstCry represented prices as tax-inclusive but added GST at the checkout stage. The relevant comparison, as drawn by the CCPA, is not merely between two labels on a single page, but between the price that brought the consumer into the purchase journey and the amount ultimately demanded at the checkout.
Confirm shaming and visual hierarchy: McAfee’s subscription renewal interface offered “Renew Now” or “Accept Risk,” with no neutral and equally prominent route to decline renewal; the decline option appeared in subdued grey while the renewal button was displayed with a prominent red background. IndiGo’s app displayed “No I will take risk” as the opt-out message for an add-on service. PhysicsWallah combined the pre-selected donation with emotionally persuasive messages encouraging users to retain the selection. Following CCPA intervention, these flows were replaced with neutral alternatives. IndiGo, for instance, adopted “No, I will not add it to my trip.”
False urgency: The Anuj Jindal coaching platform used a recurring 24-hour countdown timer and language urging users to claim a free spot. The CCPA treated this as false urgency. The enforcement position is that scarcity claims and urgency signals must be demonstrable and supported by verifiable, current evidence.
In several orders, the CCPA also connected interface design to broader findings of misleading advertising and unfair trade practices, issuing directions under Sections 20 and 21 read with Section 10 of the CPA.
The Guidelines do not contain a standalone penalty grid. The CCPA has anchored its monetary directions to the CPA, which permits penalties of up to ₹10 lakh for a first violation and up to ₹50 lakh for each subsequent violation under Section 21. Published penalties to date range from ₹1 lakh to ₹7 lakh, modest individually, but meaningful as early enforcement markers.
While the orders do not state how penalty quantum is assessed, a collective reading suggests that relevant factors include: (i) the nature and number of patterns deployed; (ii) the duration and scale of deployment; (iii) the number of consumers potentially affected; (iv) the platform’s reach and market position; (v) the monetary impact or revenue connected with the practice; and (vi) the characteristics of the affected consumer class.
Corrective action can influence the outcome, but does not extinguish liability. In the IndiGo and BookMyShow matters, issues were addressed through corrective directions and interface changes without a disclosed monetary penalty. This might suggest that early, voluntary remediation carries weight.
The CCPA, however, has made it clear that this is not a general safe harbour. In Zepto, the CCPA held that subsequent changes could not absolve past violations. In PharmEasy, it described measures adopted only after the issuance of a show-cause notice as reactive and as reinforcing the seriousness of the initial breach.
The principle is straightforward: remediation addresses continuing compliance but does not retrospectively validate a historical violation.
A defensible compliance programme should begin with the consumer journey, not with a checklist of the 13 labels in the Guidelines. Organisations should map the full lifecycle of consumer interaction: acquisition, product display, checkout, consent, renewal, cancellation, refund and grievance, across websites and applications, including logged-in and logged-out states.
Several operational principles emerge from the orders. Optional payments, memberships, donations, insurance and marketing permissions should be unselected by default and accepted only through a specific affirmative action. Unavoidable charges and the basis of the final price should appear before the point of commitment. Scarcity statements and countdown timers should be supported by demonstrable, current evidence. Opt-in and opt-out flows should use neutral language with comparable prominence, and cancellation should not involve materially greater friction than enrolment.
The aggregate penalties collected so far may not change corporate behaviour at scale, but what matters is the evolving pattern of enforcement. The CCPA has moved from advisory to audit to monetary penalty in roughly eighteen months. It has demonstrated that it will penalise even after remediation.
For digital businesses operating in India, the regulatory signal is unambiguous. The interface is not a grey zone. The consumer journey is now within regulatory jurisdiction and the standard not whether each screen, viewed in isolation, contains an accurate disclosure, but whether the journey as a whole preserves an informed and genuine choice. This indicates that the time to evaluate and fix interface design for e-commerce platforms is now, proactively, before regulatory scrutiny occurs.
The direction of enforcement is clear. The question for businesses is whether their interfaces will be reviewed by their own compliance teams first, or by the regulator.
About the authors: Naresh Pareek is a Partner, Abhishek Nair is an Associate and Shravan Kalluri is a Consultant is Lex Consult.
Disclaimer: The opinions expressed in this article are those of the author(s). The opinions presented do not necessarily reflect the views of Bar & Bench.
If you would like your Deals, Columns, Press Releases to be published on Bar & Bench, please fill in the form available here.