From “Only 2 left!” to hidden checkout charges - when does clever UI become an unlawful consumer practice?
We have all encountered them.
“Only 2 rooms left!”
“Your cart is waiting!”
“No, I will take the risk.”
“Add protection for just Rs. 49.”
“Rs 199” - and then suddenly the final payable amount becomes Rs. 247.
These may look like ordinary marketing or interface decisions. But when the design is deliberately structured to mislead, manipulate, pressure or impair a consumer's ability to make a free and informed choice, Indian consumer law can treat the conduct as a dark pattern.
The regulatory framework is now well established through the Guidelines for Prevention and Regulation of Dark Patterns, 2023, issued by the Central Consumer Protection Authority (CCPA) under Section 18 of the Consumer Protection Act, 2019.
And enforcement is no longer merely theoretical.
The CCPA has moved from warnings and advisories to actual monetary penalties, including Rs. 7 lakh against Zepto, Rs. 5 lakh against PhysicsWallah, Rs. 1 lakh against McAfee and Rs. 1 lakh against SpiceJet in different dark-pattern matters.
The 2023 Guidelines define dark patterns as practices or deceptive design patterns using user-interface or user-experience interactions on a platform that are designed to:
In simple words:
The important legal idea is therefore consumer autonomy.
A company is not prohibited from persuading consumers to purchase its product.
It becomes problematic when the interface crosses the line from persuasion to manipulation.
The Guidelines apply to:
| Covered person/entity | Application |
|---|---|
| Platforms | Platforms systematically offering goods or services in India |
| Advertisers | Advertisers covered under the applicable consumer-protection framework |
| Sellers | Sellers operating through the relevant platforms |
| E-commerce entities | Particularly relevant to online purchasing journeys |
| Digital interfaces | Websites, applications and other platform interfaces |
The prohibition is broad:
No person, including any platform, shall engage in any dark-pattern practice.
The Guidelines further state that where the same conduct is regulated under another law, the Dark Pattern Guidelines operate in addition to, and not in derogation of, that law.
That is important because dark-pattern compliance cannot be viewed in isolation from the Consumer Protection Act, E-Commerce Rules, Legal Metrology framework, advertising regulations and other applicable laws.
The Annexure to the 2023 Guidelines identifies 13 specified dark patterns.
| No. | Dark Pattern | What does it legally mean? | Typical example | What is the consumer being manipulated into doing? |
|---|---|---|---|---|
| 1 | False Urgency | Creating a false sense of urgency or scarcity to push immediate action or purchase | “Only 2 rooms left!” when the representation is false or misleading | Purchase immediately instead of evaluating alternatives |
| 2 | Basket Sneaking | Adding products, services, donations or payments to the cart without consumer consent | Travel insurance automatically added while booking a flight | Paying for something never consciously selected |
| 3 | Confirm Shaming | Using fear, shame, ridicule or guilt to influence the consumer's decision | “No, I will stay unsecured” when declining insurance | Purchasing an add-on to avoid feeling irresponsible |
| 4 | Forced Action | Making an unrelated action compulsory to obtain the originally intended product/service | Requiring newsletter subscription to buy a product | Giving information or buying/subscribing to something unnecessary |
| 5 | Subscription Trap | Making subscription cancellation impossible, hidden, confusing or unnecessarily difficult | “Cancel subscription” buried under multiple screens | Remaining subscribed because cancellation is difficult |
| 6 | Interface Interference | Designing the interface so that one option is visually prominent while another relevant option is obscured | Large bright “Renew Now” button but tiny grey “Close” button | Selecting the option preferred by the platform |
| 7 | Bait and Switch | Advertising one outcome but deceptively providing another | Cheap product shown as available, but replaced with an expensive alternative at purchase | Continuing the transaction despite changed terms |
| 8 | Drip Pricing | Revealing price components late, surreptitiously or after the consumer has progressed through the purchase | Rs. 999 shown initially, mandatory charges appearing only at checkout | Proceeding based on an artificially low initial price |
| 9 | Disguised Advertisement | Presenting advertisements as ordinary content, reviews, editorial material or user-generated content | Paid promotion presented like a normal article/recommendation | Clicking or trusting an advertisement without realising it is an advertisement |
| 10 | Nagging | Repeated, persistent interruptions asking the user to take a commercially beneficial action | Repeated requests to download the app or enable notifications | Accepting simply to stop repeated interruptions |
| 11 | Trick Question | Using confusing, vague, double-negative or misleading wording | “Do you wish to opt out of receiving updates forever” with confusing buttons | Selecting an option different from the consumer's actual intention |
| 12 | SaaS Billing | Recurring billing practices designed to obtain payments surreptitiously in subscription/SaaS models | Free trial silently converts into paid subscription | Paying recurring charges without meaningful awareness |
| 13 | Rogue Malware | Using ransomware/scareware or similar tactics to falsely suggest a device has a virus and induce payment | Fake “Your computer is infected” alert followed by paid malware-removal software | Paying for a fake solution or downloading malicious software |
The important point is that the Annexure itself says these illustrations are guidance and are not to be treated as a binding interpretation for every possible factual situation.
That means:
Imagine a hotel-booking website displays:
“Only 2 rooms left!”
and
“30 people are viewing this property right now.”
If these statements are false or presented without appropriate context, the consumer may believe that immediate booking is necessary.
This is not merely aggressive marketing.
The legal question becomes:
Was the urgency/scarcity representation genuine, or was it manufactured to distort the consumer's decision?
A genuine limited-stock statement is not automatically unlawful.
A false or misleading scarcity/urgency representation can become a dark pattern.
This is perhaps one of the easiest dark patterns for consumers to understand.
Suppose you purchase a flight.
You select:
Flight Fare - Rs. 4,500
But at checkout you discover:
Travel Insurance - Rs. 299
already selected.
You never consciously chose it.
That is the classic problem addressed by Basket Sneaking.
The Guidelines specifically recognise automatic addition of paid ancillary services and travel insurance as illustrations.
The Department of Consumer Affairs reported that the CCPA found an additional Rs. 1 per ticket contribution towards BookMyShow's BookASmile initiative being automatically added through a pre-ticked option without consumer consent.
The CCPA treated this as Basket Sneaking.
Following CCPA intervention, the platform changed the interface to provide consumers with a choice regarding the contribution.
Charity is voluntary.
Even a socially beneficial contribution cannot be made mandatory through a pre-selected option merely because the purpose is charitable.
This is where psychology enters the legal analysis.
Suppose you are booking a flight and decline insurance.
Instead of simply saying:
“No, thanks.”
the platform says:
“No, I will take the risk.”
The problem is not merely the words.
The problem is that the wording makes the consumer feel that declining the product is irresponsible.
The CCPA had issued notice to InterGlobe Aviation/IndiGo concerning alleged Confirm Shaming and lack of transparent communication regarding seat assignment.
After intervention, IndiGo changed the wording to a more neutral:
“No, I will not add to the trip.”
The Government specifically reported this as an example of action taken against a dark-pattern concern.
The regulator is not saying:
“You cannot sell insurance.”
It is saying:
“You cannot psychologically shame the consumer into buying it.”
Suppose you want to buy a Rs. 500 product.
The platform says:
“Enter your Aadhaar details to continue.”
But Aadhaar information is not necessary for that purchase.
Or:
“Subscribe to our newsletter before you can complete the purchase.”
Or:
“Download another unrelated application before you can access the service.”
This raises the question:
If not, it may amount to Forced Action.
The 2023 Guidelines specifically contemplate situations involving unnecessary personal information, unrelated subscriptions/apps and unnecessarily difficult privacy settings.
The consumer can subscribe in:
But cancellation requires:
That is precisely the type of consumer journey regulators are concerned about.
The Guidelines cover:
If subscribing is easy, cancellation should not be deliberately made disproportionately difficult.
This is where the legal analysis becomes particularly interesting.
Two choices are available:
RENEW NOW
and
CANCEL
But:
Technically, both options exist.
But practically, the interface is designed to favour one.
That is the essence of Interface Interference.
“Was the cancellation button available?”
It is:
“Was the interface designed in a way that materially distorted the consumer's ability to exercise that choice?”
Imagine:
Laptop Rs 39,999 — Available Now
You spend 15 minutes entering your details.
At checkout:
“Product unavailable.”
Then:
“Similar model Rs. 47,999.”
If the initial representation was deliberately used to attract the consumer and the promised outcome was deceptively substituted, the conduct can fall within Bait and Switch.
This is one of the biggest compliance risks for e-commerce businesses.
Consider:
| Stage | Price shown |
|---|---|
| Product page | Rs. 999 |
| Cart | Rs. 999 |
| Checkout | Rs. 999 |
| Handling fee | Rs. 49 |
| Platform fee | Rs. 20 |
| Other mandatory charge | Rs. 30 |
| Final price | Rs. 1,098 |
The consumer was attracted into the transaction based on Rs. 999.
The additional mandatory charges appeared later.
That is the basic concern behind Drip Pricing.
The Guidelines expressly cover situations where price components are not revealed upfront or are revealed surreptitiously within the user experience.
Suppose a website displays:
“Top 5 smartphones recommended by experts”
but the content is actually paid promotional material and this fact is concealed.
The consumer thinks:
“This is independent editorial content.”
But it is actually advertising.
That can become a Disguised Advertisement.
The Guidelines also link this concept with the broader framework governing misleading advertisements.
You click:
“No, thanks.”
The website asks again.
You click:
“No.”
Again:
“Download our app!”
Again:
“Turn on notifications!”
Again:
“Share your phone number!”
At some point, the consumer may simply accept because they are tired of rejecting the request.
That is the behavioural problem addressed by Nagging.
Consider:
“Do you wish to opt out of receiving our updates and discounts forever?”
Options:
YES, I WOULD LIKE TO RECEIVE UPDATES
NOT NOW
This is deliberately confusing.
The consumer is not being presented with a clean:
YES / NO
choice.
The Guidelines therefore specifically recognise confusing wording, double negatives and similar linguistic tricks.
You sign up for:
7-day FREE TRIAL
But:
The Guidelines recognise this type of recurring billing concern as SaaS Billing.
This becomes especially important for:
This is the most technically serious category.
A website displays:
YOUR COMPUTER IS INFECTED!
Then:
“Pay Rs 2,999 to remove the virus.”
But the alleged virus does not exist.
Worse, the “removal tool” itself installs malware.
That is the type of deceptive practice addressed under Rogue Malware.
This is where businesses often misunderstand the Guidelines.
For example:
does not automatically establish a dark pattern.
The regulatory question is whether the design misleads, tricks, manipulates, impairs autonomy or distorts consumer choice, in a manner falling within the applicable legal framework.
Zepto is one of the most important recent examples.
The CCPA imposed a Rs. 7 lakh penalty on Zepto in December 2025.
The major findings concerned:
Mandatory charges were disclosed late in the purchase journey rather than being transparently presented upfront.
Paid services/add-ons, including Zepto Pass, were allegedly added without proper affirmative consumer consent.
The CCPA directed corrective action, including upfront disclosure of charges and discontinuation of the identified dark patterns.
The case is particularly significant because Zepto had submitted a self-declaration stating that its platform did not deploy dark patterns. The subsequent CCPA enforcement demonstrated that a self-declaration does not immunise a company from regulatory scrutiny.
The CCPA's order against PhysicsWallah is another important development.
The CCPA found multiple problematic interface practices, including:
The penalty imposed was Rs. 5 lakh.
The particularly important legal development was the CCPA's approach to corrective action.
“We have fixed the interface now, therefore there is no violation.”
The CCPA's approach, as analysed in the subsequent legal commentary, was that post-facto correction does not necessarily extinguish liability for conduct that already occurred.
This is an extremely important compliance lesson.
In the case involving McAfee, the CCPA examined the subscription-renewal interface.
The interface allegedly presented choices such as:
while the close/exit option was less prominent.
The CCPA's analysis identified concerns relating to:
The penalty was Rs. 1 lakh.
Because it shows that dark patterns are not limited to e-commerce checkout pages.
They can arise in:
This is one of the newest examples.
The CCPA imposed a Rs. 1 lakh penalty on SpiceJet for deceptive design practices on its flight-booking platform.
The regulator found that:
Consumers were automatically enrolled into the SpiceClub loyalty programme through a pre-ticked checkbox.
A default option for promotional messages was also already selected, without the consumer taking affirmative action.
The CCPA held that this violated consumer-protection requirements, including Rule 4(9) of the Consumer Protection (E-Commerce) Rules, 2020, as well as the Dark Pattern Guidelines.
The CCPA also directed SpiceJet to discontinue the identified practices and maintain corrective measures.
Silence or default selection is affirmative consent.
BookMyShow is another useful case study.
The issue was not that charity itself was unlawful.
The issue was:
The consumer did not affirmatively choose the donation.
An additional Rs. 1 per ticket was automatically added towards BookASmile.
This was treated as Basket Sneaking.
Following regulatory intervention, BookMyShow changed the interface to allow the consumer to decide whether to contribute.
A good intention does not cure a defective consent mechanism.
The IndiGo case demonstrates Confirm Shaming.
The consumer was presented with language that effectively suggested:
If you do not purchase the additional protection, you are taking a risk.
The problem was therefore psychological pressure rather than simply the availability of the add-on.
After CCPA intervention, the wording was changed to a neutral formulation.
This requires an important correction before publishing an article.
“CCPA has penalised nine platforms for dark patterns.”
unless you are referring to a specific verified set of nine orders and each order has been independently established as a dark-pattern penalty.
The CCPA's official order database currently contains many different types of consumer-protection orders. For example, it lists dark-pattern matters involving PhysicsWallah and McAfee, while other orders involve completely different issues.
The January 2026 Rs. 44 lakh enforcement action is a particularly good example of why the distinction matters.
It involved multiple e-commerce platforms and unauthorised walkie-talkie listings, rather than being a nine-platform dark-pattern penalty.
Therefore, for a legally accurate LegalMantra article, the better headline would be:
“CCPA Intensifies Dark Pattern Enforcement: Zepto, PhysicsWallah, McAfee and SpiceJet Penalised; BookMyShow and IndiGo Also Face Regulatory Action”
That is much safer legally and factually.
| Date | Entity | Regulatory action | Core issue |
|---|---|---|---|
| 19 June 2024 | IndiGo | CCPA order/intervention | Confirm Shaming; seat-selection transparency |
| 2024–25 | BookMyShow | CCPA intervention | Basket Sneaking - Rs. 1 BookASmile donation |
| April 2025 | Zepto matter listed by CCPA | Regulatory proceedings | Dark-pattern/consumer protection matter |
| June 2025 | CCPA | Industry-wide advisory | Platforms directed to conduct self-audits |
| Dec. 2025 | Zepto | Rs. 7 lakh penalty | Drip Pricing + Basket Sneaking |
| May 2026 | McAfee | Rs. 1 lakh penalty | Confirm Shaming + Trick Question + Interface Interference |
| June 2026 | PhysicsWallah | Rs. 5 lakh penalty | Basket Sneaking + Confirm Shaming + Forced Action etc. |
| July 2026 | SpiceJet | Rs. 1 lakh penalty | Pre-ticked loyalty enrolment + promotional consent |
| 2026 | Multiple other CCPA matters | Various orders | Not all are dark-pattern cases |
The CCPA's official order database confirms the continuing expansion of consumer-protection enforcement.
In June 2025, the CCPA advised e-commerce platforms and online service providers to conduct mandatory self-audits to identify and eliminate dark patterns.
The advisory emphasised:
A number of major platforms subsequently submitted self-audit declarations, including Zepto, Flipkart, Myntra, MakeMyTrip, BigBasket, Swiggy, Zomato, Blinkit and Meesho.
But Zepto's later penalty is particularly instructive:
From a corporate compliance perspective, dark-pattern compliance should not be treated as merely an IT/UI issue.
It should be a cross-functional compliance exercise involving:
| Function | Responsibility |
|---|---|
| Legal/Compliance | Map applicable laws and identify prohibited practices |
| Company Secretary | Board-level governance, regulatory reporting and compliance oversight where applicable |
| Product Team | Review consumer journey and business logic |
| UX/UI Team | Ensure neutral presentation of choices |
| Marketing | Verify urgency, scarcity, discount and promotional claims |
| Finance | Verify pricing and additional charges |
| Data/Privacy Team | Review consent and personal-data collection |
| Customer Support | Ensure cancellation/refund journeys are not artificially obstructed |
| Internal Audit | Periodic testing and documentation |
| Management/Board | Establish accountability and monitoring |
Before launching or modifying a consumer-facing interface, companies should ask:
Is the complete mandatory price visible upfront?
Are handling/platform/service charges disclosed before commitment?
Can the final payable amount materially differ from the initially represented amount?
Are all paid add-ons genuinely opt-in?
Are checkboxes unticked by default where affirmative consent is required?
Is promotional communication based on valid consent?
Is cancellation as accessible as subscription?
Are renewal terms clearly disclosed?
Are consumers appropriately informed before recurring charges?
Are “Accept” and “Reject” choices presented neutrally?
Is any option deliberately obscured?
Is colour, font size or placement being used to steer the consumer?
Is “Only 2 left” factually accurate?
Is “sale ends tonight” genuinely time-limited?
Are recommendations actually advertisements?
Is personal information genuinely necessary?
Are users being forced to provide unnecessary information?
Are privacy settings easy to understand and modify?
Has the interface been legally reviewed?
Is there an audit trail?
Are periodic dark-pattern audits conducted?
Are corrective actions documented?
The emerging regulatory approach can be summarised in one sentence:
The law does not prohibit businesses from:
What the law targets is the deceptive architecture of choice.
If the consumer thinks:
“I chose this.”
but the interface was deliberately engineered so that the consumer was effectively pushed into it without meaningful, informed choice, the business enters dark-pattern territory.
Dark patterns were once treated largely as a UX/marketing issue.
That position is becoming increasingly difficult to defend.
The CCPA's enforcement trajectory shows a clear movement:
Guidelines --> Advisory --> Self-Audit --> Investigation --> Monetary Penalty --> Corrective Directions
The cases involving Zepto, PhysicsWallah, McAfee and SpiceJet demonstrate that the regulator is increasingly prepared to examine the actual consumer journey rather than merely rely on contractual terms or the company's explanation of its interface.
And the lesson for businesses is particularly important:
“We changed the interface after receiving the notice” is not necessarily a complete defence.
For companies operating digital platforms, dark-pattern compliance should therefore become part of the product-development lifecycle, legal review, internal audit, consumer-protection compliance and corporate governance framework.
Because in the digital economy, the interface itself can become the instrument through which an unfair trade practice is committed.
Don't just ask: “Can the consumer click NO?”
Ask:
“Can the consumer understand NO, find NO, and choose NO without being manipulated?”
That is where the real dark-pattern compliance question begins.
Source note: The legal framework above is based primarily on the CCPA Guidelines for Prevention and Regulation of Dark Patterns, 2023, supplemented with verified CCPA/Department of Consumer Affairs enforcement material and recent CCPA orders. The distinction between dark-pattern penalties and other CCPA enforcement actions is intentional, so that the article does not inaccurately describe unrelated penalties as dark-pattern cases.