+91 98726 60544 hello@mitstech.co Mon–Sat · 09:00–18:30 IST

Dark patterns: what Indian e-commerce may not do

Security By Mits Engineering Team 2 min read
Dark patterns: what Indian e-commerce may not do

In 2023 the Central Consumer Protection Authority notified Guidelines for the Prevention and Regulation of Dark Patterns, naming thirteen specific interface behaviours as prohibited. The list is worth reading as a product document rather than a legal one, because most of the items are things a growth team has been asked to build at some point: false urgency, basket sneaking, confirm shaming, forced action, subscription trap, interface interference, bait and switch, drip pricing, disguised advertisements, nagging, trick question, SaaS billing, and rogue malware.

The legal basis is not novel, which is what gives it teeth. Dark patterns are treated as unfair trade practices under Section 2(47) of the Consumer Protection Act, 2019, and the CCPA acts under Section 18 of the same Act. That means this is not a new regime with a grace period — it is an existing enforcement power applied to a newly specified list of behaviours, and the authority has been using it.

Enforcement has been concrete rather than theoretical. By order dated 19 June 2024 the CCPA directed IndiGo to change its user interface around seat selection and confirm-shaming, which the airline did. BookMyShow addressed a basket-sneaking issue involving automatically added contributions after the CCPA intervened. Show cause notices have gone to eleven companies across quick commerce and transport platforms. These are recognisable, mainstream Indian products, not obscure operators.

On 5 June 2025 the CCPA issued an advisory requiring e-commerce platforms to conduct a self-audit for dark patterns within three months. That deadline has passed. If you run or build an Indian consumer platform and no such audit has happened, the gap is not that you failed to comply with something optional — it is that you have no record of having looked, which is a poor position from which to answer a notice.

Translating this into engineering work is mostly about naming things honestly. A countdown timer that resets on refresh is false urgency. A pre-ticked insurance add-on is basket sneaking. A decline button reading 'No, I don't care about saving money' is confirm shaming. A price that grows through unavoidable fees between the listing and the payment screen is drip pricing. A cancellation flow with more steps than the signup was is a subscription trap. Each of these usually exists because somebody measured that it lifted a conversion number, which is precisely why they were regulated.

The practical approach is a documented review of every flow that involves a price, a default, a consent, an add-on or a cancellation, checked against the thirteen named patterns, with the findings and the fixes recorded. It takes a couple of days for most products. Doing it produces a document you can hand to a regulator or a customer's legal team, and it tends to produce a better product too — a checkout that states its total honestly converts worse this quarter and churns less next year.

Need help with this? Explore our Cybersecurity & Compliance services. Learn more Back to all news

Keep reading

More on Security