Digital Dark Patterns Challenge: Compliance Must Be Part of Workflows

Ensuring industry-wide compliance has become a big challenge for the government.

By Kul Bhushan | Aug 06, 2026
Freepik

Opinions expressed by Entrepreneur contributors are their own.

You're reading Entrepreneur India, an international franchise of Entrepreneur Media.

Digital Dark Patterns Challenge: Compliance Must Be Part of Workflows

The Central Consumer Protection Authority (CCPA) has found as many as nine digital entities including Zepto, BookMyShow, and IndiGo in violation of guidelines on dark patterns. 

For the uninitiated, the dark pattern is essentially aimed at subverting a consumer’s autonomy and informed decisions, causing the customer to pay more than the price they see. It is also tricking users into giving away more personal data than needed or simply making them sign up or pay for something. 

Over the last couple of years, a lot of companies have been found practicing some of these dark patterns. The government and its agencies have also acknowledged this industry-wide issue. 

ALSO READ: Dark Patterns Return to Spotlight Amid Compliance Indifference

In a written reply in Rajya Sabha, the government informed that it had found following entities in violation of norms: Anuj Jindal [coaching platform], IndiGo Airline, FirstCry
PharmaEasy, Zepto, McAfee, BookMyShow, Physics Wallah, and SpiceJet Limited. 

Of these, monetary penalties were imposed on Anuj Jindal (INR 3,00,00), FirstCry (INR 2,00,000), PharmaEasy (INR 1,00,000), Zepto (INR 7,00,000), McAfee (INR 1,00,000), PhysicsWallah (INR 5,00,000) and SpiceJet (INR 1,00,000).

The government also elaborated the dark pattern adopted by these entities. For instance, the regulatory body CCPA “observed that Zepto Marketplace Pvt. Ltd. shows lower price initially to lure consumer, on checkout page handling charge and Zepto Pass membership fee is also added Adding of handling charge during checkout amounts to Drip Pricing as the prices are not shown upfront and adding Zepto Pass Membership fee without consent of the user amounts to Basket Sneaking.”

In the case of PhysicsWallah, the CCPA took suo-motu cognizance of dark pattern practices. It discovered that the edtech firm had deployed the following dark patterns (basket sneaking i.e. a donation of INR 10 to PW Foundation was automatically pre-selected during checkout without explicit consumer consent and emotionally persuasive messaging was displayed to nudge consumers into retaining the pre-selected donation amount. Moreover, courses advertised as “free” required mandatory disclosure of personal information before access was granted. 

Digital Compliance 

In November, as many as 26 high profile ecommerce companies such as Zomato, BlinkIt, Walmart, Makemytrip, Zepto, Ajio, and JioMart had self-declared with the Ministry of Consumer Affairs, Food & Public Distribution that they were now in compliance with the Guidelines for Prevention and Regulation of Dark Patterns, 2023.

According to the ministry, these platforms either conducted self-audits or through third-party audits, which aimed to identify, assess and block the presence of such patterns. These 26 companies in their declaration have said their platforms are now free from dark patterns and no longer deploy any designs aimed at manipulating.

“The proactive industry-wide compliance demonstrates a strong commitment towards consumer transparency, fair trade practices, and ethical digital ecosystems. This voluntary alignment underscores the fact that consumer protection and business growth can go hand-in-hand, strengthening brand trust and long-term credibility,” the ministry had said. 

ALSO READ: Ecom Compliance Marks Significant Milestone, But Challenges Persist

Ensuring industry-wide compliance has become a big challenge for the government. 

“The CCPA has made some progress in pulling up non-compliant platforms in the last 12 months, however a lot more has to be done and done fast to drive compliance”, said Sachin Taparia, founder of LocalCircles. 

Taparia and LocalCircles have frequently published several reports about dark patterns in sectors beyond typical ecommerce. 

Earlier this year, it published such a report on listed platforms wherein it found that “95% of publicly listed companies with consumer-facing online platforms are riddled with dark patterns and SEBI needs to do more.”

Its report further said: “Beyond the publicly listed companies with online platforms, LocalCircles’ analysis has revealed that only 7 companies out of 23 which after self-audit, claimed themselves to be dark pattern free and submitted a self-declaration to the consumer regulator CCPA, were actually free of the deceptive manipulative practices. These include: Meesho (Meesho Ltd) William Penn Private Ltd., Jockey (Page Industries Private Ltd.), Curaden India Private Ltd., Walmart India Private Ltd., Clues Network Pvt Ltd. (Shopclues), and Flora Hypermarket Ltd.”

Taparia further told Entrepreneur India: “We at LocalCircles have activated sectoral regulators on the issue and three of them namely RBI, IRDAI and SEBI have already issued compliance mandates and we are trying to get TRAI, DGCA, and I&B to also issue similar mandates for their sectors.”

“If these sectoral mandates are put in place and CCPA starts using the class action provision for higher penalties, I am confident dark pattern compliance will drastically improve.”

Consequently, as addressing dark patterns is now becoming a vital compliance requirement, online businesses need to integrate these checks into their workflows prior to launching publicly. Experts also seek a similar implementation in the systems. 

“… Research shows that 47% to 68% of consumers cancel services or leave platforms because of hidden fees, subscription well, and unexpected  charges, which down the line affects the company. Every fee should be clearly presented upfront in bold format so customers know exactly what they are paying for. Companies should also avoid emotional manipulation messaging that pressures users into making decisions out of fear or guilt. The change made by IndiGo, from “No, I will take the risk” to an understanding version “No, I will not add to the trip”, is an example of how simple words can make all the difference. Creating awareness before mining customer’s  trust and supporting long-term compliance keeps the company on the side of light,” Zavo founder Kundan Shahi told Entrepreneur India. 

That said, every customer-facing journey, from onboarding to checkout and cancellations, should be reviewed against the CCPA’s dark pattern guidelines before launch. Companies also need regular UX audits involving product, legal and compliance teams to identify deceptive design elements early as hidden charges, pre-selected add-ons, or unclear fees put customer trust in the dark. 

As mentioned-above, even optional positive contributions, such as donations, should never be added by default, as someone might not support the cause. Before the final payment, companies should clearly display every charge, not hide it with a small checkbox, explain whether it is mandatory or optional, and if mandated, then why so. 

“Transparency builds long-term trust, while dark patterns only damage brand credibility,” Shahi continued.

Digital Dark Patterns Challenge: Compliance Must Be Part of Workflows

The Central Consumer Protection Authority (CCPA) has found as many as nine digital entities including Zepto, BookMyShow, and IndiGo in violation of guidelines on dark patterns. 

For the uninitiated, the dark pattern is essentially aimed at subverting a consumer’s autonomy and informed decisions, causing the customer to pay more than the price they see. It is also tricking users into giving away more personal data than needed or simply making them sign up or pay for something. 

Related Content