CCPA's Dark Patterns Crackdown: What E-Commerce Sellers Need to Know

The government told Parliament this month that the Central Consumer Protection Authority has fined nine digital platforms roughly Rs 20 lakh combined for using "dark patterns" — manipulative checkout and interface design. What's worth noticing in the list of penalised practices isn't malice — it's that several of them are the kind of small UX decision a well-meaning product team can make without any intent to deceive.

The Guidelines for Prevention and Regulation of Dark Patterns, 2023, issued by the CCPA under the Consumer Protection Act, 2019, identify 13 categories of deceptive interface design — false urgency, drip pricing, basket sneaking, subscription traps, confirm shaming, forced action, and others. Enforcement was relatively quiet for the first year and a half, but the government's disclosure to the Rajya Sabha in August 2026 confirms it's now real: penalties have landed on a genuinely varied set of businesses, including a quick-commerce platform fined for showing an initially lower price before adding handling charges and membership fees later in the checkout flow, an ed-tech platform fined for pre-selecting a small donation during transactions with persuasive messaging around it, and several others for false urgency countdown timers and default-added subscriptions.

Why This Matters Beyond the Nine Companies Actually Named

The government also disclosed that it received 308 dark-pattern complaints between December 2023 and March 2026, and issued a specific advisory in June 2025 calling on e-commerce platforms to conduct self-audits. Taken together, this reads less like a one-off enforcement sweep and more like the CCPA settling into a genuine, ongoing supervisory posture over digital checkout design — which matters because most of the practices penalised so far aren't obscure or unusual; they're checkout patterns that are extremely common across Indian e-commerce, including on platforms of a size well below the nine that happened to draw attention first.

The Genuinely Useful Reframe for a Small Business

Here's what we think gets lost in coverage that treats this purely as a "Big Tech gets fined" story: drip pricing — showing a low headline price and adding charges later in the checkout — and basket sneaking — adding an item, membership, or donation to a cart without clear, unambiguous consent — are things a small or mid-sized D2C brand can fall into entirely by accident, through a checkout flow designed for conversion optimisation rather than any intent to mislead. A "recommended" add-on pre-checked by default, a shipping fee that only appears at the final payment step, a subscription option framed as the default rather than a genuine opt-in — these are common product decisions across Indian e-commerce generally, made by teams optimising for completed purchases, not by anyone thinking of themselves as running a scam.

What We'd Actually Recommend

If you run or advise an e-commerce business of any size, the CCPA's own June 2025 advisory — a genuine self-audit against all 13 named dark-pattern categories — is worth treating as a real, near-term compliance task rather than something only large platforms need to worry about. Concretely: check whether your final checkout price matches your advertised price with no surprise charges added at the last step; check whether any pre-selected add-ons, insurance, or donations are genuinely opt-in with clear, unambiguous disclosure; and check whether any countdown timers or "X people are viewing this" urgency messaging on your site reflect real, verifiable information rather than a fixed design element that resets regardless of actual demand. None of these fixes are expensive or technically difficult — the entire risk here is that most businesses simply haven't looked at their own checkout flow through this specific lens yet, and a Rs 1-7 lakh penalty, plus the reputational cost of a public enforcement notice, is a genuinely avoidable outcome for a UX decision nobody meant as deceptive in the first place.


Have a question about this update? Submit a query to our team.