In an increasingly digital first environment, organisations are optimising digital experiences to drive engagement, conversion, and customer retention. As digital interactions become an integral part of consumer decision making, regulators are placing greater attention on how choices are designed and presented. Practices commonly referred to as dark patterns, which influence, mislead, or pressure users into taking actions they may not have otherwise taken, are becoming a growing area of regulatory focus across digital ecosystems.

      In response, regulators in India have introduced measures to address such practices across digital ecosystems. The Central Consumer Protection Authority (CCPA) established a framework through its Guidelines for Prevention and Regulation of Dark Patterns, 2023. More recently, sectoral regulators including the Insurance Regulatory and Development Authority of India (IRDAI) and the Reserve Bank of India (RBI) have reinforced expectations around fair customer treatment, transparent digital interactions, and responsible design practices.


      Dark patterns identified by the CCPA

      • False urgency

        Presents time or availability constraints in a way that may not reflect actual conditions, influencing users to act faster than intended

      • Basket sneaking

        Adds additional products or services to a user’s selection by default or through pre-set options, without clear and explicit user intent or active confirmation

      • Confirm shaming

        Uses language, tone, or framing that creates a sense of discomfort, guilt, or perceived risk to influence users toward acceptance rather than a neutral choice

      • Forced action

        Requires users to take additional or unrelated actions, or share information, as a condition to access the intended product or service

      • Subscription trap

        Creates an imbalance between ease of enrolment and difficulty of cancellation, often through hidden options, unclear steps, or delayed disclosures

      • Interface interference

        Designs interface elements to highlight certain options while obscuring or reducing visibility of alternatives, influencing user choice without explicit restriction

      • Bait and switch

        Presents a specific offer or outcome upfront, but alters availability or replaces it with an alternative during the conversion stage, shifting user choice post engagement

      • Drip pricing

        Delays full price visibility by introducing additional charges progressively as users move closer to transaction completion, limiting their ability to assess the overall cost upfront

      • Disguised advertisement

        Presents promotional content in a format that resembles independent, editorial, or user-generated content, reducing clarity of advertising intent

      • Nagging

        Repeatedly interrupts the user experience through persistent prompts or requests, creating pressure to take a specific action over time

      • Trick questions

        Uses ambiguous or misleading phrasing, including double negatives or unclear options, to guide users toward unintended responses

      • SaaS billing

        Implements recurring billing practices without adequate transparency on renewals, charges, or duration, leading to unintended or unnoticed payments

      • Rogue malwares

        Uses deceptive prompts or false claims to mislead users into installing harmful software disguised as security tools or content access mechanisms

      Against this backdrop, organisations are increasingly expected to assess digital journeys through the lens of consumer protection and responsible design. This requires a structured approach to the governance of digital experiences, supported by responsible design practices, periodic assessments of customer journeys, effective oversight, and ongoing monitoring of digital touchpoints. As regulatory expectations continue to evolve, strengthening these capabilities is expected to be critical for enhancing transparency, supporting informed consumer choice, fostering trust, and demonstrating alignment with responsible digital practices and regulatory requirements.


      Dark pattern in digital platforms

      Evolving regulatory landscape around dark patterns signals a shift towards greater accountability for how consumer choices are designed and presented

      Key Contacts

      Kunal Pande

      National Leader - Cyber, Risk and Compliance Services

      KPMG in India

      Rohan Padhi

      Partner, National Co-Lead, Digital Risk and Cloud Security

      KPMG in India

      Romharsh Razdan

      Partner, Digital Trust

      KPMG in India

      Ramesh Krishnamurthy

      Associate Partner, Technology Transformation - Digital Experience Design (DXD)

      KPMG in India

      How can KPMG in India help

      Use cyber security to protect your future

      Transformation driven by data, enabled by digital technology, and led by business initiatives

      KPMG in India is a leading provider of Tax, and Advisory services to companies in the Indian Technology industry

      Access our latest insights on Apple or Android devices