AMLEGALS — Strategic Lawyering
DPDPA consent · Design

Dark patterns and the DPDPA: when design defeats consent

A consent request can be technically present yet practically meaningless if the interface pushes a person toward agreeing. The DPDPA sets a standard for what consent must be. Design that works against that standard puts the consent, and the processing that relies on it, at risk.

Updated · Checked against the DPDP Act, 2023 and the DPDP Rules, 2025 · 4 min read

A gold maze of arrows funnelling toward a single bright point on a dark navy background
Short answer

The DPDPA does not use the term “dark patterns”, but its consent standard addresses them directly. Section 6(1) of the Digital Personal Data Protection Act, 2023 requires consent to be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action. A design that pre-ticks boxes, hides the refuse option, makes withdrawal harder than giving consent, or nags a person until they agree is unlikely to produce consent that meets this standard. Section 6(4) requires that withdrawing consent be as easy as giving it, which rules out asymmetric designs. Separately, the Central Consumer Protection Authority issued the Guidelines for Prevention and Regulation of Dark Patterns, 2023 under the Consumer Protection Act, 2019, which identify specified dark patterns such as false urgency, basket sneaking, confirm shaming, forced action and subscription traps. An organisation can therefore face a consent problem under the DPDPA and a consumer protection problem under the 2023 guidelines from the same interface.

  • Dark patterns
  • Consent
  • Section 6
  • Consumer protection
  • Deceptive design
  • UX
Consent standard
Free, specific, informed, unconditional, unambiguous (Section 6(1))
Withdrawal
Must be as easy as giving consent (Section 6(4))
Consumer rules
Dark Patterns Guidelines, 2023 under the Consumer Protection Act, 2019
Risk
A single interface can breach both regimes

What dark patterns are, in plain terms

A dark pattern is an interface choice that steers a person toward a decision they might not otherwise make. In a privacy setting, that usually means steering them toward giving more consent, or keeping consent they would withdraw if the path were clear.

The problem is not that a design is persuasive. The problem is that the design removes a real, equal choice. The DPDPA cares about whether the choice was genuine, and that is where design and law meet.

Two regimes, one interface

The Central Consumer Protection Authority issued the Guidelines for Prevention and Regulation of Dark Patterns, 2023 under the Consumer Protection Act, 2019. They list specified dark patterns, including false urgency, basket sneaking, confirm shaming, forced action, subscription traps, interface interference, bait and switch, drip pricing, disguised advertisement, nagging, trick questions, SaaS billing and rogue malware.

This means a consent interface can raise two separate questions. Under the DPDPA, did the design produce valid consent? Under the 2023 guidelines, did the design deceive or coerce the consumer? A review should look at both at once, because the same screen is evidence in both.

Designing consent that holds up

A consent flow that meets the Act tends to share a few traits.

  • Accept and refuse options are presented with equal weight, with no pre-selection.
  • Each purpose is stated separately, so a person can agree to one and decline another.
  • Withdrawal is reachable in the same number of steps as giving consent, from the same place.
  • No access or feature is withheld for refusing consent that is not necessary to provide it.

How AMLEGALS reviews consent design

AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder and Managing Partner, with Rohit Lalwani, Associate Partner, working on DPDPA compliance.

The team reviews consent screens, cookie banners and withdrawal flows against Section 6 and against the 2023 dark patterns guidelines, and sets out the specific changes that bring a design within both.

Questions and answers

Dark Patterns and DPDPA Consent: common questions

Does the DPDPA mention dark patterns?

No. The Act does not use the term, but its consent standard in Section 6(1) and the equal-ease withdrawal rule in Section 6(4) address the same conduct.

What law directly regulates dark patterns in India?

The Guidelines for Prevention and Regulation of Dark Patterns, 2023, issued by the Central Consumer Protection Authority under the Consumer Protection Act, 2019.

Is a pre-ticked consent box a problem?

Yes. Section 6(1) requires a clear affirmative action, so consent cannot be inferred from a pre-ticked box or from silence.

Can refusing consent block access to a service?

Only where that consent is necessary to provide the service. Withholding access to pressure consent for unrelated purposes undermines the “free” requirement.

How many dark patterns are specified in the 2023 guidelines?

The 2023 guidelines specify thirteen dark patterns, including false urgency, confirm shaming, subscription traps and basket sneaking.

Contact

Have your consent design reviewed

Share your consent screen or cookie banner. The AMLEGALS data privacy team will assess it against Section 6 and the 2023 dark patterns guidelines.

Or write to [email protected]

Your details

Name and email are enough to start. The reply comes from [email protected].

Your information is handled in accordance with our privacy obligations. No spam, ever.

Dark Patterns and DPDPA Consent: questions and answers

What is the legal framework for data protection in India?

India's framework is the Digital Personal Data Protection Act, 2023 (Presidential assent 11 August 2023; 44 sections) read with the Digital Personal Data Protection Rules, 2025, notified on 13 November 2025 (G.S.R. 846(E)) with 23 Rules and 7 Schedules.

When do DPDPA obligations apply to businesses?

The Act and Rules follow phased commencement. Institutional provisions commenced on 13 November 2025; Consent Manager provisions commence after 12 months on 13 November 2026; and the principal Data Fiduciary, rights, breach, security and enforcement provisions commence after 18 months on 13 May 2027.

What is the maximum penalty under DPDPA?

Highest listed maximum for a specified contravention: ₹250 crore under the Schedule to the Act. Penalties are imposed by the Data Protection Board of India after an inquiry, and Section 33(2) requires the Board to consider factors such as the nature, gravity and duration of the breach, the type of personal data affected, repetition, mitigation steps and proportionality.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to Dark Patterns and DPDPA Consent?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on Dark Patterns and DPDPA Consent under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on Dark Patterns and DPDPA Consent under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on Dark Patterns and DPDPA Consent?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for Dark Patterns and DPDPA Consent rather than a generic checklist.

How do I get a first view of my DPDPA exposure on Dark Patterns and DPDPA Consent?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about Dark Patterns and DPDPA Consent · DPDPA Exposure Assessment