AMLEGALS — Strategic Lawyering

Dark Patterns and DPDPA Consent: Why Tricks Are Not Agreement

Dark Patterns and DPDPA Consent: Why Tricks Are Not Agreement

If the customer had to be fooled into yes, you do not have a yes.

The scene

The opt-out link was grey on grey, below the fold, after the footer. The opt-in was a bright button labelled ‘Continue’. Conversion to marketing consent was ninety-four percent. Complaints to the grievance officer began in the second week.

Where the thinking breaks

The unclear thought What it breaks The clearer thought

Default opt-in is industry standard.

DPDPA requires a clear affirmative action; a default is not an action.

Start every marketing choice unchecked.

Confirm-shaming copy is just tone.

Manipulative design undermines ‘free’ consent and is flagged in India's dark patterns guidelines.

Write the no as clearly as the yes.

Two laws, one design

The Consumer Protection Act's dark patterns guidelines and DPDPA's consent standard point the same way. A clean design satisfies both.

Monday morning

01 Screenshot every consent and opt-out flow.

02 Mark each pre-selection and each hidden no.

03 Fix the flow with the highest traffic first.

Questions, answered plainly

Are pre-ticked boxes valid consent under DPDPA? +

Consent must be signified by a clear affirmative action. A pre-ticked box is not an action by the user and is unlikely to meet the standard.

What are dark patterns under Indian law? +

The Central Consumer Protection Authority's 2023 guidelines identify deceptive design practices such as false urgency, basket sneaking and confirm-shaming as unfair trade practices.

Sector · E-commerce & D2C Your funnel runs on consent. The Act just redefined consent. Read →

E-commerce & D2C · Deep dive Forty pixels on checkout. Forty processors without paper. Read →

E-commerce & D2C · Deep dive Inactive is not a retention strategy. Read →

Tell us where your data sits. We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner →

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).