You have met most of them this week. The decline link that says “No thanks, I like paying full price”. The countdown that starts again when you reload the page. The subscription that took one click to start and a phone call to stop. The cookie banner with a bright “Accept all” and no visible way to say no. These are dark patterns: interface design that gets a business a yes the customer did not quite mean to give. This guide names twelve of them, with the kind of example you will recognise, and then covers the part most lists skip: which EU rules each one collides with, what they have cost the companies that were caught, and what to build instead if you want customers who stay.
— Guide
Dark patterns: twelve you meet every day, and what EU law now says about them.
Twelve named dark patterns with real examples, the EU rules each one collides with, what they have cost the companies caught using them, and what to build instead.
Dark patterns examples and the EU rules they collide with
| Pattern | What it looks like | EU rule it collides with |
|---|---|---|
| Confirmshaming | A decline link that reads “No thanks, I like paying full price” | UCPD general ban on unfair practices (Art. 5); DSA Art. 25 on platforms |
| Roach motel / hard to cancel | One click to subscribe; a phone call or a maze to cancel | GDPR Art. 7(3) for consent; DSA Art. 25(3) on platforms |
| Pre-ticked boxes | Insurance, a donation or a newsletter ticked in advance | CRD Art. 22 for paid extras; GDPR Recital 32 for consent |
| Sneak into basket | An item you did not choose appears in the cart | CRD Art. 22: express consent to any extra payment |
| Drip pricing / hidden fees | A “service fee” appears at the last step | UCPD Art. 7(4)(c): price including taxes and delivery |
| Fake countdown timer | A timer that resets, or an offer that outlives it | UCPD Annex I, No. 7 |
| Fake scarcity | “Only 2 left”, whatever the real stock | UCPD Art. 6(1)(b): misleading on availability |
| Nagging | The same pop-up after you have already said no | DSA Art. 25(3) on platforms; GDPR Recital 32 |
| Disguised ads | Paid content dressed as an article or a review | UCPD Annex I, No. 11 (advertorials) |
| Buried “reject” on a cookie banner | “Accept all” on screen one, refusal several clicks away | GDPR consent rules; ePrivacy rules, as the CNIL enforced them |
| Trick questions | “Uncheck the box if you prefer not to receive email updates” | GDPR Art. 7(2): clear and plain language |
| Forced continuity | A free trial that rolls into a paid plan without warning | UCPD Art. 7: material information hidden or given too late |
A map of where each pattern collides with EU law, not legal advice: which rule applies depends on the facts, the business and the member state. UCPD = Unfair Commercial Practices Directive, CRD = Consumer Rights Directive, DSA = Digital Services Act.
What are dark patterns?
Dark patterns are design choices that benefit a website at the expense of the person using it, by steering, pressuring or deceiving them into a decision they would not otherwise have made. The researchers behind the largest study of them put it as interface choices that coerce, steer or deceive users into “unintended and potentially harmful decisions”. The definition matters because it excludes a lot. A big, clear “Buy now” button is not a dark pattern. A big “Buy now” button next to a grey, unlabelled way out can be.
The term was coined in 2010 by Harry Brignull, a UX designer who started a website to name and shame deceptive interfaces. That site, once darkpatterns.org, is now deceptive.design, and it has moved to the term “deceptive patterns”. The European Data Protection Board made the same switch in its guidelines. You will see both terms; they mean the same thing, and “dark patterns” is still the one regulators, journalists and most designers use.
Brignull’s original names stuck because they describe the experience rather than the technique: the roach motel, which is easy to get into and hard to get out of; confirmshaming; sneak into basket; forced continuity. His current catalogue lists eighteen types. The twelve below are the ones you are most likely to meet as a customer, and most likely to be asked to build as a business.
One distinction runs through everything that follows. Dark patterns are not the same as persuasion. A real deadline, a real low-stock warning and a well-designed default are all legitimate. The pattern begins where the interface says something false, or makes the honest choice harder than it needs to be.
How common are dark patterns?
Very. In 2019, a Princeton-led team crawled about 53,000 product pages on about 11,000 shopping websites and found 1,818 instances of dark patterns, across 15 types in 7 categories. They found 183 websites using patterns that were outright deceptive, and 22 third-party companies selling dark patterns as a ready-made product — plug-ins that add a ticking timer or a “low stock” message to any shop.
Europe’s own figures are worse. In a 2022 study for the European Commission, mystery shoppers found practices they perceived as dark patterns on 73 of the 75 most popular websites and apps used by EU consumers: 97%. The most common were hidden information and false hierarchy, preselection, nagging, difficult cancellation and forced registration. The study is careful to add that this is a description of what shoppers experienced, not a legal finding against any trader.
Then the regulators checked for themselves. In January 2023, the Commission and consumer authorities from 23 member states, Norway and Iceland published a sweep of 399 online shops. 148 of them, nearly 40%, used at least one of the three dark patterns being checked: 42 ran fake countdown timers, 54 steered shoppers towards subscriptions or pricier options through design or wording, and 70 hid important information such as delivery costs. 23 of those hid information specifically to push people into a subscription.
Pressure: fake urgency, fake scarcity and confirmshaming
Fake urgency is the countdown that is not counting down to anything. The Princeton study recorded every countdown timer it found and revisited the sites for five days. Of 393 timers, 157 on 140 websites were deceptive: they either reset when they reached zero, or they expired and the “ending soon” offer carried on regardless. That is the reliable tell. Reload the page, come back tomorrow, or open it in a private window; a real deadline does not move.
Fake scarcity is the same trick applied to stock. “Only 2 left”, “12 people are looking at this”, “selling fast”. The same study found 17 shops whose stock counts were invented: 16 decremented the number on a fixed schedule, one generated it randomly on every page load, and 8 of them used off-the-shelf plug-ins to do it. Some shops showed a low-stock message on nearly every product. It is worth knowing if you run a small shop yourself, because the plug-in that adds “Hurry, only 3 left!” rarely asks whether the number is true.
Confirmshaming moves the pressure from the clock to the conscience. The choice you are not supposed to make is worded so that making it feels foolish or mean: “No thanks, I hate saving money”, “No, I don’t want to protect my order”. The Princeton crawl counted 169 instances, most of them in pop-ups trading a discount for an email address. The FTC’s 2025 settlement with Amazon bans a button of exactly this kind: declining Prime can no longer mean clicking “No, I don’t want Free Shipping”.
None of the three is aimed at a careful shopper with time to think. They are aimed at the moment of hesitation, which is exactly the moment a business should be answering questions rather than creating pressure.
Sneaking: pre-ticked boxes, sneak into basket and drip pricing
Pre-ticked boxes are the quietest dark pattern, and among the most effective, because doing nothing is the easiest decision there is. Travel insurance ticked in advance, a donation added “unless you opt out”, a newsletter box already checked under the email field. The Commission’s 2022 study found preselection on the second-largest number of the sites it examined, often in privacy, advertising and notification settings that people did not know were already switched on.
Sneak into basket goes one step further and adds the product for you. The Princeton team found a flower shop that added a greeting card to the cart after the shopper had asked for none, and an electronics shop that added insurance alongside a laptop. Some shops used pre-ticked boxes to do it; others simply put the item in the basket and waited to see whether anyone noticed.
Drip pricing, or hidden costs, is the low price that grows on the way to the till: a “service fee”, a “care and handling” charge, delivery revealed only after the address step. It works on sunk cost; by the last step the shopper has invested enough effort that paying a little more feels easier than starting again. It is also the biggest single reason people abandon a checkout, which is why we covered the mechanics, and the total-price rules behind them, in why shoppers abandon a checkout.
Traps: the roach motel and forced continuity
The roach motel, which Brignull’s site now calls “hard to cancel”, is the subscription that is easy to start and hard to stop. Sign-up is one tap. Cancelling means finding a page that is not linked from the account menu, answering three retention offers, or ringing a number that is open on weekdays. The Princeton study found it on 31 shopping sites; one disclosed only in a terms-and-conditions PDF that cancelling meant calling customer service.
Forced continuity is its natural partner: the free trial that turns into a paid plan without a clear warning, or the “one-time” payment that turns out to renew every year. The same researchers found a wine retailer whose $89 service looked like a single payment and renewed annually. On its own a trial is honest. The pattern is in not saying clearly, at the point of sign-up, what happens when it ends and how to stop it.
This pair is the one regulators have pursued hardest, because the harm is easy to count: it is the money taken every month from people who wanted to leave. It is also where the largest settlement in this article comes from, as the section on costs below explains.
Interference: trick questions, nagging and disguised ads
Trick questions win by confusing rather than pressuring. The usual device is a double negative, or a box you must tick to opt out where every other box on the page means opt in. The Princeton study quotes forms such as “Uncheck the box if you prefer not to receive email updates”. Read quickly, as everyone reads forms, the honest answer and the box state point in opposite directions.
Nagging is the request that will not accept no: the pop-up asking you to turn on notifications every time you open the app, the “Are you sure?” that returns on the next page, the newsletter overlay that comes back after you closed it. Each interruption is small, which is the point. The pattern relies on people eventually saying yes just to make it stop.
Disguised ads are adverts made to look like something else. Sponsored content written as an independent review, a “top ten” where the ranking is paid for, a download button that is actually a banner ad sitting above the real one. EU law has blacklisted the editorial version since 2005: paying for editorial content without making that clear to the reader is on the list of practices that are unfair in every circumstance.
The cookie banner where “reject” is buried
The most-seen dark pattern in Europe is probably the cookie banner: “Accept all” in a bright button on the first screen, and refusal hidden behind “Manage options”, a list of toggles and a “Confirm my choices” at the bottom. The asymmetry is the pattern. Everybody can accept in one click; only the determined manage to refuse.
France’s data-protection authority, the CNIL, put a price on that asymmetry. In decisions dated 31 December 2021 it fined Google €150 million and Facebook €60 million over how hard it was to refuse cookies. In Google’s case, accepting cookies on google.fr took a single click on “J’accepte”; refusing took at least five actions, through a customisation screen and a confirmation step. The CNIL’s reasoning was blunt: making refusal more complex than acceptance amounts, in reality, to discouraging users from refusing.
The fix is not a design trend; it is a refuse button as visible as the accept button, on the same screen. A refusal link in pale grey text on white is also likely to fail the contrast requirements covered in our guide to accessibility law under the European Accessibility Act, so it can fail two sets of rules at once. How to configure a consent tool is a separate job; the principle is the one the CNIL stated.
Why dark patterns work
Because they do work, at least in the short run, and pretending otherwise is why so many businesses keep using them. The clearest evidence comes from the legal scholars Jamie Luguri and Lior Strahilevitz, who ran large experiments on representative samples of Americans and published them in 2021. Participants were offered a data-protection and credit-monitoring plan that would cost $8.99 a month after a free period.
Mild dark patterns more than doubled the share of people who signed up, and produced no measurable backlash. In the first experiment, with 1,963 participants, 11.3% of the control group accepted the plan. With mild dark patterns that rose to 25.8%, and with aggressive ones to 41.9%. The aggressive versions did annoy people, and more of them dropped out. The mild ones did not: people in that group reported much the same mood as the control group. The authors also found that the less educated participants were, the more likely they were to accept.
The Commission’s own experiment, with 7,430 participants in six member states, points the same way: hidden information, emotional pressure and personalised pressure all pushed people into choices inconsistent with their own stated preferences. It found two more things worth knowing. Transparency-based fixes, such as simply telling people more, did little to undo the effect. And once people recognised a dark pattern, they judged it negatively. That second finding is the business case against them, and the last section of this guide comes back to it.
Dark patterns and EU law: the consumer rules that already apply
There is no single EU “dark patterns law”, and there does not need to be one for most of these patterns to be illegal. The workhorse is the Unfair Commercial Practices Directive of 2005. It bans unfair commercial practices in general, treats a practice as misleading if its “overall presentation” deceives the average consumer even when every word is factually correct, and counts hiding or delaying material information as a misleading omission. In an invitation to purchase, that information includes the price with taxes and any delivery charges.
The directive also carries a blacklist in its Annex I: practices that are unfair “in all circumstances”, with no need to prove harm. Two of them read like descriptions of dark patterns. Number 7 bans falsely stating that a product, or a deal, is available only for a very limited time in order to rush a decision; that is the fake countdown. Number 11 bans paid editorial content that is not clearly marked as such; that is the disguised ad. Fake stock levels fall under the general ban on misleading consumers about a product’s availability.
The Consumer Rights Directive of 2011 deals with pre-ticked boxes directly. A trader must get the consumer’s express consent to any payment beyond the main price, and if that consent was inferred from a default the consumer had to un-tick, the consumer is entitled to their money back. A pre-ticked insurance box, or an extra slipped into the basket, does not just risk a fine; it hands every customer a refund claim.
Since the 2019 “Omnibus” reform, the penalties have teeth. In cross-border cases coordinated between national authorities, member states must be able to fine traders at least 4% of their annual turnover in the countries concerned, or at least €2 million where turnover figures are not available. Consumers harmed by an unfair practice must also have access to remedies, including compensation, a price reduction or ending the contract.
Consent: what the GDPR and the EDPB say
Where a dark pattern collects personal data or consent, the GDPR applies on top. Its definition of consent, in Article 4(11), requires a “freely given, specific, informed and unambiguous” indication of the person’s wishes, given by a statement or by a clear affirmative action. Recital 32 spells out what that excludes: “Silence, pre-ticked boxes or inactivity should not therefore constitute consent.” It also says a consent request must not be “unnecessarily disruptive” to the service, which is a fair description of nagging.
Article 7 adds two rules that cut against the roach motel and the trick question. A consent request bundled with other matters must be clearly distinguishable, “using clear and plain language”. And withdrawing consent must be “as easy” as giving it. A newsletter you joined with one tick and can leave only by emailing support fails that test.
The European Data Protection Board turned this into a design guide. Its Guidelines 03/2022, adopted in final form in February 2023, are written for social media platforms but read well for anyone designing a form. They sort deceptive patterns into six families: overloading, skipping, stirring, obstructing, fickle and “left in the dark”. Stirring, for instance, covers appeals to emotion and visual nudges; obstructing covers dead ends and journeys that are longer than necessary.
The Digital Services Act’s Article 25, and who it actually covers
The Digital Services Act is the first EU law to name the problem in its own words. Article 25 says providers of online platforms “shall not design, organise or operate their online interfaces in a way that deceives or manipulates” their users, or that otherwise “materially distorts or impairs” their ability to make free and informed decisions. It lets the Commission issue guidance on three practices in particular: giving more prominence to certain choices, repeatedly asking for a choice already made, and making a service harder to cancel than to join. Recital 67 adds examples, including presenting choices in a non-neutral way and nudging people into decisions on transactions.
For most small businesses, Article 25 is not the rule that applies — the older consumer and data-protection laws are. Article 25 covers online platforms — services such as marketplaces and social networks that host content for their users and make it public — not an ordinary company website or a shop selling its own products. It sits in a section of the DSA from which micro and small enterprises are excluded, and it explicitly does not apply to practices already covered by the Unfair Commercial Practices Directive or the GDPR. It closes a gap for platforms; it does not replace the rules above.
It has already been used. On 5 December 2025 the Commission adopted the first non-compliance decision under the DSA, fining X €120 million. One of the three breaches was Article 25(1): X’s blue checkmark, which anyone can buy without X meaningfully verifying who is behind the account, deceives users into treating accounts as verified. The Commission had issued preliminary findings in July 2024. It did not publish how much of the €120 million relates to each breach.
Is a dark patterns law coming? The Digital Fairness Act
The next step is the Digital Fairness Act, a Commission initiative aimed at deceptive or manipulative interface design, addictive design, misleading influencer marketing and unfair personalisation, with particular protections for minors. Its public consultation ran from 17 July to 24 October 2025. As of early October 2026 it is still a plan, not a law and not yet even a published proposal: the European Parliament’s legislative tracker lists it as announced, with the Commission’s proposal expected in the fourth quarter of 2026.
Anything you read about what it “requires” is therefore a forecast. Once a proposal is published it still has to pass the Parliament and the Council, and then apply after a transition period. The practical point for a business today is that the rules above already cover the patterns in this guide; a new law would add detail, not create the first obligation.
What dark patterns have cost companies
The largest bill so far is American. In September 2025 Amazon settled the US Federal Trade Commission’s case over Prime for $2.5 billion: a $1 billion civil penalty and $1.5 billion in refunds to an estimated 35 million customers. The FTC had alleged that Amazon used confusing interfaces to enrol people in Prime without their consent and made cancelling deliberately difficult. Documents quoted by the FTC showed staff describing subscription driving as “a bit of a shady world”. Amazon must now offer a clear button to decline Prime and a way to cancel using the same method people used to sign up.
Epic Games, the maker of Fortnite, agreed in December 2022 to pay $245 million in refunds over dark patterns, alongside a separate $275 million penalty for children’s privacy violations. The FTC alleged that Fortnite’s confusing button layout let players be charged with a single press, sometimes while waking the game from sleep mode, and that Epic locked the accounts of customers who disputed unauthorised charges with their card company.
In Europe, the CNIL’s €210 million in cookie fines and the Commission’s €120 million decision against X are the headline numbers. The quieter costs reach far smaller companies. The 2023 sweep was not a report for its own sake: national authorities announced they would contact the traders concerned, ask them to fix their sites and take further action where needed. And every pre-ticked paid extra is, under the Consumer Rights Directive, a refund the customer is entitled to ask for.
Then there are the costs that never reach a regulator. A customer who did not mean to buy something asks for a refund, and a customer who cannot find the cancel button asks their bank for a chargeback instead. Epic’s case shows what happens when a business responds to that by punishing the customer. Each one is a lost sale, a support ticket and, for a chargeback, usually a fee from the payment provider on top.
Persuasion or manipulation: where the line sits
A countdown to a real deadline is information; a countdown that resets is a lie. Almost every dark pattern has an honest twin. A sale that genuinely ends on Monday at midnight can say so, and a timer that counts to that moment is just a clock. A Black Friday date is that kind of deadline, which is why the campaign can be planned weeks ahead. A shop with two items left can say “2 left”. A default can be pre-selected when it is the option most customers would choose for themselves, such as standard delivery, rather than the one that earns the business most.
The test is simple to state. Would the claim still be true if the customer checked it? Is declining as easy and as respectfully worded as accepting? Would you be comfortable if the customer saw exactly how the screen was designed, and why? If the answer to any of these is no, the design is borrowing a decision rather than earning one.
What to build instead
Every pattern in this guide has an alternative that a customer will not resent. When we build a checkout, the defaults we start from are these: the total including delivery is visible in the cart, before the address step; optional extras start unticked; the decline option is a plain “No thanks”, styled as a real button rather than a faint link; and anything recurring says, next to the button, what it costs, how often, and how to stop it. None of it is clever. That is rather the point.
For subscriptions and accounts, make leaving as easy as joining: cancellation in the account menu, online, in a similar number of steps to sign-up. A single, honest retention offer is fine; a maze is not. For consent, ask once, ask clearly, put “reject” next to “accept”, and remember the answer. For urgency and scarcity, only show what is true, and remove the plug-in if you cannot make it tell the truth.
If a page is not selling, the fixes are usually duller and more durable than a timer: a clearer offer, a visible price, fewer form fields, a faster page. Those are covered in the eight usual reasons a website doesn’t convert, and none of them requires tricking anyone. The same restraint shows up in the web design trends worth adopting in 2026: interfaces that explain themselves age better than interfaces that push.
There is a newer reason, too. Some shopping research, and a little buying, is now done by software acting for people, as described in how AI agents actually buy things. A countdown aimed at human impatience is wasted on a program reading your product data, and a total that only appears at the last step is one it cannot quote correctly. Designing for honesty is also designing for the reader that does not get nervous.
The small-business maths
A dark pattern moves one number this month and sends the bill later — in refunds, chargebacks, complaints and, in the EU, fines. The number it moves is real: Luguri and Strahilevitz showed that mild patterns can double a sign-up rate without anyone visibly objecting. But the sign-up rate is the only line it improves. Refund requests, cancellations, chargebacks, support tickets and one-star reviews all move the other way, more slowly, in reports nobody connects back to the pop-up.
For a large platform, that trade has sometimes looked worth making until a regulator priced it. For a small business it rarely is, because a small business lives on repeat customers and recommendations, and a customer who feels tricked is the one most likely to say so in public. The Commission’s study found that people judge these practices harshly once they notice them. Most eventually do.
So measure what the pattern actually does: not the sign-up rate, but the refund rate, the cancellation rate and the share of customers who buy a second time. If you are choosing who builds your site, ask what they would refuse to put on it; we cover the other questions worth asking in choosing a web design agency. If you would like a second pair of eyes on your key screens, our UX Audit is a written usability review of up to five of them, and the UI/UX design and e-commerce work behind our checkouts starts from the defaults above.
Sources
Every figure, date and legal provision above comes from the regulator’s or researchers’ own publication, or from the legal text itself, checked in October 2026. Legal summaries here are general information, not legal advice for a specific business.
- Mathur et al. — Dark Patterns at Scale: Findings from a Crawl of 11K Shopping Websites (CSCW 2019) ↗
Crawled about 53,000 product pages on about 11,000 shopping sites: 1,818 dark pattern instances in 15 types and 7 categories, 183 websites with deceptive practices, 22 third parties selling dark patterns. The full paper reports 157 deceptive countdown timers on 140 sites, 17 sites with invented stock counts, 169 confirmshaming instances and Hard to Cancel on 31 sites, and credits Brignull with coining the term in 2010.
- Deceptive Patterns (deceptive.design) — Types ↗
Harry Brignull’s catalogue, formerly darkpatterns.org and started in 2010. Lists eighteen types, with definitions for confirmshaming, disguised ads, fake scarcity, fake urgency, hard to cancel, hidden costs, hidden subscription, nagging, preselection, sneaking and trick wording.
- Luguri & Strahilevitz — Shining a Light on Dark Patterns, Journal of Legal Analysis 13(1), 2021 ↗
Experiments on representative US samples. In Study 1 (1,963 participants) acceptance of an $8.99-a-month data-protection plan was 11.3% in the control group, 25.8% with mild dark patterns and 41.9% with aggressive ones; mild patterns produced no measurable backlash, and less educated participants were more likely to accept.
- European Commission — Behavioural study on unfair commercial practices in the digital environment: dark patterns and manipulative personalisation (2022) ↗
Mystery shoppers perceived dark patterns on 73 of the 75 most popular websites and apps used by EU consumers (97%), most often hidden information/false hierarchy, preselection, nagging, difficult cancellation and forced registration. An online experiment with 7,430 participants found transparency-based remedies ineffective, and that consumers judge these practices negatively once they recognise them.
- European Commission — Manipulative online practices found on 148 out of 399 online shops screened (IP/23/418, 30 January 2023) ↗
Sweep with authorities from 23 member states, Norway and Iceland: 148 of 399 shops used at least one of three dark patterns; 42 used fake countdown timers, 54 steered consumers by design or wording, 70 hid important information, 23 of them to push a subscription. Apps of 102 sites were also checked, 27 with dark patterns.
- Unfair Commercial Practices Directive 2005/29/EC — Annex I (EU text as adopted) ↗
The list of practices unfair in all circumstances. No. 7: falsely stating that a product or terms are available only for a very limited time to elicit an immediate decision. No. 11: paid editorial content not clearly identified as such (advertorial).
- Unfair Commercial Practices Directive 2005/29/EC — Article 7, misleading omissions (EU text as adopted) ↗
Hiding material information, or giving it in an unclear or untimely manner, is a misleading omission; in an invitation to purchase, material information includes the price inclusive of taxes and any additional delivery charges (Art. 7(4)(c)). Article 6(1)(b) of the same directive covers deception about a product’s availability.
- Directive (EU) 2019/2161 (Omnibus) — Article 3, amending the UCPD (EU text as adopted) ↗
Inserts UCPD Article 13(3)–(4): in coordinated cross-border enforcement the maximum fine must be at least 4% of the trader’s annual turnover in the member states concerned, or at least €2 million where turnover is unavailable. Inserts Article 11a: remedies for harmed consumers, including compensation, price reduction or termination.
- Consumer Rights Directive 2011/83/EU — Article 22, additional payments (EU text as adopted) ↗
The trader must seek the consumer’s express consent to any extra payment before the contract binds them; consent inferred from default options the consumer must reject entitles the consumer to reimbursement of that payment.
- GDPR — Article 4, definitions ↗
Article 4(11) defines consent as a freely given, specific, informed and unambiguous indication of the data subject’s wishes, by a statement or by a clear affirmative action.
- GDPR — Recital 32, conditions for consent ↗
States that “silence, pre-ticked boxes or inactivity should not therefore constitute consent”, and that a request for consent by electronic means must be clear, concise and not unnecessarily disruptive to the service.
- GDPR — Article 7, conditions for consent ↗
Article 7(2): a consent request combined with other matters must be clearly distinguishable and use clear and plain language. Article 7(3): it must be as easy to withdraw consent as to give it.
- EDPB — Guidelines 03/2022 on deceptive design patterns in social media platform interfaces ↗
Version 2.0, adopted on 14 February 2023 after public consultation. Groups deceptive design patterns into six categories: overloading, skipping, stirring, obstructing, fickle and left in the dark, each defined in the executive summary.
- Légifrance — CNIL Délibération SAN-2021-023 of 31 December 2021 (Google) ↗
The decision against Google LLC and Google Ireland under Article 82 of the French data-protection law: cookies could be accepted with one click on “J’accepte”, while refusing took at least five actions via a customisation screen and a confirmation step.
- CNIL — Sanctions issued by the CNIL ↗
Lists the decisions of 31 December 2021 fining Google €150 million and Facebook €60 million over the procedures for refusing cookies.
- Digital Services Act — Article 25, online interface design and organisation ↗
Full text of Article 25: the prohibition on deceptive or manipulative interfaces for online platforms, its exclusion of practices covered by Directive 2005/29/EC or the GDPR, and the three practices on which the Commission may issue guidelines.
- Digital Services Act — list of articles ↗
Shows Article 25 within Chapter III, Section 3 (additional provisions for online platforms, Articles 19–28), whose Article 19 excludes micro and small enterprises.
- European Commission — Commission fines X €120 million under the Digital Services Act (IP/25/2934, 5 December 2025) ↗
The first DSA non-compliance decision: €120 million for three breaches, including the deceptive design of the blue checkmark under Article 25(1); preliminary findings were adopted on 12 July 2024. No per-breach breakdown is given.
- European Parliament — Legislative Train: Digital Fairness Act ↗
Status “announced”; the Commission work programme places the proposal in Q4 2026; the public consultation closed on 24 October 2025. Page last updated 1 August 2026.
- European Commission — Commission launches open consultation on the forthcoming Digital Fairness Act ↗
The consultation ran from 17 July to 24 October 2025 and covered deceptive or manipulative interface design, misleading influencer marketing, addictive design, unfair personalisation and the protection of minors online.
- FTC — FTC Secures Historic $2.5 Billion Settlement Against Amazon (25 September 2025) ↗
A $1 billion civil penalty and $1.5 billion in refunds to an estimated 35 million consumers over Prime enrolment and cancellation; requires a clear decline button (no more “No, I don’t want Free Shipping”) and cancellation by the same method used to sign up.
- FTC — Fortnite video game maker Epic Games to pay more than half a billion dollars over FTC allegations (19 December 2022) ↗
$245 million in refunds over dark patterns that led to unwanted charges, plus a $275 million COPPA penalty; alleges single-button charges and the locking of accounts of customers who disputed unauthorised charges.
— FAQ
Frequently asked questions
Want a checkout that earns its yes?
Tell us what your site or shop asks customers to do, and we will tell you plainly what we would change — including when the honest answer is that it is already fine and you do not need us.