A combined DPDP and consumer-protection review of consent interfaces, deceptive defaults, confirm shaming, forced action, interface interference and withdrawal obstruction.
A technically clickable decline button does not create a fair choice when it is hidden, misleading or repeatedly overridden.
The DPDP framework is phased. The 14 November 2025 commencement notification brought specified institutional and enabling provisions into force immediately; Consent Manager-related provisions follow after one year; most operating duties and Rules follow eighteen months after Gazette publication. As of 22 June 2026, the control should distinguish current obligations from future-state DPDP readiness.
CCPA’s 2023 Guidelines prohibit specified deceptive design practices, and its 2025 advisory urged e-commerce platforms to conduct dark-pattern self-audits.
DPDP consent is expected to be free, specific, informed, unconditional and unambiguous with clear affirmative action when operative.
Dark patterns can affect subscription, pricing, basket additions, account deletion, marketing and data permissions.
| Check | What to examine |
|---|---|
| Choice | Equal visibility and understandable consequence. |
| Default | Pre-selection, opt-out and forced continuity. |
| Language | Confirm shaming, scarcity and urgency. |
| Journey | Signup, purchase, cancellation and withdrawal. |
| Evidence | Screens, experiment variants and conversion pressure. |
A subscription screen uses a bright ‘Continue’ button and a grey link saying ‘No, I prefer to lose my benefits.’ The wording and visual hierarchy pressure the user beyond neutral explanation.
Review all A/B variants, not only the legal-approved base screen. Growth experiments can introduce dark patterns after sign-off.
Include product metrics that detect repeated reversal, accidental purchase, complaint and cancellation friction.
Identify the people, data, systems, purpose, owner, processor, user journey and failure scenario. Review choice, default and language together. A policy statement or vendor assurance cannot replace evidence of how the live product behaves.
Apply the 14 November 2025 commencement notification provision by provision. Continue complying with currently operative CERT-In, banking, telecom, insurance, employment, consumer, contract and criminal-law requirements. Build the scheduled DPDP workflow now, but do not describe a future provision as already enforceable.
Run the workflow in the live or controlled test environment. Preserve screenshots, approvals, logs, vendor responses, user communications, exceptions and remediation. Assign a named owner and completion date to every failed control so management can distinguish an operating safeguard from a policy intention.
Privacy and cyber maturity are visible in operating behaviour: what the organisation collects, who can use it, how vendors are controlled, how users exercise choices, how incidents are handled and whether evidence survives scrutiny.
Use the current official instrument, portal or regulator publication before acting. This panel separates the category authority from page-specific references.