top of page

CCPA Cracks Down on 'Dark Patterns' on Digital Platforms; Fines PhysicsWallah ₹5 Lakh and McAfee ₹1 Lakh. DigitalEthics, ConsumerProtectionIndia, DeceptivePractices

  • Jun 3
  • 3 min read

Action Taken for Misleading Consumers and Adding Unauthorized Charges; Companies Directed to Discontinue Deceptive Interface Designs Immediately

New Delhi, June 3, 2026

The Central Consumer Protection Authority (CCPA), led by Chief Commissioner Nidhi Khare and Commissioner Anupam Mishra, has taken major action against 'dark patterns' (deceptive user interface designs) used on digital platforms to mislead consumers and manipulate their choices. The authority has imposed a penalty of ₹5 lakh on the edtech platform PhysicsWallah Limited and ₹1 lakh on cybersecurity firm McAfee Software India Private Limited.

The regulator has directed both companies to immediately remove these deceptive practices from their digital interfaces and ensure that consumers can make free and informed choices without any systemic pressure or manipulation. The penalties have been levied under the Consumer Protection Act, 2019, and the Guidelines for Prevention and Regulation of Dark Patterns, 2023.

1. PhysicsWallah (PW): Forced Data Collection and Pre-selected Mandatory Donations

The CCPA took suo motu (independent) cognizance of the interface design on the PhysicsWallah platform and found multiple elements that restricted consumers' ability to make free choices.

  • Basket Sneaking: During checkout, a ₹10 donation to the 'PW Foundation' was automatically added to the total payable bill without the explicit or active consent of the consumer.

  • Confirm Shaming: If a user attempted to remove the pre-selected donation, the interface displayed emotional messaging related to children's healthcare, education, and marriages to discourage them from opting out.

  • Forced Action: Courses advertised to the public as "free" could only be accessed after users mandatorily shared personal information, including their mobile numbers and email addresses. CCPA's investigation revealed that the course content remained identical regardless of data entry, proving that the mandatory data collection was not essential for course delivery.

CCPA's Observation: Since a vast majority of users on this edtech platform are students and minors, these practices raise severe consumer protection concerns. Consumer consent must always be obtained through a clear, affirmative action, and cannot be assumed via pre-ticked check boxes.

2. McAfee India: Deceptive Subscriptions Renewal Interface Using Fear Tactics

The CCPA also inspected McAfee's software renewal journey and found that the company denied consumers a neutral environment when deciding whether or not to extend their subscription.

  • Fear-Based Options: Users trying to manage their subscriptions were prominently presented with only two stark choices: "Renew Now" or "Accept Risk".

  • Interface Interference: By using the phrase "Accept Risk," the system deliberately implied that opting out of renewal would leave the user entirely exposed to imminent cybersecurity threats—a claim the company could neither definitively justify nor guarantee.

  • Trick Questions: The interface gave overwhelming visual prominence to the renewal link, utilizing loaded language to create artificial panic and pressure consumers into extending their paid subscriptions.

Regulatory Violations At a Glance

Both corporations were found in direct violation of the Consumer Protection Act, 2019, and accompanying digital marketplace rules:

Company

Provisions Violated

Nature of Deceptive Practice

PhysicsWallah

Sections 2(9), 2(28), 2(47) & E-Commerce Rules, 2020

Misleading advertisements (concealing mandatory registration rules for free courses), basket sneaking, confirm shaming, and automatic recording of consent via pre-ticked fields.

McAfee India

Sections 2(28), 2(47) & E-Commerce Rules, 2020

Manipulative interface design, fear-based representations regarding non-renewal consequences, and restricting explicit consumer opt-out choices.

CCPA’s Sustained Enforcement Against Deceptive Designs

The Guidelines for Prevention and Regulation of Dark Patterns were formally notified by the CCPA on November 30, 2023, identifying 13 distinct dark patterns—including basket sneaking, forced actions, and interface interference—as explicit forms of 'unfair trade practices'. Following up on enforcement, the authority had also issued a compliance advisory on June 5, 2025, directing all e-commerce platforms to run internal self-audits.

The current punitive orders reinforce the CCPA's stance that the Indian digital marketplace must remain fair and transparent. Consumer consent must always be explicit, informed, and completely free from manipulative design engineering.

Top Stories

1/15
bottom of page