Blogs

Dark Patterns and the Consumer Protection (E-Commerce) (Amendment) Rules, 2026: What Every E-Commerce Entity Must Fix Before 1 January 2027

Adv Sanchit Bhatia (Advocate)   |   07 Oct 2026

(5.0)
59 Views

Regulatory Alert · Consumer Protection / E-Commerce · September 2026

Quick Answer: On 9 September 2026, the Department of Consumer Affairs notified the Consumer Protection (E-Commerce) (Amendment) Rules, 2026 (G.S.R. 789(E)), which come into force from 1 January 2027. For the first time, compliance with the CCPA's Guidelines for Prevention and Regulation of Dark Patterns, 2023 is no longer just an advisory expectation - it is now a binding obligation under Rule 4 of the Consumer Protection (E-Commerce) Rules, 2020, backed by a mandatory annual self-audit and a compliance certificate that every e-commerce entity must prominently display on its platform.

By the LexComply Advisory & Compliance Team

Last updated: 7 October 2026 · Content current as of 29 September 2026

What Are the Key Takeaways From the 2026 Dark Patterns Amendment?

  • Dark-pattern compliance moves from guideline to rule: the 2026 Amendment inserts a specific sub-rule under Rule 4 requiring compliance with the 2023 Guidelines, an annual self-audit, and a displayed compliance certificate.
  • The 13 "specified dark patterns" under the 2023 Guidelines remain unchanged - but several are now independently codified as rule violations (e.g., manipulating search results is now barred under the new Rule 4(11)(c), on top of already being "Interface Interference" under the Guidelines).
  • New, connected obligations arrive in the same amendment: sponsored-listing disclosure, mandatory "prior price" display for any price reduction, invoice font-size parity between seller and platform names, and a ban on using consumer data to self-promote private-label goods without express consent.
  • Effective date: 1 January 2027 - giving platforms roughly 3.5 months from notification to align systems, run their first audit, and prepare the certificate.
  • This is not confined to e-commerce anymore: IRDAI has already directed insurance entities selling on e-platforms to comply with the same 2023 Guidelines, and has flagged that RBI is separately watching dark patterns in the financial sector - a sign more sectoral regulators will follow.
  • Who is unaffected: platforms that do not offer goods/services "systematically" in India, or that do not fall within the "e-commerce entity" / "marketplace e-commerce entity" definitions under the 2020 Rules - but the definition is broad, and the compliance bar keeps rising for everyone inside it.

What Is a Dark Pattern Under Indian Consumer Protection Law?

Under Rule 2(e) of the Guidelines for Prevention and Regulation of Dark Patterns, 2023 (notified 30 November 2023 by the CCPA under Section 18 of the Consumer Protection Act, 2019), a dark pattern is any practice or deceptive design using UI/UX interactions on a platform that is designed to mislead or trick users into doing something they did not originally intend, by subverting or impairing their autonomy, decision-making or choice - and which amounts to a misleading advertisement, an unfair trade practice, or a violation of consumer rights.

Two things stand out in that definition. First, it is not limited to a closed list - the Guidelines define "specified dark patterns" (Annexure 1) as the 13 named practices and any other pattern the CCPA chooses to specify later. Second, the prohibition applies to "any person, including any platform" (Rule 4) - so the obligation sits on platforms, sellers, and advertisers alike, not just the marketplace operator.

What Are the 13 Specified Dark Patterns Under the 2023 Guidelines?

Pattern What it means Typical example
False Urgency Falsely implying urgency or scarcity "Only 2 rooms left! 30 others are viewing this now" without basis
Basket Sneaking Adding items/charges at checkout without consent Pre-ticked travel insurance or "charity" add-ons
Confirm Shaming Guilt/shame language to force a choice "I will stay unprotected" instead of a neutral decline
Forced Action Requiring unrelated purchases, sign-ups, or data to complete a transaction Forcing newsletter sign-up to buy a product
Subscription Trap Making cancellation hard, hidden, or requiring payment details for a "free" trial Multi-step, buried cancellation flows
Interface Interference Design that highlights one choice and buries another A close "X" that opens another ad instead of closing
Bait and Switch Advertising one outcome, delivering another "Out of stock" at checkout, pricier item offered instead
Drip Pricing Hiding price elements until late, or charging more than shown at payment Flight priced at X, charged Y at payment
Disguised Advertisement Ads dressed up as organic content Sponsored listings that look like search results
Nagging Repeated, persistent interruptions for a commercial purpose Constant app-download or notification prompts
Trick Question Deliberately confusing wording to misdirect Double negatives in opt-out language
SaaS Billing Exploiting recurring billing to extract payment surreptitiously Silent auto-renewal without notice
Rogue Malware Fake virus/malware alerts to extract payment Scareware demanding payment for a "fix"

Each pattern in the Guidelines comes with formal illustrations - useful reference material for UX and legal teams auditing a platform, since the CCPA has effectively pre-answered several "is this borderline?" questions through worked examples.

Who Has to Comply With the Dark Patterns Guidelines in India?

Per Rule 3 of the 2023 Guidelines, the framework applies to: (i) all platforms systematically offering goods or services in India, (ii) advertisers, and (iii) sellers. Rule 6 clarifies the Guidelines do not dilute any other applicable law - they sit in addition to sectoral regulation, not instead of it. That "in addition to" language is exactly what let IRDAI layer the same Guidelines onto insurance e-platforms without needing fresh legislation (more in Section 8).

What Is the Compliance Timeline From Advisory to Binding Rule?

  • 30 November 2023 - CCPA notifies the Guidelines for Prevention and Regulation of Dark Patterns, defining the 13 patterns and prohibiting them outright (Rule 4: "No person... shall engage in any dark pattern practice").
  • 7 June 2025 - CCPA issues an advisory asking all e-commerce platforms to self-audit within 3 months and file self-declarations; a Joint Working Group (with ministries, regulators, consumer bodies and NLUs) is set up to track violations.
  • 2026 - CCPA begins enforcing the Guidelines through actual penalty orders against platforms found non-compliant, signalling the advisory phase is over.
  • 2 April 2026 - IRDAI extends the same compliance expectation to insurance entities selling on e-platforms, giving them 15 days for self-assessment and one month for a corrective action plan wherever gaps are found - and flags that RBI is watching dark patterns in the wider financial sector too.
  • 9 September 2026 - The Consumer Protection (E-Commerce) (Amendment) Rules, 2026 are notified, converting dark-pattern compliance from a Guidelines-level obligation into a Rules-level one, with an audit-and-certification mechanism attached.
  • 1 January 2027 - The Amendment Rules come into force.

What Do the E-Commerce Amendment Rules, 2026 Actually Change?

5.1 The headline change: dark patterns become an audited, certified obligation

The amendment inserts a new sub-rule into Rule 4 of the Consumer Protection (E-Commerce) Rules, 2020: every e-commerce entity must comply with the 2023 Dark Patterns Guidelines, conduct a yearly self-audit to confirm its platform is free of dark patterns, and prominently display a certificate confirming that. This is the single most consequential line in the amendment - it converts a set of prohibitions into an active, recurring, documented compliance exercise, with a public-facing artifact (the certificate) that a regulator, competitor, or consumer can point to.

5.2 Disclosure and transparency obligations (Rule 4)

  • Entity identity disclosure: legal name, principal geographic address of headquarters and all branches, website details, and contact details (email, landline, mobile) for both customer care and the grievance officer - all displayed clearly and prominently.
  • Grievance timelines, now codified: the grievance officer must acknowledge a complaint within 48 hours, provide the complainant a copy of the recorded complaint, and resolve it within one month.
  • Import disclosures: where an entity sells imported goods/services, it must name the importer and disclose the full country of origin, aligned with the Legal Metrology (Packaged Commodities) Rules, 2011.
  • National Consumer Helpline convergence: every e-commerce entity must now participate in the Centre's NCH convergence process.

5.3 Search, ranking and sponsored-content rules

A new clause under Rule 4(11) explicitly bars entities from misleading users by manipulating search results or indexes relative to their search query - this closes a gap where "Interface Interference" or "Bait and Switch" under the Guidelines could otherwise be argued as a design choice rather than a rule violation. Sponsored listings must now be distinctly identified with clear, prominent disclosure - directly addressing the "Disguised Advertisement" pattern.

5.4 Pricing transparency - the "prior price" requirement

Where a platform or seller announces a price reduction, it must now show the reduced price alongside the prior price, defined as the lowest price of that good/service in the 30 days preceding the announcement. This is a direct, enforceable counter to "Drip Pricing" and to the "false urgency" illustration in Annexure 1 about manufactured discounts.

5.5 Invoice parity and marketplace data-use restrictions

  • Sellers' names must appear on invoices in the same font size as the e-commerce entity's own name - a small but pointed fix aimed at platforms that visually diminish third-party sellers to imply the sale is direct.
  • Marketplace entities are now barred from using consumer data to (a) sell goods under a brand/name common with the marketplace's own, or (b) promote/advertise a seller as "associated" with the marketplace - unless express, affirmative consumer consent is obtained. This targets the self-preferencing concern that has dogged large marketplaces for years.
  • Marketplace entities also cannot collect bundled fees for unrelated services - loyalty/membership programmes are specifically carved out as permitted.

5.6 Seller-side disclosure (Rules 5, 6 and 7)

Sellers must now disclose ratings/aggregated feedback, and - critically - GST Identification Number and MSME registration number, where applicable (new Rule 6(5)(j)). Post-purchase, marketplace entities must furnish full seller contact details on a consumer's written request, to support dispute resolution. Platforms must also publish, in plain language, the main ranking parameters in descending order of importance - directly operationalising transparency around how search/ranking algorithms decide what a consumer sees first.

Old Position vs New Position: What Changes on 1 January 2027?

Requirement Before the 2026 Amendment From 1 January 2027
Dark pattern compliance Advisory/Guidelines-level expectation (2023 Guidelines + 2025 advisory) Binding Rule 4 obligation with annual self-audit + displayed certificate
Search manipulation Covered only indirectly via "Interface Interference"/"Bait and Switch" illustrations Explicitly barred under new Rule 4(11)(c)
Price-drop claims No standardised "prior price" reference point Must show 30-day lowest price alongside any discounted price
Sponsored listings No explicit rule-level disclosure requirement Must be distinctly and prominently identified
Seller visibility on invoices No font-size requirement Seller name must match e-commerce entity's font size
Marketplace self-promotion using consumer data Not directly addressed at Rules level Requires express, affirmative consumer consent

Does This Reach Beyond E-Commerce? IRDAI, RBI and the Sectoral Ripple Effect

The 2026 Amendment is not happening in isolation. On 2 April 2026, IRDAI directed all regulated entities offering insurance products on e-platforms to comply with the same CCPA Guidelines, requiring a 15-day self-assessment and, where gaps exist, a one-month corrective action plan. IRDAI's press release explicitly notes that RBI has separately flagged concerns about dark patterns in digital financial interfaces. Because Rule 6 of the 2023 Guidelines makes clear they apply "in addition to" other sectoral law, expect this pattern to continue: rather than each regulator drafting its own dark-pattern rulebook, they are increasingly cross-referencing the CCPA's existing framework. For any group with e-commerce, insurance, lending, or payments arms, this means dark-pattern compliance is fast becoming a group-wide, not just an e-commerce-vertical, obligation.

What Open Items Should Compliance Teams Watch Before 1 January 2027?

  • Audit methodology and certificate format: the amendment mandates a "yearly self-audit" and a displayed "certificate to this effect," but does not prescribe a template, scope checklist, or third-party verification requirement. Watch for an implementation circular or standard format from the Department of Consumer Affairs.
  • Penalty quantum specific to the amendment: the amendment itself does not restate penalty figures; enforcement continues to draw on the Consumer Protection Act, 2019's general powers (CCPA directions under Section 20/21, with penalties escalating for repeat non-compliance, and separate consequences for failing to comply with CCPA orders).
  • Interaction with DPDP Act consent requirements: several dark patterns (Forced Action, Trick Question) overlap with consent-design issues also relevant under the Digital Personal Data Protection Act, 2023 - particularly around forced data-sharing and unclear consent language. Entities running DPDP compliance programmes should treat this amendment as a natural checkpoint to align both workstreams rather than run them separately.
  • Grandfathering/transition guidance: no specific transition mechanism is set out for platforms mid-way through a product or pricing cycle as of 1 January 2027; confirm via any forthcoming FAQ from the Department.

What Are the Action Points for Businesses Before the Deadline?

Product / UX

  • Audit checkout flows against all 13 specified patterns using the Annexure 1 illustrations as a literal checklist, not just the pattern names.
  • Rebuild price-drop UI to compute and display the mandatory 30-day "prior price."
  • Separate sponsored listings visually and label them explicitly.
  • Set up the annual self-audit process now - do not wait for a template; document methodology, findings, and remediation as you go.
  • Prepare the compliance certificate design and placement strategy for prominent display.
  • Map every consumer-data use in marketing/self-promotion flows against the new express-consent requirement.

Marketing / Growth

  • Review re-engagement flows (notifications, "abandoned cart" nudges, urgency banners) against Nagging and False Urgency definitions specifically.
  • Audit affiliate/brand-common product promotions for the new consent requirement before the effective date.

Finance / Pricing

  • Build the 30-day price-history tracking needed to compute "prior price" correctly and consistently.
  • Review bundled-fee structures for anything unrelated to the core e-commerce service that is not part of a loyalty/membership programme.

How Does LexComply Facilitate Your Dark-Pattern Self-Audit and Compliance Risk Assessment?

The compliance gap most entities will actually face is not knowing the rules - it is running a defensible annual self-audit and standing behind the certificate it produces. That is where LexComply's role sits: less a software vendor handing over a checklist, more an advisory partner that scopes, facilitates and documents the audit itself, with GCMS as the system of record underneath it.

  • Annual self-audit, facilitated end-to-end: our advisory team scopes and runs the yearly dark-pattern audit against your live checkout, search, pricing and marketing flows - working through all 13 specified patterns using the CCPA's own Annexure 1 illustrations as the test, not a generic checklist, so the audit stands up to the same scrutiny a regulator would apply.
  • Evidence-backed compliance certificate: we help design the audit methodology, document findings and remediation, and prepare the compliance certificate for prominent display - so what goes on your platform is a defensible, evidenced sign-off, not an internal rubber stamp with no paper trail behind it.
  • Advisory on borderline design decisions: before a UI/UX pattern ships, our advisory desk benchmarks it against the CCPA's worked illustrations and emerging enforcement - catching a Confirm Shaming or Interface Interference risk in design review is materially cheaper than remediating it after a regulator flags it.
  • Group-wide advisory across sectors: for corporate groups with e-commerce, insurance, or lending arms, we coordinate one consistent audit-and-advisory approach across every regulated entity - working with each vertical's own regulator (CCPA, IRDAI, RBI) rather than leaving each business unit to interpret the Guidelines independently.
  • Joint audit with your DPDP workstream: where a dark-pattern finding overlaps with consent-design issues (Forced Action, Trick Question), our advisory team reviews it alongside your DPDP Act consent audit, so the two compliance exercises run as one engagement rather than two disconnected ones.
  • GCMS as the audit's system of record: the underlying platform tracks the statutory obligation the moment a notification like G.S.R. 789(E) is issued, assigns owner-tagged tasks across Product, Legal, Marketing and Finance, and stores each year's audit evidence and remediation trail - supporting the advisory relationship, not replacing it.

What Are the Common Mistakes to Avoid Before 1 January 2027?

Every point below restates an obligation already set out above; none of them adds a new rule.

  • Treating the 2023 Guidelines as advisory. From 1 January 2027 the self-audit and the displayed certificate are Rule 4 obligations, not expectations.
  • Running the audit on pattern names alone. The Guidelines carry formal illustrations in Annexure 1, and those worked examples are the test.
  • Reading the 13 patterns as the whole universe. The Guidelines allow the CCPA to specify further patterns later.
  • Assuming the obligation sits only on the marketplace operator. Rule 4 of the Guidelines applies to any person, including any platform, and Rule 3 covers advertisers and sellers too.
  • Computing a discount against a list price. The prior price is the lowest price of that good or service in the 30 days preceding the announcement.
  • Waiting for a certificate template before starting. No format, scope checklist or third-party verification requirement has been prescribed, and the deadline does not move for that.
  • Running the dark-pattern review and the DPDP consent review as two separate exercises. Forced Action and Trick Question overlap with consent design under the Digital Personal Data Protection Act.
  • Scoping the work to the e-commerce arm alone. IRDAI has already applied the same Guidelines to insurance entities on e-platforms.

This article is provided for general informational purposes and does not constitute legal advice. Verify current provisions against the Gazette notification and any subsequent Department of Consumer Affairs circulars before relying on them.

Frequently Asked Questions

When do the Consumer Protection (E-Commerce) (Amendment) Rules, 2026 come into force?

1 January 2027. The Rules were notified on 9 September 2026, giving entities roughly 3.5 months to prepare.

Is dark-pattern compliance now mandatory, or still just advisory?

Mandatory. The amendment inserts a binding sub-rule into Rule 4 requiring compliance with the 2023 Guidelines, an annual self-audit, and a prominently displayed compliance certificate.

Do the 13 specified dark patterns change under the new amendment?

No - the 13 patterns and their definitions under the 2023 Guidelines are untouched. The amendment adds new, connected obligations (search-manipulation ban, price transparency, sponsored-listing disclosure) that reinforce several of the same patterns at the Rules level.

Does this apply only to large marketplaces?

No. The Guidelines apply to "all platforms systematically offering goods or services in India," plus advertisers and sellers - not just large marketplace operators.

Is this limited to e-commerce, or does it affect other sectors?

It started in e-commerce, but IRDAI has already extended the same Guidelines to insurance entities on e-platforms (April 2026), and has flagged RBI's parallel concern in the financial sector - expect further sectoral extension.

What happens if a platform does not comply?

The amendment itself does not set out a new penalty scale; enforcement continues under the Consumer Protection Act, 2019's existing powers for unfair trade practices and non-compliance with CCPA directions.

Can LexComply help run our dark-pattern self-audit?

Yes - this is the core of our advisory role under the amendment. LexComply's advisory team scopes and facilitates the annual self-audit against the CCPA's own Annexure 1 illustrations, documents findings and remediation, and supports the compliance-certificate sign-off, with GCMS maintaining the underlying evidence trail.

Sources

  • Consumer Protection (E-Commerce) (Amendment) Rules, 2026, G.S.R. 789(E), dated 9 September 2026, Department of Consumer Affairs, Ministry of Consumer Affairs, Food and Public Distribution (F. No. J-10/3/2018-CPU).
  • Guidelines for Prevention and Regulation of Dark Patterns, 2023, F. No. CCPA-1/1/2023-CCPA(Reg), dated 30 November 2023, Central Consumer Protection Authority.
  • Press Release, Insurance Regulatory and Development Authority of India (IRDAI), "Compliance with Guidelines on Prevention and Regulation of Dark Patterns," 2 April 2026.
  • Consumer Protection (E-Commerce) Rules, 2020, G.S.R. 462(E), dated 23 July 2020 (principal rules being amended).