Skip to content

Dark Patterns: Deceptive Design and the Consent Dialog

Abstract

In July 2010 the British UX designer Harry Brignull registered darkpatterns.org to name and shame interfaces built to trick their users: the subscription that is easy to start and hard to leave, the “No thanks, I don’t like saving money” button, the settings page that shares more than the user meant to. The name stuck and the catalogue grew. Academic crawls found such designs on 11,000 shopping sites in 2019 and on almost nine in ten of the consent pop-ups sampled from the UK’s most-visited websites in 2020; regulators then turned the vocabulary into law. France fined Google and Facebook €210 million in 2022 for cookie banners that took one click to accept and several to refuse, the EU’s Digital Services Act banned deceptive interface design on online platforms, and the US Federal Trade Commission extracted $245 million from Epic Games and $2.5 billion from Amazon, whose internal name for its Prime cancellation path was the “Iliad”.

Before the Name

Selling by making refusal hard is older than software. The US Federal Trade Commission’s Negative Option Rule of 1973, in force from 1974, was written for the book-of-the-month and record clubs, which shipped goods and billed for them unless the customer returned a card in time. The rule covered those prenotification plans and nothing else, and for decades it did not reach the automatic renewals and free trials that moved online.

Brignull’s Library

Harry Brignull, a designer with a doctorate in cognitive science, registered darkpatterns.org on 28 July 2010 as a “pattern library with the specific goal of naming and shaming deceptive user interfaces.” Design pattern libraries were a familiar genre in interaction design, catalogues of good solutions to recurring problems; Brignull’s was a catalogue of bad ones, each with a memorable name and screenshots of real examples. The catalogue included:

  • Roach motel: easy to get into, hard to get out of, such as a subscription taken out in two clicks that can be cancelled only by phone or letter.
  • Confirmshaming: the decline option worded to embarrass the user into accepting.
  • Privacy Zuckering, named after Mark Zuckerberg: tricking users into sharing more personal information than they intended.
  • Friend spam: asking for access to a user’s contacts on a pretext and then messaging them in the user’s name.
  • Bait and switch, sneak into basket, hidden costs and disguised ads, each doing what its name says.

The names did the work that a taxonomy does in any young field. A product manager could be told that a flow was a roach motel, a journalist could write a story around a screenshot, and a regulator could cite a category. Brignull later worked as an expert witness in deceptive-design litigation, moved the site to deceptive.design, replaced “dark patterns” with “deceptive patterns” on the advice of the World Wide Web Foundation’s Tech Policy Design Lab to avoid associating darkness with badness, and published the book Deceptive Patterns in 2023. The older term had by then entered the statute books and stayed there.

The First Lawsuits

An early case built on what Brignull’s list called friend spam was Perkins v. LinkedIn, filed in 2013. LinkedIn’s “Add Connections” feature asked new members for access to their email address book and then sent invitations to join LinkedIn, in the member’s name and with their photograph, to the contacts it found; anyone who did not respond received two more reminders. Judge Lucy Koh let the claims about the reminder emails go forward, and in 2015 LinkedIn settled for $13 million on behalf of about 20.8 million members, and changed its disclosures and let members cancel pending invitations.

Measuring It

Academic study followed the vocabulary. Colin Gray and colleagues at Purdue collected examples that practitioners had posted online and, in a paper for the 2018 CHI conference, sorted Brignull’s categories into five broader strategies: nagging, obstruction, sneaking, interface interference and forced action. The first large measurement came in 2019, when a Princeton and University of Chicago team led by Arunesh Mathur crawled about 53,000 product pages on some 11,000 shopping websites. They found 1,818 instances of dark patterns in 15 types, from fake countdown timers to “only 2 left in stock” messages that were not true, identified 183 sites whose patterns were outright deceptive, and found 22 third-party companies selling such features to retailers as ready-made plug-ins. The last finding mattered to regulators: some of the manipulation came as a service, from a small number of vendors.

The Consent Dialog

The General Data Protection Regulation, applied from May 2018, required that consent to the processing of personal data be freely given, specific, informed and unambiguous. Its most visible result was the cookie consent pop-up, and most sites bought theirs from a handful of consent-management platforms. In 2020 Midas Nouwens and colleagues at MIT, UCL and Aarhus scraped the designs of the five most popular such platforms on the top 10,000 websites in the UK, 680 sites in all, and found that only 11.8 percent met the minimal requirements of European law as the authors read it: no pre-ticked boxes, explicit consent, and refusal as easy as acceptance. A field experiment with 40 participants then measured the effect of the designs. Removing the “reject” button from the first page raised consent by 22 to 23 percentage points; putting granular controls on the first page lowered it by 8 to 20.

On 6 January 2022 the French data-protection authority, the CNIL, published fines of €90 million on Google LLC, €60 million on Google Ireland and €60 million on Facebook Ireland, €210 million in all, because google.fr, YouTube and facebook.com let users accept all cookies with one click and required several to refuse them. The legal basis was the French transposition of the ePrivacy Directive rather than the GDPR, which let the CNIL act without deferring to the Irish regulator. The companies were given three months to offer a refusal as simple as the acceptance, or pay €100,000 for each day of delay.

Dead End: Notice and Consent

The consent pop-up was the application of a theory: that privacy could be protected by telling people what would happen to their data and letting them choose. The Nouwens experiment showed how that theory fails in practice. The choice was real on paper, but the site controlled the layout of the choice, and a layout could move a quarter of the answers without changing a word of the legal text. Users confronted with a banner on every site learned to click whatever made it go away, which on most sites was “accept”; Surveillance Capitalism describes the same habit from the side of the data it released. Regulators responded by regulating the layout itself: the CNIL’s fines were for the number of clicks, not for the wording.

Law

The terminology passed into statute within a decade of Brignull’s website. The US DETOUR Act of 2019 proposed to ban deceptive design on platforms with more than 100 million users; it did not pass. The California Privacy Rights Act, approved by voters in November 2020, provided that agreement obtained through dark patterns is not consent. In September 2022 the FTC staff published Bringing Dark Patterns to Light, a report drawn from a workshop held in April 2021, covering e-commerce, cookie banners, children’s apps and subscription cancellation.

The European Union’s Digital Services Act, adopted on 19 October 2022 and applying to all platforms from 17 February 2024, states in Article 25 that providers of online platforms “shall not design, organise or operate their online interfaces in a way that deceives or manipulates” their users or impairs their ability to make free and informed decisions. The first penalty under the Act, on 5 December 2025, was €120 million against X, and the deceptive design of its blue checkmark was one of the three breaches named: anyone could buy the “verified” badge without the company meaningfully checking who was behind the account.

The FTC’s own attempt at a general rule did not survive. Its amended Negative Option Rule of October 2024, known as “click to cancel”, required that a subscription be as easy to end as to start; on 8 July 2025, six days before it was due to take effect, the US Court of Appeals for the Eighth Circuit vacated it on procedural grounds, and in March 2026 the FTC reopened the rulemaking.

Epic and Amazon

The largest American cases were brought under existing law. In December 2022 Epic Games, the maker of Fortnite (see Tim Sweeney), agreed to pay $520 million to settle two FTC complaints: $275 million for violating the Children’s Online Privacy Protection Act and $245 million in refunds for design that led players, many of them children, into unwanted purchases, including button layouts where a single press bought an item, and for locking the accounts of customers who disputed charges with their credit card companies. The order was finalised in March 2023.

In June 2023 the FTC sued Amazon, alleging that its checkout pages enrolled customers in Prime without clear consent and that its cancellation process was designed to stop them leaving. Internally, according to the complaint, the multi-page cancellation path was called the “Iliad Flow”, after Homer’s epic of a long war, and employees described subscription practices as “a bit of a shady world” and pushing customers into unwanted subscriptions as “an unspoken cancer.” On 25 September 2025 Amazon settled for $2.5 billion, a $1 billion civil penalty and $1.5 billion in refunds to about 35 million customers, and agreed to put a clear button for declining Prime on its pages and to let customers cancel by the same method they had used to sign up.

📚 Sources