EU Privacy Law EU/EEA

Dark Patterns Are Now Illegal in the EU: DSA Article 25, GDPR, and What Enforcers Target

How the DSA's dark pattern ban, GDPR consent rules, and consumer law combine against deceptive design, with the EDPB's taxonomy and real enforcement examples.

Regulation

DSA Article 25; GDPR Articles 4(11), 5, 7, 25; UCPD

Max Penalty

Up to 6% of global annual turnover (DSA); EUR 20 million or 4% (GDPR)

Enforcing Authority

European Commission and Digital Services Coordinators; national DPAs

Official Source

eur-lex.europa.eu

Executive Summary

  • DSA Article 25 prohibits online platforms from designing interfaces that deceive, manipulate, or materially distort users' ability to make free and informed decisions.
  • GDPR reaches the same conduct through consent validity: choices extracted through manipulative design are not freely given and are void.
  • The EDPB's Guidelines 03/2022 catalogue dark pattern families on social media: overloading, skipping, stirring, hindering, fickle, and left in the dark.
  • Enforcement is real: the CNIL's Google and Facebook cookie fines targeted reject-button asymmetry, and consumer authorities have pursued cancellation mazes like Amazon Prime's, which Amazon simplified in the EU in 2022.
  • US law converges: the CPRA states consent obtained through dark patterns is invalid, and the FTC's Epic Games settlement (USD 245 million, 2023) punished billing dark patterns.

Deceptive interface design used to be a UX ethics debate; in the EU it is now a legal violation reachable by three regimes at once. The Digital Services Act prohibits dark patterns on platforms outright, the GDPR voids consent obtained through them, and consumer law catches the commercial variants. The common principle: a choice engineered so users cannot realistically make it freely does not count as a choice.

Rule sourcesDSA Art. 25; GDPR Arts. 4(11), 5(1)(a), 7, 25; UCPD
Max penalty6% of turnover (DSA); EUR 20M or 4% (GDPR)
Key guidanceEDPB Guidelines 03/2022 on dark patterns
Official textEUR-Lex CELEX 32022R2065

DSA Article 25 addresses platform interface design directly: no designing, organizing, or operating interfaces in a way that deceives or manipulates users or materially distorts their free and informed decisions. It applies to online platforms, with the Commission empowered to issue guidance on specific practices like repetitive consent nagging and difficult cancellations.

GDPR gets there through validity and fairness. Consent must be freely given, specific, informed, and unambiguous (Article 4(11)); a banner where refusal takes four clicks fails that test, which is exactly how the CNIL built its EUR 150 million Google and EUR 60 million Facebook decisions. Data protection by design (Article 25) and the fairness principle (Article 5(1)(a)) cover manipulative defaults beyond consent screens.

Consumer law rounds it out: the Unfair Commercial Practices Directive catches misleading and aggressive commercial design, which is how European consumer authorities pressured subscription cancellation mazes; Amazon simplified Prime cancellation in Europe in 2022 after coordinated action by the Commission and national authorities.

The EDPB’s Guidelines 03/2022 give the working taxonomy: overloading (drowning users in requests), skipping (design that makes users forget the data dimension), stirring (emotional steering), hindering (obstruction of privacy actions), fickle (inconsistent interfaces), and left in the dark (hiding information or controls).

What to fix first

Audit the money paths and the privacy paths with the same question: is the protective choice as easy as the profitable one? Concretely: reject as easy as accept on consent banners; cancellation flows no longer than signup; no pre-ticked boxes anywhere consent matters; neutral button styling and wording; withdrawal of consent one click from every page (GDPR Article 7(3)); and no fake urgency or guilt copy at decision points.

Then verify behavior, not just appearance, because a compliant-looking banner backed by pre-consent tag firing is a dark pattern plus a tracking violation. A free scan checks what actually fires before and after consent on your pages. Related: consent management requirements and DSA platform obligations.

Frequently Asked Questions

What is a dark pattern legally?

Interface design that deceives or manipulates users or materially distorts their ability to make free and informed decisions, as DSA Article 25 phrases it. Examples: unequal accept/reject buttons, guilt-wording, forced continuity, hidden cancellation paths, and pre-selected choices.

Which law prohibits dark patterns in the EU?

Three overlap: DSA Article 25 for online platforms, GDPR wherever the design corrupts consent or violates fairness and data protection by design, and the Unfair Commercial Practices Directive for consumer transactions. Enforcers choose whichever fits the case.

Are asymmetric cookie banners a dark pattern?

Yes, and they are the most-fined example. The CNIL fined Google EUR 150 million and Facebook EUR 60 million in 2021 because accepting took one click and refusing took several. Equal prominence for accept and reject is the enforcement baseline.

Does the DSA dark pattern ban apply to my website?

Article 25 applies to online platforms, meaning services hosting and disseminating user content, such as marketplaces and social networks. But an ordinary website using manipulative consent design is still exposed under GDPR and consumer law, so the practical rule is the same for everyone.

How do I audit for dark patterns?

Walk the paths a hostile reviewer would: signup versus cancellation effort, accept versus reject effort, default states, wording pressure, and whether declining costs functionality it should not. Then verify technically what happens before and after each choice.

Regulatory Crosswalk

CPRA dark patternsFTC Act Section 5UCPD

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.