Deceptive interface design used to be a UX ethics debate; in the EU it is now a legal violation reachable by three regimes at once. The Digital Services Act prohibits dark patterns on platforms outright, the GDPR voids consent obtained through them, and consumer law catches the commercial variants. The common principle: a choice engineered so users cannot realistically make it freely does not count as a choice.
| Rule sources | DSA Art. 25; GDPR Arts. 4(11), 5(1)(a), 7, 25; UCPD |
|---|---|
| Max penalty | 6% of turnover (DSA); EUR 20M or 4% (GDPR) |
| Key guidance | EDPB Guidelines 03/2022 on dark patterns |
| Official text | EUR-Lex CELEX 32022R2065 |
Three legal hooks for one behavior
DSA Article 25 addresses platform interface design directly: no designing, organizing, or operating interfaces in a way that deceives or manipulates users or materially distorts their free and informed decisions. It applies to online platforms, with the Commission empowered to issue guidance on specific practices like repetitive consent nagging and difficult cancellations.
GDPR gets there through validity and fairness. Consent must be freely given, specific, informed, and unambiguous (Article 4(11)); a banner where refusal takes four clicks fails that test, which is exactly how the CNIL built its EUR 150 million Google and EUR 60 million Facebook decisions. Data protection by design (Article 25) and the fairness principle (Article 5(1)(a)) cover manipulative defaults beyond consent screens.
Consumer law rounds it out: the Unfair Commercial Practices Directive catches misleading and aggressive commercial design, which is how European consumer authorities pressured subscription cancellation mazes; Amazon simplified Prime cancellation in Europe in 2022 after coordinated action by the Commission and national authorities.
The EDPB’s Guidelines 03/2022 give the working taxonomy: overloading (drowning users in requests), skipping (design that makes users forget the data dimension), stirring (emotional steering), hindering (obstruction of privacy actions), fickle (inconsistent interfaces), and left in the dark (hiding information or controls).
What to fix first
Audit the money paths and the privacy paths with the same question: is the protective choice as easy as the profitable one? Concretely: reject as easy as accept on consent banners; cancellation flows no longer than signup; no pre-ticked boxes anywhere consent matters; neutral button styling and wording; withdrawal of consent one click from every page (GDPR Article 7(3)); and no fake urgency or guilt copy at decision points.
Then verify behavior, not just appearance, because a compliant-looking banner backed by pre-consent tag firing is a dark pattern plus a tracking violation. A free scan checks what actually fires before and after consent on your pages. Related: consent management requirements and DSA platform obligations.