Dark pattern audit · Rule 4(15) · In force 1 January 2027
Evidence for the certificate someone at your company has to sign.
From 1 January 2027, every e-commerce entity in India must audit itself for dark patterns each year and prominently display a certificate that its platform is free of them. The rule prescribes no method, no evidence standard and no auditor. DarkPatternAudit tests your real customer journeys, seals what it observes, and gives your signatory a documented basis for the statement.
The rule
One sentence of law, and everything it leaves open
New sub-rule 4(15), inserted by G.S.R. 789(E) on 9 September 2026, requires every e-commerce entity to comply with the Guidelines for Prevention and Regulation of Dark Patterns, 2023, to “conduct yearly self-audit to ensure that its platform is free from dark patterns”, and to display a certificate to that effect prominently.
What it settles
- The 2023 Guidelines become binding for e-commerce entities.
- The audit is yearly, and it is a self-audit.
- The certificate is the entity's own, and it must be displayed prominently — so its absence is visible to anyone.
- It applies to every e-commerce entity, including brands selling from their own website.
What it leaves open
- No audit method, sampling rule or evidence standard.
- No certificate format, signatory or filing requirement.
- No recognised or empanelled third-party auditor.
- No meaning given to “prominently”.
The problem
The exposure is not the fine. It is the signature.
A named person has to stand behind an absolute public claim — that the platform is free from dark patterns — while the product team ships interface changes every week.
And the claim is tested in public. LocalCircles, a citizen platform, reported in 2025 that 21 of the 26 platforms that self-declared under the CCPA's advisory still showed at least one dark pattern.
A one-page declaration with nothing behind it is the weakest position to be in when that happens. A dated, reproducible record of what was tested, what was found and what was fixed is the strongest.
The method
Most dark patterns can't be seen on one screen
By our reading, eight of the thirteen patterns in the 2023 Guidelines only show up across steps, sessions or time: a timer that resets, a fee that appears at the last step, an item added to the cart without being asked for, a cancellation path far longer than sign-up. A page scanner looks at a single screen. We change one condition at a time and checks what an honest interface would have to do.
Session A, first load
09:59
“Only 2 left at this price”
Baseline recorded
Session A, reload after 3 minutes
09:59
Expected 06:59
Timer is not monotonic
Session B, fresh profile, +20 minutes
09:59
“Only 2 left at this price”
Scarcity claim never varies
Session A, after the stated deadline
00:00
Same offer, same price
Offer outlives its deadline
Decided by test
Where the question is objective — timers, cart contents, price arithmetic, default states of consent controls — the test decides, and a reviewer spot-checks.
Decided by a reviewer
Where the question needs judgement — wording that shames, visual emphasis that steers — software measures and an expert reviewer decides.
Stated by you
Some facts can't be seen from outside, such as whether a placement was paid for. Those are recorded as your company's statement, not as our finding.
Clean results are sealed exactly like findings. That is what makes the statement defensible rather than decorative.
Available now
The Audit Sprint
The yearly self-audit, done properly, in ten working days.
From ₹1.5 lakh, depending on the number of properties and journeys in scope.
You receive
- Scoped customer journeys tested across personas, sessions and time
- Findings adjudicated by a reviewer, each tied to the rule or pattern it concerns
- A remediation list your product team can work from
- One re-test after you fix
- A sealed evidence pack recording what was tested, found and fixed
- Draft statement wording in the open format, for your own declaration
We need from you
- Written authorisation naming each property in scope
- Test accounts, and allow-listing of our test traffic
- A named contact in legal or compliance
We never complete a real payment, and we only test properties you have authorised in writing.
Available now
Audit Sprint
The yearly self-audit with a sealed evidence pack, ahead of 1 January.
From Q1 2027
Continuous Assurance
Weekly replay of your journeys, so the statement stays true between audits. The daily price ledger behind Rule 4(13) starts the day you engage.
Later in 2027
Release Gate
The same tests run on staging before a change to checkout, pricing, consent or cancellation goes live.
Limits, stated plainly
What we are not
- Not a certifier. The rule makes the entity certify itself. We supply scope-limited evidence, like a penetration-test report — never a guarantee of compliance.
- Not a public league table. Findings stay with you. We never publish or rank companies.
- Not a page scanner. The patterns that attract penalties live across steps and time, which one screen cannot show.
- Not legal advice. Where a question is legal — whether a rule applies to you, or what your statement should say — the evidence pack says so, and your counsel decides.
Free to use
Start your self-audit today
No published format exists for a Rule 4(15) statement. These are ours, free to use.
Open statement format
What a defensible statement should contain: scope, exclusions, method, coverage, open items and a signed declaration. CC BY 4.0.
Self-audit checklist
All thirteen specified patterns, correctly enumerated, and the duties added in 2026, each with its rule reference.
Statement generator
Draft your statement in the browser. Nothing you type leaves your device.
This site, checked against its own rules. No countdown timers. No pre-ticked boxes. No cookies, no analytics, and no requests to any third party — your browser's developer tools will confirm it. Prices stated plainly.