Guide2023 Guidelines · Annexure 1 · Updated 5 October 2026
The 13 dark patterns, with examples and fixes
Rule 4(15) makes the Guidelines for Prevention and Regulation of Dark Patterns, 2023 binding on e-commerce entities, and the yearly self-audit is checked against the thirteen patterns they specify. Here is each one in plain language, what it typically looks like on an Indian store, and how to fix it.
01The list
Thirteen, and only these thirteen
Some published lists swap one of the thirteen for a pattern that isn't in the Guidelines; "privacy Zuckering" is the usual substitute. The thirteenth specified pattern is rogue malware. If your self-audit uses another list, check it against Annexure 1.
The examples below are illustrations, not findings about any business.
The patterns
-
False urgency
What it is. Falsely stating or implying that something is urgent or scarce, to push a purchase.
Typically. A "sale ends in 09:59" timer that restarts on every reload; "only 2 left" shown to every visitor; invented "34 people are viewing this".
Fix. Use real deadlines and real stock counts, or none at all. A genuine sale that ends when it says is fine.
-
Basket sneaking
What it is. Adding products, services, donations or charges to the cart without the shopper choosing them.
Typically. "Shipping protection" or a donation pre-added at checkout; a warranty added along with the product.
Fix. Make every add-on opt-in. Necessary charges, such as delivery or taxes, must be disclosed at the time the purchase is made.
-
Confirm shaming
What it is. Wording that uses guilt, shame or fear to steer a choice.
Typically. A decline button that reads "No thanks, I don't care about my family's safety".
Fix. Neutral wording for both options: "Add insurance" or "No thanks".
-
Forced action
What it is. Making the shopper do something unrelated in order to buy what they came for.
Typically. Requiring an app download, a sign-up or unrelated personal details just to see prices or check out.
Fix. Offer guest checkout, and ask only for what the order needs.
-
Subscription trap
What it is. Making it hard to cancel, or hiding how a subscription works.
Typically. One-tap subscribe, but cancelling needs an email or a phone call; payment details demanded for a "free" trial without saying it auto-renews.
Fix. Cancelling should be no harder than subscribing, in the same place. Disclose renewal terms up front.
-
Interface interference
What it is. Design that highlights some information and hides other information to steer a choice.
Typically. A bright "Accept" beside a pale grey "decline" link; a close button too small to find.
Fix. Give choices comparable visual weight.
-
Bait and switch
What it is. Advertising one thing and serving another when the shopper acts on it.
Typically. A low advertised price that's "unavailable" at checkout, where a costlier option is offered instead.
Fix. Advertise only what you can supply on the terms shown.
-
Drip pricing
What it is. Not revealing the full price up front, so it grows step by step.
Typically. A "convenience fee" or "platform fee" that first appears at the payment step.
Fix. Show every mandatory charge on the product page, before add-to-cart.
-
Disguised advertisement
What it is. Advertising presented as something else: content, reviews, news or recommendations.
Typically. A paid "editor's pick" or "top rated" placement with no label.
Fix. Label paid placements clearly and prominently. Rule 4(12) separately requires sponsored listings to be distinctly identified.
-
Nagging
What it is. Repeated requests or interruptions unrelated to what the shopper is doing.
Typically. A "download our app" or notifications prompt that comes back on every page after being dismissed.
Fix. Ask once; respect "no" for the rest of the visit, and longer.
-
Trick question
What it is. Deliberately confusing wording, such as double negatives, that steers an answer.
Typically. "Untick this box if you don't want to stop receiving offers."
Fix. One plain, positive question per choice, with nothing pre-ticked (Rule 4(9)).
-
SaaS billing
What it is. Collecting recurring payments in a software-as-a-service model in ways the user didn't clearly agree to.
Typically. A free trial that silently turns into a paid plan; renewals charged without notice.
Fix. Tell users before a trial converts and before each renewal, and take payment only with clear, affirmative consent.
-
Rogue malware
What it is. Using malicious software, or fake warnings, to frighten or deceive users into acting or paying.
Typically. A fake "virus detected" alert or a fake download button, often arriving through an ad network or third-party script rather than the store's own code.
Fix. Audit your third-party scripts and ad slots. Keep only what you need, and watch what they serve.
02Testing
Most of these only show across steps and time
A timer that resets, a fee that appears at the last step, a prompt that keeps returning: none of these is visible on a single screenshot. Check each journey from start to finish, then again after a reload, in a private window, and later in the day. Keep dated screenshots.
Free tools. The self-audit checklist has the question to ask for each pattern. The store check flags features on your public pages worth testing: countdown apps, add-on apps, pop-ups, subscriptions and pre-ticked boxes.
Plain-language summaries of Annexure 1, not legal advice.