In 2022, the European Data Protection Board published draft guidance addressing what were then commonly described as “dark patterns” in social-media interfaces.
The concern was straightforward.
An interface can formally present information or choices while still being designed in a way that nudges, confuses, pressures or obstructs users when they make decisions about their personal data.
The legal significance of those design choices extends beyond aesthetics or user experience.
Under the GDPR, interface design can affect whether:
- information is transparent;
- consent is freely given and informed;
- data-subject rights can be exercised effectively;
- processing is fair;
- data minimisation is respected; and
- privacy by design and by default has been implemented.
The original Privacy Minders article was published while the EDPB’s draft Guidelines 03/2022 were still under consultation.
The final Guidelines were subsequently adopted in 2023 under the title:
Guidelines 03/2022 on deceptive design patterns in social media platform interfaces: how to recognise and avoid them.
Since then, interface design has also become an express concern under the Digital Services Act.
The result is that deceptive interface design now sits at the intersection of data protection, platform regulation, consumer choice and digital governance.
From “dark patterns” to “deceptive design patterns”
Following public consultation, the EDPB revised the language used in its final Guidelines.
The term “dark patterns” was replaced by:
“deceptive design patterns”.
The final wording focuses attention on the effect of the interface rather than on a particular label.
The Guidelines address interfaces and user experiences that can lead individuals into making unintended, unwilling or potentially harmful decisions concerning the processing of their personal data.
The final version also added clarifications and additional practical illustrations intended to help designers and controllers recognise problematic patterns earlier in the design process.
For businesses, the terminology change does not alter the core issue:
a user interface can itself become part of the compliance analysis.
The GDPR starting point is fairness and transparency
The EDPB’s analysis is grounded in the GDPR rather than in a standalone prohibition labelled “dark patterns”.
Several GDPR provisions can become relevant depending on the interface and processing involved.
These include:
- Article 5 principles, particularly lawfulness, fairness and transparency;
- purpose limitation;
- data minimisation;
- accountability;
- Articles 4(11) and 7 on consent;
- Article 12 on transparent information and communications;
- the data-subject rights in Chapter III; and
- Article 25 on data protection by design and by default.
The principle of fairness is particularly important.
A controller should not design an interface in a way that exploits user expectations, asymmetries of information or behavioural tendencies in order to obtain more personal data or push users toward more intrusive processing.
The legal assessment therefore looks beyond whether required text technically appears somewhere on the screen.
The question is whether users can understand their options and exercise meaningful control in practice.
The six categories of deceptive design patterns
The final EDPB Guidelines group deceptive design patterns into six broad categories.
OVERLOADING
Users are confronted with an excessive amount of information, requests, choices or possibilities that can push them toward sharing more data or permitting processing they may not otherwise expect.
SKIPPING
The interface or user journey is designed so that individuals overlook, forget or fail to consider relevant data-protection issues.
STIRRING
The interface influences choices through emotional pressure, framing or visual nudges.
OBSTRUCTING
Users are hindered when trying to understand processing, manage privacy settings or exercise control over their personal data because relevant actions are made unnecessarily difficult.
FICKLE
The interface is inconsistent or unclear, making it difficult for users to navigate privacy controls or understand the purposes of processing.
LEFT IN THE DARK
Information or privacy controls are hidden, difficult to locate or presented in a way that leaves users uncertain about how their data is processed or what control they have.
Interface design can determine whether consent is genuinely valid
Consent is one area where deceptive design can have particularly direct legal consequences.
Under the GDPR, consent must be:
- freely given;
- specific;
- informed; and
- unambiguous.
A technically available refusal option does not necessarily mean that the overall choice is fair or freely made.
Examples of problematic design may include:
- giving the accept option substantially greater visual prominence;
- hiding refusal behind additional screens;
- using emotionally loaded language;
- repeatedly asking users to reconsider an earlier refusal;
- making privacy-preserving settings harder to find;
- presenting confusing or inconsistent explanations; or
- creating unnecessary friction around withdrawal of consent.
The design of the consent journey should therefore be assessed as part of the legal analysis rather than treated as a purely UX decision.
Deceptive design can arise throughout the user journey
The EDPB does not limit its analysis to cookie banners or initial consent requests.
The Guidelines examine deceptive design across the lifecycle of a social-media account.
Relevant stages include:
- opening and registering an account;
- receiving privacy information;
- managing consent and privacy settings;
- understanding joint-controller or data-sharing arrangements;
- receiving information about data breaches;
- exercising data-subject rights;
- changing privacy preferences; and
- closing an account.
This lifecycle approach is important.
A service can provide a clear initial consent screen but still create barriers later when a user tries to:
- withdraw consent;
- obtain access to personal data;
- change settings;
- object to processing; or
- delete an account.
Compliance therefore needs to be assessed across the complete user journey.
Privacy by design starts before the interface is launched
The EDPB links deceptive-design analysis closely to Article 25 GDPR.
Data protection by design and by default requires controllers to consider data-protection principles during the design and development of systems, rather than attempting to correct problematic interfaces only after complaints arise.
For product, UX and privacy teams, this means privacy review should occur while interface decisions are still being made.
Relevant questions include:
- Is privacy information visible at the point where the user needs it?
- Are equivalent options presented with comparable prominence?
- Is the least intrusive option genuinely accessible?
- Can users reverse earlier decisions easily?
- Are privacy controls located where users would reasonably expect them?
- Is wording consistent throughout the service?
- Are unnecessary steps creating friction around rights or refusal?
Design review should therefore form part of privacy governance rather than sitting outside it.
Children and vulnerable users require particular attention
The EDPB also highlights the potential effect of deceptive design on children and other users who may be particularly vulnerable to manipulative interface choices.
Children may be less able to understand:
- long or complex information;
- the consequences of sharing data;
- emotional or social pressure;
- default settings; or
- the longer-term effect of privacy choices.
Similar concerns can arise for individuals who are less digitally literate, older users or people with accessibility needs.
The design process should therefore consider not only the average user but also the people most likely to be disadvantaged by complexity, pressure or hidden controls.
The Digital Services Act added a separate interface-design rule
The regulatory landscape changed materially after the original 2022 article.
The Digital Services Act became generally applicable from 17 February 2024.
Article 25 DSA provides that providers of online platforms must not design, organise or operate their online interfaces in a way that:
- deceives recipients;
- manipulates recipients; or
- otherwise materially distorts or impairs their ability to make free and informed decisions.
The DSA therefore creates an express platform-regulation rule directed at manipulative interface design.
Examples identified in the Regulation include practices such as:
- giving greater prominence to certain choices;
- repeatedly requesting a choice after the user has already made it;
- making cancellation substantially more difficult than signing up;
- making certain choices unnecessarily difficult or time-consuming; and
- using defaults or interface structures that bias decision-making.
GDPR and DSA deceptive-design rules need to be distinguished
The GDPR and DSA can address similar interface behaviour, but they should not be treated as identical legal rules.
The GDPR analysis focuses on personal-data processing and requirements such as:
- fairness;
- transparency;
- valid consent;
- data-subject rights; and
- privacy by design and by default.
Article 25 DSA separately regulates online-platform interfaces that deceive, manipulate or materially impair free and informed decision-making.
Importantly, Article 25(2) DSA provides that its prohibition does not apply to practices already covered by:
- the Unfair Commercial Practices Directive; or
- the GDPR.
This means Article 25 DSA should not simply be layered mechanically on top of the GDPR for the same conduct.
The correct legal analysis depends on:
- the nature of the interface;
- the provider;
- the decision being influenced;
- whether personal-data processing is involved; and
- which EU legal framework governs the particular practice.
Choice architecture is now a regulatory issue
The regulatory focus on deceptive design reflects a broader change in EU digital regulation.
Authorities increasingly examine not only what choices are offered, but how those choices are presented.
A service may formally offer:
ACCEPT
REJECT
MANAGE SETTINGS
while still designing the user journey so that one option is easier, brighter, faster or more emotionally appealing than the others.
Similarly, an interface may technically permit account deletion or consent withdrawal while placing the user through a series of unnecessary screens or repeated confirmation requests.
The legal assessment therefore increasingly considers:
- prominence;
- order of choices;
- wording;
- visual hierarchy;
- friction;
- repetition;
- default settings;
- timing;
- accessibility; and
- the consequences attached to different user decisions.
Consent or Pay shows why interface design matters
The regulatory debate surrounding Meta’s Consent or Pay model illustrates how questions of legal basis and interface design can converge.
The issue is not only whether several options formally exist.
Regulators may also examine whether:
- the alternatives are genuinely accessible;
- one option is materially more attractive because of cost or functionality;
- the interface steers users toward more extensive processing;
- refusal creates disproportionate detriment; and
- users understand the consequences of each path.
This is one reason deceptive-design analysis increasingly needs to sit alongside broader consent and digital-regulation assessments.
What product and UX teams should test before launch
A deceptive-design review should not be left to the privacy team after an interface has already been built. Legal, privacy, product and UX teams should review the user journey together while design choices can still be changed.
01 · CLARITY AND NEUTRALITY
Users should be able to understand the decision in front of them without having to search for relevant information or decode inconsistent wording. Accept, reject and alternative options should be presented with appropriate visual balance, and the language used should remain clear, neutral and free from emotional pressure or misleading framing.
02 · FRICTION, DEFAULTS AND REVERSIBILITY
The interface should not make privacy-protective choices materially harder than more data-intensive ones without a legitimate reason. Teams should compare the number of steps, prominence, defaults and repeated prompts attached to each option. Withdrawal, objection, deletion and changes to privacy settings should also remain reasonably accessible after the initial decision has been made.
03 · THE FULL USER LIFECYCLE
Fair interface design should continue beyond registration or the first consent screen. Teams should test what happens when users later change their preferences, exercise their rights or close an account. Particular attention should be given to children, less digitally experienced users and people with accessibility needs, who may be more affected by complexity, pressure or hidden controls.
A useful test is therefore not simply whether every required option technically exists, but whether users can understand, exercise and later reverse their choices without unnecessary pressure or friction.
A practical deceptive-design review
A useful review can be organised across four layers.
01 · USER JOURNEY
Map the complete journey from sign-up to account closure and identify every point where personal-data choices are presented.
02 · INTERFACE DESIGN
Review prominence, colours, button hierarchy, wording, defaults, repeated prompts and navigation friction.
03 · LEGAL BASIS AND RIGHTS
Determine which GDPR principles, consent requirements or data-subject rights are engaged at each stage.
04 · REGULATORY SCOPE
Assess whether the same interface also falls within the Digital Services Act, consumer law or another sector-specific framework.
The output should identify both legal issues and practical design changes.
A compliant solution may therefore require changes to:
- wording;
- button placement;
- information architecture;
- number of steps;
- default settings; or
- the sequence in which choices are presented.
From dark patterns to accountable interface design
When the original Privacy Minders article was published in April 2022, deceptive interface design was still emerging as a distinct focus of European data-protection guidance.
The regulatory position has since become clearer.
The EDPB’s final Guidelines provide a detailed framework for recognising deceptive design patterns across the lifecycle of a social-media account.
The Digital Services Act has separately introduced an express prohibition on manipulative interface design for online platforms where the relevant practice is not already governed by the GDPR or consumer-law framework.
The broader lesson is that interface design can no longer be treated as legally neutral.
A compliant digital service should make it possible for users to:
- understand how their personal data is used;
- identify meaningful alternatives;
- make choices without manipulation;
- change those choices later; and
- exercise their rights without unnecessary friction.
The objective is therefore not simply to remove obvious “dark patterns”.
It is to build interfaces in which data protection, autonomy and informed choice are part of the design itself.



