Part I: Small Fines, Big Platforms: The CCPA on PhysicsWallah, McAfee, and the Cost of Getting Caught

The Central Consumer Protection Authority (CCPA) has been going after dark patterns for some time now. In this two-part post, Anjali Tripathi and Kartik Sharma analyse the CCPA orders passed against PhysicsWallah and McAfee. Part II of the post goes beyond these orders and looks at the deeper implications for design interfaces and dark pattern regulation. Anjali Tripathi is a lawyer, writer and artist with an interdisciplinary interest in critical approaches to law, visual storytelling, and design. She writes on technology, IP and culture. Kartik is a law graduate from NLSIU Bengaluru and was an analyst with SpicyIP previously. He is interested in IP and legal theory.

(Note: During the time of writing this post, the Central Consumer Protection Authority (CCPA) had passed another order against SpiceJet penalizing the company for its deceptive interface design. We have, however, decided to limit this post to PW and McAfee orders owing to word count considerations).

Introduction

Two orders, three weeks apart, arrive at the same punchline: fix your interface after you have been caught, and you will still be paying for it. On 1 June 2026, the CCPA fined PhysicsWallah Limited ₹5 lakh for deploying dark patterns on its ed-tech platform. Three weeks earlier, on 20 May, it had fined McAfee ₹1 lakh for much the same species of conduct on its subscription-renewal screen. Both companies had already changed the offending interface by the time their orders were signed. Both were penalised anyway. The CCPA’s answer, in both orders, was that post-facto corrective action, ‘though relevant for future compliance, does not extinguish liability arising from the earlier deployment’ of the interface – by the time the fixes arrived, the designs had already run at scale for months.”

We have written about dark patterns on this blog before – first in 2023, when the Guidelines were still in draft and it was anybody’s guess what they would actually prevent, and again in 2025, when the CCPA’s self-audit advisory landed and the open question was whether platforms would take any of it seriously without a single rupee changing hands. PhysicsWallah and McAfee bring us close to an answer. To be clear, these are not the first monetary penalties under the Guidelines for Prevention and Regulation of Dark Patterns, 2023Zepto was fined ₹7 lakh in December 2025, just before its IPO filing – but a run of penalty orders inside eight months reads less like scattered enforcement and more like the CCPA shifting, at last, from advisory mode into penalty mode.

The weeks since have only confirmed the shift: in July, SpiceJet became the fourth platform fined – ₹1 lakh, for a pre-ticked loyalty-programme checkbox on its booking flow – while Zepto has become the first to carry its penalty into appeal rather than pay and comply.

What makes these two orders worth sitting with is that the oldest excuse in the book – “we have already fixed it” – stopped working. That is the thread we want to pull on. Before we do, one small but important point on where the liability actually comes from: neither order treats the Guidelines as the source of the offence. Both anchor liability in Sections 2(9), 2(28) and 2(47) of the Consumer Protection Act, 2019 – consumer rights, misleading advertisement, and unfair trade practice – and use the Guidelines as an interpretive map for what “unfair” or “misleading” looks like on a screen. Hold on to that distinction; it comes back to affect us later.

Issue At Hand

In this part, we will describe the companies’ design interfaces under question and also summarise the CCPA’s decision on their legality.
On PW’s website, there was an automatically pre-selected “Donate for PW Foundation” checkbox that added Rs. 10 to the total payable amount at checkout. A user had to disable it manually.

Screenshot of the Physics Wallah website showing an order summary for the “UPSC प्रारंभ 2.0 2028” course priced at ₹29,999, with a payment summary showing a total amount of ₹30,009 including a ₹10 donation to the PW Foundation.

Reproduced from Order

A ‘Know more’ button provided further information about the intended purposes for utilization of donated funds; these included financial assistance for marriages, education of children and healthcare of underserved communities. Finally, customers had to share personal information (mobile number and email id) in order to access the ‘free’ courses.

Now onto McAfee’s controversy. McAfee’s notification for subscription renewal of the antivirus software had two options in the interface: (i) Accept Risk (ii) Renew Now. The allegation was that such a framing did not amount to a neutral opt-out mechanism where a simple ‘Cancel or Skip’ choice should have been provided. The ‘x’ or close option appeared in a subdued grey color whereas the renewal-related buttons were more visually striking.

Photograph of a McAfee notification stating that the user’s protection ends in 25 days and prompting them to renew their subscription to retain benefits, with “Accept risk” and “Renew now” options.

Reproduced from Order^

As mentioned in the introduction, both companies had fixed some of these issues after the notice. The CCPA, however, observed that the post-facto corrections did not extinguish liability for the previous violations. It found several dark patterns in both cases. First, there was ‘Confirm Shaming’ held to be present. PW’s ‘Know more’ button, combined with the pre-selected amount, was found to communicate emotionally persuasive messages to consumers to make them retain the donation option. Similarly, McAfee’s ‘Accept Risk’ framed the customer’s choice of non-renewal as irresponsible conduct involving an acceptance of danger. Second, the CCPA held these features as amounting to ‘forced action’. PW conditioned the access to free courses upon the disclosure of personal information. This created a compulsion for customers in the form of a pre-condition. McAfee’s manipulative design (including in the form of a less visible ‘close’ option) failed to provide an equally accessible opt-out mechanism.

Moreover, PW’s pre-checked donation option was considered Basket Sneaking since the addition was done without prior affirmative consent. The CCPA noted that the ‘Accept Risk’ terminology used by McAfee was vague and confusing and intended to psychologically manipulate consumers, therefore making it a trick question. Further, there was also interface interference in McAfee’s case since the renewal-related option in McAfee was displayed with significantly greater visual prominence as compared to the ‘close’ mechanism.

All these instances were held to be unfair trade practice under Section 2(47) of the 2019 Act. The listed categories under the provision are meant to be illustrative. Similarly, both companies were held to be engaging in misleading advertisements (defined under section 2(28) of the 2019 Act.) And finally, PW and McAfee were found in violation of Consumer Protection (E-Commerce) Rules 2020 that mandate free and affirmative consent and prohibit deployment of unfair trade practices.

Correct The Interface, Pay the Fine Anyway!

McAfee’s defence leaned almost entirely on the CCPA’s own order in InterGlobe Aviation (IndiGo), where “No, I will take the risk” was found to be confirm shaming but drew no penalty, because IndiGo corrected the wording once it received notice. PhysicsWallah sits closer to a different precedent – BookMyShow’s pre-ticked ₹1-per-ticket “BookASmile” donation, flagged as basket sneaking, quietly fixed, no penalty. Between them, the two companies had an on-point precedent for almost every limb of their defence: prompt correction, no proven consumer harm, full cooperation with the inquiry. Neither precedent was distinguished in any real detail. The McAfee order gestures at scale – the number of consumers exposed (3,55,133 renewals recorded before the interface changed), the duration the design stayed live – but it never sets those figures against IndiGo’s, and never tells us what scale, or what duration, would have been modest enough to earn the same leniency IndiGo got. It reads the facts, decides they cross a line, and declines to say where the line is. Which leaves the question the whole order is built on unanswered: is the CCPA building a coherent doctrine of when a post-notice fix earns a discount, or is it deciding that question afresh, in hindsight, every single time?

Was “Accept Risk” Actually a Misleading Advertisement?

Here is a contention worth taking seriously rather than nodding through. We are not convinced that “Accept Risk” satisfies the elements of misleading advertisement under Section 2(28) at all. McAfee’s own point is harder to dismiss than the order lets on: this is a cybersecurity subscription, and a device genuinely is more exposed once the protection lapses. Telling a user that declining renewal carries risk is not, on its face, false or exaggerated – it is arguably just true. The CCPA also noted that there was no guarantee of the software giving complete protection against viruses. However, can any company ever guarantee a 100% success rate for its products and services?  So it is worth testing the order’s reasoning rather than its conclusion. Under  2(28)’s elements, an advertisement is ‘misleading’ if it (i) falsely describes the product or service; (ii) gives a false guarantee, or is likely to mislead consumers as to its nature, substance, quantity or quality; (iii) conveys a representation which, if made by the seller, would constitute an unfair trade practice; or (iv) deliberately conceals important information. The definition is disjunctive – any one limb suffices, and nothing obliges the CCPA to run all four. But notice which limbs it bypassed: (i), (ii) and (iv) each require showing something actually false, deceptive or concealed in the advertisement itself. Limb (iii) requires no such showing, and that is the sole route the order takes (paragraphs 27 and 28):: because the confirm-shaming finding already qualifies as an unfair trade practice under 2(47), and because 2(28)(iii) sweeps in any representation that would amount to an unfair trade practice if made by the seller, the misleading-advertisement finding simply rides in on the back of the confirm-shaming one. Whether “Accept Risk” is manipulative in tone, and whether it is factually false, are two different questions; the order answers the first and writes as though it has answered both.

The order’s interpretation of ‘Forced Action’ can be scrutinised along similar lines. The essence of a forced action is the non-voluntary linkage of another action to the original act intended. PW’s case would fall within it. However, what was the additional product/service or consideration that McAfee users were being made to avail of or give as a pre-condition to renewal? None. If someone wants to justify CCPA’s approach by alluding to the illustrative nature of the Annexure, then any reference to it may very well be futile. 

In Part II, we step back from the two orders to ask what, if anything, constrains this interpretive approach – and what it means for anyone designing an interface in India today.

Tags: , ,

Leave a Comment

Scroll to Top

Discover more from SpicyIP

Subscribe now to keep reading and get access to the full archive.

Continue reading