Part I of the post examined the CCPA’s orders against PhysicsWallah and McAfee, and argued that neither the misleading-advertisement nor the forced-action findings in McAfee sit comfortably within their own definitions. In Part II, Anjali Tripathi and Kartik Sharma turn to the deeper problem those findings point at. Anjali is a lawyer, writer and artist with an interdisciplinary interest in critical approaches to law, visual storytelling, and design. She writes on technology, IP and culture. Kartik is a law graduate from NLSIU Bengaluru and was an analyst with SpicyIP previously. He is interested in IP and legal theory.

Where Does The Buck Stop?
That shortcut is not a one-off drafting shrug – it points at a deeper interpretive problem, and this is the part that should worry anyone who has to build an interface for a living. “Unfair trade practice” under Section 2(47) is expressly open-ended; the provision uses the word “including,” and both orders happily say so. The only constraints in the main body of Section 2(47) remain the terms ‘unfair’ and ‘deceptive’, which are again open-textured. The Guidelines’ Annexure of prohibited patterns is illustrative, not exhaustive – thirteen named patterns, “subject to modification from time to time.” Moreover, these illustrations’ interpretation can vary depending on the facts and conditions. The definition of dark patterns given in the Guideline ends with ‘amounting to misleading advertisement or unfair trade practice or violation of consumer right’. This circles back to the Act. And misleading advertisement under Section 2(28), the one comparatively closed, element-based definition in the mix, ends up folded into the open-ended one anyway, as we just saw. So nearly every provision doing real work in these orders is elastic, and the elasticity all stretches in one direction – towards a finding of liability, never away from it. Which raises the honest question neither order sits with for long: what actually stops “unfair trade practice” from catching any interface choice a regulator dislikes after the fact, and what is a company meant to treat as a guardrail before the fact?
The Bigger Picture
It is tempting to read these orders narrowly – two companies, two clumsy screens, two modest fines – and move on. We think that misses the more interesting question, and it is one worth asking precisely because law does not operate in silos. Dark-patterns enforcement sits at the junction of consumer protection, competition, and innovation policy, and the CCPA’s interpretive approach in these orders has consequences well beyond the two parties named in them.
Consider the problem from the other side of the screen – the designer’s. Every checkout flow ever built makes choices: what to place first, what to colour brightly, what to set as a default, when to nudge. That is not a bug in interface design; it is interface design. A pre-ticked donation box is basket sneaking, clearly enough. But is a “recommended plan” highlighted in a brand’s own colour interface interference? Is a perfectly accurate “your protection expires in 26 days” banner confirm shaming, or just information a user would actually want? The Guidelines hand us thirteen labels; what they do not hand us is a workable test for the vast middle ground where persuasive design shades into manipulative design. And because – as we argued above – the categories doing the work are open-ended, that line ends up drawn after the fact, order by order, by whoever happens to be reading the screenshot.
The rational response to that uncertainty is not good design. It is defensive design. If “innovative interface” and “manipulative interface” carry the same legal risk – because nobody can tell you in advance which one you have built – the safe move is to strip interfaces back to the blandest, most literal version possible and hope for the best. That is a real loss, and not only for platforms: consumers benefit from legible, well-designed interfaces too, and a regime that chills design experimentation across the board is not obviously serving the people it is meant to protect. There is a quieter competition wrinkle here as well – the cost of second-guessing every design choice, running every screen past a lawyer, is trivial for a PhysicsWallah or a McAfee and a good deal less trivial for a smaller player without counsel on retainer.
None of this is an argument that dark patterns should go unregulated – they should be, and the harms the CCPA is responding to are real ones. It is an argument that the manner of regulation matters, and that “we will know it when we see it,” applied to something as ubiquitous and unavoidable as interface design, is not a standard anyone can actually build to. Which brings us back to where the last section left off: until the CCPA, or a court on appeal, articulates what separates a legitimate nudge from an illegal one, the honest answer to “is this interface legal?” is a shrug – and a shrug is a strange thing to design a ₹5 lakh penalty around.
Conclusion
Dark patterns as a site of regulation necessitate a more fundamental deliberation: how do we conceive the relationship between regulation and innovation? The two are not necessarily always at odds; in fact, well-thought regulation can nudge players towards alternative avenues of innovation that further it in a social sense – reframing innovation as a measure that increases positive social impact. At the same time, determining where innovative and beneficial interfaces end and manipulative designs take over remains a tricky job, and the threat of regulatory chill remains. Competing players in the digital space will want to improve their design interfaces for a competitive edge, and antitrust scholarship has examined the exclusionary effects and consequent market failures that dominant platforms can bring about through dark patterns – the double-edged nature of regulating design, in its impact on small vis-à-vis large players, is hard to miss.
Within that larger deliberation, three questions outlast these orders. The first is whether the CCPA will ever say, in advance, when a post-notice fix earns leniency and when it does not – because as things stand, IndiGo walked and McAfee paid on facts that rhyme, and “scale of deployment” is doing a great deal of unexplained work. The second is whether the reasoning would survive contact with an appeal. That day may already have arrived: Zepto has carried its penalty into appeal, and findings like McAfee’s ‘forced action’ – a label pinned to conduct that does not fit its own definition – will now have to be defended rather than merely asserted. The third is whether any of this is deterring anyone. LocalCircles found that 97% of 290 major Indian platforms were still running dark patterns nearly three years after the Guidelines took effect; one industry estimate puts the annual take from these designs at up to ₹28,000 crore. Against those numbers, the penalties read less like deterrence than a toll – PhysicsWallah alone collected ₹2.47 crore through the very pre-ticked box it was fined ₹5 lakh for, and Section 21’s headroom of ₹10 lakh for a first offence and ₹50 lakh for repeat conduct has gone entirely unused. Until either the reasoning tightens or the numbers start to bite, the CCPA’s new penalty mode is a warning shot – loud enough to hear, not yet loud enough to change how anyone builds a screen.
