The Central Consumer Protection Authority (CCPA) has imposed a penalty of ₹1 lakh on SpiceJet for using deceptive design practices known as dark patterns on its flight booking platform. The airline was found to have automatically enrolled passengers into its SpiceClub loyalty programme through pre-ticked checkboxes and presumed their consent for promotional communications without any affirmative action. Chief Commissioner Nidhi Khare and Commissioner Anupam Mishra passed the order, holding that the practice violated consumer rights and undermined the principle of free and informed consent.
What Are Dark Patterns?
Dark patterns are user interface designs deliberately crafted to mislead or manipulate users into making choices they did not intend. These deceptive design techniques exploit psychological biases such as default bias, fear of missing out, and social validation to nudge consumers toward outcomes that benefit the platform rather than the user. The Guidelines for Prevention and Regulation of Dark Patterns, 2023, issued by the CCPA under Section 18 of the Consumer Protection Act, 2019, define dark patterns as any practice or deceptive design that subverts or impairs consumer autonomy and decision making.
The Guidelines, notified on 30 November 2023, identify 13 specific types of prohibited dark patterns:
| Dark Pattern | Description |
|---|---|
| False Urgency | Creating artificial time pressure or false scarcity |
| Basket Sneaking | Adding extra items to cart without user consent |
| Confirm Shaming | Using guilt-laden language to discourage opting out |
| Forced Action | Requiring unrelated actions to proceed with a service |
| Subscription Trap | Making subscription easy but cancellation difficult |
| Interface Interference | Manipulating UI elements to steer user choices |
| Bait and Switch | Advertising one thing but delivering another |
| Drip Pricing | Revealing hidden charges only at checkout |
| Disguised Advertisement | Presenting ads as organic content |
| Nagging | Persistent interruptions to push specific actions |
| Trick Question | Using confusing or negatively worded language to mislead |
| SaaS Billing | Charging for unused or cancelled subscriptions |
| Rogue Malware | Tricking users into installing harmful software |
These Guidelines apply to all platforms, advertisers, sellers, and service providers that systematically offer goods or services in India.
The SpiceJet Case: What Happened?
The CCPA initiated suo motu proceedings after examining SpiceJet’s booking interface and issued a notice to the airline on 14 May 2024. The investigation revealed that the airline’s digital platform employed pre-selected options that automatically enrolled customers into programmes and services without their explicit consent.
Pre-ticked Loyalty Programme Enrollment
SpiceJet’s booking flow displayed a pre-ticked checkbox on the passenger details page that enrolled users into the SpiceClub Loyalty Programme while simultaneously confirming that they were above 18 years of age. Customers who did not notice or manually uncheck this box were automatically enrolled. The CCPA held that this practice presumed consent through default selection instead of requiring affirmative action, thereby stripping consumers of their right to make a conscious choice.
Continued Violation After Notice
Even after the CCPA issued its notice, SpiceJet merely altered the mechanism rather than eliminating the deceptive practice. The airline replaced the pre-ticked loyalty programme checkbox with another pre-selected option related to receiving promotional communications through SMS, WhatsApp, and email. Users who left this checkbox untouched were automatically treated as having consented to receive marketing messages.
During the proceedings, SpiceJet attributed the issue to a technical error and submitted that corrective measures had been implemented. The airline argued that the loyalty programme only offered redeemable reward points and was not intended to provide monetary benefits. The CCPA, however, remained unconvinced, observing that consent obtained through default options cannot be considered voluntary or informed. The Authority directed the airline to submit an undertaking confirming that the corrective measures would remain in place permanently and file a compliance report within 15 days of receiving the order.
Three Dark Patterns Identified on SpiceJet’s Platform
The CCPA classified SpiceJet’s booking interface as involving three specific prohibited dark patterns under the 2023 Guidelines:
| Dark Pattern | How SpiceJet Used It |
|---|---|
| Forced Action | Automatic enrolment of customers into the SpiceClub Loyalty Programme through a pre-selected checkbox, requiring users to actively uncheck to opt out |
| Interface Interference | Presenting the company’s preferred option (loyalty enrollment and marketing consent) as the default choice, manipulating the user interface to steer consumers toward predetermined outcomes |
| Trick Question | Using confusing and negatively worded consent language for communication preferences, where an unchecked box reading “I do not wish to receive communications” meant the user was automatically opted in if left untouched |
The Authority observed that these practices created a “double-layered” decision process, forcing consumers to actively uncheck boxes to opt out of services they never requested. This design turned the passive act of booking a flight into a mechanism for unwanted enrollment, fundamentally undermining consumer autonomy.
Legal Framework Behind the Penalty
The CCPA’s order against SpiceJet rests on a three-tier legal architecture that governs consumer protection in India’s digital marketplace.
Consumer Protection Act, 2019
The Consumer Protection Act, 2019, which replaced the earlier Consumer Protection Act, 1986, came into force on 20 July 2020. The Act established the CCPA under Section 10 as a central regulatory authority to protect, promote, and enforce the rights of consumers as a class. The CCPA is empowered to take suo motu action, investigate violations of consumer rights, order discontinuation of unfair trade practices, and impose penalties.
The Authority held that SpiceJet’s conduct amounted to an unfair trade practice, an unfair contract, and a misleading representation under the Act. These practices are defined under Section 2(47) of the Act, which covers any practice that adopts deceptive methods for the purpose of promoting the sale of goods or services.
Consumer Protection (E-Commerce) Rules, 2020
The CCPA specifically found SpiceJet in violation of Rule 4(9) of the Consumer Protection (E-Commerce) Rules, 2020, which mandates that consent must be obtained from consumers through explicit and affirmative action. The rule explicitly prohibits automatic recording of consent through pre-ticked checkboxes or other default options. This provision was designed precisely to prevent the kind of deceptive design that SpiceJet employed on its platform.
Guidelines for Prevention and Regulation of Dark Patterns, 2023
The 2023 Guidelines, notified by the CCPA in exercise of its powers under Section 18 of the Consumer Protection Act, 2019, served as the direct basis for classifying SpiceJet’s interface designs as prohibited dark patterns. The Guidelines recognize that dark patterns constitute unfair trade practices and provide the framework for identifying and penalizing such deceptive designs across all digital platforms operating in India.
CCPA’s Growing Crackdown on Digital Deception
The SpiceJet penalty is part of a broader regulatory push by the CCPA against dark patterns in India’s digital economy. The Authority had previously taken action against several major platforms. In June 2024, the CCPA issued directions to IndiGo for using confirm shaming tactics, such as displaying the message “No, I will take risk” when passengers opted out of add-on services. IndiGo was directed to introduce clear communication informing passengers that seat selection is optional.
In February 2025, the CCPA issued a notice to BookMyShow for automatically adding a ₹1 donation to its BookASmile charity initiative through pre-ticked checkboxes, a practice categorized as basket sneaking. Following the intervention, BookMyShow modified its interface to provide users with a clear voluntary opt-in option.
In June 2025, the CCPA issued a formal Advisory directing all e-commerce platforms to conduct a mandatory self-audit within three months to detect and eliminate dark patterns. More than 26 leading e-commerce platforms submitted voluntary compliance declarations in response. The CCPA has also imposed penalties on other entities, including a ₹50,000 fine on Chaayos for default service charges and a ₹7 lakh penalty on Zepto for dark pattern violations.
These enforcement actions signal that the CCPA is actively monitoring platform conduct and is prepared to penalize any entity, regardless of size or market position, that deploys manipulative design practices.
Key Takeaways
- The Central Consumer Protection Authority (CCPA) imposed a ₹1 lakh penalty on SpiceJet for using dark patterns on its booking platform.
- Three dark patterns were identified: Forced Action, Interface Interference, and Trick Question under the Guidelines for Prevention and Regulation of Dark Patterns, 2023.
- The CCPA was established under Section 10 of the Consumer Protection Act, 2019, which came into force on 20 July 2020.
- The Guidelines for Prevention and Regulation of Dark Patterns, 2023, notified on 30 November 2023, list 13 prohibited dark patterns and apply to all platforms offering goods or services in India.
- The order also found SpiceJet in violation of Rule 4(9) of the Consumer Protection (E-Commerce) Rules, 2020, which requires explicit and affirmative consumer consent.
- The CCPA is headed by Chief Commissioner Nidhi Khare (a 1992 batch IAS officer) and Commissioner Anupam Mishra.