Edition 123 • Q2: India’s Balancing Act

Verdict

The “CCPA Shield” That Protects E-commerce Consumers From ‘Dark Patterns” Deployed on Digital Platforms

Adjudicating Authority:
Central Consumer Protection Authority, New Delhi [CCPA]

Respondent:
McAfee Software India Pvt Ltd [McAfee]

Case No. YY-2/4/2025-CCPA

In this era of e-commerce, where most business transactions are conducted online via digital platforms, this case re-establishes the robustness of the legal framework that ensures not only the consumer’s autonomy and dignity but also their protection from all conceivable fraudulent practices by digital platform providers.

Background of the Case

  • On 1st September 2025, Mr. Krishna Nigam, founder of Your Attorney, a U.P. based legal counselling firm, filed a complaint with CCPA against McAfee along with the screenshot of a digital interface as evidence.
  • The complaint was that McAfee violated CCPA guidelines pertaining to ‘dark patterns’, by providing a set of interface buttons that forced the consumer to respond in a manner that restricted his free will/intent. In the present case, McAfee displayed two interface buttons ‘Renew Now’ and “Accept Risk’ while alerting the user that the contract period of McAfee’s cybersecurity protection service was nearing its expiry.
  • After its preliminary inquiry, CCPA issued a show cause notice dated 4th December 2025 to McAfee.
  • McAfee submitted its reply dated 19th September 2025, after suitably modifying the interface buttons that pertained to renewal of its service of providing cybersecurity to consumers’ digital portals/devices. Not satisfied with the reply, CCPA initiated on 8th January 2026 a detailed investigation by the Director General (Investigation) into the scale, duration and impact of this and other interfaces designed by McAfee. The Director General (Investigation) [DG(I)] submitted his detailed report [Report] on 20th February 2026. He also shared the report with McAfee on 16th March 2026.
  • McAfee submitted on 26th March’26 its detailed responses/comments on the Report. Its representatives appeared before CCPA to make submissions in its defense on 27th March’26 and 1st April ‘26.         
  • CCPA issued its Judgement Order on 1st June 2026, imposing a penalty of Rs.1,00,000 on McAfee, based on (i) Consumer Protection Act, 2019 [Act], (ii) Consumer Protection (E-Commerce) Rules, 2020 [Rules] and (iii) Guidelines for Prevention and Regulation of Dark Patterns, 2023 [Guidelines]. 

Issues involved in this Case and Judgment

  1. Is McAfee guilty of fraudulent practices in restricting/impairing consumers from making a free, informed decision on the renewal of its cybersecurity service, in spite of promptly rectifying the specific interface? 
  2. Can a penalty be imposed on digital platform providers for indulging in fraudulent / restrictive practices? If so, under which legal provision?

Analysis

  • CCPA contended that by providing interface buttons ‘Renew Now’ and ‘Accept Risk’ instead of a fairer, more transparent ‘Cancel’ or ‘Skip’, McAfee resorted to several dark patterns that included ‘Confirm Shaming’, ‘Forced Action’, ‘Interface Interference’, ‘Trick Question’, ‘Unfair Trade Practice’ and ‘Misleading Advertisement’ as recognised in the Rules and the Guidelines. 
  • As for ‘Confirm Shaming’, McAfee submitted that the buttons merely reflected the risk of not having protection after contract expiry. There was no false/misleading representation and, as such, there was no ‘Confirm Shaming’. With regard to ‘Forced Action’, McAfee contended that there was no compulsion on the user for renewal; in fact, they were clearly enabled by an ‘X’ button located at top right hand corner of the interface page to dismiss the interface. 
  • The CCPA, though, construed that the term ‘Accept Risk’ induced the effect of (i) creating a sense of fear of exposure to cyber risk in the user and thereby (ii) nudging the user to press the ‘Renew Now’ button even though he/she may not be naturally inclined to renew the service. This button thus amounted to both ‘Confirm Shaming’ and ‘Forced Action’. 
  • As for the ‘X’ button, it was displayed in an inconspicuous manner unlike the ‘Accept Risk’ button that was prominently shown in bright colour. CCPA contended that this could clearly be construed to be ‘Interface Interference’ as defined in the Guidelines.
  • Instead of presenting the user with a simple ‘Yes’ or ‘No’ choice on renewal of subscription, McAfee’s users had to choose between  ‘Renew Now’ or ‘Accept Risk’. McAfee deliberately used confusing words that led the user to take a specific action of renewal. These words could be qualified as ‘Trick Question’, one of the ‘dark patterns’ recognised under the Guidelines. 
  • The CCPA further opined that the ‘Renew Now’ and “Accept Risk’ buttons were an ingrained design feature of the platform and impacted many other users in large numbers (more than 35,000 renewals as admitted by McAfee), thus attracting the intervention of CCPA for ‘class action’ under the Act.
  • Even though McAfee, upon receipt of the show cause notice, replaced the disputed interface buttons with ‘Skip’ and ‘Renew Subscription’ buttons, CCPA felt that this post-facto corrective action was a response limited only to the disputed issue and that McAfee did not address or explain larger issues of compliance with all the Rules and Guidelines prior to the show cause notice. Also, it did not extinguish the liability of McAfee with all the other users who had renewed the service prior to the button modification, thus necessitating a detailed investigation into the pre-modification period.
  • Against McAfee’s contention that there were no complaints from users of coercive renewal of service, CCPA submitted that absence of complaints could not be taken as proof of non-coercive nature of the interface. Moreover, McAfee failed to furnish evidence of audits, specific checks or any other verifiable mechanisms of compliance with the Rules and Guidelines, thus violating compliance as per the Act.
  • The Act clearly enunciates that any method or practice that effectively impairs user’s choice or induces him into transactions against his natural unhindered choice can be construed as ‘Unfair Trade Practice’. In McAfee’s case, ‘Accept Risk’ button was deployed for the purpose of promoting renewal and for continuing sale of their cybersecurity protection service. This button also conveyed an impression that non-renewal would automatically expose user to cyber risks, thus inducing him to renew subscription.
  • CCPA observed that McAfee furnished no tangible proof that non-renewal would result in cyber threat to user’s devices. McAfee also did not give guarantee that usage of its antivirus software would completely eliminate all cyber risks. ‘Accept Risk’ therefore created an exaggerated and misleading image of the usefulness of its service and portrayed non-renewal itself as user’s acceptance of the threat. 
  • Section 21 of the Act empowers CCPA to levy penalties on the concerned manufacturer, trader, endorser, advertiser or publisher for ‘false or misleading advertisement that is prejudicial to the interest of any consumer or is in contravention of consumer rights’. Maximum penalty for first offense shall be Rs.10,00,000 (ten lakhs) and Rs.50,00,000 for every subsequent offense committed under the Act.  

Judgement passed and Order issued by CCPA

  1. McAfee shall ensure that no ‘dark patterns’ are deployed in any of its platforms or digital interfaces.
  2. McAfee shall strictly comply with all provisions of the Act, Rules and Guidelines.
  3. McAfee shall pay a penalty of Rs.1,00,000 (rupees one lakh).
  4. McAfee shall submit a report to CCPA within 15 days, on having complied with above 3 directions.