Ecommerce Website Development in Pune: Designing Checkouts That Survive the CCPA's Dark Pattern Crackdown
India's Central Consumer Protection Authority (CCPA) has spent the last three years turning "dark patterns" from a UX design term into a legal liability, and on 6 August 2026 it fined nine platforms — including Zepto, BookMyShow and IndiGo — close to Rs 20 lakh in total for exactly this. For anyone commissioning ecommerce website development in Pune today, this changes what "good checkout design" means: a countdown timer, a pre-ticked donation box, or a "no thanks, I don't want to save money" decline button is no longer just a conversion-rate tactic — it is a specific, named unfair trade practice that a government authority is actively fining companies over.
This article walks through what the CCPA guidelines actually prohibit, what has happened in real enforcement cases so far, and what a practical audit of your product pages and checkout flow should look like before you launch or relaunch a store built for Indian customers.
What the CCPA Dark Pattern Guidelines Actually Say
The Guidelines for Prevention and Regulation of Dark Patterns, 2023 were notified by the Central Consumer Protection Authority, under India's Consumer Protection Act, 2019, and took effect from 30 November 2023. They apply to any seller, advertiser, or platform that systematically offers goods or services to consumers in India — including sellers and platforms based outside the country if they serve Indian customers. That last point matters for anyone running a Shopify, WooCommerce, or custom-built storefront that ships internationally but sells into India: the guidelines follow the customer, not the company's registered address.
The CCPA defines a "dark pattern" as any practice or deceptive design using user interface or user experience elements that is designed to mislead or trick a user into doing something they did not originally intend, by subverting their autonomy or decision-making, and that amounts to a misleading advertisement, an unfair trade practice, or a violation of consumer rights under the Act. That is a broad definition on purpose — it is meant to cover new manipulative patterns as they appear, not just the specific list that follows.
The 13 named categories
The guidelines (as later clarified through the CCPA's 2025 advisory to e-commerce platforms) identify thirteen specific dark pattern categories that are treated as unfair trade practices:
- False urgency
- Basket sneaking
- Confirm shaming
- Forced action
- Subscription trap
- Interface interference
- Bait and switch
- Drip pricing
- Disguised advertisement
- Nagging
- Trick questions
- SaaS billing (recurring/hidden billing patterns specific to subscription software)
- Rogue malware / misleading ads that install unwanted software
Each of these has a plain description in the guidelines document, and each maps directly onto specific, common checkout and product-page UI decisions — which is why this is not an abstract compliance topic for a Pune-based store owner. It is a design-review checklist.
Enforcement So Far: What Has Actually Happened
Guidelines on paper are one thing. What makes this relevant to a live production website is that the CCPA has already acted against named platforms, and has told the entire e-commerce sector to self-audit.
The August 2026 fines: nine platforms, close to Rs 20 lakh
The clearest sign that this has moved from guideline to active enforcement came on 6 August 2026, when the CCPA imposed monetary penalties totalling close to Rs 20 lakh on nine platforms in a single action: Zepto, BookMyShow, IndiGo, Physics Wallah, FirstCry, PharmEasy, SpiceJet, McAfee and the coaching platform Anuj Jindal Academy. Zepto drew the largest individual fine, Rs 7 lakh, for drip pricing (showing a lower headline price, then adding handling charges) and basket sneaking (automatically adding a paid membership to the cart). Physics Wallah was fined Rs 5 lakh after a Rs 10 donation to its foundation was found pre-selected by default — another basket-sneaking case. The remaining platforms drew fines between Rs 1 lakh and Rs 3 lakh each, for a mix of hidden charges, misleading countdown timers, and manipulative subscription-renewal flows.
IndiGo and BookMyShow are worth walking through individually, because both patterns recur constantly in ordinary Indian checkout flows and predate this specific fine round — the CCPA had already pushed both companies toward the same fixes in an earlier 2024 intervention, before this year's formal penalty action.
IndiGo's seat-selection flow
IndiGo's booking app displayed the decline option for paid seat selection as "No, I will take the risk" — implicitly framing the free option as reckless rather than neutral. The CCPA classified this as confirm shaming (wording a decline option to make the user feel foolish or unsafe for choosing it), combined with interface interference that made the free path harder to find than the paid one. Following the CCPA's intervention, IndiGo changed the wording to the neutral "No, I will not add to the trip."
BookMyShow's pre-checked contribution
BookMyShow's "BookASmile" charitable add-on automatically added a small per-ticket contribution to the cart through a pre-ticked box, rather than asking the customer to opt in. This is a textbook case of basket sneaking — adding an item, service, or charge to a cart without an explicit customer action. The CCPA directed BookMyShow to make the contribution something a customer actively chooses, rather than something added by default that has to be manually removed.
What this means beyond the nine named platforms
None of the nine companies fined are small operators — several run dedicated legal and compliance teams, and were still fined for patterns that are common on far smaller Indian storefronts: a pre-ticked add-on checkbox, a countdown timer on a product page, a "no thanks" link styled to be harder to see than the "yes" button. The CCPA's willingness to name and fine platforms of this size is the clearest available signal that the guidelines are enforced in practice, not just published in principle, and that scale does not provide cover.
The June 2025 self-audit advisory
The most consequential development for ordinary online stores came in June 2025. Following a stakeholder meeting where the Ministry of Consumer Affairs identified the same 13 dark pattern categories as being widespread across Indian e-commerce, the CCPA issued a formal advisory (effective from early June 2025) directing all e-commerce platforms to carry out a self-audit within three months, identify any dark patterns present on their sites, correct them, and be prepared to make self-declarations of compliance. This advisory is not limited to the handful of large platforms that have already received notices — it is addressed to the sector as a whole, which functionally includes any Pune-based business running its own online store.
The practical upshot: the CCPA is not treating this as a one-time notice cycle against a few large names. It has set an expectation that every e-commerce operator reviews its own product pages and checkout flow against these categories, on an ongoing basis, not just once.
The Dark Pattern Categories, Explained With Real Checkout Examples
The table below maps each named category to how it commonly shows up on an Indian e-commerce checkout, and what a compliant version of the same feature looks like. This is the level of detail an actual design or development audit needs to work with — not just the category name.
| Dark pattern | Typical example on an Indian checkout | Compliant alternative |
|---|---|---|
| False urgency | A countdown timer that resets every time the page reloads, or "Only 2 left!" stock labels that never change regardless of actual inventory | Show real stock counts pulled from inventory data, or remove urgency messaging where stock is not genuinely limited |
| Basket sneaking | A "delivery protection," insurance add-on, or donation checkbox that is pre-ticked and adds to the cart total automatically | Leave optional add-ons unchecked by default; require an explicit tap or click to add them, with the price shown before selection |
| Confirm shaming | Decline buttons worded to guilt or mock the user, e.g. "No, I don't want to save money" instead of "No thanks" | Use neutral, symmetrical language for accept and decline options, matched in size and visual weight |
| Forced action | Requiring account creation, a newsletter subscription, or an app download before a customer can complete checkout or even see the final price | Allow guest checkout and let customers see full pricing without forced sign-up steps |
| Subscription trap | Easy one-click signup for a paid plan or auto-renewal, but cancellation buried several menus deep, requiring a call, or requiring an email | Make cancellation reachable in the same number of steps as signup, ideally self-service in account settings |
| Interface interference | Greying out or visually de-emphasizing the "skip" or "no" option while highlighting the "yes" or upsell option in a bright colour | Give both options equal visual prominence and equal ease of interaction |
| Bait and switch | Advertising one product or price, then substituting a different (often costlier) item or an "out of stock, but here's an alternative" swap at checkout | Only advertise what is actually available at the advertised price; clearly flag substitutions as optional, not automatic |
| Drip pricing | Displaying a low headline price on the product page, then adding handling fees, "convenience fees," or platform fees only at the final payment screen | Show all mandatory charges — GST, shipping, handling — on the product page or cart, before the final payment step |
| Disguised advertisement | Sponsored listings or paid placements shown in search results without any label distinguishing them from organic results | Label sponsored or promoted listings clearly, distinguishable from organic search results |
| Nagging | Repeated pop-ups pushing the same upsell, app-install prompt, or offer every time a customer navigates the site | Limit repeat prompts to a reasonable frequency, with a clear and persistent way to dismiss them permanently |
| Trick questions | Ambiguous checkbox wording where checking a box has the opposite effect of what it appears to say (e.g. a double negative in a marketing opt-out) | Use plain, unambiguous language for every checkbox and toggle, tested with someone outside the design team |
| SaaS/recurring billing traps | Auto-charging a card for a "free trial" without a clear reminder before the first paid charge | Send an advance reminder before any trial converts to a paid charge, and confirm the billing amount and date clearly at signup |
| Rogue malware / misleading ads | Ad creatives or pop-ups designed to look like system alerts or security warnings to drive clicks | Use honest ad creative that does not mimic OS or browser system messages |
Any team doing ecommerce website development in Pune should treat this table as a literal review checklist against a live staging build, not a one-time reading exercise. Several of these — drip pricing, forced action, and interface interference in particular — are easy to introduce accidentally through templates, plugins, or third-party checkout widgets that were not built with the CCPA guidelines in mind.
Beyond the CCPA: Other Rules That Touch Your Checkout Design
The CCPA guidelines are not the only relevant framework. Two other developments shape what a compliant Indian checkout should look like in 2026.
ASCI's advertising-side guidelines
The Advertising Standards Council of India (ASCI), a self-regulatory advertising body, issued its own Guidelines for Online Deceptive Design Patterns in Advertising in mid-2023, in force from 1 September 2023. These focus specifically on advertising and marketing creative rather than the full checkout flow, and call out four techniques by name: drip pricing, bait and switch, false urgency, and disguised ads. Because ASCI's guidelines and the CCPA's guidelines overlap on these categories, an ad campaign that uses a false-urgency banner and then links to a product page repeating the same false urgency claim is exposed on two fronts at once.
Consumer Protection (E-commerce) Rules
Separately from the dark pattern guidelines, the Consumer Protection (E-commerce) Rules made under the Consumer Protection Act set baseline transparency obligations for marketplaces and sellers — disclosure of seller details, return and refund policies, grievance officer information, and country-of-origin labelling, among others. These rules predate the dark pattern guidelines but sit alongside them: a checkout audit done properly should check both sets of obligations together, since a missing return policy disclosure and a drip-pricing pattern are both compliance gaps, just under different rules. If you are auditing beyond checkout UX specifically, related legal-compliance topics for Indian online stores are covered in our GST compliance checklist for Indian e-commerce.
What This Means for Ecommerce Website Development in Pune Right Now
If you are commissioning a new store, or reworking an existing one, the dark pattern guidelines change three things about how the build should be scoped.
Checkout UX decisions need a compliance sign-off, not just a conversion review
Historically, checkout flow tweaks — urgency banners, pre-selected add-ons, upsell pop-ups — were reviewed purely on conversion impact. That review now needs a second lens: does this pattern fall into one of the 13 named categories? A pattern that lifts conversion by 2% but exposes the business to a CCPA notice is not a good trade for a Pune-based retailer that cannot absorb the reputational cost of a public enforcement action.
Template and plugin choices matter more than before
A large share of dark pattern risk on Indian stores does not come from deliberate manipulation — it comes from default behaviour baked into third-party checkout plugins, theme templates, or payment gateway widgets that were built for a different regulatory environment. Drip pricing in particular is common by default: many gateway integrations only calculate and display convenience fees at the final payment step unless the integration is deliberately configured otherwise. A custom checkout and payment system build gives you control over exactly where and when each charge is disclosed, rather than inheriting a plugin's default flow.
Two-factor authentication and payment-flow rules intersect with this too
Checkout compliance in India is not only about dark patterns. RBI's additional factor of authentication requirements for card-on-file and recurring payments also shape how a checkout screen is built, and the two sets of rules interact — a poorly designed 2FA step can itself become a forced-action or nagging pattern if it repeats unnecessarily. We cover this in more detail in our guide to RBI's 2FA requirements for e-commerce checkouts. For a broader view of what a compliant, modern store build in Pune should include end to end, see our pillar guide to e-commerce website development in Pune.
How We Approach This at Govindani Infotech
When we build or audit a checkout for an e-commerce client, dark pattern review is now a standard part of the process, not an optional add-on. We walk through every step of the cart and payment flow against the CCPA's named categories — checking default-checked boxes, urgency messaging, fee disclosure timing, cancellation paths for subscriptions, and the wording on decline or skip buttons — before a build goes live, and we flag any third-party plugin or gateway widget whose default behaviour introduces a pattern the client did not ask for and would not want. We do not treat this as a legal-compliance checkbox exercise disconnected from design; a checkout that is honest about pricing and easy to exit tends to convert better over time anyway, because it does not generate the chargebacks, refund disputes, and support tickets that manipulative flows eventually produce. Our own pricing for checkout and store builds is confirmed directly with our team based on your specific requirements — the fastest way to get a number is to get in touch with us.
Frequently Asked Questions
Do the CCPA dark pattern guidelines apply to small or single-owner online stores, or only large platforms?
The guidelines apply to any seller, advertiser, or platform that systematically offers goods or services to consumers in India, which is not limited by company size. The 2025 advisory calling for self-audits was addressed to e-commerce platforms broadly, so a smaller Pune-based store is within scope even though enforcement attention so far has focused on larger, more visible platforms.
Is a countdown timer on a product page automatically illegal?
Not automatically — the guidelines target false urgency, meaning urgency messaging that misrepresents actual availability or time pressure. A countdown timer tied to a real, verifiable sale end date or actual stock levels is different from a timer that resets on every page load or a stock counter that never changes regardless of real inventory.
What is the actual penalty if the CCPA finds a dark pattern on our site?
The Consumer Protection Act gives the CCPA authority to issue directions, require corrective changes, and in more serious cases impose penalties for unfair trade practices or misleading advertising, in addition to the reputational cost of a public notice. In the enforcement cases seen so far, platforms were directed to make specific design changes to remove the identified pattern rather than facing an immediate financial penalty, but the CCPA's own communications describe further consequences for continued non-compliance.
Does using a well-known e-commerce platform (Shopify, WooCommerce, etc.) protect us from dark pattern risk?
No. The platform itself is a tool; the responsibility sits with the seller configuring the checkout. Default themes, checkout plugins, and payment integrations frequently include patterns — like fees revealed only at final payment, or pre-selected add-ons — that were never reviewed against Indian consumer protection rules, so the configuration needs to be audited regardless of which platform it runs on.
How is a subscription trap different from a normal recurring-billing subscription model?
A legitimate subscription model discloses the recurring charge amount and renewal date clearly at signup and makes cancellation reasonably easy to find and complete. It becomes a subscription trap when signup is frictionless but cancellation requires calling a support line, sending an email, or navigating an unreasonable number of steps that a normal user would not persist through.
Should we wait for a CCPA notice before reviewing our checkout, or act now?
Acting now is the lower-risk and lower-cost option. The June 2025 advisory already put the entire sector on notice to self-audit, and the enforcement cases so far show the CCPA is willing to name and act against platforms directly. A planned review during a redesign or rebuild costs far less than a reactive fix under regulatory pressure.
Where to Start
A practical first pass does not require a legal team — it requires someone going through your live checkout screen by screen against the categories above. Use this as a starting checklist:
- Load your checkout on a fresh browser session and note every checkbox, toggle, or add-on that is pre-selected by default.
- Check whether your total price on the product page matches the price on the final payment screen, or whether new charges appear only at the last step.
- Read every "no" or "skip" button out loud — does it sound neutral, or does it guilt the customer?
- Try to cancel any subscription or recurring plan yourself, and count how many steps it takes compared to signing up.
- Check whether any countdown timer or "limited stock" label reflects real data or is static/decorative.
- Confirm sponsored or promoted product listings are visibly labelled as such.
- Confirm guest checkout is available and does not force account creation or app installs before showing price.
If that review turns up more than a couple of items, or you are planning a new store build and want compliance handled from the first wireframe rather than retrofitted later, our team can walk through your specific flow — reach out to Govindani Infotech and we will tell you plainly what needs to change.
Sources:
- Business Standard — CCPA fines IndiGo, Zepto, BookMyShow and six others over 'dark patterns'
- afaqs! — CCPA fines Zepto, BookMyShow, IndiGo and six others over 'dark patterns'
- PIB India — CCPA Acts Against Dark Patterns on Digital Platforms
- AZB & Partners — Regulatory Crackdown on Dark Patterns: CCPA's Enforcement Actions and Emerging Compliance Landscape in Indian E-Commerce
- AZB & Partners — Central Consumer Protection Authority Issues Advisory to E-Commerce Platforms for Self-Audit
- News on Air — Central Consumer Protection Authority Advises All E-Commerce Platforms to Not Engage in Deceptive, Unfair Trade Practice
- SCC Online — ASCI Guidelines on Deceptive Design Patterns in Digital Media Advertisements to Be Applicable from 01-09-2023