Showing posts with label dark patterns. Show all posts
Showing posts with label dark patterns. Show all posts

Wednesday, 14 January 2026

Dutch court upholds Fortnite fine for UCPD violations

 While the "Digital Fairness Act" may or may not become a thing in the near future, it is interesting to see how regulators have started to perhaps gain more confidence in the enforcement of existing rules in the digital context. A most recent example comes from a Dutch decision published today in Epic Game's case against the Dutch Authority for Consumer and Market's decision to fine the Fortnite producer for a number of prohibited practices embedded in the game. 

According to the ACM, Epic Games exposed children to advertisements which directly exhorted them to buy a product (a banned practice under the UCPD's annex) and put them under pressure to decide about a complex and unclear offer within a short time (para 1 decision).

Epic Games had earlier accepted parts of the ACM's decision, in so far as it concerned timers in the Item Shop that created the false impression that an item or offer may soon run out or disappear. They challenged, however, 1) the existence of exhortation to purchase directed at children, as well as 2) the ACM's claim that the game's Item Shop was designed in such a way to create artificial scarcity, putting players under pressure to decide within a short period of time whether to buy certain items. 

As to the first point, this hinged on the interpretation of the text in the annex. From the judgment it appears that Epic Games wanted the District Court to decide on the ACM's assumption that "children" in the UCPD's annex covers all minors, which was challenged on the basis that it failed to differentiate between young children and older teenagers. The court considers that this distinction may matter for the amount of the fine but not for the question of whether the finding of an infringement was justified and hence declines to examine the issue in detail since Epic Games has not challenged the entity of the fine. Even without a detailed examination, this element in the decision may in fact embolden authorities, which have found it tricky to claim that practices constituted direct exhortation to buy directed at children whenever a product was not exclusively marketed to very small children. There was otherwise relatively little in the decision that tried to suggest that the practices at stake (see picture, from decision) did not constitute direct exhortation to purchase.

As to the second point, the ACM (see decision para 17 and sub-paras) was relying not on a direct prohibition but on a savvy reading of the general prohibition of unfair practices which go against "professional diligence" and distort the average consumer's decision making (art 5 UCPD). In this respect, the Court says, the ACM has understood professional diligence through "the principles and international rules on ethical design such as transparency and the avoidance of damaging or misleading design". The ACM also claims that professional diligence requires abstaining from exploiting behavioural pitfalls of consumers through so-called "dark patterns".  In particular, lack of transparency about the offer was due to a mix of several elements:  items potentially disappearing from the item shop, lack of information about the items' significance within the game and their rarity (which all connected to their price), all combined with time pressure (because the Item Shop content was refreshed every 24 hours), made it difficult for consumers/children to decide without excessive pressure. The Court has accepted the ACM's analysis and characterisation of the practice, rejecting Epic Games' contention that the analysis relied on the wrong test. 

A final challenge concerned the burden of proof: did the ACM need to prove that the concerned practices had actually influenced the behaviour of children as a result of the factors that its analysis identified? The Court finds that no proof has to be provided of actual influence: it is sufficient that the analysis makes it sufficiently plausible (aannemelijk) that these effects would occur. Among other things, the court points to ACM relies on research reporting that 37% of the kids playing the concerned version of the game (namely, Battle Royale) do make in-game purchases and that significant numbers of children who make in-game purchases regret their choices afterwards (see decision para 21.1). 

The confirmed fine amounts to 1.1 million euros. It is clear from the points raised in the case that Epic Games was here seeking to establish a principled precedent against the ACM's interpretation of the UCPD and their recent steps in digital enforcement. This may suggest that the decision will be appealed - which we should know within a few weeks. Interesting case in any event!

Wednesday, 25 October 2023

Addictive design of digital services

Today the Committee on the Internal Market and Consumer Protection (IMCO) of the European Parliament adopted the draft report on Addictive design of online services and consumer protection in the EU single market (file to the procedure is here). This times nicely with the increased attention give to addictive online design by the European Commission, which intends to devote one of its two panels to this topic at the forthcoming 3rd Annual Digital Consumer Event (held on 30 November - more information and agenda is here). 

By Rodion Kutsaiev on Unsplash
The report draws attention to psychological vulnerabilities that 'certain' platforms and tech companies exploit online. The main concerns are about addictive, behavioural and manipulative design that maximises the frequency and duration of user visits. This is seen as leading to both non-material and material harm. Thus IMCO calls on the European Commission to conduct more evaluation whether new regulation could help 'close existing regulatory gaps with regard to consumer vulnerabilities, dark patterns and addictive features of digital services'. This follows from the assessment that existing measures (Digital Services Act and AI Act, but also Unfair Commercial Practices Directive) are insufficient to address these issues. As examples of dark patterns that current legislation would not consider as unfair the report mentions: infinite scroll, default auto play function, constant push notifications, read receipt notifications. 

Interestingly, in the report: 

  • Point 3 - mentions the need to re-evaluate the main current notions of EU consumer law from the perspective of digital age, such as 'consumer', 'vulnerable consumer' and 'trader'. 
  • Point 4 - draws attention to the limited function of transparency to fight deceptive design and calls for urgent need to assess whether certain practices should not be blacklisted under the UCPD (rather than transparently disclosed). 
  • Point 6 - argues for (amongst others): 
    • the integration of the concept of digital asymmetry into the UCPD; 
    • reversal of the burden of proof for practices presumed to be addictive; 
    • an obligation to ethically design digital services, which would be necessary to comply with professional diligence obligation.
  • Point 7 - concerns the need to re-evaluate addictive and mental health effects of interaction-based recommender systems, incl. hyper-personalised systems. Overall, this point calls for the re-assessment of the desirability of online personalisation, and replacing recommender systems based on it with such that are based on chronological order or that give users more control.
  • Point 8 - proposes introduction of the digital 'right not to be disturbed' by 'turning all attention-seeking features off by design'.
  • Point 9 – calls for fostering of ethical design by default, which could be supported by the Commission upholding a list of good design practices. As best practices it mentions: 
    • ‘think before you share’, 
    • turning of all notifications by default, 
    • more neutral recommendations, 
    • up-front choice between colour and greyscale apps, 
    • warnings when users have spent more than 15-30 minutes on a specific service, 
    • automatic locks for certain services after a preset time of use, 
    • weekly summaries of total screen time (but also with an option for a break-down), 
    • in-app awareness campaigns on potential risks. Educational campaign should promote ‘self-control strategies to help individuals develop safer online behaviours and new healthy habits’.

The European Parliament intends for the principle of ethical design to be predominant for digital services and products (see press release here) in order to counteract harmful impact of digital addiction on mental health. The attention to mental health issues arising from online interactions, especially amongst minors, is rising, not only in the EU. The UK has just finished accepting submissions to its inquiry into Preparedness for online safety regulation (see here). This sensitive topic definitely requires more attention, thus we will be keeping an eye on the forthcoming discussions on this.

Thursday, 22 June 2023

Iliad aka cancelling Amazon Prime subscription

Most of our readers probably have already seen this news, but it is still interesting to address it: Federal Trade Commission (FTC) charged Amazon for the use of dark patterns/manipulative practices in its practices related to subscription (and its cancellation) to Amazon Prime (see FTC Takes Action Against Amazon...). Whilst this case plays out in the US, it will be fascinating to follow it and learn from it for European academics and enforcement authorities alike. 

The topic has been alive in the European academia, amongst the consumer protection and market authorities and policymakers for a few years now (see the recording of the debate on dark patterns as a challenge to online consumer protection, held during the Internet Governance Forum 2022, in which I took part, here). On EU level, in 2022, the EDPB issued Guidelines 3/2022 on Dark patterns in social media platform interfaces (see here). The European Commission addressed the issue of data-driven practices and dark patterns in its 2021 guidance to the Unfair Commercial Practices Directive (see here). The Commission indicated the applicability of the UCPD framework to combat such practices, when they apply to B2C relations. Yet, the Commission released results of a screening of retail websites in January 2023, which was conducted with the CPC Network, showing the prevalence of various manipulative practices online in the EU as well (see here). Clearly, more enforcement is needed, which highlights the importance of the FTC case.

The main charge against Amazon is that it knowingly, by use of 'online manipulative, coercive, or deceptive user-interface designs', caused consumers to enrol in Amazon Prime, an automatically-renewing subscription service, without their consent. This was done, e.g. by making it difficult to locate an option to purchase a product on Amazon without subscribing simultaneously to Amazon Prime.

Image by Jo Justino from Pixabay
Amazon also purposefully complicated the cancellation process, instead of enabling subscribers to cancel, stopping them from doing so. They showed multiple pages consumers had to go through, rejecting various other options than cancellation, e.g. stopping the auto-renewal, accepting subscription at a discount. How complex did they make it? Amazon itself used the term 'Iliad' to describe this cancellation process: 'an allusion to Homer’s epic poem set over twenty-four books and nearly 16,000 lines about the decade-long Trojan War' (see Project Iliad...). What defence will they use and how will the case unfold? To be continued. 

Thursday, 27 October 2022

OECD report on Dark Patterns

 Yesterday, aka 26 October 2022, the OECD has released a report on Dark Patterns which had been in the making for almost two years. LLM students who would like to write about the topic or just about anyone looking for a clear intro to the subject - this report is your friend! It contains not only a helpful classification of different types of dark patterns but also a quite comprehensive review of relevant regulatory frameworks/interventions, known case-law and much (if not all, and if arguably too US-centred and English-based) of the literature you may also want to look at, including... Joasia's 2019 JCP paper The Transparent Trap! Kudos there.

A working definition is provided at the outset which may or may not gain traction in the field: dark patterns, accordingly, are 

"business practices employing elements of digital choice architecture, in particular in online user interfaces, that subvert or impair consumer autonomy, decision-making or choice. They often deceive, coerce or manipulate consumers and are likely to cause direct or indirect consumer detriment in various ways, though it may be difficult or impossible to measure such detriment in many instances."

[The first part of the report, where dark patterns are typified and their impact assessed, I skip for now - but you can find it all online!]

The report acknowledges that more enforcement is necessary in the EU, while ultimately praising the UCPD's relative ability to address the problem in comparison with other instruments: if on the one hand resonance with the black listed items in the annex makes it possible to address certain black patterns with a degree of legal certainty, the report observes, the "principle-based" prohibition of unfair commercial practices works quite well to cover technological and commercial developments like the ones at hand. 

One critical point that is (thankfully) mirrored in the report is known criticism of the average consumer standard: this standard is hard to square with consumers' apparent vulnerability to dark patterns & other online perils &, the report observes, seems particularly problematic in the context of increasing online personalisation. The report also highlights criticism of disclosure rules, in particular as a way of preventing consumers from falling for dark traps: it turns out, the report concludes, that all experiments trying to measure the effects of disclosures in this area failed to detect any serious improvement. Hence the relevance of information may be limited to broader education campaigns and possibly to a limited set of dark patterns. 

The report also interestingly reviews examples of technical supports that are being developed - essentially, dark pattern-blockers for one's browser. These are, apparently, useful in some cases but less so when the dark patterns is not to be "written away" in code (p 47). I would like an app like that though!

As a scholar who reads Law & Econ work with a mix of interest and skepticism, I was less impressed by the report's discussion of nudges on page 37, under "Digital choice architecture". The title reflects a trend that has been going on for a long time of course; the report, however, brings together under one technique concerns that may need to be kept separated. "Privacy by design", that is mentioned as example, is not the same as a "bright pattern" based on extrapolating "welfare enhancing" choices from supposed "preferences or expectations". While the report necessarily gives a limited overview on each issue, conflating privacy protection with "consumertarian" views and hard-core nudge advocates is to my mind quite problematic.

Anyway, this is really a good starting point but also, as far as I can tell, a fairly comprehensive restatement that those already in the debate will also benefit from. Recommended read!

Thursday, 4 February 2021

CMA's paper on algorithms & online platforms: comprehensive report on benefits and perils of AI regulation

The UK Competition and Market’s Authority recently published a report on the consequences of the online platforms’ use of algorithms (‘sequences of instructions to perform a computation or solve a problem’) for consumer protection and for competition (here). This report builds on the CMA’s 2018 paper on pricing algorithms (here). The report starts by highlighting that the increasing sophistication of algorithms usually means decreasing transparency. The CMA’s report acknowledges the benefits of algorithms to consumers, such as the possibility to save consumers’ time by offering them individualized recommendations. Additionally, algorithms benefit consumers by increasing efficiency, effectiveness, innovation and competition. However, the main goal of the report is to list (economic) harms caused to consumers as a result of algorithms.

The report highlights that big data, machine learning, and AI-based algorithms are at the core of major market players such as Google (e.g. their search algorithm) and Facebook (e.g. their news’ feed algorithm). The CMA also acknowledges that many of the harms discussed in this report are not new but were made more relevant by recent technological advances. Finally, the report acknowledges that the dangers brought by algorithmic regulation are even greater where it impacts consumers significantly (such as decisions about jobs, housing or credit).

The harms discussed in the report deal mainly with choice architecture and dark patterns (e.g. misleading scarcity messages on a given product or misleading rankings). Additionally, personalization is depicted as a particularly dangerous harm, since it cannot be easily identified and because it manipulates consumer choice without that being clear to consumers. Personalization is also worrying because it targets vulnerable consumers. In particular, the CMA is worried about possible discrimination as a result of personalization of offers, prices and other aspects.

Personalized pricing implies that firms charge different prices to different consumers according to what the firm (and their algorithms) think that the consumer is willing to pay. While this has some benefits – like lowering search costs for consumers, the CMA warns that consumers might lose trust in the market as a consequence of personalized pricing practices. While some personalized pricing techniques are well-known – such as offering coupons or charging lower prices to new customers, others are more opaque and harder to detect. Non-price related personalization is also described as potentially harmful, such as personalized search results rankings or personalized recommendation systems (e.g. what videos to show next). In particular, the CMA warns that these systems may lead to unhealthy overuse or addiction of certain services by consumers and to a fragmented understanding of reality and public discourse.

Additionally, the use of algorithms harms competition since it can exclude competitors (e.g. through platform preferencing, via ranking, of their own products). Through exclusionary practices, dominant firms can stop competitors from challenging their market position. A prominent example of this is that of Google displaying its own Google Shopping service in the general search results page more favorably than competitors that offer similar services. Finally, the CMA report zooms in on algorithmic collusion, or the use of algorithmic systems to sustain higher prices.

The report also highlights the obstacles brought by lack of transparency, particularly when it comes to platform oversight. The CMA warns that this lack of transparency and the misuse of algorithms may lead consumers to stop participating in digital markets (e.g. deleting social media apps). This justifies, in the CMA’s opinion, the regulators’ intervention. In particular, the CMA considers that regulators can provide guidance to businesses as to how to comply with the law or to elaborate standards for good practices. Overall, the report brings attention to the fact that many laws in place do not apply to algorithmic regulation, such as to discrimination in AI systems. Moreover, the CMA highlights that the application of consumer law to protect consumers against algorithmic discrimination is still an unexplored area.

The report ends with a call for further research on the harms caused by algorithmic regulation. The CMA suggests techniques to investigate these harms that do not depend on access to companies’ data and algorithms, such as enlisting consumers to act as ‘mystery shoppers’ or through crawling or scraping data from websites. The CMA also suggests specific investigation techniques when there is access to the code.

Overall, this is an extremely comprehensive report that not only explains the biggest consumer harms brought by AI regulation but also contains several practical examples, as well as concrete methodological suggestions for further research and for better enforcement. Definitely a recommended read for both academics and practionners alike.

Tuesday, 26 January 2021

Norwegian Consumer Council - sheriff of online consumer protection

The Norwegian Consumer Council (Forbrukerrådet) has published two interesting news reports this month. 
 
First, on Jan 14 it has reported on potentially unfair commercial practices of Amazon, which make it difficult for consumers to cancel their Amazon Prime subscription (You can log out, but you can never leave). The Norwegian Consumer Council identified many of these practices as Amazon using dark patterns to manipulate consumers online, hindering them in making informed choices, trying to nudge them away from actually cancelling the subscription (by misdirection, visual interferences, confirmshaming). This may be achieved through making consumers go through many pages, asking them to confirm their choices in a manner that causes confusion with consumers, etc. Generally, the Norwegian survey looked into practices of digital service providers, where consumers would take out a subscription for services. Such subscriptions involve automatic payments, content is delivered online, and thus if consumers stop using a service they may forget about it, it becomes invisible to them. Therefore, it may be especially important to facilitate consumers' termination of such services. And yet, the survey found that 25% of respondents have experienced problems with cancelling such subscriptions due to a difficult process having been set up.

Today, it has reported that another Norwegian authority - Norwegian Data Protection Authority (Datatilsynet) - issued a fine of over 9.5 million Euro to the dating app Grindr (10% of their global annual revenue), following on the Norwegian Consumer Council's complaint from a year ago about infringements of privacy by this app (Historic victory for privacy as dating app receives gigantic fine). The breach of GDPR occurred due to the app collecting and sharing personal data without sufficiently informed and explicit users' permission to such practices (more in the report 'Out of control', on Grindr specifically as of p. 72).

Friday, 13 November 2020

Dark patterns and conditions for a valid consent to data processing - judgment of the CJEU in C‑61/19 Orange Romania

Earlier this week, the Court of Justice delivered a judgment in case C-61/19 Orange Romania, concerned with the conditions for a valid consent to the processing of personal data under EU data protection law (the Data Protection Directive 95/46/EC and the General Data Protection Regulation 2016/679, which remains in effect as of May 2018). The case follows up on the previous ruling in C-673/17 Planet49, on which we commented last year (see also: Planet49: Pre-Ticked Checkboxes Are Not Sufficient...). Aside from confirming the importance of an "active" consent, the Court elaborates on the requirement for consent to be informed, specific, unambiguous and freely given, building bridges to important categories known from consumer law, such as transparency and misleading practices.

Facts of the case

The dispute goes back to a fine imposed by the Romanian data protection authority on the provider of mobile telecommunications services, Orange România, for an allegedly unlawful storage of the copies of customers' identity documents. In particular, the authority argued, the data controller failed to demonstrate that the data subjects had given their valid consent to the contested processing. What makes the case interesting is that the storage of ID cards was, in fact, explicitly mentioned in the contracts which Orange concluded with its customers. Specifically, the following wording is cited:

"The customer states that: ... (ii) Orange România has provided the customer with all the necessary information to enable him or her to give his or her unvitiated, express, free and specific consent to the conclusion and express acceptance of the contract; (iii) he or she has been informed of, and has consented to [numerous types of processing, including the storage of copies of documents containing personal data for identification purposes]."

As seen from above, both the declaration of "consent" and the confirmation of having received the associated information were pre-forumlated by the trader. At least in certain cases they were also already "pre-ticked". In fact, however, consent to the storage of the copies of ID cards was not necessery for entering into a contract and customers, who refused to consent, were not prevented from the contract conclusion. Data subjects who did not wish their ID cards to be copied, though, were asked to go through additional steps, most notably confirm their refusal in a specific form, which, like pre-ticked checkboxes, can be regarded as an example of dark patterns in action (or, in this case, "sludge"). 

Against this backgroud, doubts have been raised, among others, as to whether the clauses on data processing were sufficiently distinct from the remaining parts of the documents, whether the data subjects were not misled about the possibility of refusing consent to the storage of ID cards and, if so, whether this could have an impact on the validity of their consent.

Legal provisions

Even though the contested fine was imposed on Orange România prior to the date of application of the GDPR, the Court of Justice decided to provide guidance on both Directive 95/46/EC and Regulation 2016/679. Key norms subject to the analysis where those laying down conditions for a valid consent. Focusing on the GDPR, attention should be drawn to its Article 6(1)(a), listing data subject's consent among the grounds for the lawful professing of his or her personal data, and to Article 4(11), which defines "consent" as any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her. Of relevance are further the associated information duties in Article 13 as well as (non-binding) clarification of the above in recitals 32 and 42.

Judgment of the Court

While the specific assessment of the case at hand has been left to the national court (in line with the nature of preliminary reference procedure), the judgment provides important guidance on the legal provisions to be applied. In particular:

  • The Court recalls that for consent to be validly expressed (by the data subject) and later demonstrated (by the controller), the corresponding wish of the data subject should be reflected in his or her active behaviour. In particular, unambiguous and informed consent cannot be inferred from the fact that the data subject did not deselect a pre-ticked checkbox (paras. 35-37, 45-46; on the burden of proof, see also paras. 42, 51).
  • The judgment goes on to discuss the definition of consent as a "specific" indication of data subject wishes, highlighting the requirements of Article 7(2) (presentation of the request for consent in a manner which is clearly distinguishable from the other matters) and recital 42 of the GDPR (presentation of pre-formulated declarations in an intelligible and easily accessible form, using clear and plain language). The latter is especially worth highlighting, as it directly refers to Directive 93/13/EEC on unfair terms in consumer contracts. Transparency of declarations is also considered relevant for establishing whether consent so expressed has been informed. What is more, corresponding information provided by the controller "must enable the data subject to be able to determine easily the consequences of any consent he or she might give", which again brings to mind the requirements for substantive transparency known from consumer law stricto sensu (paras. 38-40, 47-48). The latter may have significant impliactions for the validity of consent to the processing of personal data in the context of automated decision-making.
  • Finally, an important part of the judgment concerns the requirement for consent to be freely given (and again informed). In para. 41, the Court observes that "in order to ensure that the data subject enjoys genuine freedom of choice, the contractual terms must not mislead him or her as to the possibility of concluding the contract even if he or she refuses to consent to the processing of his or her data" (similarly para. 49). This brings to mind the notions of misleading actions and ommissions, known from Articles 6 and 7 of Directive 2005/29/EC on unfair commercial practices (note that the Directive refers directly to the "freedom of choice" only in the subsequent provision on aggressive practices). At a later point of the judgment, the Court also questions the free nature of consent in the case at hand in view of the additional burden (sludge) imposed by the controller on the data subjects who wish to refuse consent (para. 50). As in the other instances, however, an assessment is ultimately left to the referring court. 

Concluding thoughts

Overall, the judgment provides for a range of important reference points, which may help to increase the level of consumer and data protection in the EU. Worth noting are the recurring references to the requirement of an "informed" consent, which appears to complement and reinforce all other conditions. The judgment underlines the close connection between data protection and consumer law stricto sensu, which has long been observed in the literature. Recognition of the role of (substantive) transparency and of potentially misleading practices in assessing consent validity is also to be welcomed. Both seem especially relevant in the digital market, where the consequences of consent are often difficult to determine and where dark patterns remain prevalent.