Legal analysis finds uneven European Union regulatory coverage of manipulative interface designs across platforms, highlighting enforcement gaps regarding non-material harm and third-party data.
Technological advancements have transformed the ways in which individuals interact with digital platforms, giving rise to data-driven ecosystems in which interface design plays a central role. Within these environments, dark patterns and manipulative and deceptive design techniques shape user behaviour in ways that undermine privacy, autonomy, and informed consent. This paper develops a harm-based analytical framework for privacy dark patterns by deriving a typology of privacy-relevant design mechanisms through a structured consolidation of four independently produced taxonomies. It then constructs a harm typology by combining an injury-based framework with the harm categories developed by regulatory authorities and maps each design mechanism to the harms it is structurally apt to produce. Finally, it identifies the provisions of EU law that each mechanism engages, across the GDPR, consumer protection law, the Digital Services Act, the Digital Markets Act, the Data Act and the AI Act. The analysis finds that the GDPR engages every mechanism identified, that coverage by post-GDPR instruments is uneven, and that one mechanism—the exploitation of relational and third-party data—engages no post-GDPR instrument squarely. The deficiency in the EU framework therefore lies not in the substance of its prohibitions but in the coordination of enforcement and in the evidentiary architecture through which non-material harm must be established.
No takes yet. Share an insight, caveat, or question.
Kitsos et al. (2026) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: