Dark pattern audit · Rule 4(15) · In force 1 January 2027

Evidence for the certificate someone at your company has to sign.

From 1 January 2027, every e-commerce entity in India must audit itself for dark patterns each year and prominently display a certificate that its platform is free of them. The rule prescribes no method, no evidence standard and no auditor. DarkPatternAudit tests your real customer journeys, seals what it observes, and gives your signatory a documented basis for the statement.

The rule

One sentence of law, and everything it leaves open

New sub-rule 4(15), inserted by G.S.R. 789(E) on 9 September 2026, requires every e-commerce entity to comply with the Guidelines for Prevention and Regulation of Dark Patterns, 2023, to “conduct yearly self-audit to ensure that its platform is free from dark patterns”, and to display a certificate to that effect prominently.

What it settles

  • The 2023 Guidelines become binding for e-commerce entities.
  • The audit is yearly, and it is a self-audit.
  • The certificate is the entity's own, and it must be displayed prominently — so its absence is visible to anyone.
  • It applies to every e-commerce entity, including brands selling from their own website.

What it leaves open

  • No audit method, sampling rule or evidence standard.
  • No certificate format, signatory or filing requirement.
  • No recognised or empanelled third-party auditor.
  • No meaning given to “prominently”.

The problem

The exposure is not the fine. It is the signature.

A named person has to stand behind an absolute public claim — that the platform is free from dark patterns — while the product team ships interface changes every week.

And the claim is tested in public. LocalCircles, a citizen platform, reported in 2025 that 21 of the 26 platforms that self-declared under the CCPA's advisory still showed at least one dark pattern.

A one-page declaration with nothing behind it is the weakest position to be in when that happens. A dated, reproducible record of what was tested, what was found and what was fixed is the strongest.

The method

Most dark patterns can't be seen on one screen

By our reading, eight of the thirteen patterns in the 2023 Guidelines only show up across steps, sessions or time: a timer that resets, a fee that appears at the last step, an item added to the cart without being asked for, a cancellation path far longer than sign-up. A page scanner looks at a single screen. We change one condition at a time and checks what an honest interface would have to do.

Session A, first load

09:59

“Only 2 left at this price”

Baseline recorded

Session A, reload after 3 minutes

09:59

Expected 06:59

Timer is not monotonic

Session B, fresh profile, +20 minutes

09:59

“Only 2 left at this price”

Scarcity claim never varies

Session A, after the stated deadline

00:00

Same offer, same price

Offer outlives its deadline

Illustration: a behavioural test for false urgency. A genuine limited-time sale holds all three invariants. No language model is involved in the decision; every probe is recorded and replayable.

Decided by test

Where the question is objective — timers, cart contents, price arithmetic, default states of consent controls — the test decides, and a reviewer spot-checks.

Decided by a reviewer

Where the question needs judgement — wording that shames, visual emphasis that steers — software measures and an expert reviewer decides.

Stated by you

Some facts can't be seen from outside, such as whether a placement was paid for. Those are recorded as your company's statement, not as our finding.

Clean results are sealed exactly like findings. That is what makes the statement defensible rather than decorative.

Available now

The Audit Sprint

The yearly self-audit, done properly, in ten working days.

From ₹1.5 lakh, depending on the number of properties and journeys in scope.

You receive

  • Scoped customer journeys tested across personas, sessions and time
  • Findings adjudicated by a reviewer, each tied to the rule or pattern it concerns
  • A remediation list your product team can work from
  • One re-test after you fix
  • A sealed evidence pack recording what was tested, found and fixed
  • Draft statement wording in the open format, for your own declaration

We need from you

  • Written authorisation naming each property in scope
  • Test accounts, and allow-listing of our test traffic
  • A named contact in legal or compliance

We never complete a real payment, and we only test properties you have authorised in writing.

Available now

Audit Sprint

The yearly self-audit with a sealed evidence pack, ahead of 1 January.

From Q1 2027

Continuous Assurance

Weekly replay of your journeys, so the statement stays true between audits. The daily price ledger behind Rule 4(13) starts the day you engage.

Later in 2027

Release Gate

The same tests run on staging before a change to checkout, pricing, consent or cancellation goes live.

Limits, stated plainly

What we are not

  • Not a certifier. The rule makes the entity certify itself. We supply scope-limited evidence, like a penetration-test report — never a guarantee of compliance.
  • Not a public league table. Findings stay with you. We never publish or rank companies.
  • Not a page scanner. The patterns that attract penalties live across steps and time, which one screen cannot show.
  • Not legal advice. Where a question is legal — whether a rule applies to you, or what your statement should say — the evidence pack says so, and your counsel decides.

This site, checked against its own rules. No countdown timers. No pre-ticked boxes. No cookies, no analytics, and no requests to any third party — your browser's developer tools will confirm it. Prices stated plainly.