Specification · Draft for comment
Open Self-Audit Statement format
A format for the dark-pattern self-audit statement that every e-commerce entity in India must display from 1 January 2027. Free to use, adapt and build on.
- Version
- 0.1, published 1 October 2026
- Status
- Draft for public comment. If the Central Consumer Protection Authority prescribes a format, that format takes precedence.
- Licence
- Creative Commons Attribution 4.0 (CC BY 4.0)
- Maintained by
- DarkPatternAudit, VatsGlobal Ventures Private Limited
- Machine-readable
- JSON Schema · Worked example
Why a format is needed
Sub-rule 4(15) of the Consumer Protection (E-Commerce) Rules, 2020, inserted by G.S.R. 789(E) on 9 September 2026, requires every e-commerce entity to conduct a yearly self-audit for dark patterns and to display a certificate prominently. It prescribes no method, no evidence standard and no format.
The declarations made under the CCPA's 2025 advisory were reported to omit, for the most part, the method used, the sample examined and the findings. A statement that a reader can rely on — or test — has to say what was examined, how, what was left out, and what was found and fixed. This format sets that out.
Principles
- 1. Self-attestation, not accreditation. The entity writes and signs the statement. No vendor, tool or format publisher certifies it.
- 2. Scope first. What was not examined is stated with the same prominence as what was.
- 3. Findings, not verdicts. Outcomes record what was found. The format has no “pass”, “fail” or “compliant”.
- 4. Open items are always stated. The number may be zero, but it must be given, with an owner and date when it is not.
- 5. No implied authority. No emblems, seals, shields, ticks, or wording that suggests government or third-party approval.
- 6. Durable. A self-contained document that stays meaningful if any linked service disappears.
Sections
A statement in this format contains the following sections, in this order.
| Section | Required | Contents |
|---|---|---|
| Title and basis | Yes | “Dark patterns self-audit statement”, the entity's legal name, and the statutory basis: Rule 4(15) of the Consumer Protection (E-Commerce) Rules, 2020, as amended by G.S.R. 789(E). |
| Entity | Yes | Legal name. CIN or LLPIN, GSTIN and registered address where available. |
| Platforms | Yes | Every website and app the statement covers. At least one. |
| Dates | Yes | Audit date and next audit due. Period covered, where the audit observed the platform over time. |
| Scope | Yes | Surfaces examined — public journeys, logged-in journeys, mobile app — and the journeys tested. |
| Exclusions | Yes | Everything not examined: surfaces not covered, coverage items marked “not examined”, and any other limitation. Displayed with the same prominence as the scope. |
| Limitation | Yes | The standard limitation text below. |
| Method | Yes | How the audit was done. Optionally, the SHA-256 hash of a sealed evidence record and a link to check its integrity. |
| Coverage | Yes | An outcome for each of the thirteen specified dark patterns and each listed duty under the Rules. See the coverage list. |
| Open items | Yes | The number of issues open and remediated. Where any are open, an owner and a target date. |
| Declaration | Yes | Name, designation and date of the signatory, and a declaration limited to the scope described. |
| Disclaimer | Yes | The standard disclaimer text below. |
| Attribution | Recommended | The format name, version and a link to this page. |
Outcome vocabulary
Each coverage item takes exactly one of these outcomes. There is deliberately no outcome meaning “compliant”: the format records what was found, and the declaration is the entity's own.
| Value | Displayed as | Meaning |
|---|---|---|
no_issue_identified | No issue identified | Examined within the stated scope; nothing found. |
issue_remediated | Issue identified and remediated | Found, and fixed before the statement was published. |
issue_open | Issue open | Found and not yet fixed. Counted in open items. |
not_applicable | Not applicable | The pattern or duty does not apply to this entity. |
not_examined | Not examined | Not covered by this audit. Listed as an exclusion. |
Standard text
Limitation
This self-audit examined the scope described above, by the method described above. The absence of a finding is not proof that no dark pattern exists.
Disclaimer
This is a self-audit statement published by [entity]. It is not issued, endorsed, accredited or verified by any government authority, or by the publisher of the statement format, and it is not legal advice.
Declaration
The declaration is the signatory's own and should be limited to the scope described. Where items are open, it should say so. Whether a particular declaration satisfies Rule 4(15) is a question for the entity's counsel.
Machine-readable form
A published statement embeds its full contents as JSON, so it can be read by software as well as people:
<script type="application/json" class="osas-data">containing the statement, valid against the JSON Schema;<script type="application/ld+json">describing the document in schema.org terms (DigitalDocument).
The statement generator produces both. A worked example is available.
Changelog and comments
- 0.1
- 1 October 2026. First public draft.
Comments are welcome, especially from counsel, company secretaries and compliance teams: hello@vats.global. Changes are versioned; a published version is never altered.