Specification · Draft for comment

Open Self-Audit Statement format

A format for the dark-pattern self-audit statement that every e-commerce entity in India must display from 1 January 2027. Free to use, adapt and build on.

Version
0.1, published 1 October 2026
Status
Draft for public comment. If the Central Consumer Protection Authority prescribes a format, that format takes precedence.
Licence
Creative Commons Attribution 4.0 (CC BY 4.0)
Maintained by
DarkPatternAudit, VatsGlobal Ventures Private Limited
Machine-readable
JSON Schema · Worked example

Why a format is needed

Sub-rule 4(15) of the Consumer Protection (E-Commerce) Rules, 2020, inserted by G.S.R. 789(E) on 9 September 2026, requires every e-commerce entity to conduct a yearly self-audit for dark patterns and to display a certificate prominently. It prescribes no method, no evidence standard and no format.

The declarations made under the CCPA's 2025 advisory were reported to omit, for the most part, the method used, the sample examined and the findings. A statement that a reader can rely on — or test — has to say what was examined, how, what was left out, and what was found and fixed. This format sets that out.

Principles

  • 1. Self-attestation, not accreditation. The entity writes and signs the statement. No vendor, tool or format publisher certifies it.
  • 2. Scope first. What was not examined is stated with the same prominence as what was.
  • 3. Findings, not verdicts. Outcomes record what was found. The format has no “pass”, “fail” or “compliant”.
  • 4. Open items are always stated. The number may be zero, but it must be given, with an owner and date when it is not.
  • 5. No implied authority. No emblems, seals, shields, ticks, or wording that suggests government or third-party approval.
  • 6. Durable. A self-contained document that stays meaningful if any linked service disappears.

Sections

A statement in this format contains the following sections, in this order.

SectionRequiredContents
Title and basisYes“Dark patterns self-audit statement”, the entity's legal name, and the statutory basis: Rule 4(15) of the Consumer Protection (E-Commerce) Rules, 2020, as amended by G.S.R. 789(E).
EntityYesLegal name. CIN or LLPIN, GSTIN and registered address where available.
PlatformsYesEvery website and app the statement covers. At least one.
DatesYesAudit date and next audit due. Period covered, where the audit observed the platform over time.
ScopeYesSurfaces examined — public journeys, logged-in journeys, mobile app — and the journeys tested.
ExclusionsYesEverything not examined: surfaces not covered, coverage items marked “not examined”, and any other limitation. Displayed with the same prominence as the scope.
LimitationYesThe standard limitation text below.
MethodYesHow the audit was done. Optionally, the SHA-256 hash of a sealed evidence record and a link to check its integrity.
CoverageYesAn outcome for each of the thirteen specified dark patterns and each listed duty under the Rules. See the coverage list.
Open itemsYesThe number of issues open and remediated. Where any are open, an owner and a target date.
DeclarationYesName, designation and date of the signatory, and a declaration limited to the scope described.
DisclaimerYesThe standard disclaimer text below.
AttributionRecommendedThe format name, version and a link to this page.

Outcome vocabulary

Each coverage item takes exactly one of these outcomes. There is deliberately no outcome meaning “compliant”: the format records what was found, and the declaration is the entity's own.

ValueDisplayed asMeaning
no_issue_identifiedNo issue identifiedExamined within the stated scope; nothing found.
issue_remediatedIssue identified and remediatedFound, and fixed before the statement was published.
issue_openIssue openFound and not yet fixed. Counted in open items.
not_applicableNot applicableThe pattern or duty does not apply to this entity.
not_examinedNot examinedNot covered by this audit. Listed as an exclusion.

Standard text

Limitation

This self-audit examined the scope described above, by the method described above. The absence of a finding is not proof that no dark pattern exists.

Disclaimer

This is a self-audit statement published by [entity]. It is not issued, endorsed, accredited or verified by any government authority, or by the publisher of the statement format, and it is not legal advice.

Declaration

The declaration is the signatory's own and should be limited to the scope described. Where items are open, it should say so. Whether a particular declaration satisfies Rule 4(15) is a question for the entity's counsel.

Machine-readable form

A published statement embeds its full contents as JSON, so it can be read by software as well as people:

  • <script type="application/json" class="osas-data"> containing the statement, valid against the JSON Schema;
  • <script type="application/ld+json"> describing the document in schema.org terms (DigitalDocument).

The statement generator produces both. A worked example is available.

Changelog and comments

0.1
1 October 2026. First public draft.

Comments are welcome, especially from counsel, company secretaries and compliance teams: hello@vats.global. Changes are versioned; a published version is never altered.