🆕  2025 U.S. State Privacy Laws: what you need to know

Dark patterns matter– and consumers are the victims

Explore the impact of default settings on your data privacy and learn about dark patterns, deceptive UX, and the future of AI-driven data management.
Read time
5 min read
Last updated
December 5, 2024
Ketch is simple,
automated and cost effective
Book a 30 min Demo

The default settings on our devices wield significant influence over our data privacy. From the staggering sums tech giants invest to secure default positions to the insidious tactics of dark patterns, let’s delve together into the complexities of consumer choice, manipulation, and the urgent need for a paradigm shift in data privacy practices.

Understanding the real value of your user data

Princeton programmer-turned-sociologist Zeynep Tufekci had an important piece in the New York Times last year touting the importance of the default settings that come pre-installed on our phones, apps, and the countless other digital tools upon which we now depend.

As Tufekci wrote, these default settings come with big wins and losses: 

  • Google pays $26.3 billion a year to be the default search engine on key platforms including the iPhone. 
  • Facebook lost $10 billion after Apple toggled off a default setting that allowed tech giants to identify users’ devices in order to track them online. 

These numbers show the real value of users’ data — and the futility of relying on consumers themselves to make smart choices about how their data is used. 

“If it were all as simple as people changing their settings, Google wouldn’t be forking over a sum larger than the G.D.P. of entire countries to have Apple users start with one setting rather than another,” Tufecki writes. “The default way the technology industry does business needs to change now.”

The problem with dark patterns

I couldn’t agree more. Anyone who works in tech knows that while consumers do care about their data and their privacy, it’s an open question as to how much effort they’ll actually put into enforcing the rights they say matter to them.

This has been digital marketers’ dirty secret since the industry began. 

Cookies, after all, depend on people’s passivity, and their readiness to click away their rights in order to clear a “consent” message and access the content they’re actually looking for. 

What is the problem with dark patterns?

Privacy policies are much the same: everyone knows that consumers don’t actually read them — and let’s face it, they aren’t designed to be read by anyone who doesn’t have a JD. From there it’s a short step to full-blown dark patterns and UX that actively manipulates users into giving up their data rights. 

What is a dark pattern? 

A dark pattern is some kind of deceptive, manipulative way for a company to convince a user to do something they would not otherwise do on the company website. It tricks the user into taking an action that doesn’t align with their privacy preferences. 

A few examples of this could include: 

  • A multi-step process to request data deletion, or turn on privacy features that are otherwise off by default
  • A “consent” button that’s larger and more eye-catching than the button used to reject a consent request
  • Disguising an advertisement to appear as organic or earned content to trick the user into thinking it’s not an ad 

Example of a dark pattern from personal experience

When I bought a new iPhone recently, I was able to complete the transaction in just a few clicks. Not long afterward, I started getting new “pre-screened” credit card offers based on the transaction I’d made — and in the small print, it said I’d need to personally call or write to the consumer credit bureaus in order to avoid getting such offers in future. That asymmetry of effort, requiring so much of me to assert my rights, is a perfect example of a dark pattern in action.

Are dark patterns illegal?

The legality of dark patterns varies globally. While some practices might breach consumer protection laws, enforcement and interpretation differ across jurisdictions.

Certain countries, such as the European Union member states under GDPR (General Data Protection Regulation), have specific provisions against deceptive design practices that infringe upon users' rights to privacy and informed consent. 

However, enforcement and interpretation of these laws can differ, and not all dark patterns may be explicitly illegal. Nevertheless, ethical considerations and consumer backlash are increasingly pressuring companies to adopt more transparent and user-friendly design practices.

Regulators have been pushing back against dark patterns, but as Tufekci points out, it isn’t enough to stop marketers from putting their thumbs on the scales. As long as we allow privacy settings to be turned off by default — or hidden behind “opt out” options that consumers are never meant to actually use — we’ll continue to see consumers’ data being used in ways to which they would never have explicitly consented.

The future of dark patterns, data privacy, and AI

The entrenched use of dark patterns, and subtler forms of consent manipulation like default settings, is bad enough in a world of web tracking and targeted digital advertising. But it’s about to get a whole lot worse as we move into a world of ubiquitous AI and immersive technologies such as gaze and pupil dilation monitors, body language cameras, neural interfaces, and more.

The reality is that we’re using data in transformative new ways, and we need new ways to control and manage data effectively. That starts with building out programmatic data control and data permissioning systems that allow consumers to express their preferences clearly and then have them reflected fluidly across the entire data ecosystem.

The goal can’t simply be to make privacy technically attainable for consumers who care enough to dig through endless lists of preferences and settings. To prepare for a world powered by AI and immersive tech, we need to empower consumers — and that starts with a new approach to data privacy. Using data responsibly and making new technologies safe, sustainable, and consumer-friendly needs to start with making strong, effective privacy protection the default setting.

Read time
5 min read
Published
April 24, 2024
Need an easy-to-use consent management solution?

Ketch makes consent banner set-up a breeze with drag-and-drop tools that match your brand perfectly. Let us show you.

Book a 30min Demo
Need an easy-to-use consent management solution?

Ketch makes consent banner set-up a breeze with drag-and-drop tools that match your brand perfectly. Let us show you.

Book a 30 min Demo

Continue reading

Product, Privacy tech, Top articles

Advertising on Google? You must use a Google certified CMP

Sam Alexander
3 min read
Marketing, Privacy tech

3 major privacy challenges for retail & ecommerce brands

Colleen Barry
7 min read
Marketing, Privacy tech, Strategy

Navigating a cookieless future with Google Privacy Sandbox

Colleen Barry
7 min read
Get started
with Ketch
Begin your journey to simplified privacy operations and granular data control across the enterprise.
Book a Demo
Ketch was named top consent management platform on G2