- Deceptive defaults: Pre-checked boxes, opt-out settings, or buried privacy controls trick users into sharing data by making sharing the easiest or default action.
- Misleading language: Ambiguous, technical, or false wording (e.g., “help personalize your experience”) obscures what data is collected and how it’s used.
- Forced consent and bundling: Combining consent for essential service with consent for data sharing (no granular choice) coerces users into surrendering data to access features.
- Obstruction and friction: Hiding privacy settings behind many clicks, small buttons, or time-limited prompts discourages users from limiting data collection.
- Privacy Zuckering: Interfaces designed to make users publicly share more information than intended (named after Facebook examples).
- Sneaky notifications and bait-and-switch: Promising one outcome (discount, feature) but requiring data access, then using that data for profiling or marketing.
- Dark pattern-driven data harvesting for profiling: Collected data is combined, inferred, and sold to advertisers, brokers, or used to micro-target vulnerable users (price discrimination, political persuasion).
- Continuous and persistent tracking: Using subtle UI cues or consent resets to maintain long-term access to location, contacts, or behavioral data.
Consequences: loss of control over personal information, unwanted targeted advertising, discrimination, security risks, and erosion of informed consent.
References: Brayne (2017) on surveillance and data markets; Gray et al. (2018) “The Dark (Patterns) of UX”; Nissenbaum (2010) on privacy as contextual integrity.