Technological advancements have transformed the ways in which individuals interact with digital platforms, giving rise to data-driven ecosystems in which interface design plays a central role. Within these environments, dark patterns and manipulative and deceptive design techniques shape user behaviour in ways that undermine privacy, autonomy, and informed consent. This paper develops a harm-based analytical framework for privacy dark patterns by deriving a typology of privacy-relevant design mechanisms through a structured consolidation of four independently produced taxonomies. It then constructs a harm typology by combining an injury-based framework with the harm categories developed by regulatory authorities and maps each design mechanism to the harms it is structurally apt to produce. Finally, it identifies the provisions of EU law that each mechanism engages, across the GDPR, consumer protection law, the Digital Services Act, the Digital Markets Act, the Data Act and the AI Act. The analysis finds that the GDPR engages every mechanism identified, that coverage by post-GDPR instruments is uneven, and that one mechanism—the exploitation of relational and third-party data—engages no post-GDPR instrument squarely. The deficiency in the EU framework therefore lies not in the substance of its prohibitions but in the coordination of enforcement and in the evidentiary architecture through which non-material harm must be established.
‹ All reading
Privacy and Manipulation in the Platform Economy: An EU Framework for Regulating Dark Patterns
Consolidates four taxonomies into a typology of privacy-relevant design mechanisms, maps each to the harms it is apt to produce and to the EU provisions it engages, and finds the GDPR reaches every mechanism while later instruments cover them unevenly.