Definition
There are numerous ways to interfere with the visual design of a page to hide, obscure or disguise information. Visual perception can be manipulated by using small, low contrast text. Comprehension can be manipulated by creating a chaotic or overwhelming interface. User's expectations can be violated by placing important information in styles or location they would not expect.
Example
In 2019, Tesla added an eCommerce feature to their mobile app, allowing Tesla car owners to buy upgrades for their vehicles, such as an autopilot that would unlock "Full Self-Driving" capabilities for $4,000. Some customers purchased this by mistake, and were outraged when they discovered that Tesla was refusing to provide a refund. Renowned author Nassim Nicholas Taleb complained on Twitter: _"I unintentionally hit the buy button while the app was in my pocket". _
Hidden on the purchase screen was some small, low contrast text stating "upgrades cannot be refunded". This text was the lowest contrast text on the page, and was difficult to see (Image source: Reddit, 2019).
References
Misdirection (Brignull, 2010), False hierarchy (Gray et al., 2018), Visual interference (Mathur et al., 2019).
Related laws
Users must give informed and unambiguous consent and receive clear information about cookies, including processing purposes and data controller identity, according to the law.
Requires website operators to obtain user consent before storing or accessing information on the user's device through cookies or similar technologies.
Consent is a voluntary agreement by an individual for their personal data processing, after being informed of its specific purposes and conditions.
Legal basis for processing personal data are performance of contract, legal obligations compliance, protection of vital interests, controller's legitimate interests, and data subject's consent.
Requires personal data to be processed lawfully, fairly, and transparently.
Ensures transparent information and easy access for individuals to their personal data processing, with the right to obtain a copy in a clear and common format.
Controllers must provide identity, contact details, processing purposes and legal basis, recipient information, retention period, and data subject rights when collecting personal data.
Specifies required information for data subjects when collecting personal data from other sources, including controller identity, processing purposes, personal data categories, recipients, and retention period.
Valid consent conditions include being freely given, specific, informed, and unambiguous, and the data subject should be able to withdraw it anytime.
Mandates that data protection must be incorporated into the design of systems, and that privacy must be a default setting for all data processing activities.
Prohibits deceptive acts or practices that misrepresent or omit material facts.
Requires companies to obtain consumer's consent before charging their credit or debit cards for goods or services offered through a "negative option feature."
Prohibits deceptive practices, fraud, and misrepresentations in the sale or advertisement of merchandise.
Related cases
Implementing a new consent based solution.
€3,000,000 in fines
Final decision pending
Reprimand issued
$85 million settlement
€345 million in fines
Pending