Данные и приватность · 1 июля 2024 · 5 мин чтения

Deceptive data practices The U.S. experience

In July 2024, amendments to data laws23 became effective in 3 US states: Texas, , Florida and Colorado. . These states have adopted the concept of “dark patterns”, the practices that manipulate the user interface to violate a user's autonomy, i.e., the ability to feel free to make decisions or choices about use of data. For example, consent to personal data transactions obtained fraudulently; prac

Из выпуска мониторинга No. 7, July 2024 · выпуск целиком, PDF · на сайте Института Гайдара

In July 2024, amendments to data laws1 became effective in 3 US states: Texas, , Florida and Colorado. . These states have adopted the concept of “dark patterns”, the practices that manipulate the user interface to violate a user's autonomy, i.e., the ability to feel free to make decisions or choices about use of data. For example, consent to personal data transactions obtained fraudulently; practices designed to collect information from children beyond what is required to receive a service; or an offer to opt out of data protection in a game or social media site.

It also establishes the authority of the Federal Trade Commission to determine lists of prohibited practices whose use is considered a violation of the personal data law.

Experience of international

organizations and the EC

In July 2024, a study published by the US FTC in collaboration with ICPEN, GPEN, outlines the results of a review of over 1000 websites and apps for the use of “dark2 patterns”. Earlier, similar studies were34 organized in 2022 by the OECD and the EU. “Dark patterns” are used in the design of a website to manipulate consumer opinion, for example:

1. Forcing them to provide more personal information than is necessary to receive products or services.

2. Forcing to accept less secure data processing practices.

3. Preventing users from obtaining information about the protection of their data.

The following patterns were estimated:

1) Complex and confusing language technical or excessively long privacy policies that are difficult to understand. 89% of the resources studied contained either excessively long privacy policies (more than 3000 words) or technical and confusing language that was difficult to read.

2) Interface interference - design elements that affect users' perception and understanding of their actions related to the PD. Identified in 43% of the resources studied. Examples of practices:

- False hierarchy, visually highlighting some interface elements and hiding others, directing users to less secure PD protection operations. For example, a method is proposed that provides less data protection is highlighted by color contrast.

− Selection of “default” data processing options that provide less data protection.

− Use of phrases that may cause guilt in the consumer. 29% of sites discouraged users from deleting accounts with a warning, such as the phrase “if you click ‘Delete User Account’, you will lose your VIP privileges.”

The EU also highlighted the practice of manipulating consumers' emotions. For example, asking you to inform on your location, so that you can supposedly be found by other users and not be alone, although the platform actually collects such data for its own purposes.

3) Persistence - repeated requests for users to take certain actions that may reduce data protection, such as requests to enable notifications or provide the ability to track geolocation. This practice was used by 41% of sites.

The EU also highlights the practice of “overloading,” when a user receives a large number of requests, the user gets tired and agrees to all the proposed options in relation of PD and unintentionally agrees to actions he/she did not want to agree before.

For example, constantly asking for a phone number or access to contacts, making it easier for the user to agree to provide information rather than continually refuse.

4) Creating barriers, such as providing the opportunity to register an account but lacking tools to delete the account or necessity to take inconvenient steps (filling out a long form or sending a written request to the organization) to delete an account; forcing users to make multiple clicks to get information about the use of their PD. The practice was used by 39% of resources.

5) Compulsory use: a requirement to provide more data to access a service than is necessary. For example, creating an account through the use of third-party social networks to gain access to a user's data about that social network's usage. Such practices were used by 26% of resources. The OECD highlights the practice of demanding information, for example, about user contacts for further spamming of consumer contacts, including allegedly on behalf of the consumer.

Russia’s experience

Russia has not adopted the concept of “dark patterns” or other equivalents for abusive data collection practices. However, misleading users about the privacy terms of their data may be grounds for sanctions. For example, according to the decision of the Moscow City Court, the LinkedIn platform was blocked in Russia in 2016 for violating the requirement of personal data localization. The court found that LinkedIn collected behavioral data through cookies, but did not comply with localization requirements with respect to the collected data and imposed a condition in the user agreement on the platform's right to transfer all collected5 data to third parties. Russia has regulations to prevent misleading users in terms of consumer protection legislation and as part of personal data legislation.

It would make sense if Roskomnadzor develops a checklist of signs of “dark patterns” on digital platforms and establishes an open case bank identified on Russian-language platforms based on general regulations and taking into account judicial practice. The open case bank may be supplemented with materials provided by users to inform them of the risks and motivate platforms to adjust their user data collection policies prior to proceedings by Roskomnadzor.

  1. countries, parties to the Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data and 34 countries that are not. The latter are included in the list if their legal provisions and measures to ensure the confidentiality and security of personal data are in line with the provisions of this convention.
  2. The US was absent in the editions of Roskomnadzor's Order No. 274 dated 15.03.2013.
  3. https://capitol.texas.gov/tlodocs/88R/billtext/html/HB00004F.htm
  4. https://flsenate.gov/Session/Bill/2023/262/BillText/er/HTML
  5. https://leg.colorado.gov/sites/default/files/2021a_190_signed.pdf
  6. International Consumer Protection and Enforcement Network (international organization)
  7. Global Privacy Enforcement Network (international organization)
  8. https://www.privacyenforcement.net/system/files/2024-07/GPEN%20Sweep%202024%20- %20%27Deceptive%20Design%20Patterns%27_0.pdf
  9. OECD report on “Dark commercial practices” https://one.oecd.org/document/DSTI/CP(2021)12/FINAL/en/pdf
  10. Guiding principles No.3/2022 on “Dark patterns in the interfaces of the social networks platforms” https://www.edpb.europa.eu/system/files/2022-03/edpb_03-2022_guidelines_on_dark_patterns_in_social_media_platform_interfaces_en.pdf
  11. https://mos-gorsud.ru/mgs/services/cases/appeal-civil/details/19d661b0-6b14-48eb-b753-9adbf19fe32a
  12. https://storage.courtlistener.com/recap/gov.uscourts.nysd.575368/gov.uscourts.nysd.575368.54.0_2.pdf
  13. Felicity Harber v The Commissioners for HMRC https://caselaw.nationalarchives.gov.uk/ukftt/tc/2023/1007
  14. Jurisdiction extends to the courts of the Western District of North Carolina
  15. https://www.ncwd.uscourts.gov/sites/default/files/Standing%20Order%20In%20Re-%20Use%20of%20Artificial%20Intelligence2.pdf

From the monitoring issue No. 7, July 2024. Download the full issue (PDF) · issue page at the Gaidar Institute

Читайте также