Forced action · European Union

Contact harvesting and coerced referrals

The label “Contact harvesting and coerced referrals” describes this recurring design mechanism: the service extracts contact information, sends or prepares unwanted invitations, or ties functionality to recruiting other people. It is a design and research taxonomy, not a standalone legal conclusion. Depending on the complete journey and likely effect, current EU consumer or sector rules may require separate assessment. No published Digital Fairness Act proposal currently creates a pattern-specific prohibition or duty under this label.

Editorial analysis
Also known as
  • friend spam
  • address book leeching
  • social pyramid

Definition

What is this pattern?

The service extracts contact information, sends or prepares unwanted invitations, or ties functionality to recruiting other people. The label describes a recurring design mechanism; whether a particular implementation is harmful or unlawful depends on the complete journey, audience, evidence and rules within scope.

How it works

The service extracts contact information, sends or prepares unwanted invitations, or ties functionality to recruiting other people. Progress depends on exposing or contacting other people, turning a referral or address-book permission into the price of access to an unrelated feature.

Warning signs

  • Contact access, recipient selection, invitation or referral is involved.
  • Consent, recipient choice or downstream use is unclear, defaulted or coerced.
  • The behaviour is linked to access, reward or normal progression.

Potential harms

  • Contacts who never used the service may be exposed or invited, while the new user loses a meaningful refusal.
  • The user is pressured to disclose other people’s contact data and send messages unrelated to the export task.

Learn by comparison

What does this look like?

These fictional examples make the design mechanism easier to recognise. They do not depict a real company and do not establish that an individual interface is unlawful.

Illustrative example 1 · Social app onboarding

A fictional community app stops onboarding at an address-book permission screen and gives no visible way to continue without uploading contacts.

Potential consumer harm: Contacts who never used the service may be exposed or invited, while the new user loses a meaningful refusal.

Illustrative example 2 · Collaboration workspace

A fictional workspace keeps export disabled until the user supplies three colleagues’ addresses and sends invitations from the service.

Potential consumer harm: The user is pressured to disclose other people’s contact data and send messages unrelated to the export task.

What is a fairer alternative?

Make contact access and referrals optional, granular and previewable; require affirmative confirmation for every recipient and message.

Context matters

Context and boundary cases

  • Contact access, recipient selection, invitation or referral is involved.
  • Consent, recipient choice or downstream use is unclear, defaulted or coerced.
  • The behaviour is linked to access, reward or normal progression.
  • Exclude or qualify the label where voluntary one-recipient sharing with preview and confirmation.
  • Exclude or qualify the label where clearly optional referral program with no functional penalty.

When a similar design can serve a legitimate purpose

  • A similar design should not be classified this way where voluntary one-recipient sharing with preview and confirmation.
  • A similar design should not be classified this way where clearly optional referral program with no functional penalty.

Operational review

What teams should review

Teams
  • Product
  • UX
  • Legal
  • Engineering
  • Content design
  1. What functional need makes “Allow contacts” necessary for the social app onboarding goal, and can that need be met with less disclosure or commitment?
  2. Can the dialog be dismissed, what action does each control trigger, and what later state confirms or contradicts “Contact access, recipient selection, invitation or referral is involved”?
  3. Could the stated purpose make this dependency genuinely necessary under the boundary “Voluntary one-recipient sharing with preview and confirmation”, and what product evidence would demonstrate that necessity?
  4. What functional need makes “Add contacts” necessary for the collaboration workspace goal, and can that need be met with less disclosure or commitment?
  5. Test the control across refresh, device and account states; is “Consent, recipient choice or downstream use is unclear, defaulted or coerced” still observable after persistence is considered?
  6. Could the stated purpose make this dependency genuinely necessary under the boundary “clearly optional referral program with no functional penalty”, and what product evidence would demonstrate that necessity?
  7. Which complete journey evidence supports or contradicts the contact harvesting and coerced referrals classification?

Evidence to retain

  • Versioned captures of the Signup and Account Management states before, during and after the relevant decision
  • Configuration, content and event records supporting the observed contact harvesting and coerced referrals mechanism
  • Responsive, keyboard and assistive-technology review of every material option and consequence

Legal map and implementation tools

Evidence base

Sources

  1. Dark commercial patternsOrganisation for Economic Co-operation and Development · Secondary · checked 2026-09-14 · OECD Digital Economy Papers No. 336
  2. Unfair Commercial Practices DirectiveEuropean Parliament and Council of the European Union · Primary · checked 2026-08-09 · Directive 2005/29/EC; CELEX 02005L0029-20220528
  3. Digital Fairness Act: call for evidence for an impact assessmentEuropean Commission · Primary · checked 2026-08-09 · Initiative 14622; Ares(2025)6275573
  4. Commission work programme 2026: Europe's Independence MomentEuropean Commission · Primary · checked 2026-09-14 · COM(2025) 870 final; CELEX 52025DC0870; Annex I item 30