Forced action · European Union

Forced disclosure or excessive data request

The label “Forced disclosure or excessive data request” describes this recurring design mechanism: access or progression is conditioned on disclosing personal information that appears unnecessary, excessive or used for an insufficiently explained secondary purpose. It is a design and research taxonomy, not a standalone legal conclusion. Depending on the complete journey and likely effect, current EU consumer or sector rules may require separate assessment. No published Digital Fairness Act proposal currently creates a pattern-specific prohibition or duty under this label.

Editorial analysis
Also known as
  • forced registration
  • privacy zuckering
  • bundled action
  • Forced action and data disclosure
  • Forced action and unnecessary data disclosure
  • excessive data requests
  • forced communication
Journey stages

Definition

What is this pattern?

Access or progression is conditioned on disclosing personal information that appears unnecessary, excessive or used for an insufficiently explained secondary purpose. The label describes a recurring design mechanism; whether a particular implementation is harmful or unlawful depends on the complete journey, audience, evidence and rules within scope.

How it works

Access or progression is conditioned on disclosing personal information that appears unnecessary, excessive or used for an insufficiently explained secondary purpose. The interface makes apparently disproportionate personal information a prerequisite and withholds the selected result when a field or permission is refused.

Warning signs

  • Personal data is mandatory or refusal blocks a desired goal.
  • Necessity is apparently unrelated, disproportionate or unexplained.
  • The requested data creates a plausible privacy or choice detriment.

Potential harms

  • The visitor must disclose identity and contact information that is unrelated to a preliminary delivery-availability check.
  • The user may disclose more personal information than the preliminary comparison reasonably needs.

Learn by comparison

What does this look like?

These fictional examples make the design mechanism easier to recognise. They do not depict a real company and do not establish that an individual interface is unlawful.

Illustrative example 1 · Furniture delivery estimate

A fictional furniture shop requires a visitor to disclose an exact birth date and mobile number before showing whether delivery is available to the entered postcode.

Potential consumer harm: The visitor must disclose identity and contact information that is unrelated to a preliminary delivery-availability check.

Illustrative example 2 · Insurance comparison

A fictional comparison tool requires occupation, exact birth date, mobile number and marketing preference before showing the plans that are available in a postcode.

Potential consumer harm: The user may disclose more personal information than the preliminary comparison reasonably needs.

What is a fairer alternative?

Request only data necessary for the current goal, make secondary uses optional, and explain purpose and consequences clearly.

Context matters

Context and boundary cases

  • Personal data is mandatory or refusal blocks a desired goal.
  • Necessity is apparently unrelated, disproportionate or unexplained.
  • The requested data creates a plausible privacy or choice detriment.
  • Exclude or qualify the label where data evidently required for delivery, payment, security, age, safety or law.
  • Exclude or qualify the label where voluntary field with a clear skip path and purpose.

When a similar design can serve a legitimate purpose

  • A similar design should not be classified this way where data evidently required for delivery, payment, security, age, safety or law.
  • A similar design should not be classified this way where voluntary field with a clear skip path and purpose.

Operational review

What teams should review

Teams
  • Product
  • UX
  • Legal
  • Engineering
  • Content design
  1. What functional need makes “Submit personal details” necessary for the furniture delivery estimate goal, and can that need be met with less disclosure or commitment?
  2. Which fields or permissions are required, what happens on refusal, and does the resulting state support this criterion: “Personal data is mandatory or refusal blocks a desired goal”?
  3. Could the stated purpose make this dependency genuinely necessary under the boundary “Data evidently required for delivery, payment, security, age, safety or law”, and what product evidence would demonstrate that necessity?
  4. What functional need makes “Reveal plans” necessary for the insurance comparison goal, and can that need be met with less disclosure or commitment?
  5. Which fields or permissions are required, what happens on refusal, and does the resulting state support this criterion: “Necessity is apparently unrelated, disproportionate or unexplained”?
  6. Could the stated purpose make this dependency genuinely necessary under the boundary “voluntary field with a clear skip path and purpose”, and what product evidence would demonstrate that necessity?
  7. Which complete journey evidence supports or contradicts the forced disclosure or excessive data request classification?

Evidence to retain

  • Versioned captures of the Pricing states before, during and after the relevant decision
  • Configuration, content and event records supporting the observed forced disclosure or excessive data request mechanism
  • Responsive, keyboard and assistive-technology review of every material option and consequence
  • Control defaults, validation rules and consent or selection state changes

Legal map and implementation tools

Evidence base

Sources

  1. Dark commercial patternsOrganisation for Economic Co-operation and Development · Secondary · checked 2026-09-14 · OECD Digital Economy Papers No. 336
  2. Unfair Commercial Practices DirectiveEuropean Parliament and Council of the European Union · Primary · checked 2026-08-09 · Directive 2005/29/EC; CELEX 02005L0029-20220528
  3. Digital Fairness Act: call for evidence for an impact assessmentEuropean Commission · Primary · checked 2026-08-09 · Initiative 14622; Ares(2025)6275573
  4. Commission work programme 2026: Europe's Independence MomentEuropean Commission · Primary · checked 2026-09-14 · COM(2025) 870 final; CELEX 52025DC0870; Annex I item 30