Obstruction · European Union
Privacy maze
The label “Privacy maze” describes this recurring design mechanism: privacy controls are fragmented, inconsistently labelled or layered so that limiting collection or use is unnecessarily difficult. It is a design and research taxonomy, not a standalone legal conclusion. Depending on the complete journey and likely effect, current EU consumer or sector rules may require separate assessment. No published Digital Fairness Act proposal currently creates a pattern-specific prohibition or duty under this label.
- Family
- Obstruction
- Also known as
- Journey stages
Definition
What is this pattern?
Privacy controls are fragmented, inconsistently labelled or layered so that limiting collection or use is unnecessarily difficult. The label describes a recurring design mechanism; whether a particular implementation is harmful or unlawful depends on the complete journey, audience, evidence and rules within scope.
How it works
Privacy controls are fragmented, inconsistently labelled or layered so that limiting collection or use is unnecessarily difficult. Related controls are distributed across inconsistent labels, menus or channels, preventing the user from seeing and maintaining one coherent privacy state.
Warning signs
- A meaningful privacy-restrictive outcome exists in principle.
- The route contains unnecessary branching, repeated settings or inconsistent terminology.
- The less-private route is materially easier or the maze is likely to cause abandonment.
Potential harms
- A person may fail to restrict optional uses because the controls are fragmented and inconsistently described.
- The user cannot maintain a reliable privacy preference across interfaces.
Learn by comparison
What does this look like?
These fictional examples make the design mechanism easier to recognise. They do not depict a real company and do not establish that an individual interface is unlawful.
Illustrative example 1 · Privacy settings
A fictional service places audience ads, partner sharing and measurement controls under three differently named menus with no summary of the final state.
Potential consumer harm: A person may fail to restrict optional uses because the controls are fragmented and inconsistently described.
Illustrative example 2 · Connected-device account
A fictional account lets users disable activity sharing on the web, but opening the mobile app silently restores the setting under a different label.
Potential consumer harm: The user cannot maintain a reliable privacy preference across interfaces.
Advertising opt-out split across unrelated menus
A fictional service places audience ads, partner sharing and measurement controls under three differently named menus with no summary of the final state.
Manage experience controls. Related advertising choices are scattered across “Experience”, “Partners” and “Insights”.. Open another menu. Unconfirmed state: Open another menu
Optional data uses. All related purposes and current states are visible in one navigable overview.. Turn off optional uses. Saved state: Turn off optional uses. Persisted account state, expanded: The saved state behind “Turn off optional uses” remains consistent after refresh and across supported channels.
Why the first version can mislead: The route adds avoidable effort between the user’s stated intention and completion. In this privacy settings example, the obstacle is: “Related advertising choices are scattered across “Experience”, “Partners” and “Insights”.” Evidence should show whether the alternative remains usable and whether “Turn off optional uses” reaches the represented state. A person may fail to restrict optional uses because the controls are fragmented and inconsistently described.
What a fairer design does: Provide a coherent overview, consistent purpose names and a clear summary of what each choice changes.
Show annotated differences (2)
- Unconfirmed state: Open another menuIn “Advertising opt-out split across unrelated menus”, this element shows how privacy maze can shape the decision.
- Persisted account state, expanded: The saved state behind “Turn off optional uses” remains consistent after refresh and across supported channels.In “Advertising opt-out split across unrelated menus”, this element keeps the clearer alternative visible at the same decision point.
Review questions (3)
- How many steps, waits and channel changes separate “Open another menu” from the completed privacy settings outcome?
- Test the control across refresh, device and account states; is “A meaningful privacy-restrictive outcome exists in principle” still observable after persistence is considered?
- Measure the same task through the clearest available route: does the effort difference persist once “Granular controls with a clear overview and global options” is accounted for?
Privacy choice silently re-enables elsewhere
A fictional account lets users disable activity sharing on the web, but opening the mobile app silently restores the setting under a different label.
Personalised activity · Off. The mobile app later restores the same sharing under “Smart recommendations”.. Setting may change. Unconfirmed state: Setting may change
Activity sharing · Off everywhere. Web and app show the same persisted state and audit date.. Keep off across devices. Saved state: Keep off across devices. Persisted account state, expanded: The saved state behind “Keep off across devices” remains consistent after refresh and across supported channels.
Why the first version can mislead: The route adds avoidable effort between the user’s stated intention and completion. In this connected-device account example, the obstacle is: “The mobile app later restores the same sharing under “Smart recommendations”.” Evidence should show whether the alternative remains usable and whether “Keep off across devices” reaches the represented state. The user cannot maintain a reliable privacy preference across interfaces.
What a fairer design does: Use one persistent state across channels, announce conflicts and require a deliberate choice before changing it.
Show annotated differences (2)
- Unconfirmed state: Setting may changeIn “Privacy choice silently re-enables elsewhere”, this element shows how privacy maze can shape the decision.
- Persisted account state, expanded: The saved state behind “Keep off across devices” remains consistent after refresh and across supported channels.In “Privacy choice silently re-enables elsewhere”, this element keeps the clearer alternative visible at the same decision point.
Review questions (3)
- How many steps, waits and channel changes separate “Setting may change” from the completed connected-device account outcome?
- Test the control across refresh, device and account states; is “The route contains unnecessary branching, repeated settings or inconsistent terminology” still observable after persistence is considered?
- Measure the same task through the clearest available route: does the effort difference persist once “complexity strictly required by genuinely distinct processing purposes” is accounted for?
What is a fairer alternative?
Provide a coherent privacy-control overview, consistent labels and direct controls for common restrictive choices.
Legal and information status
Legal position at a glance
Privacy controls are fragmented, inconsistently labelled or layered so that limiting collection or use is unnecessarily difficult. Related controls are distributed across inconsistent labels, menus or channels, preventing the user from seeing and maintaining one coherent privacy state. Risk increases where the mechanism changes a material consumer choice, hides a consequence or makes a genuine alternative harder to use. The taxonomy label remains a review prompt and does not establish an infringement.
Dark-pattern research taxonomy
Editorial analysis
The cited research sources support identification and comparison of this recurring interface mechanism. They do not determine that a particular interface is unlawful.
UCPD Articles 5 to 9, where applicable
Possible risk indicator
Depending on the trader, audience, overall presentation, material information and likely transactional effect, the facts may require a separate assessment under the applicable UCPD provisions.
Evidence layers and open questions
Applicable law, enforcement records, policy preparation, stakeholder input, editorial analysis and unknown future details remain visibly distinct.
Current lawCurrent law
The UX label “Privacy maze” is not a standalone EU offence. Depending on the trader, audience, complete presentation, omitted information and likely transactional effect, the observed facts may require a separate assessment under the applicable UCPD provisions or another instrument within scope.
Under considerationUnder consideration
The Commission is preparing a Digital Fairness Act initiative, but the call for evidence does not select a final rule for privacy maze or establish that this taxonomy term will appear in a proposal.
Editorial analysisEditorial analysis
The pattern definition, variants and examples on this page use the cited research taxonomy sources to support recognition and comparison. That analytical classification is not a legal conclusion about an individual interface.
UnknownUnknown
No published DFA proposal currently establishes a definition, covered actor, legal threshold, duty, remedy, transition rule or application date for privacy maze. Those details remain unknown pending primary legislative text.
Context matters
Context and boundary cases
- A meaningful privacy-restrictive outcome exists in principle.
- The route contains unnecessary branching, repeated settings or inconsistent terminology.
- The less-private route is materially easier or the maze is likely to cause abandonment.
- Exclude or qualify the label where granular controls with a clear overview and global options.
- Exclude or qualify the label where complexity strictly required by genuinely distinct processing purposes.
- Exclude or qualify the label where information-only privacy policy.
When a similar design can serve a legitimate purpose
- A similar design should not be classified this way where granular controls with a clear overview and global options.
- A similar design should not be classified this way where complexity strictly required by genuinely distinct processing purposes.
- A similar design should not be classified this way where information-only privacy policy.
Operational review
What teams should review
- Teams
- How many steps, waits and channel changes separate “Open another menu” from the completed privacy settings outcome?
- Test the control across refresh, device and account states; is “A meaningful privacy-restrictive outcome exists in principle” still observable after persistence is considered?
- Measure the same task through the clearest available route: does the effort difference persist once “Granular controls with a clear overview and global options” is accounted for?
- How many steps, waits and channel changes separate “Setting may change” from the completed connected-device account outcome?
- Test the control across refresh, device and account states; is “The route contains unnecessary branching, repeated settings or inconsistent terminology” still observable after persistence is considered?
- Measure the same task through the clearest available route: does the effort difference persist once “complexity strictly required by genuinely distinct processing purposes” is accounted for?
- Which complete journey evidence supports or contradicts the privacy maze classification?
Evidence to retain
- Versioned captures of the Account Management states before, during and after the relevant decision
- Configuration, content and event records supporting the observed privacy maze mechanism
- Responsive, keyboard and assistive-technology review of every material option and consequence
Legal map and implementation tools
Evidence base
Sources
- An Ontology of Dark Patterns KnowledgeGray et al.; ACM CHI 2024 · Secondary · checked 2026-09-14 · DOI 10.1145/3613904.3642436; arXiv:2309.09640
- Behavioural study on unfair commercial practices in the digital environmentEuropean Commission, Directorate-General for Justice and Consumers · Secondary · checked 2026-09-14 · DOI 10.2838/859030; ISBN 978-92-76-52316-1
- Unfair Commercial Practices DirectiveEuropean Parliament and Council of the European Union · Primary · checked 2026-08-09 · Directive 2005/29/EC; CELEX 02005L0029-20220528
- Digital Fairness Act: call for evidence for an impact assessmentEuropean Commission · Primary · checked 2026-08-09 · Initiative 14622; Ares(2025)6275573
- Commission work programme 2026: Europe's Independence MomentEuropean Commission · Primary · checked 2026-09-14 · COM(2025) 870 final; CELEX 52025DC0870; Annex I item 30
