Obstruction · European Union

Privacy maze

The label “Privacy maze” describes this recurring design mechanism: privacy controls are fragmented, inconsistently labelled or layered so that limiting collection or use is unnecessarily difficult. It is a design and research taxonomy, not a standalone legal conclusion. Depending on the complete journey and likely effect, current EU consumer or sector rules may require separate assessment. No published Digital Fairness Act proposal currently creates a pattern-specific prohibition or duty under this label.

Editorial analysis
Also known as
  • privacy settings maze
  • privacy zuckering by obstruction
Journey stages

Definition

What is this pattern?

Privacy controls are fragmented, inconsistently labelled or layered so that limiting collection or use is unnecessarily difficult. The label describes a recurring design mechanism; whether a particular implementation is harmful or unlawful depends on the complete journey, audience, evidence and rules within scope.

How it works

Privacy controls are fragmented, inconsistently labelled or layered so that limiting collection or use is unnecessarily difficult. Related controls are distributed across inconsistent labels, menus or channels, preventing the user from seeing and maintaining one coherent privacy state.

Warning signs

  • A meaningful privacy-restrictive outcome exists in principle.
  • The route contains unnecessary branching, repeated settings or inconsistent terminology.
  • The less-private route is materially easier or the maze is likely to cause abandonment.

Potential harms

  • A person may fail to restrict optional uses because the controls are fragmented and inconsistently described.
  • The user cannot maintain a reliable privacy preference across interfaces.

Learn by comparison

What does this look like?

These fictional examples make the design mechanism easier to recognise. They do not depict a real company and do not establish that an individual interface is unlawful.

Illustrative example 1 · Privacy settings

A fictional service places audience ads, partner sharing and measurement controls under three differently named menus with no summary of the final state.

Potential consumer harm: A person may fail to restrict optional uses because the controls are fragmented and inconsistently described.

Illustrative example 2 · Connected-device account

A fictional account lets users disable activity sharing on the web, but opening the mobile app silently restores the setting under a different label.

Potential consumer harm: The user cannot maintain a reliable privacy preference across interfaces.

What is a fairer alternative?

Provide a coherent privacy-control overview, consistent labels and direct controls for common restrictive choices.

Context matters

Context and boundary cases

  • A meaningful privacy-restrictive outcome exists in principle.
  • The route contains unnecessary branching, repeated settings or inconsistent terminology.
  • The less-private route is materially easier or the maze is likely to cause abandonment.
  • Exclude or qualify the label where granular controls with a clear overview and global options.
  • Exclude or qualify the label where complexity strictly required by genuinely distinct processing purposes.
  • Exclude or qualify the label where information-only privacy policy.

When a similar design can serve a legitimate purpose

  • A similar design should not be classified this way where granular controls with a clear overview and global options.
  • A similar design should not be classified this way where complexity strictly required by genuinely distinct processing purposes.
  • A similar design should not be classified this way where information-only privacy policy.

Operational review

What teams should review

Teams
  • Product
  • UX
  • Legal
  • Engineering
  • Content design
  1. How many steps, waits and channel changes separate “Open another menu” from the completed privacy settings outcome?
  2. Test the control across refresh, device and account states; is “A meaningful privacy-restrictive outcome exists in principle” still observable after persistence is considered?
  3. Measure the same task through the clearest available route: does the effort difference persist once “Granular controls with a clear overview and global options” is accounted for?
  4. How many steps, waits and channel changes separate “Setting may change” from the completed connected-device account outcome?
  5. Test the control across refresh, device and account states; is “The route contains unnecessary branching, repeated settings or inconsistent terminology” still observable after persistence is considered?
  6. Measure the same task through the clearest available route: does the effort difference persist once “complexity strictly required by genuinely distinct processing purposes” is accounted for?
  7. Which complete journey evidence supports or contradicts the privacy maze classification?

Evidence to retain

  • Versioned captures of the Account Management states before, during and after the relevant decision
  • Configuration, content and event records supporting the observed privacy maze mechanism
  • Responsive, keyboard and assistive-technology review of every material option and consequence

Legal map and implementation tools

Evidence base

Sources

  1. An Ontology of Dark Patterns KnowledgeGray et al.; ACM CHI 2024 · Secondary · checked 2026-09-14 · DOI 10.1145/3613904.3642436; arXiv:2309.09640
  2. Behavioural study on unfair commercial practices in the digital environmentEuropean Commission, Directorate-General for Justice and Consumers · Secondary · checked 2026-09-14 · DOI 10.2838/859030; ISBN 978-92-76-52316-1
  3. Unfair Commercial Practices DirectiveEuropean Parliament and Council of the European Union · Primary · checked 2026-08-09 · Directive 2005/29/EC; CELEX 02005L0029-20220528
  4. Digital Fairness Act: call for evidence for an impact assessmentEuropean Commission · Primary · checked 2026-08-09 · Initiative 14622; Ares(2025)6275573
  5. Commission work programme 2026: Europe's Independence MomentEuropean Commission · Primary · checked 2026-09-14 · COM(2025) 870 final; CELEX 52025DC0870; Annex I item 30