Research explained · Regulatory guidance
The EDPB’s deceptive-design guide is practical, but narrower than it looks
The EDPB’s final Guidelines 03/2022 organise deceptive design in social-media interfaces into six broad categories and follow users through account opening, information, settings and account closure. The document is unusually practical because it connects interface examples to GDPR principles and design recommendations. Its scope is also specific: it addresses social-media providers acting as controllers under the GDPR. It is not a horizontal Digital Fairness Act rule for every service.
- Original work
- Guidelines 03/2022 on deceptive design patterns in social media platform interfaces: how to recognise and avoid them
- Authors
- European Data Protection Board
- Published
- 2023-02-24
- Venue
- EDPB final guidelines, Version 2.0
- Method
- Regulatory analysis organised around GDPR principles, six design-pattern categories and social-media account-lifecycle use cases.
- Sample or scope
- Illustrative social-media interfaces covering account opening, information, consent and settings, data-subject rights and account closure.
Read the evidence carefully
From research question to useful conclusion
- 1
Question
The EDPB’s final Guidelines 03/2022 organise deceptive design in social-media interfaces into six broad categories and follow users through account opening, information, settings and account closure.
- 2
Method
Regulatory analysis organised around GDPR principles, six design-pattern categories and social-media account-lifecycle use cases.
- 3
Finding
The guidelines examine deceptive design across lifecycle stages rather than treating one isolated screen as the entire data-protection experience.
- 4
Boundary
The guidance is directed to social-media providers and GDPR processing; applying an example to retail, games or another service requires a separate scope analysis.
A guide written around moments, not abstractions
Many regulatory documents begin with principles and stay there. The EDPB guidelines do something more tangible. They follow people through the life of a social-media account and show how design can overload, rush, confuse or obstruct them at specific moments.
That makes the document immediately useful to designers. “Obstructing” becomes more than an abstract concern when the route to close an account is buried or repeatedly interrupted. “Left in the dark” becomes visible when the interface withholds the information needed to understand a choice.
The six-category lens
The framework groups examples under overloading, skipping, stirring, obstructing, fickle and left in the dark. Some categories describe information pressure; others describe emotional steering, inconsistent presentation or unnecessary effort.
The labels overlap with other taxonomies but are not identical. That is expected: the EDPB is organising examples around data-protection principles and social-media processing, not trying to publish a universal consumer-interface dictionary.
The portal’s glossary therefore treats these terms as routes into related mechanisms. It does not create a duplicate page for every vocabulary variation.
A strong model for fairer alternatives
The guidelines are valuable because they do not stop at naming a problem. Recommendations point towards understandable language, consistent controls, clear hierarchy and routes that allow people to exercise their choices. This resembles the paired approach used in the visual examples gallery: show the problematic decision environment, then show a neutral alternative and explain what changed.
The neutral version is not a legal safe harbour. It is a design comparator that helps legal, UX and product teams discuss the same evidence.
The scope boundary that must stay visible
The EDPB guidance sits within the GDPR. Its primary audience is social-media providers acting as controllers, and its examples are tied to processing and data-subject relationships. A team should not lift an example into an unrelated product and announce a universal ban.
Nor should the document be described as the Digital Fairness Act. The two may share policy themes, but a published GDPR guideline and an announced legislative initiative occupy different legal layers.
The practical takeaway
Review the whole lifecycle. A clear sign-up notice does not cure an obstructed settings route. A prominent privacy control does not help if its state changes elsewhere without explanation. Build an evidence map that covers entry, ongoing settings, rights and exit, then apply the law and role that actually govern each step.
Source check on 14 September 2026
The EDPB publication record still identifies Version 2.0 as final. This explainer now uses its category names: overloading, skipping, stirring, obstructing, fickle and left in the dark. In particular, obstructing replaces the earlier hindering label. The document concerns data-protection choices in social-media interfaces; it does not make this taxonomy a universal consumer-law test.
What to retain
Three findings worth carrying into review
The journey matters
The guidelines examine deceptive design across lifecycle stages rather than treating one isolated screen as the entire data-protection experience.
Six categories organise the examples
Overloading, skipping, stirring, obstructing, fickle and left in the dark provide a memorable framework for recurring interface problems.
Fair design is affirmative
The document pairs problematic examples with recommendations grounded in transparency, fairness, accountability and data protection by design and default.
What this evidence cannot establish
- The guidance is directed to social-media providers and GDPR processing; applying an example to retail, games or another service requires a separate scope analysis.
- A category label is not an automatic infringement finding and does not establish the contents or legal effect of a future Digital Fairness Act.
Questions for a journey review
- At which account-lifecycle stage does the user first understand the purpose, consequence and route to a privacy choice?
- Does the same control remain understandable and equally available across settings, notices, rights requests and account closure?
- Which GDPR role, principle and processing operation is actually in scope before an EDPB example is used in a legal assessment?
Evidence base
Sources
- Guidelines 03/2022 on deceptive design patterns in social media platform interfacesEuropean Data Protection Board · Primary · checked 2026-09-14 · Guidelines 03/2022, Version 2.0
