Friday, September 11, 2026

India's New Ecommerce Rules Hit Fake Discounts

You open a shopping app three days before Diwali. The banner says the price has been slashed. There is a timer running, a red strike-through above the number, and a line telling you that stock is nearly gone. None of it is checkable. You cannot see what that item cost last week, you cannot tell whether the top result is the best match or the best-paying seller, and if the timer resets tomorrow, nobody will tell you. India's new ecommerce rules, notified on 11 September 2026, are aimed squarely at that screen.

Timeline graphic tracing India's ecommerce rules from the 2025 dark pattern advisory to 2027

The Consumer Protection (E-Commerce) (Amendment) Rules, 2026 finally give shoppers a checkable baseline, but they still ship without a penalty attached.

  • Discount claims must be measured against the previous month's lowest price, not an invented crossed-out number.
  • Platforms owe an annual dark pattern self-audit and a signed compliance certificate.
  • Search ranking parameters have to be disclosed and sponsored listings clearly labelled.
  • Everything switches on 1 January 2027, so this year's festive sales run under the old regime.

Why These Ecommerce Rules Matter More Than A 2025 Advisory

The amendment matters because it converts a voluntary June 2025 self-audit request into a standing annual duty, and because it finally puts a checkable number, the preceding month's lowest price, behind every discount claim.

The Department of Consumer Affairs has been circling this problem for three years. The 2023 dark pattern guidelines named the behaviours. The Central Consumer Protection Authority then asked platforms to go and look for those behaviours themselves, on their own timetable, and report back. Large platforms duly reported back that they had looked and found very little. That is where Indian consumer regulation usually ends, and it is why this notification reads differently: the audit is no longer a favour asked of industry, it is a line item that recurs every year with a certificate attached to somebody's signature.

The price rule is the part I would actually defend. Everything else in the amendment asks a platform to disclose something, and disclosure is easy to satisfy badly. A prior-price floor is arithmetic. Either the item was cheaper in the last month or it was not, and the number sits in the platform's own order history where a regulator can go and get it. National Consumer Helpline figures cited with the notification put roughly 29% of 2025's grievances in e-commerce, and most of those are not fraud complaints. They are complaints about a transaction that behaved differently from how it was sold.

A pattern is worth naming here. India has spent two years writing rules that describe good behaviour precisely and leave the consequence vague, and the same shape shows up in India's consent manager deadline arriving with no board constituted to enforce it and in India's AI labelling rules six months on, where the labels landed and the enforcement did not. A rule that names thirteen bad practices and prices none of them is one a large platform can budget around.

The honest question is not whether the amendment is well drafted. It reads fine. It is whether an annual certificate changes anything for a company that already certified itself clean once and carried on.

Self-audit window

3 months

granted by the 2025 advisory

Helpline grievances

17,71,622

logged across 2025

Still using manipulative design

97%

LocalCircles audit, mid-2025

Penalty written into the guidelines

Rs 0

the linking clause was dropped

The survey figure is the one to sit with. LocalCircles gathered it between June and September 2025, exactly the window platforms were using to audit themselves, and it found manipulative design still close to universal at the end of it. Two readings of the same months cannot both be right. Either the audits looked somewhere the shoppers were not, or they looked and decided that what they found did not count.

"

Thirteen named dark patterns, an annual compliance certificate, and still not one rupee of penalty written against any of them. That is a rulebook missing its enforcement page.

What Are Dark Patterns In Online Shopping?

Dark patterns are interface choices built to push you into a decision you did not intend, and India's 2023 guidelines name 13 of them, from false urgency and basket sneaking to drip pricing and subscription traps.

Most of them are not exotic. You have met them this month. The countdown that restarts when you reload. The insurance line item that was already ticked. The cancel flow that asks whether you are sure you want to miss out. The guidelines gave these things names so that a complaint could describe one without arguing about intent, which was genuinely useful, and then stopped short of saying what happens next.

  • False urgency and interface interference shape what you click by controlling what you can see and how long you think you have.
  • Basket sneaking and drip pricing both work on the total, one by adding a line, the other by revealing charges late.
  • Subscription traps and forced action make leaving cost more effort than joining did.
  • Disguised advertisements are the one the ranking disclosure rule is built for, because a sponsored result that looks organic is a pricing decision wearing a relevance costume.

Enforcement so far has been example-led rather than systematic, and the examples came from household names rather than fly-by-night sellers. That is standard practice at the centre of the market, not a gap at its edges.

When Do India's New Rules Actually Come Into Force?

The rules were notified on 11 September 2026 and come into force on 1 January 2027, which leaves 111 days of runway and puts the entire 2026 festive sale season outside their reach.

That gap is my own arithmetic, not a published figure, and it is the most consequential detail in the notification. The heaviest discounting quarter of the Indian retail year runs from the first big sale event through Diwali into the new year clearances, and all of it happens before the prior-price floor applies. Here is what changes when the calendar turns.

CategoryDetailInsight
Prior priceAny reduced price shown against the lowest price offered in the previous 30 daysFlash discounts lose their invented baseline
Audit cycleOne self-audit and one compliance certificate every year, against the 2023 guidelinesAnnual paperwork, no external auditor required
RankingsRanking parameters disclosed; sponsored listings carry clear and prominent labelsPaid placement stops passing as relevance
ComplaintsMandatory helpline tie-up; complainant receives the complaint as recordedA written record survives the call centre
ListingsReturns, refunds, warranty, delivery, payment terms, importer identity and country of originImported goods can no longer hide origin
TimingNotified 11 September 2026, in force 1 January 2027, a 111 day runwayFestive 2026 runs under the old rules
PenaltyNo sum specified; action falls back on the Consumer Protection Act, 2019Route exists, price tag does not

Read down that Insight column and the shape of the amendment is clear. Four of the seven changes give a shopper something to check. The last one tells you what happens when the check fails, and the answer is a general statute rather than a number.

5 Jun 2025. 20 Nov 2025. 11 Sep 2026. 1 Jan 2027. CCPA advisory issued. Self-audit requested. 26 platforms file. CCPA calls it exemplary. Amendment notified. Audit becomes annual. Rules commence. Price floor applies.

Dates from the Press Information Bureau release of 20 November 2025 and the Department of Consumer Affairs notification reported by Business Standard on 11 September 2026.

Friction Points: Who Actually Pays For Compliance

Marketplaces do not set most prices, individual sellers do, so the duty to prove a month of price history lands hardest on small merchants who have no compliance team and reprice constantly.

Industry voices quoted by Business Standard on the day of notification made this point bluntly, and they are not wrong. A marketplace builds price-history tooling once and amortises it across lakhs of listings. A seller running a few hundred SKUs from a warehouse in Tiruppur cannot, and will end up buying that capability from the same marketplace whose rankings they compete inside. Rules written to constrain platform power have a habit of deepening it, which is the quiet cost nobody prices in.

The ranking disclosure has a different problem. Disclosing parameters is not the same as disclosing weights, and any platform can publish a truthful list of the seventeen things its algorithm considers while telling you nothing about which one decided the order you saw. Compare that with how the payments stack got reshaped by credit on UPI changing the way India checks out: the change there was structural, not declaratory, and it moved behaviour within months.

  • No named auditor. The certificate can be signed internally, which is how a clean audit and a 97% failure rate coexisted last year.
  • Only 18 of 25 declarations were published in the 2025 round. Seven were never made public, and by my count that is 28% of the filings that nobody outside the regulator has read.
  • Price history is seller-side data. A marketplace can only certify what its sellers report, so the audit trail is one hop away from the party being regulated.
  • Compliance dates cluster badly. Firms already working through hardware and privacy deadlines, including the draft ITSAR phone security standards, now have one more January obligation.

What the enforcement record actually looks like

  • BookMyShow, February 2025. A pre-ticked box added Re 1 per ticket as a charity contribution, the textbook version of basket sneaking.
  • IndiGo, June 2024. An opt-out worded as "No, I will take risk", with the skip-seat-selection option pushed out of easy reach.
  • The pattern. Both surfaced through public attention rather than through an audit, and both involved companies large enough to have a design review process already.

So do the thing the rules will not do for you until 2027. Pick the items you mean to buy in this year's festive sale and write down today's price against each one. Check it again on sale day. If the discount survives that comparison it was real, and if it does not, you have a dated record and a helpline that is about to owe you a copy of your own complaint.

Thursday, September 3, 2026

India's Consent Manager Deadline Arrives With No Regulator To Register

You open a food delivery app you last used in 2019. It still holds your home address, your office address, a card you cancelled two years ago, and every order you placed during a lockdown you would rather not revisit. No button in that app takes any of it back.

India's Consent Manager Deadline Arrives With No Regulator To Register

TL;DR: From 13 November 2026, Indian users are supposed to manage every app consent from one interoperable dashboard run by a registered consent manager. The regulator that registers them, the Data Protection Board of India, still has no chairperson and no members. The right arrives; the plumbing does not.

Why It Matters

A consent manager is not another privacy policy. Under the Digital Personal Data Protection Rules notified in November 2025, it is a licensed intermediary sitting between you and every company that holds your data, and its duty runs to you rather than to them. Consent given through it can be reviewed and pulled back in one place, and the withdrawal is meant to travel to the company on its own. One screen instead of forty settings pages.

The conventional read is that India is copying Europe, late. That gets it backwards. GDPR handed Europeans a right to withdraw and left them to exercise it one company at a time, which is precisely why almost nobody does. India's version is the more ambitious of the two, because it puts a registered institution in the middle whose entire job is to make a withdrawal actually propagate. Ambitious is not the same as working.

And here is the part nobody planned around. A LiveLaw analysis published in August 2026 found that the Data Protection Board of India, the body that must register consent managers and hear complaints against companies, had no appointed chairperson and no appointed members roughly ten months after the rules took effect. Nominations went out. No seat was filled. The shape of this will be familiar to anyone who followed India's AI labelling rules at their six month mark, where the rule existed, the enforcement did not, and a High Court ended up doing the regulator's work for it.

Court-Set Decision Window

15 Days

ordered of an empty bench

Maximum Penalty

₹250 Crore

available on paper, unused

MeitY Nomination Calls

2 Rounds

May and June, both open

Board Seats Filled

0%

chairperson and members alike

Take that court-ordered decision window. A High Court bench in Madhya Pradesh sent a petitioner to file before the Board and told the Board to decide inside a fortnight, which reads as ordinary case management right up until you remember there is nobody at the other end to open the envelope. That is what a vacant regulator does to everything downstream of it. It does not collapse in public. It quietly converts a right into a queue.

"

Ten months of rules in force, and not one seat on the board that enforces them has been filled. That is not a delay any more. That is a decision.

The framework itself is not vague. It is unusually precise about what a consent manager has to be, which makes the missing registrar more conspicuous rather than less.

Category Detail What It Decides
Deadline Twelve months after the rules were notified Legacy consents must be revalidated by then
Entry Bar ₹2 crore minimum net worth, Indian incorporation Prices out the small privacy startups
Data Blindness Cannot read the personal data it routes A broker of permission, never of data
Retention Seven years of consent records held Your refusal outlives the app itself
Registrar Data Protection Board, zero members seated No desk accepts an application today
Breach Route Section 8(6) notifications land nowhere Reporting duty exists, recipient does not
Full Powers Adjudication expected around May 2027 Enforcement lands well after the deadline

Read down that middle column and the shape is obvious. Every line is a barrier to entry, and every barrier assumes a working gate behind it. What exists is a wall with no gate cut into it, and a date circled on a calendar.

12 months 6 months rules in force · board empty deadline passed · powers pending notification full powers

The eighteen month runway from notification to full enforcement powers, split at the point where the consent obligations bite.

Friction Points

The gap between the deadline and real enforcement is where the damage sits. From November, companies are supposed to have revalidated every legacy consent sitting in their databases. Nothing checks whether they did. Nothing, in the sense that no one holding statutory authority is currently in a position to look.

There is a second problem the industry does not much enjoy discussing. A consent manager is a new intermediary, and new intermediaries have to earn a living somewhere. The rules say it must be blind to the data it carries, which is the right instinct. But blindness is a technical property, not a revenue model, and India has watched the same gap open before: India's draft phone security standards ran into an industry with every reason to comply slowly and none to fund the work early.

Before you trust anything that calls itself a consent manager, check the following.

  • Registration is mandatory, and until the Board is seated, no operator in India holds it.
  • Withdrawal stops future processing. It does not erase an inference a company already drew from data it held lawfully.
  • Interoperability is a requirement on paper. Ask which fiduciaries a platform actually connects to today, by name.
  • The record of your refusal is kept about you too, long after you have stopped using the service.

Key takeaways

  • The duty of a consent manager runs to you, not to the company holding your data. That reversal is the entire design idea, and it is genuinely rare in Indian regulation.
  • Interoperability is what separates this from a cookie banner. One withdrawal is meant to reach every fiduciary you have linked, without you chasing any of them.
  • A dashboard is only as strong as the body that licenses it. Until seats are filled, the honest label for what exists is a well drafted intention.

Do not wait for the dashboard. Open the five apps you actually use, go into their existing privacy settings this week, and delete what you can while the deleting is still manual. The consent manager is a better answer than doing it by hand. It just is not an answer yet.

Related: India's new ecommerce rules on fake discounts and dark patterns

Thursday, August 20, 2026

India's AI Labelling Rules Six Months On: Courts Still Needed

A video of a Union Minister pocketing money lands in your family WhatsApp group. It looks right. The voice is his, the office is his, the lighting is ordinary enough to pass. Nothing on the screen tells you a machine built it, and by the time anyone official says so, your uncle has forwarded it twice.

India's AI Labelling Rules Six Months On: Courts Still Needed
TL;DR: India's IT Amendment Rules 2026 have required visible labels on AI-generated media and fast takedowns since 20 February. Six months on, a Union Minister still needed a Bombay High Court order to get deepfakes of himself pulled down. The label arrived. The enforcement did not.

Why It Matters

The rules were notified on 10 February 2026 and came into force ten days later. They do two things worth caring about. Synthetically generated information, meaning audio or video created or altered by a machine so it reads as authentic, now has to carry a label an ordinary person can actually see. And platforms have to embed permanent provenance markers into that content wherever it is technically feasible, then stop anyone from stripping them out. It is the same regulatory instinct that produced 83 security standards aimed at the handset in your pocket: fix it at the device or the platform, because chasing individual bad actors across the open internet has never scaled.

The draft wanted something blunter. A watermark covering ten percent of the frame, fixed, non-negotiable. That died before notification and was replaced by a principle: the label must be clear and prominent. Good. A hard percentage would have been unreadable on a phone and ridiculous on a television, and every design team in the country would have spent a year gaming the geometry instead of improving the disclosure. But turn it around and the change reads as an admission. Nobody could describe what a good label looks like, so the rule now describes a feeling and leaves the rest to whoever ships the app.

Then there is the clock, and the clock is where the framework quietly hands the work back to you. Platforms now face a hard deadline to pull flagged unlawful synthetic content once a lawful notice reaches them, cut sharply from the old window. Cross the significant intermediary threshold and a second duty lands: ask uploaders whether their material is machine-made, then verify that answer with technical measures instead of taking it on trust. On paper, aggressive. In practice, none of it moves until somebody notices, reports, and is believed. McAfee's State of the Scamiverse survey, published in February 2026, found Indians now spend 102 hours a year working out whether the messages hitting their phones are genuine. That is the real bill, and a shortened takedown window does nothing to it.

Takedown deadline

3 hours

Down from thirty six

Average scam loss

₹93,915

Per affected Indian respondent

Strict-tier threshold

50 lakh users

Registered accounts inside India

Cannot spot a fake

1 in 3

Indians surveyed, November 2025

The tier threshold is the number to watch, because it is a cliff rather than a slope. Cross it and you inherit the declaration-and-verification duty, which in engineering terms means building a classifier that guesses whether an upload is synthetic and then owning every case it gets wrong. Stay under it and you inherit almost nothing. Every mid-sized Indian app now has a live commercial reason to keep its registered account count comfortably short of the line, and no regulator has said a word about what happens when they do. TRAI has spent years watching this exact arithmetic play out in telecom without moving on it.

"

A three hour takedown clock means nothing to the person it was written for, because the clock only starts once she has already found the video, reported it, and been believed.

August gave the framework its first properly public test, and it is worth setting the written rule beside what actually happened in a courtroom.

Category Detail Insight
Legal basis An amendment to the existing intermediary guidelines, not a standalone AI statute Existing framework extended, not rewritten
Scope Audio, visual and audio-visual material altered to appear authentic Text-only output sits outside the rule
Label test Clear and prominent, with the draft's fixed frame percentage dropped Flexibility bought at the cost of certainty
Provenance Permanent markers embedded where feasible, with removal blocked by design Traceability outlasts any visible badge
Exemptions Routine editing, good-faith technical correction, accessibility work Ordinary photo cleanup stays untouched
Verification Uploader declares, platform checks the declaration with technical measures Platforms now own the classification mistakes
Trigger A lawful order or notice from a court or an authorised government agency Nothing moves without an external complaint
August test Bombay High Court, 5 August 2026, before Justice Arif Doctor Meta and Google agreed after court intervention

Read down that Trigger row again. The entire machine is reactive. Provenance markers, declaration duties, a stopwatch on removals, and every one of them waits for a complaint to arrive from outside. Which is why the story of the last six months is not the rule failing. It is the rule working exactly as drafted, on a schedule set by whoever has the time and standing to complain.

More wary than a year ago · 82% Social account compromised · 70% Lost money to a scam · 51% Hit by a voice-clone scam · 20% 0% 100%

The same McAfee fieldwork, run across seven countries, puts the Indian exposure picture in one frame: most people have already been hit, and most of them know it.

Friction Points

Earlier this month the Bombay High Court heard Nitin Gadkari's application against Meta Platforms over face-swapped videos and fabricated quotes tying him to the E20 ethanol controversy. Justice Arif Doctor called the material absolutely vile and abusive and said it should have no place on a public platform accessible to everyone, including the young. Meta and Google agreed in court to remove the listed content and were directed to hand over basic subscriber information for the accounts behind it. The next hearing sits roughly four weeks out. Note what that sequence required: a sitting Union Minister, senior counsel, and a High Court listing, half a year after the deadline took effect. If that is the cost of entry, the rule is not built for the woman whose face was pasted into something at two in the morning.

Here is the part nobody in the drafting room seems to have answered, and I would put it as opinion rather than fact: a labelling regime binds the people who were already going to behave. The model that stamps provenance into its output and the platform that surfaces the badge are both following rules that a deliberate faker simply routes around, using an offshore tool, a screen recording, a re-encode. So the label ends up certifying the harmless half of the internet while the harmful half stays unmarked, and no one has told readers what they are supposed to conclude from a video that carries no label at all. Absence of a badge is not evidence of authenticity. It might just mean the rule was ignored.

And there is a cost on the other side that gets less attention than it deserves. Compressing removal into hours, with safe harbour hanging on compliance, pushes platforms toward automated over-removal, because deleting a borderline clip is cheaper than defending it. Satire, political commentary, parody accounts (and yes, that includes the stuff you actually wanted to see) all sit in the blast radius. The Internet Freedom Foundation has argued the shortened windows leave no room for meaningful human review, and on that narrow point the criticism looks right to me even if the underlying goal does not.

  • An unlabelled video proves nothing either way. Treat missing provenance as unknown, not clean.
  • The clock starts at the notice, not at the upload. Reporting fast matters more than knowing the law.
  • Text is out of scope, so machine-written fake quotes and fake screenshots carry no labelling duty at all.
  • Smaller apps sit below the strict tier and owe you far less, which is where a lot of this content will migrate.
  • Provenance markers survive the label. If a clip matters, the metadata is the thing worth preserving before you forward it.
Check · Report · Hold Look for provenance data, not a corner watermark. Screenshots strip it out. Use the in-app report flow, not a comment. Only a notice starts it. Do not forward while you are still checking. Reach beats correction.

Three habits, none of which require you to read a gazette notification.

The rules are a real improvement over having nothing, and they are nowhere near what the marketing around them implied. India moved faster than most countries here, which counts for something, in the same way moving first on credit through UPI counted for something before the fine print landed. If you want a version of this that protects your household rather than a minister, the move is not legal. Go into the settings on every account your family uses, turn on whatever synthetic-media reporting the platform already offers, and use it the first time rather than the fifth, the same discipline that makes switching off Shorts on the living room television actually stick. The label is not going to save you. The report button might.