“What I’m interested in is something that violates the law”: Regulatory practitioner views on automated detection of deceptive design patterns
Authors
Paper Title
“What I’m interested in is something that violates the law”: Regulatory practitioner views on automated detection of deceptive design patterns
Publication Info
- Topic area: Automated detection of deceptive design patterns in regulatory enforcement.
- Keywords: deceptive design patterns, dark patterns, regulatory enforcement, automated detection, machine learning, large language models, user interfaces, legal violations, enforcement technologies, transparency.
Background and Problem
- Problem / challenge: Deceptive design patterns (DPs) are pervasive online, manipulating users and violating legal norms. Regulatory enforcement struggles to keep pace with the scale and evolution of these practices, and existing automated tools often fail to meet the evidentiary and operational needs of regulators.
- Significance: Addressing deceptive design patterns is critical for protecting user autonomy, ensuring fair business practices, and upholding legal compliance in digital environments.
- Motivation and related work: Prior research has developed tools for detecting DPs, often relying on machine learning and large language models. However, these tools are primarily designed for academic purposes and lack alignment with the practical requirements of regulatory enforcement, such as legal validation, traceability, and transparency.
Solution
- Proposed approach: An interview study with nine regulatory practitioners to understand their activities, requirements, and views on automated DP detection tools.
- Novelty:
- Mapping regulatory enforcement activities to identify gaps where automated tools can assist.
- Highlighting the disconnect between academic tooling and regulatory needs.
- Proposing actionable recommendations for aligning tool development with enforcement requirements.
- Exploring broader themes such as transparency, confidentiality, and interdisciplinary collaboration.
- Procedure and key techniques:
- Conducted interviews with practitioners from EU regulatory bodies, NGOs, and businesses.
- Used thematic analysis to extract insights on enforcement activities, tool usage, and constraints.
- Analyzed existing academic tools to assess their applicability to regulatory processes.
Results
- Concrete findings:
- Regulatory enforcement involves seven key phases: Preventative Action, Sweep Collection, Screening, Further Information Gathering, Establishing Violations, Taking Action, and Checking Change Implementation.
- Current academic tools primarily support early phases like Sweep Collection and Screening but fail to address later stages requiring legal validation and robust evidence.
- Transparency, traceability, and human oversight are critical for tool adoption in regulatory contexts.
- Advantage over baselines: Academic tools provide inspiration for regulatory systems but lack direct applicability due to gaps in evidentiary standards and operational alignment.
- Experiments / evaluation:
- Interviews revealed practitioners’ reliance on diverse tools for data collection and analysis, emphasizing manual validation for legal compliance.
- Analysis of academic tools showed limited attention to regulatory requirements like timestamping, confidentiality, and mapping DPs to legal violations.
- Limitations and future work:
- Small sample size of nine participants limits generalizability.
- Focused on EU regulations; findings may not fully apply to other jurisdictions.
- Did not include academic tool-makers or commercial detection tools; future work should address these gaps.
Summary
This study examines the intersection of academic research on automated detection of deceptive design patterns and the practical needs of regulatory enforcement. Interviews with EU practitioners revealed critical gaps in current tools, particularly in their ability to provide legally admissible evidence and align with enforcement workflows. While academic tools inspire regulatory innovations, they require significant adaptation to meet transparency, traceability, and confidentiality standards. Recommendations include mapping DPs to legal violations, engaging regulators in tool development, and fostering interdisciplinary collaboration. Future work should explore scalable solutions for enforcement and bridge the gap between academic research and regulatory practice.
Research Questions / Practical Problems
Question signals indexed for this paper.
- 71%
Dark Patterns and the EU Digital Services Act: Mapping Autonomy Violations and Design Factors
CHI '26· Dark Patterns Recognition +2
- 67%
Dark Patterns and the Legal Requirements of Consent Banners: An Interaction Criticism Perspective
CHI '21· Privacy by Design & User Control +1
- 67%
Online Terms & Conditions: Improving User Engagement, Awareness and Satisfaction through UI Design
CHI '22· Privacy by Design & User Control +1
- 67%
Dark Patterns in the Opt-Out Process and Compliance with the California Consumer Privacy Act (CCPA)
CHI '25· Privacy by Design & User Control +1
- 63%
"I Know I'm Being Observed:" Video Interventions to Educate Users about Targeted Advertising on Facebook
CHI '24· Privacy by Design & User Control +2
Based on Jaccard similarity of research subtopics & professions (≥60%)