CCPA fines SpiceJet ₹1 lakh for dark patterns, bans default-consent enrollment

The consumer watchdog penalized SpiceJet for pre-ticked checkboxes auto-enrolling users into SpiceClub loyalty and promo messaging, ordering a permanent end to default-consent practices. The ruling sets an enforcement precedent for all Indian booking and e-commerce platforms.

— Source publishedFri, 17 Jul, 2026, 21:01 IST·First seen Fri, 17 Jul, 2026, 21:04 IST·Source The Hindu BusinessLine

What happened

CCPA fined SpiceJet ₹1 lakh for deploying dark patterns—pre-ticked checkboxes auto-enrolling users into SpiceClub loyalty and promotional messaging. The airline

Key facts

  • ₹1 lakh penalty
  • Rule 4(9) E-Commerce Rules 2020
  • Dark Patterns Guidelines 2023

Why this matters

Diligence on any Indian booking or e-commerce target must now include a dark-pattern and consent-mechanism review, as regulatory exposure is a live and expanding liability.

What to watch

  • CCPA notices or investigations against other named platforms
  • Formal amendment or tightening of dark-pattern guidelines
  • Increase in penalty quantum in subsequent rulings
  • Consumer group litigation or class complaints citing this precedent
  • Drop in reported loyalty program active-member growth across sector
  • Audit all pre-ticked checkboxes and default opt-ins across booking, loyalty, and promo flows
  • Rebuild consent UX to explicit granular opt-in with clear separation of loyalty vs marketing consent
  • Brief legal and product teams on 2023 dark-pattern guidelines exposure (drip pricing, false urgency, forced action)
  • Model revenue impact from reduced marketing-consent and loyalty enrollment rates
  • Prepare public compliance statement to preempt regulator and reputational scrutiny

Also reported by