Dark patterns are deceptive user experiences that take advantage of people’s habits of using websites and apps to trick them into doing something they did not intend to do.

Dr Harry Brignull, an UX designer, coined the term on July 28, 2010, with the registration of the domain darkpatterns.org (now deceptive.design), a site devoted to naming and shaming deceptive user interfaces.

Brignull identified 12 categories of dark patterns:

  • Friend spam happens when someone asks for your contacts under false and good pretenses but then sends spam to them, claiming it’s from you
  • Forced continuity occurs when your free trial ends, and you get charged, so it is a hurdle for you to cancel
  • Ads disguised as different kinds of content or navigation within the website, so you click on them
  • Confirmshaming, which is an act of guilting the user into opting in for something by shaming them into compliance
  • Bait-and-switch is when you set out to do one thing for a given outcome, but a different and undesirable effect happens instead
  • Hidden costs, which make something appear cheaper only so at the last step of the checkout process, you are told of the additional charges
  • Roach motels, which are designed to make it very easy for you to get into a certain situation, but then hard to get out of it, like a subscription
  • Privacy zuckering, named after the Meta CEO, is used to trick you into publicly sharing more information about yourself than you want
  • Misdirection, which intentionally focuses your attention on one thing to distract you from something else
  • Price comparison prevention is when the retailer makes it hard to compare prices of items, so you cannot make an informed decision – thankfully, this is mostly outdated now.

Each of the above practices have now become recognized by various legislative bodies. For example, European Data Protection Board, which published a special guidelines of using dark patterns in social media platforms.

You may also like:


  • Life after GA4: Why EU organizations are going local

    When Universal Analytics was phased out in 2023, and GA4 rolled out with complexity, many European organisations were forced to rethink how they measure success. For more and more, the solution is clear: use analytics built for Europe, by Europe. Why sovereignty matters Data sovereignty isn’t just a buzzphrase. Under GDPR and the Schrems II…

  • Telehealth analytics: Optimizing virtual care experiences in a HIPAA-compliant way

    As patients increasingly turn to digital platforms for medical care, healthcare organizations must understand user behavior and tailor their responses to meet these expectations. Patients want flexible, digital-first options, while providers seek to optimize efficiency, reduce costs, and expand care to more people.