Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

EDPB on Dark Patterns: Lessons for Marketing & Technical Teams

By Peter Craddock on March 23, 2022
Email this postTweet this postLike this postShare this post on LinkedIn

“Dark patterns” – social media platform interfaces that can lead users to make unintended and potentially harmful decisions regarding the processing of their personal data – are a subject of increasing scrutiny in the EU. New guidelines of the European Data Protection Board (EDPB) on “dark patterns in social media platform interfaces” confirm the focus of EU authorities on such practices. The guidelines contain lessons for all websites and applications. The bad news for marketers: the EDPB doesn’t always like it when dry legal language is made catchier or dull interfaces more enticing.

To illustrate, in a section of the guidelines regarding the selection of an account profile photo, the EDPB considers the example of a “help/information” prompt saying “No need to go to the hairdresser’s first. Just pick a photo that says ‘this is me.’” According to the EDPB, such a practice “can impact the final decision made by users who initially decided not to share a picture for their account” and thus makes consent invalid under the General Data Protection Regulation (GDPR). In another example, the EDPB criticises a cookie banner with a humourous link to a bakery’s cookie recipe that incidentally says “we also use cookies,” stating that “users might think they just dismiss a funny message about cookies as a baked snack and not consider the technical meaning of the term ‘cookies.’” The EDPB even suggests that the data minimisation principle, and not security concerns, should ultimately guide an organisation’s choice of which two-factor authentication method to use.

Do these new guidelines reflect privacy paranoia or common sense? The answer should lie somewhere in between, but the whole document (64 pages long) in our view suggests an overly strict approach, one that we hope will move closer to common sense as a result of a newly started public consultation process.

Click here for our analysis of what useful lessons – or warnings – can be drawn from the EDPB’s new guidelines.

Photo of Peter Craddock Peter Craddock

Peter Craddock helps companies innovate and use data better in the European Union (EU) and worldwide by providing strategic advice and legal assistance in the areas of privacy, data protection, data governance, AI governance, cybersecurity, e-commerce, digitalization, and software contracting. Peter’s practice covers…

Peter Craddock helps companies innovate and use data better in the European Union (EU) and worldwide by providing strategic advice and legal assistance in the areas of privacy, data protection, data governance, AI governance, cybersecurity, e-commerce, digitalization, and software contracting. Peter’s practice covers advisory work, contract drafting, and negotiation, as well as representation of clients in litigation before data protection authorities or the courts.

He has recognized in-depth knowledge in complex matters such as online advertising and content personalization, data-intensive operations such as credit scoring and anti-fraud profiling, and digital marketing.

Peter’s legal experience and distinctive background as a software developer serve him well in advising global clients on new and existing technologies, from artificial intelligence (AI) to novel user identification techniques, and in analyzing data protection laws and regulations with a fresh perspective. He counsels clients through the intricacies of developing new initiatives in compliance with data protection and cybersecurity requirements and has developed smart compliance tools for clients to that end. Among the tools made available to a broader public, a data breach risk assessment tool that he built was awarded a “Highly Commended” label at the Financial Times Innovative Lawyers Awards 2019, and his General Data Protection Regulation (GDPR) fine calculation tool, DeFine, helps organizations better understand data protection financial risks.

Prior to joining Keller and Heckman, Peter was a partner at an international law firm in Brussels, where he focused on providing data protection advice under EU and local law.

Read more about Peter CraddockEmailPeter's Linkedin Profile
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Consumer Protection Connection
  • Organization:
    Keller Heckman
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo