Research explained · Institutional research

What Australia’s “Patterns in the dark” report adds to the debate

The Data Standards Body commissioned the University of South Australia to map deceptive-pattern research, build a typology and consider how online manipulation could affect the Consumer Data Right. The report is valuable because it joins psychological mechanisms, interface examples, literature and Australian data-sharing concerns in one landscape. It is not legislation or a regulator finding. Official committee discussion also recorded concerns about the report’s legal and jurisdictional limits.

Institutional research
Original work
Patterns in the dark: deceptive practices in online interactions
Authors
University of South Australia for the Data Standards Body
Published
2024-08-08
Venue
Australian Government Data Standards Body research publication
Method
A landscape assessment combining literature review, cross-taxonomy analysis, psychological mechanisms, interface examples and Consumer Data Right context.
Sample or scope
Published deceptive-pattern research and regulatory taxonomies reviewed for an Australian data-sharing and consent setting.

Read the evidence carefully

From research question to useful conclusion

  1. 1

    Question

    The Data Standards Body commissioned the University of South Australia to map deceptive-pattern research, build a typology and consider how online manipulation could affect the Consumer Data Right.

  2. 2

    Method

    A landscape assessment combining literature review, cross-taxonomy analysis, psychological mechanisms, interface examples and Consumer Data Right context.

  3. 3

    Finding

    The report depicts deceptive practices across degrees of manipulation, benefit and legality rather than treating every observed design as identical.

  4. 4

    Boundary

    The publication is a broad landscape assessment and literature review; it does not measure prevalence in a representative sample of current Australian services.

A map of a moving field

The UniSA report arrives at deceptive design from a particular Australian concern: systems that ask people to share, manage or withdraw access to data can satisfy formal interface requirements while still shaping the decision in ways that weaken control.

To explore that problem, the report surveys research, describes psychological vulnerabilities and builds a typology. Its value is synthesis. A reader can see how techniques that once appeared as isolated annoyances relate to broader strategies of obstruction, information interference, pressure or hidden consequences.

The spectrum is more useful than a binary label

One of the report’s diagrams places patterns in a space shaped by deception, benefit and legality. That is a better starting point than assuming every persuasive design is forbidden or every technically available choice is fair.

A reminder can help a person complete an intended task. The same visual form can become nagging if refusal is temporary while acceptance is permanent. A default can reduce effort, or it can hide a material selection. Context changes the analysis.

The seven-family practice library uses this mechanism-first approach and then shows a neutral alternative. It deliberately does not label every example a breach.

Why the Consumer Data Right context matters

Data-sharing journeys create unusual asymmetries. Organisations understand the system, the consent duration and the value of the data. Consumers may see only a sequence of screens. The October 2024 committee discussion of a separate follow-up report also raised questions about metadata and knowledge of a person’s existing arrangements being used outside the core CDR journey.

That means review should follow the state across channels: what the person authorised, when the consent expires, which interface explains the change and whether web, app and support show the same position.

Official discussion also recorded limits

Committee minutes surrounding the work are important reading. Members recognised the relevance of deceptive design to informed choice and control, while also questioning parts of the regulatory analysis and international coverage. That is not a reason to discard the report. It is a reason to read it as research rather than final doctrine.

The distinction is especially important now that Australia has enacted a new unfair-trading prohibition. The report predates the final section 28B wording. Its taxonomy can inform evidence questions, but the section 28B guide remains the place to work through the enacted elements and commencement.

The practical takeaway

Use the report to widen the field of view. Record the surrounding decision environment, not just the control that submits a consent. Then identify the precise current or future legal provision and preserve the distinction between what the interface did, what research suggests and what the law requires.

Source check on 14 September 2026

The DSB publication remains dated 8 August 2024. The 9 October 2024 committee minutes separately describe a second CDR vulnerability report. Findings about metadata targeting and specific CDR design choices belong to that later discussion, rather than being presented as empirical results of the published landscape review.

What to retain

Three findings worth carrying into review

Patterns sit on a spectrum

The report depicts deceptive practices across degrees of manipulation, benefit and legality rather than treating every observed design as identical.

Consent can be undermined by context

A technically available choice may still be weakened by the information, timing, defaults and path through which a person encounters it.

Taxonomy supports discussion

The proposed typology gives policy, design and research teams a shared starting point, while later work is needed to test specific systems and responses.

What this evidence cannot establish

  • The publication is a broad landscape assessment and literature review; it does not measure prevalence in a representative sample of current Australian services.
  • Data Standards Advisory Committee minutes record concerns about legal coverage and jurisdictional comparison, so the report should not be treated as settled regulatory doctrine.

Questions for an Australian journey review

  1. Could a compliant-looking data or consent control still be undermined by the surrounding route, timing or information hierarchy?
  2. Which taxonomy level describes what the team actually observed, and which claimed effect still needs user or operational evidence?
  3. What current ACL, privacy, CDR or future section 28B question is genuinely in scope for this service and date?

Evidence base

Sources

  1. Patterns in the dark: deceptive practices in online interactionsUniversity of South Australia for the Data Standards Body · Secondary · checked 2026-09-14