Obstruction · Australia
Privacy maze
Privacy maze is a working label for this design mechanism: Privacy controls are fragmented, inconsistently labelled or layered so that limiting collection or use is unnecessarily difficult. This is editorial implementation guidance for Australian journeys, not a finding of unlawfulness. From 1 July 2027, a similar interface is relevant to ACL section 28B only if the complete consumer-connection, manipulation or unreasonable-distortion and actual-or-likely-detriment test is met. Current ACL rules require a separate assessment.
- Family
- Obstruction
- Also known as
- Journey stages
Definition
What is this pattern?
Privacy controls are fragmented, inconsistently labelled or layered so that limiting collection or use is unnecessarily difficult. This is a design and research taxonomy for learning and evidence review, not a statutory offence label or an automatic finding that an interface is unlawful.
How it works
Privacy controls are fragmented, inconsistently labelled or layered so that limiting collection or use is unnecessarily difficult. Related controls are distributed across inconsistent labels, menus or channels, preventing the user from seeing and maintaining one coherent privacy state.
Warning signs
- A meaningful privacy-restrictive outcome exists in principle.
- The route contains unnecessary branching, repeated settings or inconsistent terminology.
- The less-private route is materially easier or the maze is likely to cause abandonment.
Potential harms
- A person may fail to restrict optional uses because the controls are fragmented and inconsistently described.
- The user cannot maintain a reliable privacy preference across interfaces.
Learn by comparison
What does this look like?
These fictional examples make the design mechanism easier to recognise. They do not depict a real company and do not establish that an individual interface is unlawful.
Illustrative example 1 · Advertising opt-out split across unrelated menus
A fictional service places audience ads, partner sharing and measurement controls under three differently named menus with no summary of the final state.
Potential consumer harm: A person may fail to restrict optional uses because the controls are fragmented and inconsistently described.
Illustrative example 2 · Privacy choice silently re-enables elsewhere
A fictional account lets users disable activity sharing on the web, but opening the mobile app silently restores the setting under a different label.
Potential consumer harm: The user cannot maintain a reliable privacy preference across interfaces.
Advertising opt-out split across unrelated menus
A fictional service places audience ads, partner sharing and measurement controls under three differently named menus with no summary of the final state.
Manage experience controls. Related advertising choices are scattered across “Experience”, “Partners” and “Insights”.. Open another menu. Unconfirmed state: Open another menu
Optional data uses. All related purposes and current states are visible in one navigable overview.. Turn off optional uses. Saved state: Turn off optional uses. Persisted account state, expanded: The saved state behind “Turn off optional uses” remains consistent after refresh and across supported channels.
Why the first version can mislead: The route adds avoidable effort between the user’s stated intention and completion. In this privacy settings example, the obstacle is: “Related advertising choices are scattered across “Experience”, “Partners” and “Insights”.” Evidence should show whether the alternative remains usable and whether “Turn off optional uses” reaches the represented state. A person may fail to restrict optional uses because the controls are fragmented and inconsistently described.
What a fairer design does: Provide a coherent overview, consistent purpose names and a clear summary of what each choice changes.
Show annotated differences (4)
- Related advertising choices are scattered across “Experience”, “Partners” and “Insights”.Why this state matters: The route adds avoidable effort between the user’s stated intention and completion. In this privacy settings example, the obstacle is: “Related advertising choices are scattered across “Experience”, “Partners” and “Insights”.” Evidence should show whether the alternative remains usable and whether “Turn off optional uses” reaches the represented state. A person may fail to restrict optional uses because the controls are fragmented and inconsistently described.
- Unconfirmed state: Open another menuReview prompt: How many steps, waits and channel changes separate “Open another menu” from the completed privacy settings outcome?
- All related purposes and current states are visible in one navigable overview.Fairer design: Provide a coherent overview, consistent purpose names and a clear summary of what each choice changes.
- Persisted account state, expanded: The saved state behind “Turn off optional uses” remains consistent after refresh and across supported channels.Review prompt: Test the control across refresh, device and account states; is “A meaningful privacy-restrictive outcome exists in principle” still observable after persistence is considered?
Review questions (3)
- How many steps, waits and channel changes separate “Open another menu” from the completed privacy settings outcome?
- Test the control across refresh, device and account states; is “A meaningful privacy-restrictive outcome exists in principle” still observable after persistence is considered?
- Measure the same task through the clearest available route: does the effort difference persist once “Granular controls with a clear overview and global options” is accounted for?
Privacy choice silently re-enables elsewhere
A fictional account lets users disable activity sharing on the web, but opening the mobile app silently restores the setting under a different label.
Personalised activity · Off. The mobile app later restores the same sharing under “Smart recommendations”.. Setting may change. Unconfirmed state: Setting may change
Activity sharing · Off everywhere. Web and app show the same persisted state and audit date.. Keep off across devices. Saved state: Keep off across devices. Persisted account state, expanded: The saved state behind “Keep off across devices” remains consistent after refresh and across supported channels.
Why the first version can mislead: The route adds avoidable effort between the user’s stated intention and completion. In this connected-device account example, the obstacle is: “The mobile app later restores the same sharing under “Smart recommendations”.” Evidence should show whether the alternative remains usable and whether “Keep off across devices” reaches the represented state. The user cannot maintain a reliable privacy preference across interfaces.
What a fairer design does: Use one persistent state across channels, announce conflicts and require a deliberate choice before changing it.
Show annotated differences (4)
- The mobile app later restores the same sharing under “Smart recommendations”.Why this state matters: The route adds avoidable effort between the user’s stated intention and completion. In this connected-device account example, the obstacle is: “The mobile app later restores the same sharing under “Smart recommendations”.” Evidence should show whether the alternative remains usable and whether “Keep off across devices” reaches the represented state. The user cannot maintain a reliable privacy preference across interfaces.
- Unconfirmed state: Setting may changeReview prompt: How many steps, waits and channel changes separate “Setting may change” from the completed connected-device account outcome?
- Web and app show the same persisted state and audit date.Fairer design: Use one persistent state across channels, announce conflicts and require a deliberate choice before changing it.
- Persisted account state, expanded: The saved state behind “Keep off across devices” remains consistent after refresh and across supported channels.Review prompt: Test the control across refresh, device and account states; is “The route contains unnecessary branching, repeated settings or inconsistent terminology” still observable after persistence is considered?
Review questions (3)
- How many steps, waits and channel changes separate “Setting may change” from the completed connected-device account outcome?
- Test the control across refresh, device and account states; is “The route contains unnecessary branching, repeated settings or inconsistent terminology” still observable after persistence is considered?
- Measure the same task through the clearest available route: does the effort difference persist once “complexity strictly required by genuinely distinct processing purposes” is accounted for?
What is a fairer alternative?
Provide a coherent privacy-control overview, consistent labels and direct controls for common restrictive choices.
Legal and information status
How Australian law may apply
Privacy controls are fragmented, inconsistently labelled or layered so that limiting collection or use is unnecessarily difficult. Related controls are distributed across inconsistent labels, menus or channels, preventing the user from seeing and maintaining one coherent privacy state. These harms describe a review risk, not an automatic legal conclusion. Australian section 28B commences on 1 July 2027 and requires its complete, context-specific test. Existing ACL provisions remain a separate current-law assessment.
ACL section 28B, inserted by the 2026 Act
Possible risk indicator
In account management journeys, the privacy maze mechanism may warrant review where it manipulates a consumer or unreasonably distorts the decision environment and causes, or is likely to cause, detriment. The obstruction label and an interface similarity do not establish a contravention; the complete section 28B test, scope, facts and evidence must be applied from 1 July 2027.
Dark-pattern research taxonomy
Editorial analysis
The cited research sources support this working pattern within the obstruction family. It is editorial implementation guidance, not an Australian statutory category, regulator finding or legal safe harbour.
Evidence layers and open questions
Applicable law, enforcement records, policy preparation, stakeholder input, editorial analysis and unknown future details remain visibly distinct.
Final Act mappingEditorial implementation guidance
This editorial practice label is not itself an express statutory prohibition. Apply the complete provision and its scope to the facts.
Possible general-test applicationCommences 1 July 2027
ACL section 28B, inserted by the 2026 Act: In account management journeys, the privacy maze mechanism may warrant review where it manipulates a consumer or unreasonably distorts the decision environment and causes, or is likely to cause, detriment. The obstruction label and an interface similarity do not establish a contravention; the complete section 28B test, scope, facts and evidence must be applied from 1 July 2027.
Existing ACLCurrent enforcement
Existing ACL provisions continue to apply on their own elements before and after commencement. The 2027 provisions must not be applied early.
Verified enforcement contextCurrent enforcement
No named pattern-specific enforcement example is asserted on this page. Existing ACL analysis remains fact-specific and separate from the 2027 provisions.
RegulationsRegulation pending
Later regulations may affect specified exclusions, matters or exceptions. That uncertainty does not postpone a core enacted rule unless the provision itself depends on prescription.
Regulator implementation materialGuidance pending
Government funding and parliamentary material anticipate regulator education and guidance. No dedicated final ACCC implementation guide is treated here as published.
Journey and evidence recommendationsEditorial implementation guidance
Provide a coherent privacy-control overview, consistent labels and direct controls for common restrictive choices. This is editorial portal guidance, not a statutory duty, regulator safe harbour or compliance certificate.
Context matters
Context and boundary cases
- A meaningful privacy-restrictive outcome exists in principle.
- The route contains unnecessary branching, repeated settings or inconsistent terminology.
- The less-private route is materially easier or the maze is likely to cause abandonment.
- Boundary to test: Granular controls with a clear overview and global options
- Boundary to test: complexity strictly required by genuinely distinct processing purposes
- Boundary to test: information-only privacy policy
When a similar design can serve a legitimate purpose
- Granular controls with a clear overview and global options
- complexity strictly required by genuinely distinct processing purposes
- information-only privacy policy
Operational review
What teams should review
- Teams
- How many steps, waits and channel changes separate “Open another menu” from the completed privacy settings outcome?
- Test the control across refresh, device and account states; is “A meaningful privacy-restrictive outcome exists in principle” still observable after persistence is considered?
- Measure the same task through the clearest available route: does the effort difference persist once “Granular controls with a clear overview and global options” is accounted for?
- How many steps, waits and channel changes separate “Setting may change” from the completed connected-device account outcome?
- Test the control across refresh, device and account states; is “The route contains unnecessary branching, repeated settings or inconsistent terminology” still observable after persistence is considered?
- Measure the same task through the clearest available route: does the effort difference persist once “complexity strictly required by genuinely distinct processing purposes” is accounted for?
Evidence to retain
- Annotated account management screenshots at each responsive breakpoint
- The complete state sequence before, during and after the consumer decision
- Design-system component, content, default and configuration records for the reviewed release
- Operational records substantiating price, availability, timing and eligibility claims
- Usability, accessibility, reversal, complaint and support evidence relevant to consumer impact
- A dated product and legal review record identifying evidence, uncertainties and release decisions
Legal map and implementation tools
Evidence base
Sources
- An Ontology of Dark Patterns KnowledgeGray et al.; ACM CHI 2024 · Secondary · checked 2026-09-14 · DOI 10.1145/3613904.3642436; arXiv:2309.09640
- Behavioural study on unfair commercial practices in the digital environmentEuropean Commission, Directorate-General for Justice and Consumers · Secondary · checked 2026-09-14 · DOI 10.2838/859030; ISBN 978-92-76-52316-1
- Competition and Consumer Amendment (Unfair Trading Practices) Act 2026Federal Register of Legislation · Primary · checked 2026-09-14 · C2026A00064
- Competition and Consumer Act 2010, including Schedule 2: Australian Consumer LawFederal Register of Legislation · Primary · checked 2026-09-14 · C2004A00109
- Unfair trading tricks and traps to be bannedTreasury Ministers · Primary · checked 2026-09-14
- Inquiry into the Competition and Consumer Amendment (Unfair Trading Practices) Bill 2026Senate Economics Legislation Committee · Primary · checked 2026-08-09