Back to the hub

CCPA dark patterns: what 11 CCR 7004 actually prohibits

California Consumer Privacy Act regulations at 11 CCR 7004 ban dark patterns by requiring symmetry in choice: the path to a more privacy-protective option cannot be longer or harder than the path to a less protective one. A user interface that subverts choice does not obtain valid consent.

Applies to: Any CCPA-covered business that runs a cookie banner, a consent prompt, an opt-out flow, or a loyalty program signup, and anyone reviewing that interface before launch.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

"Dark pattern" is a design term that became a legal term. In California it is now a rule with worked examples, and the examples are unusually specific about interfaces most businesses already ship. If your cookie banner offers "Accept All" and "More Information", the regulation has already decided.

The rule is about symmetry, not aesthetics

11 CCR 7004(a) opens by requiring businesses to design methods for submitting CCPA requests and obtaining consent around five principles: easy to understand, symmetry in choice, no confusing language or elements, no choice architecture that impairs the consumer's ability to choose, and easy to execute.

Symmetry is the one that does the most work. The regulation states it plainly:

"The path for a consumer to exercise a more privacy-protective option shall not be longer or more difficult or time-consuming than the path to exercise a less privacy-protective option because that would impair or interfere with the consumer's ability to make a choice."

That is a measurable standard. You can count the steps on each path and compare them. Most failing banners fail on step count, not on wording.

The five examples the regulator wrote into the text

Subsection (a)(2) carries five illustrative examples, lettered (A) through (E). Taken together they describe a large share of real consent interfaces:

(A) An opt-out process that requires more steps than the opt-in process. The regulation measures the opt-out from the click on the "Do Not Sell or Share My Personal Information" link to completion of the request.

(B) An opt-in offering only "Yes" and "Ask me later". The regulation's reasoning is that "Ask me later" implies the consumer has delayed rather than declined, and that the business will keep asking. It states the symmetrical alternative: "Yes" and "No".

(C) A banner offering only "Accept All" and "More Information", or "Accept All" and "Preferences". Named twice, with the fix named too: "Accept All" and "Decline All".

(D) A choice where the "yes" button is more prominent, whether larger in size or in a more eye-catching color, than the "no" button.

(E) A financial incentive program where the option to participate is preselected by default, or featured more prominently than the option not to participate.

(D) and (E) are worth pausing on, because they are about visual weight rather than structure. Two buttons in the same place with the same number of clicks can still be asymmetrical if one is styled to be found first.

Confusing language is a separate ground

Subsection (a)(3) is not about symmetry at all. It prohibits double negatives, misleading statements or omissions, affirmative misstatements, and deceptive language, and requires toggles or buttons to clearly indicate the consumer's choice. Then it states the rule that resolves a lot of arguments: "A consumer's silence or failure to act affirmatively does not constitute consent."

The examples under (a)(3) include the double-negative "Yes / No" choice next to "Do Not Sell or Share My Personal Information"; bare "on" or "off" toggles with no clarifying language; unintuitive button placement, given as a business that consistently offers "Yes" then "No" and then reverses the order at the point where reversal would contravene the consumer's expectation; pop-ups dismissed without an affirmative "I accept"; and false urgency, given as a countdown clock claiming that time is running out to consent and receive a limited discount where the discount is not actually limited.

Choice architecture and bundling

Subsection (a)(4) reaches the structure of the decision rather than its presentation. It requires that businesses not design methods in a way that impairs the consumer's ability to exercise choice, "because consent must be freely given, specific, informed, and unambiguous".

The bundling example is the most useful one for product teams. A business providing a location-based service, the regulation says a mobile application that finds gas prices near the consumer, cannot require the consumer to consent to incompatible uses such as selling geolocation to data brokers together with the reasonably necessary use of geolocation to deliver the service, which requires no consent at all. The business must provide a separate option for the incompatible use.

The terms-of-use example at (a)(4)(C) closes a common workaround: acceptance of general or broad terms of use containing processing descriptions alongside other unrelated information prevents consent from being freely given, specific and informed.

Friction counts as a violation

Subsection (a)(5) requires methods to be easy to execute and prohibits unnecessary burden or friction. Two specifics matter operationally. After a consumer clicks the "Do Not Sell or Share My Personal Information" link, the business cannot require them to search or scroll through a privacy policy to find the request mechanism. And a business that knows of, but does not remedy, circular or broken links is treated as adding friction.

That second point turns an unmaintained opt-out flow into a compliance problem rather than a bug. The standard is knowledge plus inaction.

Why this rule bites harder than it looks

The consequence of a dark pattern is not only a standalone violation. Where the interface was how you obtained consent, a failure under Section 7004 means you did not obtain consent, and every downstream processing activity that depended on it loses its footing. That is why the regulation ties the section to the definition of consent rather than leaving it as an interface-quality rule.

The practical review is short. Open your own banner. Count the steps to decline. Compare the two buttons side by side. Try to close the pop-up without choosing. Most of Section 7004 can be tested in five minutes on a phone.

Next step

Compliance checklist

  • Count the clicks on both paths. Under 11 CCR 7004(a)(2)(A), the steps from the 'Do Not Sell or Share My Personal Information' link to a completed opt-out must be the same or fewer than the steps to opt in.
  • Remove double negatives and unlabeled toggles. 11 CCR 7004(a)(3)(A) treats 'Yes / No' next to 'Do Not Sell or Share My Personal Information' as a confusing double negative, and (a)(3)(B) treats bare 'on' or 'off' toggles as confusing without clarifying language.
  • Unbundle consent. 11 CCR 7004(a)(4)(B) prohibits bundling a use that needs no consent together with an incompatible use, and requires a separate option for the incompatible one.
  • Stop treating broad terms of use as consent. 11 CCR 7004(a)(4)(C) says acceptance of general terms containing processing descriptions alongside unrelated information prevents consent from being freely given, specific and informed.
  • Test the flow end to end. 11 CCR 7004(a)(5) requires methods to be tested so they are functional, and treats known but unfixed circular or broken links as added friction.

Sources

Last verified: 2026-09-16

Informational, not legal advice.