https://www.eff.org/deeplinks/2021/04/deceptive-checkboxes-should-not-open-our-checkbooks Skip to main content * About + Contact + Press + People + Opportunities + EFF 30th Anniversary * Issues + Free Speech + Privacy + Creativity and Innovation + Transparency + International + Security * Our Work + Deeplinks Blog + Press Releases + Events + Legal Cases + Whitepapers * Take Action + Action Center + Electronic Frontier Alliance + Volunteer * Tools + Privacy Badger + HTTPS Everywhere + Surveillance Self-Defense + Certbot + Atlas of Surveillance + Cover Your Tracks + Crocodile Hunter * Donate + Donate to EFF + Shop + Other Ways to Give + Membership FAQ * Donate + Donate to EFF + Shop + Other Ways to Give * Search form Search [ ] --------------------------------------------------------------------- Email updates on news, actions, and events in your area. Join EFF Lists * Copyright (CC BY) * Trademark * Privacy Policy * Thanks Electronic Frontier Foundation Donate EFF TURNS 30! LEARN MORE ABOUT US, AND HOW YOU CAN HELP. EFF TURNS 30! LEARN MORE. Electronic Frontier Foundation * About + Contact + Press + People + Opportunities + EFF 30th Anniversary * Issues + Free Speech + Privacy + Creativity and Innovation + Transparency + International + Security * Our Work + Deeplinks Blog + Press Releases + Events + Legal Cases + Whitepapers * Take Action + Action Center + Electronic Frontier Alliance + Volunteer * Tools + Privacy Badger + HTTPS Everywhere + Surveillance Self-Defense + Certbot + Atlas of Surveillance + Cover Your Tracks + Crocodile Hunter * Donate + Donate to EFF + Shop + Other Ways to Give + Membership FAQ * Donate + Donate to EFF + Shop + Other Ways to Give * Search form Search [ ] Deceptive Checkboxes Should Not Open Our Checkbooks DEEPLINKS BLOG By Shirin Mori and Jason Kelley April 9, 2021 Consent Dark Patterns Deceptive Checkboxes Should Not Open Our Checkbooks Share It Share on Twitter Share on Facebook Copy link Consent Dark Patterns Last week, the New York Times highlighted the Trump 2020 campaign's use of deceptive web designs to deceive supporters into donating far more money than they had intended. The campaign's digital donation portal hid an unassuming but unfair method for siphoning funds: a pre-checked box to "make a monthly recurring donation." This caused weekly withdrawals from supporters' bank accounts, with some being depleted. "Make this a monthly recurring donation." The checkbox in question, from the New York Times April 3rd piece. A pre-checked box to donate more than you intended is just one example of a "dark pattern"--a term coined by user experience (UX) designer Harry Brignull to define tricks used in websites and apps that make you do things that you didn't mean to, such as buying a service. Unfortunately, dark patterns are widespread. Moreover, the pre-checked box is a particularly common way to subvert our right to consent to serious decisions, or to withhold our consent. This ruse dupes us into "agreeing" to be signed up for a mailing list, having our data shared with third party advertisers, or paying recurring donations. Some examples are below. The DEMOCRATS WANT TO STEAL THIS ELECTION! There will be FRAUD like you've never seen, plain and simple! We need YOUR HELP to ensure we have the resources to protect the results and keep fighting even after Election Day. Don't wait, step up NOW to DEFEND the integrity of our Election! Make this a weekly recurring donation until 12/14". A screenshot of the November 3rd, 2020 donation form from WinRed on donaldjtrump.com, which shows two pre-checked boxes: one for monthly donations, and one for an additional automatic donation of the same amount on an additional date. The National Republican Congressional Committee, which uses the same WinRed donation flow that the Trump campaign utilizes, displays two instances of the pre-checked boxes. "We're on track to have November be our BIGGEST MONTH YET! Help continue to WIN for Conservatives and join our November Cash Blitz Now! Donate an additional $0 automatically on 11/30." A screenshot of the National Republican Congressional Committee donation site (nrcc.org), from the WayBack Machine's crawl on November 3rd, 2020. The Democratic Congressional Campaign Committee's donation site, using ActBlue software, shows a pre-selected option for monthly donations. The placement is larger and the language is much clearer for what users should expect around monthly contributions. However, this may also require careful observation from users who intend to donate only once. The donation form from dccc.org showing suggested amounts, and a section labeled "Make it monthly!" The selected option is "Yes, count me in!" The inactive option is "No, donate once." A screenshot from August 31, 2020 of a pre-selected option for monthly contributions on the Democratic Congressional Campaign Committee (dccc.org). What's Wrong with a Dark Pattern Using Pre-Selected Recurring Options? Pre-selected options, such as pre-checked boxes, are common and not limited to the political realm. Organizations understandably seek financial stability by asking their donors for regular, recurring contributions. However, the approach of pre-selecting a recurring contribution can deprive donors of choice and undermine their trust. At best, this stratagem manipulates a user's emotions by suggesting they are supposed to give more than once. More maliciously, it preys on the likely chance that a user passively skimming doesn't notice a selected option. Whereas, requiring a user to click an option to consent to contribute on a recurring basis puts the user in an active position of decision-making. Defaults matter: whether making donations monthly is set as "yes, count me in" by default or "no, donate once" by default. So, does a pre-selected option indicate consent? A variety of laws across the globe have aimed to minimize the use of these pre-selected checkboxes, but at present, most U.S. users are protected by no such law. Unfortunately, some U.S. courts have even ruled that pre-selected boxes (or "opt-out" models) do represent express consent . By contrast, Canadian spam laws require a separate box, not pre-checked, for email opt-ins. Likewise, the European Union's GDPR has banned the use of pre-selected checkboxes for allowing cookies on web pages. But for now, much of the world's users are at the whims of deceptive product teams when it comes to the use of pre-selected checkboxes like these. Are there instances in which it's okay to use a pre-selected option as a design element? For options that don't carry much weight beyond what the user expects (that is, consistent with their expectations of the interaction), a pre-selected option may be appropriate. One example might be if a user clicks a link with language like "become a monthly donor," and ends up on a page with a pre-selected monthly contribution option. It also might be appropriate to use a pre-selected option to send a confirmation email of the donation. This is very different than, for example, adding unexpected items onto a user's cart before processing a donation that unexpectedly shows up on their credit card bill later. How Do We Better Protect Users and Financial Contributors? Dark patterns are ubiquitous in websites and apps, and aren't limited to financial contributions or email signups. We must build a new landscape for users. UX designers, web developers, and product teams must ensure genuine user consent when designing interfaces. A few practices for avoiding dark patterns include: * Present opt-in, rather than opt-out flows for significant decisions, such as whether to share data or to donate on a monthly level (e.g. no pre-selected options for recurring contributions). * Avoid manipulative language. Options should tell the user what the interaction will do, without editorializing (e.g. avoid "if you UNCHECK this box, we will have to tell __ you are a DEFECTOR"). * Provide explicit notice for how user data will be used. * Strive to meet web accessibility practices, such as aiming for plain, readable language (for example, avoiding the use of double-negatives). * Only use a pre-selected option for a choice that doesn't obligate users to do more than they are comfortable with. For example, EFF doesn't assume all of our donors want to become EFF members: users are given the option to uncheck the "Make me a member" box. Offering this choice allows us to add a donor to our ranks as a member, but doesn't obligate them to anything. We also need policy reform. As we've written, we support user-empowering laws to protect against deceptive practices by companies. For example, EFF supported regulations to protect users against dark patterns, issued under the California Consumer Privacy Act. Related Issues Privacy Share It Share on Twitter Share on Facebook Copy link Join EFF Lists Join Our Newsletter! Email updates on news, actions, events in your area, and more. Email Address [ ] Postal Code (optional) [ ] Anti-spam question: Enter the three-letter abbreviation for Electronic Frontier Foundation: [ ] Don't fill out this field (required) [ ] [Submit] Thanks, you're awesome! Please check your email for a confirmation link. Oops something is broken right now, please try again later. Related Updates Zuckerberg Facebook Deeplinks Blog by Cory Doctorow | April 5, 2021 553,000,000 Reasons Not to Let Facebook Make Decisions About Your Privacy Another day, another horrific Facebook privacy scandal. We know what comes next: Facebook will argue that losing a lot of our data means bad third-party actors are the real problem that we should trust Facebook to make more decisions about our data to protect against them. If history is any... The angular outline of three faces as a computer might see them, colored like a rainbow Deeplinks Blog by Adam Schwartz | March 26, 2021 Dystopia Prime: Amazon Subjects Its Drivers to Biometric Surveillance Some high-tech surveillance is so dangerous to privacy that companies must never deploy it against a person without their voluntary opt-in consent. It comes as little surprise that Amazon, the company that brought you Ring doorbell cameras and Rekognition face surveillance, has a tenuous understanding of both privacy and consent... California Privacy Deeplinks Blog by Alexis Hancock | March 17, 2021 Additional Regulations Approved for the California Consumer Privacy Act The California Attorney General recently published new regulations that implement the California Consumer Privacy Act (CCPA), a law that takes some important steps to empower consumer choice. What stands out the most in the new regulations is the explicit prohibitions around deceitful... [eff-pr-og] Press Release | March 16, 2021 EFF's Crowd-Sourced Atlas of Surveillance Project Honored with Award for Advancing Public's Right to Know About Police Spying SAN FRANCISCO--The Electronic Frontier Foundation (EFF) is pleased to announce it has received the James Madison Freedom of Information Award for Electronic Access for its groundbreaking, crowd-sourced Atlas of Surveillance, the largest-ever collection of searchable data on the use of surveillance technologies by law enforcement agencies across the... [eff-pr-og] Press Release | March 10, 2021 EFF to Supreme Court: Users Must Be Able to Hold Tech Companies Accountable in Lawsuits When Their Data is Mishandled Washington, D.C.--The Electronic Frontier Foundation (EFF) today urged the Supreme Court to rule that consumers can take big tech companies like Facebook and Google to court, including in class action lawsuits, to hold them accountable for privacy and other user data-related violations, regardless of whether they can show they suffered... Privacy issue banner, a colorful graphical representation of a padlock Deeplinks Blog by Rebecca Jeschke | March 10, 2021 Internet Advocates Call on ISPs to Commit to Basic User Privacy Protections This blog post was co-written by EFF, the Internet Society, and Mozilla.As people have learned more about how companies like Google and Facebook track them online they are increasingly taking steps to protect themselves, but there is one relatively unknown way that companies and bad actors can collect... Privacy issue banner, a colorful graphical representation of a padlock Deeplinks Blog by Karen Gullo | March 9, 2021 EFF to Supreme Court: States Face High Burden to Justify Forcing Groups to Turn Over Donor Names Throughout our nation's history--most potently since the era of civil rights activism--those participating in social movements challenging the status quo have enjoyed First Amendment protections to freely associate with others in advocating for causes they believe in. This right is directly tied to our ability to maintain privacy over what... A woman being watched behind a one-way mirror Deeplinks Blog by Bennett Cyphers | March 3, 2021 Google's FLoC Is a Terrible Idea Update, April 9, 2021 : We've launched Am I FLoCed, a new site that will tell you whether your Chrome browser has been turned into a guinea pig for Federated Learning of Cohorts or FLoC, Google's latest targeted advertising experiment. The third-party cookie is dying, and Google is trying... [sls-bodycam-2018_0] Deeplinks Blog by Matthew Guariglia, Adam Schwartz | March 2, 2021 The Justice in Policing Act Does Not Do Enough to Rein in Body-Worn Cameras Reformers often tout police use of body-worn cameras (BWCs) as a way to prevent law enforcement misconduct. But, far too often, this technology becomes one more tool in a toolbox already overflowing with surveillance technology that spies on civilians. Worse, because police often control when BWCs are turned on and... [icon-2019-privacy] Deeplinks Blog by Hayley Tsukayama | February 25, 2021 Virginia's Weak Privacy Bill Is Just What Big Tech Wants Virginia's legislature has passed a bill meant to protect consumer privacy--but the bill, called the Virginia Consumer Data Protection Act, really protects the interests of business far more than the interests of everyday consumers.Take ActionVirginia: Speak Up for Real PrivacyThe bill, which both Microsoft and Amazon supported, is... Join Our Newsletter! Email updates on news, actions, events in your area, and more. Email Address [ ] Postal Code (optional) [ ] Anti-spam question: Enter the three-letter abbreviation for Electronic Frontier Foundation: [ ] Don't fill out this field (required) [ ] [Submit] Thanks, you're awesome! Please check your email for a confirmation link. Oops something is broken right now, please try again later. Share It Share on Twitter Share on Facebook Copy link Related Issues Privacy Back to top EFF Home Follow EFF: * twitter * facebook * instagram * youtube * flicker * rss Contact * General * Legal * Security * Membership * Press About * Calendar * Volunteer * Victories * History * Internships * Jobs * Staff * Diversity & Inclusion Issues * Free Speech * Privacy * Creativity & Innovation * Transparency * International * Security Updates * Blog * Press Releases * Events * Legal Cases * Whitepapers * EFFector Newsletter Press * Press Contact Donate * Join or Renew Membership Online * One-Time Donation Online * Shop * Other Ways to Give * Copyright (CC BY) * Trademark * Privacy Policy * Thanks JavaScript license information *