Businesses should stop using harmful web designs and practices that encourage users to hand over more of their personal data than they’d like to, the Information Commissioner’s Office (ICO) and Competition and Markets Authority (CMA) have urged.
In a joint paper published today, the two regulatory bodies have called for all businesses, developers, and designers to cease using web design practices that undermine people’s control of their personal information.
Harmful design practices include overly complicated privacy controls or, on the other hand, bundling privacy choices together in a manner that pushes users to share more data than they would wish to.
Highlighted as a particularly common example of harmful design is the lack of consumer controls over cookies, not least as cookie policy choices can impact users — and their wellbeing — in the medium- and longer-term.
“Some of these design practices are so subtle and have gone on for so long, you wouldn’t even realise you’re handing over your personal information until it’s too late – and it’s possible these techniques are embedded into thousands of websites across the UK,” commented Stephen Almond, the executive director of regulatory risk at the ICO.
“These website design tricks can have real and negative impacts on consumers’ lives. For example, if someone is recovering from a gambling problem, being steered to ‘accept all’ cookies can mean being continually bombarded with betting adverts, which could be incredibly harmful.
“We want to make consumers aware of these potentially harmful techniques to help them protect their data online – and, if necessary, make informed choices about which websites they choose to frequent.
“Businesses should take note that if they deliberately and persistently choose to design their websites in an unfair and dishonest way, the ICO will not hesitate to take necessary enforcement action.”
As Almond touched on, action will be taken by the ICO if improvements aren’t made on this front. In particular, it will be assessing cookie banners of the UK’s most frequently used websites.
Similarly, the CMA is set to continue to tackle issues caused by harmful design through consumer and competition enforcement powers.
In the joint paper, the regulators stipulated ways to support good online choice architecture, suggesting that companies should put the users at the heart of design choices, use design that empowers user choice and control, test and trial design choices, and comply with data protection, consumer, and competition law.
Recommended reading
- 18% of UK IT Leaders Unconfident About Their Firm’s GDPR Compliance
- Online Sites Given One Hour to Remove Harmful Content Under French Law
- Ofcom to Gain More Powers Over UK Social Media
Relatedly, in September of last year, the ICO published the results of its 2022 Public Awareness Survey.
The survey uncovered that while 90% of people are concerned about their personal data being used without their permission, many also don’t know about their legal rights around data storage and usage by companies.
For instance, 31% didn’t know it was a legal right to be informed of when an organisation is collecting and/or using your personal data, while 26% didn’t know that the right to ask a company to delete the personal information it holds about you is protected by law.
Further, 50% aren’t happy about their data being used to show them adverts that they may be interested in, 80% of people either don’t mind or are happy for their data to be used for “social good” purposes, including research done for the public good.
When it comes to the public’s confidence that companies are abiding by laws and regulations to protect people’s data, 7% said they were very confident, 39% were fairly confident, 22% were not particularly confident, 6% were not at all confident, and 26% were neither confident nor unconfident.





