Critically analyse the institutional architecture created under the Consumer Protection Act, 2019 to safeguard consumers in the digital economy.
In this answer
The Consumer Protection Act, 2019 replaced the 1986 law by creating a dedicated regulator — the Central Consumer Protection Authority (CCPA) — alongside a three-tier redressal commission structure, and empowered the Department of Consumer Affairs to frame the Consumer Protection (E-Commerce) Rules, 2020 [1][2]. Its architecture is forward-looking in design, but its effectiveness rests largely on soft enforcement.
Strengths of the architecture
- Dedicated regulator with suo motu powers: CCPA acts against unfair trade practices under Section 18, notifying the Guidelines for Prevention and Regulation of Dark Patterns, 2023 (30 November 2023) listing 13 dark patterns such as false urgency, drip pricing and subscription traps [2].
- Rule-based platform duties: the 2020 Rules fix liabilities of marketplace and inventory entities and mandate grievance redressal — complaints acknowledged within 48 hours and resolved within one month [4].
- Embedded accountability: proposed amendments require a Chief Compliance Officer, a 24x7 nodal contact person for law-enforcement coordination and a Resident Grievance Officer, mirroring the intermediary regime under the IT Rules, 2021 [3].
- Responsive regulation: the CCPA's advisory of 5 June 2025 mandated a self-audit within three months to detect dark patterns, with 26 leading platforms declaring compliance [5][6].
Limitations
- Reliance on advisories and self-audit shifts the compliance burden to platforms; self-declaration is not independent verification [5][6].
- Enforcement is largely penal-lite, working through notices and modest fines rather than deterrent sanctions [7].
- Regulatory overlap with CCI, the DPDP Act and Legal Metrology rules risks fragmented oversight, while several 2021 draft amendments remain unnotified [3].
- Capacity and awareness gaps leave first-time and rural online consumers dependent on slow adjudication.
The architecture thus marks a decisive shift from passive redressal to active regulation, yet its promise is only partly realised. Institutionalising third-party algorithmic audits, notifying the pending amendments and strengthening CCPA's technical capacity would convert advisory persuasion into enforceable accountability — giving real content to the consumer's right to informed choice in a digital marketplace.
Sources
- 1Consumer Protection Act, 2019 comes into force (PIB)2019 Act replacing 1986 law; creation of CCPA
- 2CCPA issues 'Guidelines for Prevention and Regulation of Dark Patterns, 2023' (PIB)Section 18 powers, 30 Nov 2023 notification, 13 dark patterns
- 3Proposed Amendments to the Consumer Protection (E-commerce) Rules, 2020 (PIB)Chief Compliance Officer, nodal person, Resident Grievance Officer; draft status
- 4Rules for E-Commerce Entities Under Consumer Protection Act (PIB)marketplace/inventory liabilities; 48-hour and one-month grievance timelines
- 5CCPA advisory to e-commerce platforms for self-audit within 3 months (PIB, 5 June 2025)mandatory self-audit for dark patterns
- 626 Leading E-Commerce Platforms Declare Compliance with Self-Audit (PIB)self-declaration by 26 platforms
- 7CCPA Acts Against Dark Patterns on Digital Platforms (PIB)enforcement through notices and fines