SpiceJet Fined by CCPA for Misleading Booking Practices
India's consumer watchdog fined SpiceJet ₹1 lakh for using dark patterns, including pre-ticked consent boxes and misleading opt-ins.
SpiceJet Got Caught Twice With the Same Trick, and India's Booking Platforms Are Now on Notice
India's Central Consumer Protection Authority fined SpiceJet ₹1 lakh on July 17, 2026 for deploying three distinct dark patterns on its flight booking platform, automatically enrolling users in its SpiceClub loyalty programme through a pre-ticked checkbox, treating promotional consent as given by default, and using negatively worded language designed to confuse users into subscription. The airline was ordered to permanently discontinue all such practices.
The fine is small. The detail that makes it significant is what SpiceJet did after it received the CCPA's initial notice, it replaced the first pre-ticked checkbox with another one.
Three Dark Patterns, One Booking Flow
The CCPA identified the violations with clinical precision. The first was forced action, a pre-selected checkbox enrolling users in SpiceClub without any deliberate opt-in from the passenger. The second was interface interference, presenting SpiceJet's preferred commercial option as the default choice, nudging consumers toward decisions that benefit the airline rather than them. The third was a trick question, an unticked checkbox reading "I prefer not to receive future communication and newsletter from SpiceJet over text, WhatsApp or e-mail." That double negative construction is not accidental design. It is a deliberate attempt to make opting out feel like opting in.
SpiceJet's defence during proceedings was that the pre-ticked boxes resulted from a technical error. The CCPA rejected that explanation cleanly. An airline does not accidentally write a negatively worded consent clause or accidentally design an unticked opt-out box. These are product decisions that go through design reviews.
The Part That Made the CCPA Tougher
After receiving its initial notice from the regulator, SpiceJet removed the SpiceClub enrolment checkbox and replaced it with another pre-ticked box, this one for promotional messages via SMS, WhatsApp and email. The CCPA's order notes this explicitly. An airline that receives a regulatory notice for deceptive consent design and responds by implementing a different version of the same deceptive consent design has made a considered choice to continue the practice, not a technical correction.
That sequence is why the CCPA directed SpiceJet to submit a formal undertaking confirming corrective measures are implemented and will remain in place permanently, not just a promise to fix it, but a legally binding commitment.
The Wider Problem the Fine Exposed
The CCPA's action comes off the back of a broader industry survey that found 80% of respondents reported airlines disclosing convenience or platform fees only at the final payment stage, a practice known as drip pricing, with Air India, SpiceJet and Akasa cited most frequently. 35% of respondents reported encountering guilt-inducing language when declining add-ons, such as travel insurance opt-outs asking users to select "I will stay unsecured." False urgency through countdown timers and repeated upselling prompts were reported across the board.
The ₹1 lakh penalty on SpiceJet is not a deterrent by itself — it is the equivalent of a rounding error in an airline's weekly operating costs. What it signals is that the CCPA has the legal framework, the audit methodology and the political will to take on airline booking platforms directly. Future penalties for repeat offences or larger-scale violations could be significantly higher, and the CCPA has already issued advisory notices to all e-commerce platforms directing self-audits for dark pattern compliance.
For every airline running a booking platform in India, that audit notice is now the more important document.