A French regulator with a track record
On September 1, 2025, France's data protection authority, the CNIL, fined Shein's Irish subsidiary €150 million for placing advertising cookies before users could consent, running consent banners that omitted the cookie's purpose, and building "Refuse all" buttons that didn't actually stop tracking (CNIL). That fine sat alongside a €325 million penalty against Google in the same enforcement cycle. Together they made up 97.5% of the €486.8 million the CNIL levied across 83 sanctions in 2025 — nearly nine times its 2024 total (CNIL). These are textbook dark patterns: interface tricks that push users toward choices they wouldn't otherwise make, dressed up as a genuine "choice."
Against that backdrop, the European Commission is preparing something bigger. Commissioner Michael McGrath, tasked by President von der Leyen with the file, is developing a Digital Fairness Act (DFA), expected as a formal proposal in the fourth quarter of 2026 (European Parliament Legislative Train). It would directly ban dark patterns, manipulative interface design, exploitative personalization and addictive product design at the EU level, rather than leaving each of them to be inferred from consumer-protection or data-protection law case by case (European Commission consultation). McGrath has described the aim as closing "clear gaps" — his concern is that consumers "don't have confidence to bring a case" under today's patchwork.
The case for centralizing
That concern is not manufactured. A 2022 Commission-commissioned study found that 97% of the most popular websites and apps used by EU consumers deployed at least one dark pattern, with hidden information, forced registration and deliberately hard-to-cancel subscriptions among the most common (European Commission behavioural study). A platform operating across 27 member states can currently be investigated by 27 different national authorities using slightly different theories, timelines and remedies — a genuine source of both delay and arbitrage. The Digital Services Act already shows what a Commission with direct fining teeth can do: on December 18, 2025, Brussels fined X €120 million — its first DSA non-compliance decision — over a deceptive paid verification badge and opaque ad-transparency practices, precisely the kind of interface manipulation the DFA is meant to cover more broadly (Pinsent Masons). If that model works for the largest platforms, extending something similar to dark patterns generally has an obvious logic: one enforcer, one standard, no forum-shopping.
Why the CNIL model shouldn't be discarded
But the steelman only goes so far, and the evidence sits mostly on the other side of the ledger. The CNIL's 2025 numbers are not the record of a toothless regulator waiting to be rescued — they are the record of a national authority moving faster and hitting harder, in a single year, than the Commission's entire DSA enforcement docket has managed since 2023. The DSA's first non-compliance fine against a VLOP took more than two years to land after the law entered into force. National regulators like the CNIL and the DGCCRF, by contrast, can inspect a site, issue formal notice and sanction within a single enforcement cycle, because they aren't managing 27 governments' worth of political sign-off.
Centralizing fining power at Commission level doesn't obviously fix McGrath's stated problem — inconsistent enforcement — so much as relocate it. Companies already navigate parallel DSA and DMA investigations touching the same conduct; layering a Commission-run DFA enforcement track on top of active CNIL cookie cases and DGCCRF consumer-law actions risks the opposite of legal clarity: two regulators, two legal bases (data protection versus unfair commercial practices), potentially two fines for the same interface. The Commission's own tracking materials concede enforcement design isn't settled — it may lean on the existing Consumer Protection Cooperation network of national authorities with only "an enhanced role" for Brussels in cross-border cases, not full displacement of regulators like the CNIL.
The honest framing of the Digital Fairness Act, at this stage, is a proposal — not yet a text, expected late 2026 — that would be strengthened by explicitly building on national enforcement rather than routing around it. A single dark pattern banned at EU level is good law. A single dark pattern investigation now potentially open to CNIL, DGCCRF and the Commission simultaneously is not proportionate regulation; it's duplication dressed up as protection. If Brussels wants the DSA's direct-fining model, it should say so plainly and write clear supremacy rules — not leave France's demonstrably effective regulator to find out by litigation which agency actually has the last word.
The risk isn't that Brussels bans dark patterns. It's that it builds a second enforcement track on top of a French regulator that already works.