Free digital services are not legally free: data, dark patterns, and addictive design

Social media, online games, dating apps, and generative AI all have one thing in common: consumers can use many of these services without paying directly with money. However, that does not automatically mean the legal relationship between the provider and the user falls outside the scope of consumer law.
The Directive on Digital Content and Digital Services, implemented in the Netherlands in Title 7.1AA of the Dutch Civil Code, provides consumer protection when they acquire digital content or a digital service. This protection is not limited to paid subscriptions. Providing personal data can also result in a free digital service falling within the scope of these regulations.
For startups and scale-ups, this is an important starting point. A freemium or free model may be commercially attractive, but the choice not to charge money does not mean there are no contractual obligations toward users. This becomes especially relevant when personal data is used for personalization, advertising, or other purposes that go beyond what is strictly necessary to provide the service.
Why ‘free’ digital services are legally complex
The classic image of a consumer agreement is simple: the business provides a product or service, and the consumer pays a price. With digital services, that reality is much less straightforward.
A user can open a platform without signing up for a subscription. Meanwhile, the provider can collect data on things like the device used, location, service usage, or content viewed. Those who create an account may also provide profile information, messages, images, search queries, or other data.
This data can then be used to personalize the service or tailor advertisements to the individual user. This creates an economic relationship where, although the user does not transfer money, their data plays a significant role in the provider's business model.
This is precisely where the Directive on Digital Content and Digital Services comes into play. The regulation does not only apply to situations where a consumer pays a monetary amount. It can also apply when a consumer provides personal data or commits to providing personal data.
There is an important exception to this. When personal data is processed solely to provide the digital service or to comply with legal obligations, the situation may fall outside this part of the scope. The question of what is truly necessary for the performance of the service therefore becomes crucial.
When does a free digital service fall under consumer law?
Several legal questions arise simultaneously with free digital services. For tech companies, four points are particularly important: the existence of an agreement, the way personal data is provided, the relationship between the data and the service, and the necessity of the data processing.
Free use can also result in an agreement
The fact that a user does not click a ‘buy’ button does not automatically mean that no agreement is formed.
Many digital providers use terms of service stating that using the platform or service constitutes acceptance of those terms. For services where registration is mandatory, the contractual nature is usually relatively clear. The consumer creates an account and accepts the applicable terms in the process.
More interesting is the situation where someone can use a digital service without an account. Think of viewing certain content or using a limited version of an online service.
An agreement can be formed in these cases as well. After all, a provider makes a service available under certain conditions, and a consumer then makes use of it. Under certain circumstances, that use can be seen as acceptance of the offer.
For startups, it is therefore risky to assume that visitors without an account are legally merely ‘visitors’ to whom almost no contractual obligations apply. Even limited use of a digital service can become part of a contractual relationship.
Personal data does not always have to be entered consciously
A second question is whether a consumer must actively provide personal data before the rules for digital services become relevant.
For some data, this is evident. A user creates a profile, posts content, enters a search query, or provides information about themselves. In these cases, the user is performing a clear, deliberate action.
However, digital services also collect a great deal of data without the consumer consciously entering information every time. Think of technical information, location data, a user ID, and data regarding the use of the service.
A strict distinction between actively entered and automatically collected data does not align well with how modern digital products work. Therefore, when assessing a free digital business model, it is not enough to look only at the information contained in a registration form.
Data processing that occurs during the use of the product can also be relevant.
For product teams, legal teams, and founders, this means that the legal analysis should not stop at onboarding. The entire data flow surrounding the service may be significant.
Is personal data the consideration for the service?
The phrase "paying with personal data" is sensitive. Personal data is not a standard currency, and data protection law remains fully applicable. Nevertheless, within contract law, the provision of personal data can fulfill a function comparable to a consideration.
This is particularly relevant when a service is presented as free, while personal data plays a central role in how the provider generates revenue or personalizes the user experience.
It does not automatically make a difference if the terms of service and the privacy policy are legally or textually separated. The actual design and operation of the service remain relevant.
Moreover, many digital services require users to provide certain accurate or current information. On a platform where personalization is part of the service, data processing can be closely intertwined with what the user receives.
For startups and scale-ups, an important point of attention is visible here. The word "free" in itself says little about the applicable consumer law rules. The way the product is economically and technically structured is much more important.
A free consumer product that processes hardly any personal data may be judged differently from a legal perspective than a service where user behavior is extensively collected for personalization and commercial purposes.
The crucial question: which data is truly necessary?
Not every processing of personal data automatically brings a free digital service under the same consumer law regulations.
The exception for data that is strictly necessary to provide the service is therefore important. However, "necessary" should not be interpreted too broadly.
A provider might, for example, present personalization as an essential part of their product. That does not automatically mean that all personal data used for that purpose is strictly necessary to perform the contract.
Especially when data is used for personalized advertising, extensive profiling, or further personalization, it becomes more difficult to argue that the processing takes place solely because the service could not otherwise be provided.
For some services, the situation may be more nuanced. For a digital service that genuinely requires certain data to perform the requested functionality, processing may fall within the exception. The deciding factor is then that the processing does not go beyond what is strictly necessary to execute the contract.
In practice, this can even lead to differences between users of the same service. A consumer's legal position may depend on how the product is used and what data is processed in the process.
For tech companies, this is a good reason not only to conduct a general privacy analysis but also to link data processing to specific product functionalities. Which processing is necessary for the core function? Which processing serves personalization? Which data is used for advertising or optimization? That distinction can be relevant under consumer law.
Applicability also implies quality obligations
Why is the classification of a free digital service so important? Because the applicability of rules for digital content and digital services can grant consumers concrete contractual rights.
The requirement of conformity is central. Simply put, the digital service provided must meet what the consumer can reasonably expect from it.
This involves both subjective and objective criteria.
The subjective aspect concerns what has actually been agreed upon between the provider and the consumer. For digital services, this is not always easy to determine. Many terms and conditions describe in detail what a user may or may not do, but are significantly less concrete about the quality the provider itself must deliver.
Objective conformity requirements therefore provide an important supplementary framework. This can include looking at public statements and features that consumers may reasonably expect from similar services. Aspects such as accessibility, continuity, compatibility, and security can play a role here.
Necessary updates are also part of the level of protection.
For a startup, this means that terms and conditions are not just a tool to cover risks. When consumer law applies, mandatory law can set minimum requirements that cannot simply be set aside with a broad disclaimer.
A provision stating that a digital service is provided 'as is' does not, therefore, automatically solve that problem.
A digital service cannot be modified without limitation
Digital products are constantly changing. Features are added, functionalities disappear, algorithms change, and entire product components can be redesigned.
From a product development perspective, this makes sense. Legally, however, that freedom is not unlimited.
When the rules for digital services apply, changes to the service may also be subject to conditions. For example, a change may not simply result in additional costs for the consumer, and users must be informed about changes in a clear and understandable manner.
Even the complete discontinuation of a service is not necessarily something a provider can do at its own discretion without contractual limitations.
For startups and scale-ups, this directly touches on product governance. A general provision stating that the company may modify, remove, or terminate any functionality at any time does not necessarily offer the freedom the text suggests.
This is especially relevant for companies that iterate quickly. The faster a product changes, the more important it becomes to incorporate consumer law obligations into the release process.
Dark patterns can be more than just a UX problem
Dark patterns are design choices that can significantly disrupt or hinder users' ability to make autonomous and informed decisions.
Examples can occur in cookie banners, account settings, consent screens, payment flows, or other decision-making moments. The design then steers the user toward an outcome that is primarily beneficial to the provider.
For digital companies, this is often approached as a privacy or UX issue. But in consumer agreements, the impact can be broader.
When a service processes personal data, the requirements of the GDPR remain relevant. Consent must be given freely, and data must be processed not only lawfully but also fairly. An interface that manipulates users into sharing more data may be at odds with this.
These rules can subsequently also affect the question of whether the digital service is contractually compliant.
This is legally significant. A dark pattern can lead not only to a debate about the validity of consent or the lawfulness of data processing, but potentially also to the conclusion that the consumer is not receiving the digital service they are entitled to.
For startups, privacy compliance cannot be viewed in isolation from contract law and product design. The same design decision can affect multiple legal regimes simultaneously.
Addictive design can also become relevant to conformity.
In addition to dark patterns, addictive design is also receiving increasing attention.
This concerns design techniques aimed at keeping users engaged with a service for as long as possible or encouraging them to spend more time or money on the product. Think of infinite scroll, autoplay, ephemeral content, push notifications, or certain forms of gamification.
Personalization can further amplify the effect of such techniques.
For services used by minors, the legal sensitivity is even greater. Under the Digital Services Act, specific obligations apply to certain providers regarding the protection of minors. This may imply that certain forms of addictive design are difficult to reconcile with the required level of protection.
If legal obligations help determine what a consumer can reasonably expect from a digital service, such rules can also influence the conformity assessment.
This makes product design part of a contract law discussion.
In this context, an interface is not just the packaging of the service. The way features, recommendations, notifications, and choices are designed can help determine whether the service meets the level that consumers are entitled to expect.
What can a consumer do in the case of a non-conforming digital service?
When a digital service falls under the regulation and does not meet the applicable conformity requirements, the consumer has contractual remedies at their disposal.
In principle, the consumer can demand that the service be brought into conformity. Under certain circumstances, more extensive remedies, including termination of the contract, may also become relevant.
This makes the discussion about dark patterns and addictive design particularly interesting. When a design choice actually leads to non-conformity, it does not stop at the abstract determination that an interface is legally problematic. The consumer may then be able to claim adjusted, compliant service delivery.
In the case of dark patterns, this may mean that a service must be offered without the problematic design choices. For minor users, there may also be a debate about default settings and functionalities that encourage addictive use.
For providers, this makes the risk more concrete. Design choices then affect not only supervision and enforcement, but potentially also the individual contractual relationship with users.
What does this mean for startups and scale-ups?
For young tech companies, it is especially important to realize that consumer law can become relevant much sooner than is often thought.
A product does not necessarily need a paid subscription. A free consumer version can also create a contractual relationship. Personal data can be sufficient to make digital service regulations applicable, especially when data is processed for purposes that go beyond what is strictly necessary to provide the core functionality.
This means that various departments within a tech company directly impact one another.
The product architecture determines which data is collected. The business model determines what that data is used for. The terms and conditions determine what is agreed upon between the parties. The privacy policy explains how data is processed. UX design influences how users make choices. And all these components can ultimately be relevant to the question of what a consumer can legally expect from the service.
For founders and management teams, this means that a free model should not be viewed solely as a marketing or growth strategy.
A practical legal assessment should therefore at least examine whether an agreement with the user is formed, what personal data is collected during use, why that data is processed, which functionalities have actually been promised, and how changes to the service are implemented. Personalization, advertising models, dark patterns, and design choices that encourage prolonged use also deserve attention.
It is therefore not just about having good terms and conditions. The legal assessment cuts right through the product itself.
Freemium, personalization, and ‘pay or OK’
A unique model arises when consumers can choose between paying with money and a free version in which personal data is used more intensively, for example for personalized advertisements.
For providers, such a choice seems straightforward at first glance. The user chooses between a paid and a free product themselves.
Legally, however, this does not automatically make things simpler.
Even with the free version, it must be investigated which data is processed and for what purposes. When profiling and personalization play a significant role, the application of consumer law is more likely than when only data that is technically necessary for providing the service is processed.
This also means that different versions of the same product can have different legal implications.
For scale-ups experimenting with paid subscriptions alongside ad-driven or data-driven free versions, it is therefore wise not to compare only the price structure. The contractual and data-related position of users can also differ per product variant.
Terms and conditions are not the only benchmark
Many tech companies try to create flexibility with broad contractual provisions. The provider guarantees as little as possible, reserves the right to adjust functionalities, and retains the right to terminate the service.
However, such provisions do not provide complete control over the legal relationship.
Mandatory compliance requirements can set limits on what can be contractually excluded. Moreover, it is not just the literal text of the agreement that is considered. Objective expectations and relevant legal standards can also carry weight.
For a startup drafting its legal documentation, it is therefore important that the product, terms, and actual service delivery are aligned.
Anyone presenting a high-quality, secure, or continuously available service cannot simply assume that very broad disclaimers will neutralize every consumer expectation.
The same applies to privacy and design. A carefully drafted privacy policy does not prevent the actual interface from being problematic if users are steered toward certain choices via dark patterns.
The line between consumer law, privacy, and platform rules is blurring
One of the most significant developments in digital services is the increasing interconnectedness of various legal domains.
Contract law determines what a consumer can expect from a service. The GDPR sets requirements for the processing of personal data. The Digital Services Act contains additional obligations for certain digital services and platforms. Standards from these regulations can, in turn, be relevant when assessing contractual conformity.
For startups and scale-ups, a siloed compliance approach is therefore becoming increasingly illogical.
A privacy question can also become a contract law question. A product change can affect both UX and consumer law. A recommendation system can be relevant to data protection, platform regulation, and the quality of the service provided.
This requires a different way of working legally. Instead of checking only when terms and conditions are updated, legal requirements must be integrated into product development, onboarding, personalization, and feature changes.
Towards stricter rules for digital fairness
The rules for free digital services are not yet easy to apply in every respect. In particular, the distinction between data that is necessary for a service and data processed for additional purposes can lead to complex borderline cases.
The conformity requirement also does not always provide a concrete answer to the question of what quality can be expected from an online platform, game, dating app, or AI service.
Further development towards rules on digital fairness may therefore become important. It is likely that topics such as dark patterns, manipulative personalization, and addictive design will continue to receive significant attention.
For tech companies, it is especially important to realize that new rules will not stand alone. Existing obligations regarding digital services, personal data, and platform design are already intertwined.
Those who only react when new regulations are finalized are missing a significant part of the current legal framework.
Free is a business model, not a legal exemption
Offering a digital service for free can be a smart way to reach users quickly, create network effects, or build a freemium model. Legally, however, "free" is not an exemption.
When consumers provide personal data and that data is used for more than what is strictly necessary to deliver the digital service, consumer law for digital content and services may apply. This entails obligations regarding conformity, updates, changes, and contractual remedies.
Dark patterns and addictive design make this discussion even more relevant. Design choices can touch upon privacy, digital regulation, and ultimately the question of whether the consumer is receiving what they are legally entitled to.
For startups and scale-ups, the most important lesson is simple: when looking at a free digital product, do not just look at price and privacy. Look at the entire relationship with the user. That is exactly where contract, data, and product design converge.



















