In cybersecurity, we have a subject called "security theater" which means implementing a feature that only looks like a real security mechanism but doesn't do anything literally.
Is it against the law for, let say, a company to implement a layer of security which is indeed nothing but a theater (in both deliberately and indeliberately cases)?
It gives false confidence for the users of the system thinking their data are protected by the machine while it's not.
 
    