Surveillance Pricing: When Personalized AI-Driven Pricing Creates Privacy and Antitrust Exposure

Retailers, landlords, delivery platforms, and e-commerce companies are deploying artificial intelligence tools that set prices not based on market conditions — but based on you. Your location data, browsing history, the device you use, what you left in your cart last Tuesday, how often you open the app, and whether you seem price-sensitive all feed into algorithms that assign individualized prices designed to extract the maximum amount each specific customer will pay. This practice has a name: surveillance pricing.

For most of the past decade, surveillance pricing lived in a regulatory gray zone. That zone is closing fast. In 2025 and 2026, federal agencies, state attorneys general, and state legislatures moved simultaneously on multiple legal theories — privacy law, antitrust law, and consumer protection law — to address what regulators increasingly describe as an unfair and deceptive practice. If your business uses any form of AI-driven personalized pricing, or if you sell or license pricing technology to other businesses, you now face overlapping legal exposure that did not exist two years ago.

This post walks through the current regulatory landscape: what surveillance pricing is, what the federal government found when it studied it, where state law stands today, and the compliance steps businesses should be taking right now.


What Is Surveillance Pricing?

Regulators and advocates use the term “surveillance pricing” to distinguish personalized pricing from two other common practices that have long been considered legally acceptable:

  • Dynamic pricing adjusts prices based on market-level signals — hotel room rates that rise during a conference, airline tickets that get more expensive closer to departure, surge pricing when demand spikes. The price changes because of market conditions, not because of anything specific about you.
  • Segmented pricing (or group pricing) charges different prices to defined groups — student discounts, senior discounts, bulk pricing. These categories are transparent and based on characteristics you voluntarily disclose.

Surveillance pricing is different. It uses individual consumer data — often collected without any clear disclosure — to set a price unique to that specific person at that specific moment. The goal is price discrimination at the individual level: charging each consumer the highest price they will likely accept, inferred from their data profile.

The Federal Trade Commission’s January 2025 Research Summary — the product of a Section 6(b) market study launched in July 2024 — documented how pervasive this practice has become. The study examined eight companies: Mastercard, Accenture, PROS, Bloomreach, Revionics, McKinsey & Co., and two others. The findings were striking. These intermediaries collectively access consumer data including:

  • Precise geolocation
  • Browsing history and search patterns
  • Purchase history and abandoned-cart data
  • Mouse movements on webpages
  • Device type and operating system
  • Demographic inferences
  • Income estimates and credit-risk proxies

The FTC found that consumer behaviors as granular as mouse movements on a webpage or which items a consumer leaves unpurchased in a cart can be tracked and fed into pricing algorithms. The study concluded that these tools are designed specifically to maximize revenue extraction at the individual level — not to reflect market conditions.


The Federal Regulatory Framework

FTC Section 5: Unfair Methods of Competition and Unfair or Deceptive Acts

The FTC’s primary statutory hook for surveillance pricing is Section 5 of the FTC Act, which prohibits both “unfair or deceptive acts or practices” (UDAP) and “unfair methods of competition” (UMC). These are distinct theories that can apply in different circumstances.

Under the deception prong, a practice is unlawful if it involves a material misrepresentation or omission that is likely to mislead reasonable consumers. When a consumer visits a website and sees a price without any disclosure that the price has been personalized to their data profile, there is a strong argument that the omission of that fact is material and deceptive. Most consumers do not know that the price they see differs from the price their neighbor sees.

Under the unfairness prong, a practice is unlawful if it causes or is likely to cause substantial harm to consumers that is not reasonably avoidable and not outweighed by countervailing benefits. The FTC has signaled that surveillance pricing may meet this standard — particularly when prices are inflated for consumers who have demonstrated, through behavioral data, that they are less price-sensitive, or when data is used to target consumers in financial distress with higher prices.

As of mid-2026, the FTC has not yet brought a major Section 5 enforcement action specifically targeting surveillance pricing. However, in December 2025 the agency issued a Civil Investigative Demand to a delivery service company seeking information about its use of an AI pricing tool. In congressional testimony in April 2026, FTC leadership confirmed that staff work on surveillance pricing continues and that additional disclosure requirements are under consideration.

Price Discrimination: The Robinson-Patman Act

The Robinson-Patman Act prohibits price discrimination between competing purchasers of commodities of like grade and quality when the discrimination tends to lessen competition. While this statute is primarily aimed at B2B pricing — a supplier charging different prices to competing retailers — the principle that individualized pricing can harm market competition runs through the FTC’s current approach to surveillance pricing.

Antitrust Theories Beyond Price Discrimination

Where multiple businesses use the same algorithmic pricing platform fed by competitively sensitive data from all platform users, regulators have argued that this creates an implicit coordination mechanism — a hub-and-spoke structure where the platform is the hub and its customers are the spokes. The DOJ has pursued this theory aggressively in the residential rental market (discussed in more detail in posts 68, 69, and 70 in this series), and the theory applies with equal force to retail and e-commerce contexts.


State Law: The Exploding Landscape

New York’s Algorithmic Pricing Disclosure Act

New York enacted the first state disclosure law specifically targeting algorithmic pricing. Effective November 10, 2025, the Algorithmic Pricing Disclosure Act requires any business that uses an algorithm based on a specific consumer’s personal data to set a price to display a mandated disclosure: “THIS PRICE WAS SET BY AN ALGORITHM USING YOUR PERSONAL DATA.”

The disclosure must appear “near and contemporaneous with” every advertisement, display, image, offer, or announcement of the personalized price. The statute defines personal data broadly as “any data that identifies or could reasonably be linked, directly or indirectly, with a specific consumer or device.”

Penalties are up to $1,000 per violation. The New York Attorney General has signaled active enforcement intent and has already issued a consumer alert encouraging consumers to report companies that fail to display adequate disclosures.

This law is addressed in detail in Post 68 of this series.

Maryland’s Outright Ban

Maryland went further. In April 2026, Maryland enacted the first state law to ban surveillance pricing in certain industries outright, prohibiting its use by food retailers and third-party delivery service providers. This represents a significant escalation beyond disclosure: the practice itself is unlawful in covered sectors.

Other State Legislation

As of mid-2026, more than 20 state legislatures have introduced legislation to regulate or ban surveillance pricing in at least some industries. A number of these bills include:

  • Private rights of action for consumers
  • Statutory damages provisions (allowing recovery without proof of actual harm)
  • Attorney fee-shifting provisions that create strong plaintiff-side incentive to sue

California’s Attorney General launched a surveillance pricing investigation in January 2026. New York’s Attorney General has launched a separate investigation into a specific consumer-facing company’s surveillance pricing disclosures. The House Committee on Oversight and Government Reform opened its own investigation in March 2026.

The trajectory is clear: what began as a single federal study in 2024 has become a multi-front enforcement and legislative campaign by mid-2026.


Consumer Privacy Statutes: The Hidden Exposure

Surveillance pricing creates substantial exposure under state consumer privacy laws that most businesses already know they need to comply with, but may not have connected to their pricing practices.

California Consumer Privacy Act (CCPA / CPRA)

The CCPA, as amended by the California Privacy Rights Act (CPRA), gives California consumers the right to know what personal information a business collects about them and how it is used. Critically, it also requires that businesses disclose in their privacy policy all purposes for which personal information is used.

If a business uses consumer data to set personalized prices and does not disclose that in its privacy policy — or if the privacy policy says personal data is used for “improving the customer experience” without specifying personalized pricing — the business may be violating the CCPA’s disclosure requirements. California also gives consumers the right to limit the use of “sensitive personal information,” a category that can overlap with some of the data inputs used in surveillance pricing systems.

The CPRA enforcement amendments effective in 2023 gave the California Privacy Protection Agency (CPPA) authority to bring enforcement actions, and the agency has been building its enforcement program. Privacy-related pricing practices are a recognized enforcement priority.

Other State Privacy Laws

Seventeen states now have comprehensive consumer privacy laws. While the specifics vary, virtually all of them require disclosure of purposes for personal data use, provide some form of consumer rights to access or limit use of their data, and prohibit using personal data in ways not disclosed to consumers. A surveillance pricing system that feeds on consumer data without adequate disclosure creates violation risk under each of these frameworks in states where they apply.


This is the question businesses and their counsel need to answer: is all use of consumer data in pricing unlawful? No. The regulatory frameworks emerging from federal and state action draw distinctions, though the lines are not yet fully settled. Here is the current map:

Likely lawful:
– Dynamic pricing based on aggregate market signals (inventory levels, broad demand data, time-of-day demand patterns) that applies equally to all consumers in a given market context
– Loyalty pricing or member pricing that consumers affirmatively opt into with clear notice
– Geographic pricing based on ZIP code or region as a proxy for market-level cost differences (though this is increasingly scrutinized as ZIP codes can correlate with race and income)
– Price personalization with clear, prominent, opt-in consent and full disclosure of what data is used

High-risk:
– Pricing based on inferred income, wealth, or financial distress
– Pricing based on behavioral signals consumers did not know were being tracked (mouse movements, browsing patterns)
– Pricing based on data aggregated from third-party data brokers without consumer notice
– Using real-time consumer data shared among competitors through a common platform
– Pricing that effectively functions as geographic or demographic price discrimination without disclosure


Practical Compliance Steps

If your business uses any form of personalized pricing — or if you are evaluating pricing technology vendors — here is a compliance framework based on current regulatory guidance.

1. Audit Your Pricing Systems

Map every data input into your pricing algorithms. Document what data you collect, where it comes from (first-party, third-party, inferred), how it flows into pricing logic, and what the pricing output looks like at the individual consumer level. You cannot disclose what you do not understand, and you cannot defend against regulatory scrutiny without documentation.

2. Review and Update Your Privacy Policy

Does your current privacy policy disclose that personal data is used to set individualized prices? Most do not. If you use personalized pricing, your privacy policy must disclose that practice clearly and specifically. Boilerplate language about “improving your experience” will not satisfy disclosure obligations under the CCPA, the New York Algorithmic Pricing Disclosure Act, or emerging state privacy laws.

3. Implement the New York Disclosure (Broadly)

If you do business in New York or with New York consumers and you use algorithm-driven personalized pricing, you are required to display the mandated disclosure as of November 10, 2025. Evaluate whether to deploy this disclosure nationally — a single disclosure standard is operationally simpler, reduces multi-state compliance complexity, and positions you favorably if the same requirement spreads to other states.

4. Evaluate Your Vendor Relationships

If you use a third-party pricing technology vendor, review your contracts and vendor documentation carefully. Understand whether your vendor’s algorithms incorporate data from other businesses using the same platform. If they do, you may face the same antitrust exposure that led to the DOJ’s enforcement actions in the residential rental market, regardless of your industry.

5. Assess Your Data Sources

Pricing algorithms fed by data from data brokers, location data aggregators, or advertising technology platforms carry the highest regulatory risk. These are the data types that the FTC study identified as most likely to create exposure. Audit whether your pricing system relies on any third-party behavioral or location data, and assess whether that data use is adequately disclosed.

6. Do Not Confuse Dynamic Pricing with Surveillance Pricing

The legal distinction between dynamic pricing (lawful) and surveillance pricing (high-risk) is real and significant. Make sure your internal and external communications accurately characterize your pricing practices. Calling a surveillance pricing system “dynamic pricing” in public materials while internal documents describe it differently creates exactly the kind of paper trail that regulators find in investigations.

7. Watch the States

With more than 20 state legislatures actively considering surveillance pricing legislation as of mid-2026, and Maryland already having enacted a ban for certain industries, the state law environment is moving fast. Businesses with national consumer-facing operations should monitor this landscape quarterly and be prepared to update practices as new laws take effect.


What This Means for Technology Companies and Platforms

If your business provides pricing software, pricing algorithms, or data analytics products to other businesses, you face a distinct layer of exposure that your business customers may not. The DOJ’s enforcement actions against RealPage and data intermediaries examined in the FTC study make clear that the technology provider is a target, not just a bystander.

Platform providers should:
– Avoid aggregating real-time competitively sensitive data from multiple competing clients
– Build disclosure functionality into pricing tools as a default feature, not an optional add-on
– Document clearly how their algorithms work and what data they use, in terms that their clients can incorporate into client-facing disclosures
– Review whether their terms of service and data sharing practices create antitrust exposure independent of their clients’ conduct


The Bottom Line

Surveillance pricing is no longer a theoretical regulatory concern. The FTC has conducted a formal study and continues active investigation. The DOJ has obtained consent decrees restructuring how algorithmic pricing tools operate. New York has enacted disclosure requirements already in effect. Maryland has banned the practice in food retail. More than 20 states have active legislation. State attorneys general in New York and California have launched investigations.

The simultaneous convergence of privacy law, antitrust law, and consumer protection law onto the same set of practices creates compounding exposure: a single pricing system can simultaneously violate a privacy statute, require an antitrust consent decree, and trigger state consumer protection enforcement. Businesses that build compliance programs now — before enforcement actions land — will be far better positioned than those that wait.


This post is for general informational purposes only and does not constitute legal advice. Reading this post does not create an attorney-client relationship. If you have questions about your specific situation, consult a qualified attorney.



Leave a Reply