Legal Alerts Banner 2600x660 1

‘Surveillance Pricing’: A Practical Guide for Businesses Navigating Its Regulatory Risk

  • California’s Automated Decisionmaking Technology regulations, effective January 2027 for significant decisions, will require pre-use notice, opt-out rights and explanations of how automated pricing decisions affect consumers.
  • The FTC is proposing enforcement action against businesses that fail to disclose when personalized pricing is used and what data powers it.
  • New York and Maryland have enacted or proposed laws requiring specific disclosures when algorithms use personal data to set prices.
  • Companies using personal data to estimate individual willingness to pay without disclosure face the highest enforcement risk under FTC Section 5.

“Surveillance pricing” describes the use of formulas, software or AI to set prices dynamically when those systems incorporate personal information (e.g., browsing history, purchase patterns, demographic profiles, device identifiers or inferred willingness to pay) to tailor prices to individual consumers. This practice is distinct from broader “algorithmic pricing,” which relies on market-wide inputs such as supply-and-demand conditions, inventory levels and timing without targeting individuals based on their personal data.

Surveillance pricing raises significant privacy and consumer protection risks, as it may involve harvesting and extracting maximum value from individual consumers’ personal data, often without their knowledge or meaningful consent.

Businesses aiming to stay on the right side of privacy law should have a clear understanding of the legal landscape.

Why Surveillance Pricing Has Attracted Heightened Scrutiny

The FTC put surveillance pricing squarely in its crosshairs in July 2024, when it issued orders to companies seeking information on how intermediary firms use personal data to set individualized consumer prices. The resulting January 2025 report, “FTC Surveillance Pricing 6(b) Study: Research Summaries A Staff Perspective,” documented the breadth of data inputs powering these systems. They come from direct behavioral data, inferred consumer characteristics, first-party loyalty and rewards data, third-party data broker inputs, IP addresses, device types, browser settings, clicks, scrolling behavior, video viewing, cart activity, and even mouse movements. They also range industries, from grocery and apparel to financial services, car rentals and online casinos.

The following year, on Aug. 19, 2026, the FTC issued a Proposed Enforcement Policy Statement Regarding Personalized Pricing, its most targeted guidance to date. The proposed policy draws a clear line regarding price variation: Although consumers may expect prices to vary based on market conditions, local supply and demand, taxes, or risk-based factors such as insurance underwriting, they generally do not expect a retail price to reflect an algorithm’s estimate of their individual willingness to pay. Given that reasonably held consumer expectation, the FTC signaled it will treat the failure to clearly and conspicuously disclose personalized pricing (including the basis for personalization and the types of data used) as a potentially deceptive practice under Section 5 of the FTC Act.

The proposed policy’s illustrative examples indicating the breadth of conduct that could run afoul of its requirements: a food delivery company charging more based on data suggesting the consumer is less able to leave home; a grocery chain charging more for milk based on children living in the home; a hotel charging more based on inferred funeral travel; or a rideshare company charging more because data shows the user lacks competitor apps.

Surveillance Pricing and State Data Protection Law

Surveillance pricing triggers a separate and overlapping set of obligations under data privacy law. Under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act, personal information encompasses “information that identifies, relates to, or could reasonably be linked to a particular consumer or household,” including geolocation data, browsing history and inferences about preferences.[1] This broad definition captures precisely the data inputs that surveillance pricing systems rely upon — behavioral signals, location patterns and algorithmically derived conclusions about a consumer’s willingness to pay. Sensitive personal information, such as precise geolocation and financial account data, receives heightened protection, and consumers have the right to limit its use to purposes strictly necessary for providing requested goods or services. The CCPA’s “sale” and “sharing” provisions further complicate surveillance pricing models: If a business discloses consumer data to third-party pricing analytics vendors, consumers may exercise their right to opt out of such transfers, potentially undermining the data flows these systems require. Critically, the CCPA’s purpose limitation and data minimization requirements mandate that “collection, use, and retention of … personal information” be “reasonably necessary and proportionate”[2] to the disclosed purposes — a standard that surveillance pricing systems, which by definition consume personal data for pricing advantage, may struggle to meet absent clear and specific disclosures to consumers about how their data informs the prices they see.

The CPPA’s final Automated Decisionmaking Technology (ADMT) regulations, adopted July 24, 2025, and effective Jan. 1, 2026, define ADMT as technology that “processes personal information and uses computation to replace human decision-making or substantially replace human decision-making,” including profiling.[3] Algorithmic surveillance pricing tools fit squarely within this definition. When ADMT is used for a “significant decision” (defined to include decisions affecting financial services, housing, employment, education or healthcare), businesses must, by Jan. 1, 2027, provide consumers with pre-use notice, the ability to opt out when applicable and “meaningful information about how the ADMT functioned and how it affected” the consumer, as well as conduct privacy risk assessments.[4] Enforcement risk is real: The California Attorney General and the CPPA have signaled aggressive enforcement priorities around profiling and automated systems. The CPPA also retains regulatory definitions of “financial incentive” and “price or service difference” that encompass any difference in price related to the collection, retention, sale or sharing of personal information, concepts that surveillance pricing implicates directly. Businesses using these practices should anticipate that regulators will scrutinize whether dynamic pricing differentials constitute impermissible discrimination against consumers who exercise their privacy rights, a prohibition the CCPA explicitly enshrines.

State Legislatures and Enforcers Are Moving Fast

Beyond the CPPA, states are building a patchwork of disclosure mandates and prohibitions related to pricing practices.

  • New York enacted the Algorithmic Pricing Disclosure Act, requiring sellers to disclose when surveillance pricing is used with the statement: “THIS PRICE WAS SET BY AN ALGORITHM USING YOUR PERSONAL DATA.”[5]
  • Maryland’s HB 1475 would impose a nearly identical disclosure requirement for “personalized algorithmic pricing,” defined as dynamic pricing set by an algorithm that uses personal data (excluding location data), with violations constituting unfair, abusive, or deceptive trade practices under the Maryland Consumer Protection Act. The bill has a proposed effective date of Oct. 1, 2026.
  • Colorado enacted SB26-189, effective May 14, 2026, establishing consumer notice requirements and rights to meaningful human review when automated decision-making technology is used for consequential decisions.

At the same time, state attorneys general are exercising their enforcement authority over adjacent data practices. These developments collectively reinforce that businesses using personal data to set or adjust prices face scrutiny from multiple enforcement vectors, including the FTC, the California Privacy Protection Agency (CPPA), and a growing coalition of state attorneys general and legislatures.

Practical Considerations

Surveillance pricing compliance centers on data discipline, transparency and proactive governance. The following summarizes the essential legal and practical considerations:

  • When personal data informs pricing, clear and conspicuous disclosure is mandatory. New York and Maryland require specific statutory notices, and the FTC’s proposed policy requires disclosure of how personalization works, what drives pricing decisions and what types of data are used.
  • Downstream liability exposure depends on upstream data provenance. Third-party pricing vendors may introduce undisclosed data sources or opaque algorithmic logic that creates compliance risk.
  • Compliance requires visibility into all personal information flows in pricing systems, including whether any data qualifies as sensitive under the CCPA and whether collection is “reasonably necessary and proportionate” to disclosed pricing purposes.
  • California’s ADMT regulations (effective Jan. 1, 2027, for significant-decision requirements) will require pre-use notices, opt-out mechanisms, infrastructure to explain automated pricing decisions and privacy risk assessments.
  • Using personal data to estimate individual willingness to pay without disclosure is the practice most likely to trigger FTC Section 5 enforcement.
  • Repurposing behavioral or demographic data collected for other purposes (e.g., improving user experience) to power personalized pricing without disclosure violates secondary use restrictions and CCPA purpose limitation requirements.
  • Industry carve-outs (insurance, GLBA-covered financial institutions and subscription-based loyalty programs) are narrow and jurisdiction-specific and may not apply as broadly as expected.

The regulatory trajectory is clear: surveillance pricing requires privacy and information governance around personal data inputs, transparency and robust consumer rights protections.

The FTC’s 2026 proposed policy on personalized pricing, California’s ADMT regulations and the proliferation of state disclosure mandates signal that the window for self-correction is narrowing. For businesses using pricing technology that incorporates personal data, the compliance analysis must begin with a foundational question: What data does your algorithm actually use?

McGuireWoods’ AI Practice Group is available to assist clients with questions regarding surveillance pricing compliance, including how to build appropriate governance mechanisms to navigate the evolving regulatory landscape.


[1] Cal. Civ. Code § 1798.140(v).

[2] Id. § 1798.100(c).

[3] Cal. Code Regs. tit. 11, § 7001(e).

[4] Id. § 7220.

[5] N.Y. GEN. BUS. LAW § 349-a.

Subscribe