Surveillance Pricing Explained: What Businesses Need to Know featured image

Surveillance Pricing Explained: What Businesses Need to Know

by John DiGiacomo

Partner

Revision Legal

Retailers and online platforms are increasingly using personal data—your location, browsing history, shopping behavior, and even demographics—to set prices that vary from customer to customer. This practice, known as surveillance pricing, has attracted growing scrutiny from federal and state regulators. If your business uses algorithmic pricing tools or third-party data to inform pricing decisions, you need to understand what these rules require and what liability exposure you may face.

What Is Surveillance Pricing?

Surveillance pricing—also called dynamic personalized pricing or algorithmic pricing—occurs when a seller uses consumer data to set individualized prices rather than offering a uniform price to all buyers. Unlike traditional dynamic pricing (where prices fluctuate based on supply and demand), surveillance pricing tailors the price specifically to the individual consumer based on what that person is predicted to be willing to pay.

Data inputs commonly used in surveillance pricing include:

  • Location data — zip code, neighborhood, or precise GPS coordinates
  • Browsing and search history — what products a user has recently viewed or searched
  • Shopping and purchase history — past orders, brand preferences, spending patterns
  • Device type — whether the consumer is shopping on a premium smartphone vs. an older Android device
  • Demographic inferences — age, income level, household composition inferred from data brokers
  • Behavioral signals — how long a user lingers on a product page, whether they have abandoned a cart

The result is a system in which two consumers viewing the same product at the same moment may see materially different prices—without either one being aware that personalized pricing is occurring.

Federal Regulatory Scrutiny

The Federal Trade Commission launched a formal investigation into surveillance pricing in early 2024, issuing orders requiring eight major pricing technology companies—including Mastercard, Revionics, Bloomreach, JPMorgan Chase, Accenture, McKinsey, and others—to disclose their data practices and pricing methodologies. The FTC’s concern is that surveillance pricing may constitute an unfair or deceptive trade practice under Section 5 of the FTC Act, 15 U.S.C. § 45, if consumers are not aware that their personal data is being used to set a price specifically tailored to extract the maximum amount they will pay.

The FTC’s investigation found that these firms market surveillance pricing services to retailers across grocery, apparel, consumer electronics, and travel sectors. In many cases, the consumer never knows the price they received was personalized—much less that it may be higher than what another consumer paid for the identical product.

State Law: New York and California Lead the Way

Several states are moving to codify disclosure requirements for algorithmic and data-driven pricing. Two developments are particularly important for businesses operating in New York and California.

New York GBL § 349-a

New York’s General Business Law § 349-a requires businesses that use algorithmic pricing based on personal data to disclose that practice to consumers at or before the point of sale. The statute is designed to ensure that New York consumers know when a price is the product of their personal data rather than a standard market rate. Businesses that fail to make this disclosure may face enforcement under New York’s broader consumer protection framework, including private rights of action and statutory damages.

California: CCPA Implications and AB 2564

In California, the California Consumer Privacy Act (CCPA), Cal. Civ. Code § 1798.100 et seq., already creates a framework relevant to surveillance pricing. If a business is using personal information to set prices, consumers have the right to know what categories of personal information are collected and how they are used. A pricing algorithm that draws on CCPA-covered personal information must be disclosed in the business’s privacy notice.

Beyond the CCPA, California AB 2564 (introduced February 2026) would go further by requiring explicit pre-transaction disclosure when personalized pricing is used. If enacted, businesses selling to California consumers would need to affirmatively notify customers—before they complete a purchase—that the displayed price reflects personal data collected about that individual. This would represent a significant new compliance obligation for e-commerce platforms and retailers using third-party pricing engines.

Antitrust Considerations

Surveillance pricing raises distinct concerns under federal antitrust law, particularly when multiple competing businesses use the same third-party pricing algorithm. If competing retailers each feed their cost and demand data into a shared algorithmic pricing platform, and that platform recommends prices across all of them simultaneously, regulators and courts may view this as a form of coordinated pricing that violates Section 1 of the Sherman Act, 15 U.S.C. § 1.

The Department of Justice has signaled interest in this theory. Businesses that rely on shared algorithmic pricing vendors should assess whether that arrangement creates horizontal pricing coordination risk, even if each competitor is technically making independent pricing decisions through the platform.

What Businesses Should Do Now

If your business uses any form of algorithmic or data-driven pricing, take the following steps to reduce regulatory and litigation risk:

  • Audit your pricing technology. Identify every tool, vendor, or platform that influences your pricing decisions. Determine what data inputs each one uses and whether any of those inputs constitute personal information under applicable state privacy laws.
  • Update your privacy notice. If personal information is used to set prices, your CCPA privacy notice must disclose that purpose. Review the “purposes for use” section and confirm pricing is included where applicable.
  • Assess point-of-sale disclosure obligations. In New York and potentially California, disclosure at or before purchase may already be required or soon will be. Consider adding a clear, consumer-facing disclosure when personalized pricing is in use.
  • Evaluate shared-platform antitrust risk. If you use an industry-wide pricing platform also used by competitors, have antitrust counsel analyze whether the arrangement creates Sherman Act exposure.
  • Document your compliance rationale. Regulators conducting investigations—like the FTC’s current inquiry—will request documentation. Maintain records of what data your pricing tools use, what disclosures you make, and how you decided on your compliance approach.

The Transparency Imperative

Surveillance pricing sits at the intersection of consumer protection law, privacy law, and antitrust law—three regulatory areas that are all moving simultaneously. The common thread across federal and state responses is transparency: regulators want consumers to know when data about them is being used to set a price. Businesses that get ahead of disclosure requirements now will be better positioned as enforcement activity increases.

If you are uncertain whether your pricing practices trigger disclosure obligations or create regulatory exposure, the attorneys at Revision Legal’s e-commerce and digital business practice can help you assess your risk and develop a compliance strategy tailored to your business model. Contact us today for a consultation.

Extra, Extra!
Related Posts

Online Sales and Refund Policies: What California E-Commerce Businesses Need to Disclose

Online Sales and Refund Policies: What California E-Commerce Businesses Need to Disclose

Revision Legal

If your e-commerce business sells to customers in California, you are subject to a detailed pre-sale disclosure regime that goes beyond typical terms-of-service requirements. California law mandates that sellers make specific disclosures about their business identity, address, and return and refund policies before accepting payment from any California buyer. Failure to comply can expose your […]

Read more about Online Sales and Refund Policies: What California E-Commerce Businesses Need to Disclose

Is Your Business Liable for What Your AI Chatbot Tells Customers?

Is Your Business Liable for What Your AI Chatbot Tells Customers?

Revision Legal

When an AI chatbot speaks to your customers, it is speaking on your business’s behalf. If it gets something wrong — inventing a return policy, promising capabilities a product does not have, quoting an incorrect price, or providing inaccurate information about a service — saying “the AI made a mistake” is unlikely to protect you. […]

Read more about Is Your Business Liable for What Your AI Chatbot Tells Customers?

What to Look for When Buying an Existing E-Commerce Business

What to Look for When Buying an Existing E-Commerce Business

Revision Legal

Buying an existing e-commerce business can look like a shortcut to an established brand, a proven customer base, and immediate revenue. But what you are actually buying is a bundle of legal assets and obligations — trademarks, copyrights, domain names, software licenses, customer data, supplier contracts, and platform accounts — and if any of those […]

Read more about What to Look for When Buying an Existing E-Commerce Business

Put Revision Legal on your side