Two laws, ten days apart
Maryland's House Bill 895, the Protection From Predatory Pricing Act, was signed into law on April 28, 2026 and took effect October 1. Seattle's City Council passed its own Fair and Transparent Pricing policy on September 22 by a 7 to 2 vote, with councilmembers Kettle and Rivera opposed, and it now awaits Mayor Katie Wilson's signature. Together, a state law and a city ordinance targeting the same practice went live within ten days of each other, which is a fast pace for privacy and pricing regulation to move from statehouse to enforcement.
Both laws target the same underlying practice: setting a different grocery price for different shoppers based on personal data the retailer or a delivery platform holds about them, rather than based on objective factors like location, shipping cost, or supply and demand. Maryland calls it dynamic pricing in its statutory text. Seattle and its supporting advocacy groups call it surveillance pricing, a framing meant to emphasize the data collection behind the practice rather than the pricing outcome itself. The naming difference reflects two different political framings of the same underlying technical capability, aimed at two different audiences.
What exactly gets banned
Maryland's law defines the prohibited practice broadly: offering a personalized price specific to a consumer based on that consumer's personal data, regardless of whether the retailer collected the data itself or purchased it from a third party data broker. That data purchase clause closes an obvious workaround where a retailer might claim it never directly tracked a shopper but instead bought a broker's profile to set that shopper's price without ever running its own tracking code.
Seattle's ordinance is more specific about the categories of data in scope, naming race, gender, location, employment status, web browsing history, social media activity, and even chatbot conversation history as inputs that cannot be used to set an individualized price. All grocery prices must be clearly posted and equally available to every shopper under the policy, with no hidden segment seeing a different number. Both laws carve out explicit exceptions for loyalty programs, subscription contracts, and standard promotional or retention discounts, keeping the target narrowly focused on personalized base pricing rather than discounting as a whole.
The enforcement mechanics
Maryland's penalties run up to 10,000 dollars for an initial violation and 25,000 dollars for repeat violations, enforced exclusively by the state attorney general, with no private right of action and a 45 day cure period before penalties attach. That structure gives retailers a defined remediation window rather than exposing them to immediate litigation risk from individual consumers, which is a meaningfully different enforcement posture than many recent state privacy laws.
Seattle's enforcement details will depend on the final signed ordinance, but the political coalition behind it, including UFCW 3000, MLK Labor, Consumer Reports, and TechEquity Action, suggests sustained monitoring and public pressure even where formal enforcement mechanisms are still being worked out. Mayor Katie Wilson's own framing, that people do not want their data fed into algorithms to set their grocery prices, signals the city intends to treat this as a consumer protection priority rather than a symbolic gesture.
Why this hits grocery technology stacks directly
Grocery retailers and delivery platforms have invested heavily over the past several years in personalization engines that use browsing behavior, loyalty data, and sometimes third party data to tailor offers and, in some cases, prices themselves. These two laws leave personalization of promotions and offers intact while drawing a hard line specifically around base price, which is the highest risk application of that personalization infrastructure from a consumer protection standpoint and the one regulators chose to target first.
Any retailer or delivery platform operating in Maryland or Seattle needs to audit whether its current pricing engine can distinguish between personalized promotions, which remain legal, and personalized base pricing, which does not. That is a nontrivial technical distinction to enforce reliably inside a system that was likely built to optimize price and promotion together as a single decision, rather than as two clearly separated systems with different compliance rules attached to each.
What CTOs should do now
Treat this as the opening wave rather than an isolated pair of laws. Council member Alexis Mercedes Rinck's comments in Seattle, framing the issue as national grocery corporations profiting from leveraging private information to manipulate prices, read like language built for replication in other city councils, and Maryland's bill text is the kind of model legislation that tends to get copied by neighboring states facing the same political pressure. Build your compliance posture assuming more jurisdictions adopt similar bans within the next year, rather than waiting to react once each new law individually takes effect in a market you operate in.
Practically, that means auditing your pricing architecture now for a clean separation between promotional personalization, which both laws protect, and base price personalization, which both laws prohibit outright. Retailers who can demonstrate that separation clearly to regulators, with logs and documentation to back it up, will have a much easier compliance path than those whose pricing and personalization logic are tangled together in a single system that was never designed with this distinction in mind. That audit is worth running even in states without a law yet, since the pattern of enactment suggests the question is a matter of when, not whether, your own jurisdiction follows.


