A federal comment period with teeth pointed at retail
The Federal Trade Commission released a proposed enforcement policy statement on August 19, 2026, opening a public comment period on personalized pricing, the practice of adjusting prices for individual shoppers based on data about them rather than showing every customer the same listed price. The agency framed the issue in unusually direct consumer language. FTC Chairman Andrew Ferguson said: "When consumers see a listed price, they expect it to be the same price that everyone else sees, not the retailer's estimate of how much they are willing to pay based on their personal data."
The FTC does not have the authority to prohibit personalized pricing outright, and the comment period is not itself an enforcement action. What it signals is where enforcement is likely to land: businesses that fail to disclose how consumer data influences the price a shopper is shown may be found to violate Section 5 of the FTC Act, the agency's core unfair and deceptive practices authority. Disclosure, not the pricing model itself, is the exposure point.
What personalized pricing looks like in practice
Personalized pricing already runs in production systems today, well beyond the theoretical debate a policy comment period might suggest. It adjusts prices based on browsing history, device type, location, purchase history, or estimated price sensitivity, and it extends well beyond traditional retail into any marketplace where dynamic pricing algorithms run against individual-level data rather than aggregate demand signals. Ride-hailing, food delivery, travel booking, and grocery e-commerce all run some version of this today, frequently justified internally as personalization or yield optimization rather than as pricing discrimination.
The practice is distinct from ordinary dynamic pricing tied to supply and demand, inventory levels, or time of day, which consumers broadly understand and accept as a function of market conditions. The FTC's concern is specifically with pricing that varies between two shoppers looking at the identical item at the identical moment, based on what the algorithm has inferred about each of them individually rather than about market conditions everyone faces equally. That distinction, between pricing tied to the market and pricing tied to the individual, is the line compliance teams now need to draw clearly inside their own systems.
The receipts the FTC is working from
The FTC's action arrives alongside concrete documented examples rather than theoretical concern. A Consumer Reports investigation found that Instacart grocery prices for identical items varied by up to 23 percent between different customers, a spread large enough to represent a materially different total basket price for two shoppers buying the same groceries at the same time. Uber and Lyft showed an even wider gap, with roughly 42 percent median price differences between the lowest-priced and highest-priced customer groupings for comparable rides.
These are the kinds of figures that turn an abstract policy debate into a concrete compliance question for any technology organization running pricing algorithms against individual customer data, whether in grocery delivery, ride-hailing, or any retail vertical using similar personalization techniques on price rather than just on product recommendations. A 23 percent spread on a routine grocery basket, or a 42 percent spread on a routine ride, is large enough that regulators do not need a theoretical harm to make their case. The documented gap speaks for itself once it is placed in front of a comment docket.
A state-level patchwork already forming
Federal action is arriving after, not before, state legislatures started moving. Maryland has already implemented restrictions on surveillance pricing, and Connecticut has banned the practice outright. According to law firm Holland & Knight, more than 40 surveillance pricing bills have been introduced across more than two dozen states, meaning any retailer or CPG brand operating a personalized pricing system nationally is already navigating, or will soon be navigating, a patchwork of state rules well before any final federal rule exists.
That sequencing, states moving first and federal regulators following with a comment period rather than a final rule, is a familiar pattern in US tech regulation, and it means compliance teams cannot simply wait for federal clarity before acting. The state rules that already exist are enforceable now, and the direction of travel across additional statehouses is unambiguous: more than two dozen states already have a bill in motion, and each one that passes adds another jurisdiction-specific disclosure or restriction a national retailer's pricing engine has to account for.
Why disclosure is the practical exposure, not the algorithm itself
The core lesson from the FTC's framing is that the pricing algorithm is not automatically the legal problem. Opacity about its existence and its inputs is. A retailer that personalizes pricing and clearly discloses that pricing is personalized, and on what basis, sits in a meaningfully different legal and reputational position than one running the identical algorithm silently. Jon Picoult, founder of Watermark Consulting, put the business risk in blunt terms: "If your pricing strategy leaves customers feeling exploited, it's not going to end well for you."
That reputational risk carries its own weight independent of the legal exposure. A 2024 Consumer Reports study found two-thirds of US consumers oppose personalized pricing outright, meaning the practice carries a built-in trust deficit even before any regulatory action, independent of whether it is ultimately found unlawful in any specific implementation. A retailer can win every argument about the legality of its pricing model and still lose the argument that matters most to a customer deciding where to shop next.
What retail and CPG technology leaders should do now
The immediate action item is an internal audit: does any pricing system in production adjust prices based on individual-level customer data rather than aggregate market conditions, and if so, is that fact disclosed anywhere a customer would actually see it? Technology and legal teams should treat this comment period as a compliance planning window, not a signal to wait, given that state rules are already live and the federal direction is now explicit from the agency's own chairman. Waiting for a final rule before starting that audit means starting the remediation work at the same moment enforcement actually begins.
The second action item is documentation. If personalization exists for legitimate reasons, loyalty discounts, regional cost differences, inventory clearance, the underlying methodology needs to be defensible and disclosed clearly enough to survive exactly the kind of Section 5 scrutiny the FTC has now put every retail and marketplace technology team on notice to expect. Teams that can point to a clear, disclosed rationale for every price variation will be in a fundamentally stronger position than teams that discover, mid-investigation, that nobody documented why the algorithm does what it does.



