AnalyticsSeptember 24, 2026·9 min read

Surveillance pricing: a six-step audit for pricing teams

Seattle just banned surveillance pricing in grocery. What the new laws target, what they leave alone, and a six-step audit your pricing team can run this week.

On September 22, 2026, Seattle's City Council passed a ban on surveillance pricing in grocery - the first city in the US to do so. It follows state laws in Maryland, Connecticut and New Jersey, a disclosure law in New York, and a long-standing disclosure rule in the EU. If your team sets prices with any kind of algorithm, the question you will get from legal, from the board, or from a journalist is no longer "do we do surveillance pricing?" It is "can you prove you don't?"

Most pricing teams can't answer that yet. Not because they profile shoppers, but because nobody has written down every input that touches a price. This guide explains what surveillance pricing actually is, what the new laws target, and a six-step audit your team can run before someone asks.

This is a practitioner's guide, not legal advice. Take the final read on any specific law to your counsel.

What is surveillance pricing?

Surveillance pricing is setting a different price for an individual shopper based on personal data about that shopper - browsing history, real-time location, device, purchase history, or inferences about income, family size or health. Two people look at the same product at the same moment and see different prices, because a model decided one of them would pay more.

Regulators also call it personalized pricing or, when a model does the work, algorithmic pricing based on personal data. The key word in every definition is individual. That is what separates it from the pricing practices retailers have used for decades:

  • Dynamic pricing changes the price over time - by demand, stock, season or competitor moves - but everyone sees the same price at the same moment.
  • Zone pricing sets different prices by store, region or market. The input is the location of the store, not a profile of the person.
  • Competitive pricing reacts to competitor shelf and web prices. The input is the market, not the shopper.
  • Published segment discounts - seniors, students, members, a loyalty tier - give a lower price to anyone who meets rules that are written down and available to all.

Surveillance pricing sits outside all four. It uses data about one person to set that person's price, usually without them knowing.

The surveillance pricing law map, September 2026

The rules are a patchwork, and they are moving fast. Here is where things stand for teams selling into the US and the EU.

United States

  • New York - the Algorithmic Pricing Disclosure Act took effect on November 10, 2025. It does not ban personalized pricing. It requires a clear notice next to any price set by an algorithm using personal data: "THIS PRICE WAS SET BY AN ALGORITHM USING YOUR PERSONAL DATA." Penalties run up to $1,000 per violation.
  • Maryland - the Protection from Predatory Pricing Act (H.B. 895), signed in April 2026, covers food retailers and third-party delivery services. Read its text closely: it reaches dynamic pricing by food retailers, not only the use of personal data.
  • Connecticut - H.B. 5563, signed in June 2026, bars surveillance pricing by retail sellers and delivery services doing business in the state.
  • New Jersey - has also signed a ban, according to Consumer Reports.
  • Seattle - the Fair Pricing and Transparency Act (CB 121267) bans personalized grocery pricing based on personal data, while explicitly keeping coupons and transparent discounts for groups such as seniors or veterans. The mayor's office frames the rule simply: prices must be clearly posted and available to all shoppers.
  • California - A.B. 2564, introduced in February 2026, would ban surveillance pricing with penalties of up to $12,500 per violation. It carves out cost-based price differences, publicly disclosed eligibility criteria and loyalty programs (Paul, Weiss).

At the federal level, the FTC has studied surveillance pricing since 2024 and has recently asked for public comment on how it should approach personalized pricing enforcement.

European Union

EU retailers have had a rule on the books for longer than most US states. Since May 28, 2022, the Consumer Rights Directive (as amended by the Omnibus Directive 2019/2161) requires online sellers to tell shoppers when a price has been personalized on the basis of automated decision-making. GDPR adds its own layer: profiling needs a lawful basis, and people have the right to object to it and to a meaningful explanation of automated decisions.

The next step is the Digital Fairness Act, which the European Commission is preparing. Commentators expect it could let consumers opt out of personalized offers, or limit personalization to strictly necessary data. For a retailer in Poland, Czechia or the Baltics selling online, "we'll deal with it when it arrives" is already a year late.

Why this is a pricing problem, not only a legal one

The shoppers these laws protect have a point. When Consumer Reports had nearly 400 people buy identical baskets on a grocery delivery app at the same time, it found price differences as high as 23% on some products, which it estimated could cost a family more than $1,200 a year. An earlier Consumer Reports investigation found a single shopper's data profile at a large grocer ran to 62 pages, including inferences about income, family size and education.

Most mid-market retailers are nowhere near that. Their exposure is different, and in some ways harder to spot: they cannot show what drives their prices. Common gaps we see:

  • A repricing tool or marketplace plug-in that nobody on the team can explain end to end.
  • An e-commerce platform that shows different prices to logged-in and logged-out visitors, set up years ago for a campaign and never switched off.
  • Personalized coupons issued by the CRM team, with eligibility rules that live in someone's head.
  • Price changes made in spreadsheets, with no record of which rule or input produced them.

None of these is surveillance pricing on purpose. All of them make it impossible to prove it isn't happening. Legal can interpret the statute. Only the pricing team can say what actually sets the price.

A six-step surveillance pricing audit

Here is the audit we would run with a category or pricing team. It takes days, not months, if your pricing logic is written down. If it isn't, that is the first finding.

1. Inventory every input that can touch a price

List every data field that feeds a regular price, a promo price, a markdown or a discount. Include every system that can write a price: the pricing tool, the ERP, the e-commerce platform, marketplace connectors, the CRM, the loyalty engine. Teams usually find more writers than they expected.

2. Classify each input

Put every input into one of five buckets. Most will land in the first four, and that is the point of the exercise.

  • Product - cost, margin target, category role, price ladder, pack size.
  • Market - competitor prices, price index, demand trends, seasonality.
  • Store or zone - the location, format or channel the price applies to.
  • Published segment - a group anyone can join by meeting written rules (members, students, seniors, a loyalty tier).
  • Individual - anything about one specific person or device: browsing, location of the shopper, past purchases used to predict willingness to pay, inferred income or household.

Any input in the fifth bucket that changes a price is the thing the new laws target. Flag it, name an owner, and decide with legal whether to remove it, disclose it, or confirm it is exempt.

3. Test price parity across shoppers

Don't rely on what the configuration says. Check the same basket of products online in the same zone across a logged-out session, a logged-in account, a mobile device and a desktop, and two accounts with very different purchase histories. Record the prices and time stamps. If prices differ, trace the difference back to an input from step 1. If you can't, you have found an undocumented price writer.

4. Put every discount rule in writing

Most US proposals and the Seattle ordinance keep discounts that are available to anyone who qualifies. That protection only holds if the eligibility rules are written down and published. For each loyalty tier, member price and coupon program, write the rule in one sentence ("members get 10% off private label") and check that the system applies exactly that rule. Individually targeted offers, where a model picks who gets how much off, need a separate review.

5. Log every price change with its reason

An audit is a snapshot. A price log is the ongoing proof. For every price change, keep the old price, the new price, the time, the rule that fired and the inputs it used, and who approved it. When a regulator, a journalist or a customer asks why a price changed, the answer is a lookup, not an investigation. If you only do one thing from this list, do this one.

6. Assign an owner and a review cadence

Pricing logic drifts. A new campaign tool, a new marketplace connector or a new "smart discount" feature can add an individual-level input without anyone in pricing noticing. Name one owner for the input inventory, review it every quarter, and add a pricing sign-off to any new tool that can write prices.

What this doesn't change

It is easy to overreact to headlines about "AI price-gouging." Most of what a good pricing team does stays exactly as it was:

  • Competitor-based pricing is based on the market, not the shopper. Matching or indexing to competitor prices is untouched by these laws.
  • Zone pricing by store, region or channel uses the location of the store, not a profile of the person.
  • Markdowns and clearance driven by stock, age and sell-through apply to everyone.
  • Published loyalty and member prices remain allowed in the rules we have seen, as long as eligibility is transparent.

Two caveats. First, time-based dynamic pricing is mostly outside these laws, but not everywhere: Maryland's statute covers dynamic pricing by food retailers, so grocery teams selling there need their counsel to read it line by line. Second, disclosure rules like New York's and the EU's apply even where personalization is legal. "Allowed" and "allowed without a notice" are not the same thing.

Explainable pricing makes the question easy to answer

The retailers who will handle this well are not the ones with the best lawyers. They are the ones who can open their pricing logic and show it. That is an argument for rules-based pricing over black-box repricing, and it has little to do with regulation. When every price comes from a rule written in plain language - "hold a 98 price index against the two nearest competitors on KVIs, floor at 22% margin" - you can see which inputs it uses. And none of them is about the shopper.

The same logic applies to AI. An agentic pricing setup where an agent proposes price changes, explains each one, and applies them within guardrails you set is auditable by design. An agent that optimizes against signals nobody can list is exactly the kind of system these laws were written for.

Surveillance pricing bans will keep spreading, city by city and state by state, and the EU's next consumer law is on its way. Teams that treat this as a one-off legal review will be doing it again next year. Teams that make their pricing explainable, auditable and rules-based only have to show their work once.

If you want to see what an auditable price-change log looks like in practice, or pressure-test your own input inventory with someone who has run a pricing team, get in touch. We are happy to compare notes.

See the agentic pricing platform behind the writing.

A 20-minute walkthrough of Retailgrid on a real retail dataset. No signup. No sales script.