On 19 August 2026, the Federal Trade Commission issued a proposed enforcement policy statement on personalized pricing and opened it for 30 days of public comment. The vote authorising the Federal Register notice was 2–0.

A policy statement is not a rule. It creates no new obligation and it binds nobody. What it does is tell the market, in writing and in advance, the theory under which the agency intends to sue. When a regulator publishes its theory of liability before bringing cases, it is doing companies a favour and building a record at the same time.

Here is the theory.

What the FTC Means by “Personalized Pricing”

The statement defines the practice as using consumer data — browsing history, location data, demographic information, purchasing patterns — to set an individualised price based on a consumer’s estimated willingness to pay or their likelihood of comparison shopping.

Note what is being estimated. Not your risk, not your cost to serve, not any input that varies the seller’s expenses. Your willingness. The model’s job is to find the highest number you personally will not walk away from, and charge you that.

This is not the same as a coupon, a loyalty discount, a member rate, or a sale. Those are price variations you can see and qualify for. Personalized pricing is a price variation you cannot see, cannot qualify for, and cannot compare, because the comparison shopper next to you is looking at a different screen.

The most consequential choice in the whole document is which law the FTC reached for.

It did not build the case on unfairness, or on price discrimination doctrine, or on a privacy theory about the underlying data collection. It built it on deception under Section 5 of the FTC Act — and the deception is about consumer expectations.

The statement’s reasoning: consumers generally expect that the price they see is the same price offered to other consumers for the same product or service. A retailer who represents or implies that a price is static, when the price in fact varies by individual, is at risk of engaging in a deceptive act or practice.

That framing has three big consequences.

It makes disclosure the safe harbour. Under a deception theory, the violation is the mismatch between the implied representation and the reality. Close the gap and the violation closes with it. A retailer who clearly discloses that prices are individualised has, on this theory, largely solved its FTC problem — while continuing to do the thing.

It sidesteps the hardest question. Whether it is legitimate to charge two people different amounts for the same item based on inferred desperation is a substantive question about fairness. Deception doctrine does not require the agency to answer it. That is why this theory can be deployed now, with a 2-0 vote, rather than after years of litigation over unfairness.

It puts the burden on the shopper. The remedy for a disclosed practice is comparison shopping — by a consumer who has just been told that the seller has modelled how likely they are to comparison shop.

Where the Data Comes From

The FTC’s definition is a fairly precise description of the commercial data supply chain we have been mapping all year. Browsing history and purchasing patterns come from the adtech ecosystem. Location comes from mobile SDKs embedded in apps that have nothing to do with retail. Demographics come from brokers.

That is the same pipeline behind California’s DROP deletion platform, the same pipeline behind the ad-supply-chain mapping work, and the same pipeline that ends at government contracts. Personalized pricing is that infrastructure pointed at your wallet instead of at a case file.

Which is the useful thing about this statement: it establishes, at the federal level and on the record, that data broker inputs have a direct, measurable, monetary cost to the individual consumer. Privacy harms are usually argued in the abstract — dignity, chilling effects, future risk. “You paid more than the person next to you” is a harm with a dollar sign, and dollar signs travel further in American law than dignity does.

What Happens Next

The comment period runs 30 days from publication. Expect three distinct pressure groups:

  • Retail and airline trade associations will argue that the statement sweeps in ordinary dynamic pricing — surge, yield management, time-of-day — which varies by market conditions rather than by individual, and that the line between the two is blurrier in practice than in the statement.
  • Adtech and data brokers will argue that they supply signals, not prices, and that liability should sit with the merchant.
  • Consumer groups will argue the opposite of the retailers: that disclosure is not a cure, and that the agency should have used its unfairness authority to reach the practice itself rather than its packaging.

State attorneys general are not waiting. Several states have already opened inquiries into surveillance pricing, and state UDAP statutes generally track Section 5 — meaning a federal theory published in August becomes a state complaint template by winter. New York already requires disclosure when personalised algorithmic pricing is used.

How to Tell If It Is Happening to You

You cannot prove it from one screen. You can gather evidence:

Compare across a clean boundary. Load the same product page in a normal window and in a private window with a different IP — a phone on mobile data versus a laptop on home wifi. Different prices across that boundary, repeatedly, on the same item, is a signal.

Watch for the abandoned-cart discount. A price that drops after you leave and return is a model updating its estimate of your willingness to pay. That is the mechanism working exactly as designed.

Check whether logged-in differs from logged-out. An account is the highest-quality identifier a retailer has. If the logged-in price is consistently higher on items you have browsed before, the account is the input.

Look at travel and delivery most closely. Airlines, hotels, ride-hailing and food delivery have the richest per-user signal and the longest history of individualised pricing.

What To Do

  1. File a comment. The docket is open for 30 days at regulations.gov via the FTC’s notice. Comments from ordinary consumers describing concrete experiences of price variation are exactly the record the agency needs, and they are read.

  2. Disable your mobile advertising ID. Android: Settings → Privacy → Ads → Delete advertising ID. iOS: Settings → Privacy & Security → Tracking → off. This is the identifier that stitches your browsing to your demographic profile to your location, and it is the cheapest input in the whole model.

  3. Shop logged out, then log in only to pay. It is not a fix, but it removes the strongest identifier from the pricing decision on most sites.

  4. Turn off location for retail and delivery apps — set to “While Using” at most, never “Always.” Location is a proxy for income, and income is a proxy for willingness to pay.

  5. Use a broker deletion route. California residents should use DROP. Everyone else: the major brokers all have opt-outs, and the demographic layer of the pricing model is exactly what they sell.

  6. Screenshot price differences with timestamps. If enforcement moves — federal or state — contemporaneous consumer evidence is what turns a policy statement into a complaint.