Skip to content

Regulatory Pulse

FTC proposes personalized-pricing enforcement policy: disclosures, consent and data use

The FTC proposes treating undisclosed or inadequately disclosed use of personal data for personalized pricing as potentially unfair or deceptive under Section 5. The proposal is not final and does not ban personalized pricing.

United States
Privacy, consumer protection and AI governance
Guidance
Official source reviewed

PrivacyBuilt Editorial · Source published Proposed consumer-protection enforcement policy · Reviewed 4 September 2026 · 8 min read

The 60-second summary

On 19 August 2026, the Federal Trade Commission voted 2-0 to seek comment on a proposed enforcement policy statement addressing personalized pricing: using personal data to set a price based on what a business believes an individual is willing to pay. The FTC says it cannot prohibit personalized pricing in all circumstances. Where consumers reasonably expect prices not to vary based on their personal data, the proposal says businesses should clearly and conspicuously disclose that the price is personalized, the basis for personalization and the types of data used. Inadequate disclosure, misleading price representations, or pricing-related data use without adequate notice or consent may be treated as unfair or deceptive under Section 5. On 3 September 2026, the FTC extended the comment deadline by seven days. Comments are now due 25 September 2026. The statement remains a proposal and creates no new binding rule.

Timeline that matters

  1. 19 August 2026

    Proposal announced

    The FTC voted 2-0 to release the proposed enforcement policy statement for public comment.

  2. 19 August 2026

    Docket opened

    The proposal was posted under docket FTC-2026-1057.

  3. 25 September 2026

    Comments due

    The FTC extended the public-comment period by seven days on 3 September 2026. The official comment page now lists 25 September 2026.

  4. After comment review

    Possible next action

    The Commission may finalise, revise or withdraw the statement; no final date has been announced.

What changed

The FTC has set out a proposed enforcement position for data-driven personalized pricing. It distinguishes ordinary market-wide price variation and inherently individualized risk pricing from situations where a business uses personal data to estimate a consumer's willingness to pay for goods or services that consumers ordinarily expect to carry a non-personalized price. The proposal says failure to disclose personalization, its basis and the types of data used is likely to constitute an unfair or deceptive practice. It also connects risk to misleading price claims and to data collection, use or disclosure without adequate notice or consent. The proposal does not ban the practice, bind courts or the public, and is not final. On 3 September 2026, the FTC extended the public-comment period by seven days, moving the deadline from 18 September to 25 September 2026. The extension does not change the proposal’s substantive status or content.

Who should pay attention?

Retailers, marketplaces and subscription services

Teams that adjust consumer prices, discounts, fees or offers using personal data should assess disclosures, representations and consent.

Pricing, data-science and AI teams

Model inputs, inferred willingness to pay, proxy variables and output testing may become central evidence in an investigation.

Data brokers and pricing vendors

Third-party data and decisioning services create dependencies that require transparency, provenance and assurance evidence.

Privacy, legal and consumer-protection teams

Privacy notices alone may not address the proposal's focus on clear, conspicuous disclosures where a personalised price is presented.

Product, marketing and customer-support teams

Claims about discounts, uniform prices or the reason for price variation must remain accurate and explainable.

What the guidance clarifies

This is a proposal
The Commission has requested public comment. The statement is not final, is not a rule and does not itself create a new binding obligation.
Personalized pricing is not universally prohibited
The FTC expressly says it lacks authority to ban personalized pricing in all circumstances.
The focus is undisclosed data-driven variation
The proposal targets situations where consumers reasonably expect prices not to vary based on personal data.
Disclosure content matters
The proposal says businesses should disclose that the price is personalized, the basis for personalization and the types of data used.
Consent and data-use representations matter
Collection, use or sharing of personal data for pricing without adequate notice or consent may support an unfairness or deception theory.

Global relevance — data-driven pricing is a cross-functional governance issue

Why this matters for global organisations

Personalised pricing can combine customer data, behavioural signals, inferred circumstances, automated decisioning and third-party models. Even where a particular proposal does not apply directly, organisations should be able to identify when personal data changes a price, explain the logic, substantiate consumer-facing claims, govern vendors and preserve evidence.

  • Treat pricing models as governed data-processing systems, not only commercial optimisation tools.
  • Align privacy, consumer-protection, product, AI, marketing and pricing reviews before launch.
  • Keep point-of-decision disclosures consistent with privacy notices, consent flows and actual model inputs.
  • Require vendors to provide data provenance, model documentation, change notices and testable assurance.
  • Design controls that can accommodate stricter local rules without fragmenting the core evidence model.

12 actions to start now

  1. Inventory every pricing workflow that uses personal data, inferred traits, device signals, browsing activity, purchase history, loyalty data, location, urgency indicators or third-party scores.
  2. Distinguish personalized pricing from market-wide dynamic pricing and document why each pricing variable is used.
  3. Map the responsible entities, retailers, marketplaces, analytics providers, data brokers and pricing-software vendors.
  4. Review whether point-of-decision notices state when a price is personalized, the basis for personalization and the types of data used.
  5. Verify that consent and preference records cover collection, use and disclosure of personal data for pricing.
  6. Block sensitive, vulnerability-related or unexpected inferences from pricing models without documented legal and ethical review.
  7. Test outputs across representative profiles for hidden differentials, misleading discount claims, unexplained mark-ups and proxy variables.
  8. Require vendors to disclose model inputs, data provenance, decision logic, testing evidence, change controls and incident-cooperation duties.
  9. Create a support path for questions, access requests, corrections, complaints and challenges concerning data-driven prices.
  10. Preserve model versions, inputs, disclosures, consent records, test results, approvals and pricing logs.
  11. Monitor model drift, vendor changes, complaint patterns and disclosure consistency.
  12. Track the FTC docket and reassess controls if the statement is finalised, revised or withdrawn.

Suggested next steps

  • Use 25 September 2026 as the current comment deadline. Track the docket and official FTC pages for finalisation, revision, withdrawal or any further extension.

Evidence worth retaining

  • Inventory of pricing systems, models, vendors, data sources and owners.
  • Data-flow maps showing collection, enrichment, inference, sharing and pricing use.
  • Model documentation covering features, proxy variables, objectives, limitations and version history.
  • Screenshots and archived copies of pricing disclosures at each relevant user journey.
  • Consent language, preference records, withdrawal handling and proof of the purpose communicated.
  • Records substantiating discount, comparison-price and uniform-price representations.
  • Testing results comparing outputs across user profiles, devices, locations and account states.
  • Assessments of sensitive data, vulnerability indicators and unexpected inferences.
  • Vendor due diligence, contracts, audit rights, data provenance and model-change notices.
  • Human review, escalation, complaint-handling and consumer-redress records.
  • Approval minutes showing privacy, legal, product and pricing review.
  • Monitoring records for model drift, disclosure changes, incidents and regulatory updates.

Questions to take to counsel or your conformity team

These are discussion prompts, not legal advice or conclusions.

  • Would consumers reasonably expect this price to be the same for others at the same time and in the same context?
  • Which personal data or inferences cause the price, fee, discount or offer to change?
  • Is the price personalized, market-wide dynamic, risk-based or a mixture?
  • Are users told where the price is displayed that it is personalized, why and using which data categories?
  • Does the organisation have evidence that the communicated purpose covered pricing?
  • Could a variable reveal or proxy health, financial distress, family circumstances, urgency, vulnerability or lack of alternatives?
  • Can the organisation reproduce the price shown to a user and explain the governing model version?
  • Do vendor contracts provide enough information and audit evidence to defend the practice?
  • Could a claimed discount actually be a personalised mark-up relative to another consumer?
  • Which additional sectoral, privacy, anti-discrimination, competition or state laws may apply?

Official sources

PrivacyBuilt / PrivacyBuilt is an independent educational publisher. It is not affiliated with, or endorsed by, any regulator or the European Union.

PrivacyBuilt publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.