Salta al contenuto principale

Surveillance Pricing Bans in 2026: What Maryland, Connecticut, and New York's New Laws Mean for Your Business

8 minuti di letturaMike ThriftMike Thrift
Surveillance Pricing Bans in 2026: What Maryland, Connecticut, and New York's New Laws Mean for Your Business

Imagine two customers open the same product page five minutes apart. One sees $49. The other, whose browser history shows they've been comparison-shopping for an hour and whose phone says they're standing in a wealthier zip code, sees $59. Neither price is a typo, a sale, or a mistake — it's the output of a pricing algorithm quietly doing its job. Until this year, that job was almost entirely unregulated. That's changing fast, and if your business touches dynamic or personalized pricing in any way, the rules are about to matter to you directly.

What "Surveillance Pricing" Actually Means

Surveillance pricing — sometimes called algorithmic or personalized pricing — is the practice of using software to set a price for an individual customer rather than a price for a product. Instead of one sticker price for everyone, the algorithm ingests signals like:

  • Browsing and purchase history
  • Device type (iPhone users have, in some studies, been shown higher prices than Android users for identical items)
  • Location or zip code
  • Time spent on a page, scroll behavior, or even mouse movement
  • Membership in a loyalty program, or lack thereof
  • Broader demographic inferences pulled from data brokers

The algorithm then decides, in real time, what you specifically are likely willing to pay — and charges accordingly.

This is different from ordinary dynamic pricing, like airline seats getting more expensive as a flight fills up, or a landscaping company charging more during peak season. Those adjustments respond to supply, demand, and cost. Surveillance pricing responds to you — your data, your inferred willingness to pay, sometimes even your inferred vulnerability. Regulators have started drawing a hard line between the two, and the line matters a lot for compliance.

Why Regulators Moved Now

Surveillance pricing has been technically possible for years, but 2026 is the year state legislatures actually acted on it. A few things converged:

  • Federal Trade Commission research into how retailers use third-party data brokers to power real-time price personalization put a spotlight on the practice.
  • Reporting on airlines, ride-share apps, and grocery delivery platforms varying prices by device and inferred income level generated public backlash.
  • Advocacy groups reframed the issue as a consumer-protection and privacy problem rather than just a pricing-strategy question — which pulled it into the same legislative lane as data privacy laws.

The result: more than 40 bills addressing surveillance or algorithmic pricing have been introduced across at least two dozen states in 2026 alone. Three have already become law.

The Three Laws on the Books Right Now

Maryland — the first outright ban

Maryland's Protection From Predatory Pricing Act, signed in April 2026, is the first law in the country to flatly prohibit surveillance pricing rather than just require disclosure of it. It bans food retailers with at least 15,000 square feet of retail space — plus third-party delivery services — from using personal data to charge individual consumers higher food prices. It also separately bars using protected-class data (race, religion, and similar categories) in any way that denies service based on those characteristics.

Carve-outs matter here: loyalty program discounts, promotional offers, cost-based adjustments (shipping, taxes), and pricing offered to customers who affirmatively consent to share their data all remain legal. Violations carry penalties up to $10,000 per offense, $25,000 for repeat violations, enforced by the Maryland Attorney General — there's no private right of action, so this is a regulator-driven risk, not a lawsuit-driven one. The law takes effect October 1, 2026.

Connecticut — a ban with a disclosure escape hatch

Connecticut's SB 4, part of a broader privacy law overhaul, prohibits retail sellers and third-party delivery services from setting customized prices using personal data. What makes Connecticut's approach distinct is that other businesses outside that core prohibition aren't banned outright — they can still use surveillance pricing, but only if they display a clear, specific disclosure: "THIS PRICE WAS INCREASED USING YOUR PERSONAL DATA." Like Maryland, Connecticut carves out temporary discounts, promotions, and pricing based on objective cost differentials or genuine supply-and-demand shifts.

New York — disclosure-first, with a ban now on the governor's desk

New York moved first with an Algorithmic Pricing Disclosure Act requiring retailers to label algorithmically personalized prices. In June 2026, the state legislature went further and passed the One Fair Price Act, which would prohibit using algorithms fed by personal data to charge different customers different prices for the same goods or services — and would also bar sharing personal data with third parties for the purpose of enabling that kind of pricing. As of this writing it's awaiting the governor's signature. If it's signed, New York becomes the first state to move from "tell customers" to "don't do it at all."

It's Not Just These Three States

California's Attorney General opened an investigative sweep in January 2026, sending inquiry letters to retail, grocery, and hotel businesses with a significant online presence to determine whether their data-driven pricing practices violate the state's existing privacy law — no new statute required, just enforcement of what's already on the books. Illinois, Vermont, and a growing list of other states have bills in progress using either the disclosure model or the outright-ban model. If your business sells across state lines — which describes most e-commerce and delivery businesses — you should assume this is a multi-state compliance question, not a one-state one, and that the list of applicable states will be longer by the end of the year than it is today.

What This Means If You Run a Small Business

Most small businesses aren't running sophisticated real-time pricing algorithms, but a surprising number are closer to this issue than they think:

  • You use a SaaS platform with "smart pricing" or "dynamic discounting" features. E-commerce platforms, delivery apps, and some point-of-sale systems now bundle pricing-optimization tools that factor in customer data. If you've flipped that switch on, you may be a surveillance-pricing user by definition even if you didn't build the algorithm yourself.
  • You vary prices by loyalty tier or membership. This is generally still fine everywhere as long as it's a genuine, disclosed program a customer opts into — but the line between "loyalty discount" and "personalized pricing" is exactly where regulators are focused, so document why your program qualifies as the former.
  • You sell through a marketplace or delivery platform (think food delivery, ride-share-adjacent services, or third-party marketplaces). Some of these laws reach the platform and the seller. If your delivery partner is adjusting your listed price by customer, you may be a data controller in this by extension — check your platform agreement.
  • You're a multi-location or franchise business. A single non-compliant pricing tool used across locations in Maryland, Connecticut, or New York multiplies your exposure per-location, per-transaction.

A short compliance checklist

  1. Audit what data touches your pricing. List every tool that sets or adjusts customer-facing prices, and identify whether personal data (versus cost or inventory data) feeds into it.
  2. Separate cost-based dynamic pricing from personalized pricing. Document why a price varies — inventory, season, shipping cost — so you can show a regulator the adjustment was cost-driven, not customer-driven.
  3. Review loyalty and membership programs to confirm they're opt-in, disclosed, and available to any customer who joins — not silently tiered by inferred spending power.
  4. Don't rely on a privacy-policy mention alone. Multiple analyses of these laws note that burying a disclosure in a general privacy policy isn't enough — Connecticut's model, for example, requires a specific, visible price-level disclosure.
  5. Watch your platform vendors, not just your own systems, if you sell through delivery apps or marketplaces that manage pricing on your behalf.

The Bookkeeping Angle

None of this is really about accounting — until an investigation, an audit, or a state AG inquiry lands, and you need to reconstruct exactly what price a customer was charged, when, and why. If your point-of-sale or delivery platform generates a different price per customer, your revenue records need to capture that variance cleanly, not just a single blended daily total. Clean, itemized, auditable records — tied to specific transactions rather than rolled-up summaries — are what let you demonstrate a price difference was a legitimate discount or cost adjustment rather than something a regulator would flag.

Keep Your Pricing and Financial Records Auditable

As pricing itself becomes a compliance surface, the ability to show exactly what happened in your books — transaction by transaction, with a clear paper trail — matters more than ever. Beancount.io provides plain-text accounting that gives you complete transparency and version-controlled history over your financial data, so nothing is buried in a black-box ledger when you need to answer for it. Get started for free and see why developers and finance professionals are switching to plain-text accounting.

Condividi questo articolo