The FTC Is Cracking Down on Companies Using Your Data To Set Prices

The FTC wants companies to disclose the personal data they use to set prices, giving consumers more transparency over how their information is used.
We receive compensation from the products and services mentioned in this story, but the opinions are the author's own. Compensation may impact where offers appear. We have not included all available products or offers. Learn more about how we make money and our editorial policies.

The Federal Trade Commission (FTC) has proposed cracking down on personalized pricing, a practice in which businesses use your personal data to determine how much you might be willing to pay for a product or service.[1] This could involve sensitive information such as your income, location, interests, credit history, shopping habits, and even medical conditions.

This surveillance pricing puts consumers at risk of paying more than they otherwise would, but the bigger long-term concern is what happens to all that personal data and how it could be used against you.

The FTC cannot outright ban personalized pricing, but it can take action against companies that use it deceptively. Under its proposed policy, businesses would need to clearly disclose when a price is personalized, what the personalization is based on, and what types of data were used to determine the price.

In other words, the move could give consumers more visibility into how their personal data is being used to set prices, and potentially give them a chance to dispute incorrect data or avoid its collection.

Here's what the FTC says would cross the line, why its own proposal names VPNs and private browsing as consumer defenses, and why some critics warn the policy could kill the discounts you rely on.

In this article
The FTC’s new rules for personalized pricing
Where the FTC draws the line
Why critics say the rules could backfire
How do companies collect your personal data and why is it dangerous?
What can you do to protect yourself
Bottom line

The FTC’s new rules for personalized pricing

Under the FTC's new proposed enforcement policy, released August 19, 2026, businesses that engage in personalized pricing should disclose not only that the price is personalized, but also the basis for the personalization and the data the company relied on to determine that personalized price.

That obligation applies specifically in markets where consumers reasonably expect prices won't vary based on their personal data, like the price on a store shelf or the price on a product listing anyone else would see. Any failure to make these disclosures could violate Section 5 of the FTC Act and constitute an unfair or deceptive trade practice.

The Commission approved the proposal on a 2-0 vote, and the public gets 30 days to weigh in once the statement is published in the Federal Register. The public can submit comments through the FTC's public docket.

The policy statement builds on a warning FTC Chair Andrew Ferguson issued in a 2024 concurring statement, written when he was still a minority commissioner. Modern data collection, he wrote, can reveal some of consumers' most intimate details:

  • Identities
  • Interests
  • Credit history
  • Location
  • Sexual interests
  • Medical conditions
  • Religious and political beliefs

The new policy statement makes the same point about how little consumers know: “Many Americans do not understand just how much data they generate every second of their lives. Nor do they necessarily understand how those data are collected and stored, to whom they may be sold, or how they may be used.”

Where the FTC draws the line

The same FTC policy statement acknowledges that several industries, such as insurance and credit, have pricing that naturally varies from customer to customer based on the nature of the product.

Other industries also have prices that may vary based on supply and demand. For instance, ride-share prices could differ from one neighborhood to another based on market conditions and demand. The FTC acknowledges that such variations can be legitimate and within its provisions.

However, the FTC also notes that some industries expect consumers to be offered the same price, regardless of personal preferences or circumstances. The agency listed seven scenarios that could cross the line.

A food delivery app charging more because it knows you might not be able to leave home. A grocery chain charging more for milk because data shows several children in your household. A hotel charging more after learning you're traveling for a funeral. A ride-share charging more to reach a medical facility, or charging more simply because your phone shows no competing apps installed, and therefore no easy way to price-shop.

A retailer could also cross the line by charging more for a home security camera after court filings show you were recently the victim of a crime, or by raising a price on its website because your location data puts you inside its store.

Why critics say the rules could backfire

Of the dozens of people who submitted comments to the docket, most welcomed stronger action, calling the practice “abhorrent” and “atrocious,” Ars Technica reported. Commenters said low-income households would be hit hardest, and argued that race, religion, gender, and sexual preferences should never factor into what someone pays.

But some supporters of tougher rules worry this particular proposal could backfire. Commenter Jessie Shettleroe pointed out that the FTC never actually defines personalized pricing. “The operative phrase is prices that ‘vary based on their personal data.’ That covers my grocery loyalty card, emailed coupons, and app-only prices. Those save me money,” Shettleroe told the FTC. If businesses can’t tell which practices are covered, he argued, “the first thing to disappear will be the discounts, not the surcharges.”

A full ban would take an act of Congress. A bill introduced in July 2025, the Stop AI Price Gouging and Wage Fixing Act, would do that by prohibiting companies from using automated systems to set individualized prices and wages. It has not advanced out of committee.

How do companies collect your personal data and why is it dangerous?

Companies rely on several sources to get their hands on personally identifiable information about you.

First and foremost, companies use their own apps, websites, and analytics to understand a user’s behavior. Retailers could track what you click, how long you hover over a product, and which items you abandon in your cart to gauge your preferences. They could also determine price sensitivity by looking at your sorting and filtering patterns.

Next, there are cookies and tracking pixels. Every website you visit may include cookies and tracking pixels embedded by third-party ad networks. Even a single site visit could quietly set cookies from dozens of different companies at once.

Similarly, mobile apps may include software development kits (SDKs) that send data to the companies that provide them. Data brokers can then pull it together, enrich it, and resell it to other third parties and advertisers. This stitches together a profile of you that spans far more than any one company could gather alone.

Another source of personal data is your geolocation from phones and apps. This could potentially pinpoint your location, including whether you are inside a store or in a parking lot while browsing a website or using an app. Location could also be inferred from your IP address.

Loyalty and rewards programs are another major source of sensitive data. Many retailers require demographic information, such as age, income bracket, and address, to sign up.

This data could then be correlated with your browsing behavior and information from third-party sources to build a more complete personal profile, enough to determine not only what you’re willing to buy, but also how much you’re willing to pay.

The bigger concern is that the more personal information companies collect and combine about you, the more damaging it could be if that data falls into the wrong hands.

Cybercriminals could use details such as your email address, phone number, location, shopping habits, or other personal information to launch highly personalized phishing and social engineering attacks. Those attacks can lead to identity theft and financial fraud.

What can you do to protect yourself

While it’s virtually impossible to outright eliminate the collection of your personal information, there are a few steps you can take to limit the amount of data companies might collect.

The first two are the FTC's own suggestions. Its policy statement argues that undisclosed personalized pricing harms shoppers precisely because it denies them the chance to use a virtual private network or a private browsing session to avoid a higher price.

  1. Use a virtual private network (VPN): A VPN can mask your original IP address and make it look like your internet traffic is coming from another location. Since companies can use location data to fine-tune prices, you could limit this by using a VPN while shopping online. However, note that if you log in to your Amazon or any third-party retailer account while using a VPN, it won’t help much, since your activity could still be tied to your account details. That said, a VPN could still come in handy when you’re window shopping or comparing various retailers before making a purchase decision.
  2. Use incognito or private mode: Although incognito mode doesn't hide your IP address, it can prevent your browser from retaining cookies, login sessions, and browsing history from previous visits. This could make it harder for sellers to recognize you based on buying behavior, past searches, or account activity.
  3. Block third-party cookies and trackers: Many browsers, such as Firefox and DuckDuckGo, have built-in third-party cookie and tracker blocking; for others, you can download ad and tracker blocking extensions such as uBlock. This can disable a large share of the tracking mechanisms embedded on websites that data brokers may rely on to build your profile.
  4. Be selective with permissions: Whenever you install a new app, pause and think before granting it extensive permissions. For instance, you could set app location access to “while using” instead of “always.” Both iOS and Android also let you turn off advertising identifiers in your phone’s privacy settings, which can limit how your cross-app data is linked.
  5. Use an identity theft protection service: If you’re an avid online shopper, much of your private information may already be out there with various retailers, sellers, or data brokers. If such information falls into the wrong hands, it could cause much more damage than targeted advertising or personalized pricing. That’s why you should consider getting an identity theft protection service. These tools scan known databases and the dark web and alert you if they find any of your personally identifiable information in the wild.

Bottom line

Although this is only a proposed policy statement right now, the FTC is keen to make brands and companies rethink their personalized pricing strategies and be more transparent about the data they use to set prices.

While the matter is yet to be decided, you can take several measures right now to limit how much personal data companies collect and use about you. This includes using a VPN, a secure browser, and an identity theft protection service.

Fast & Unlimited Protection for All Your Devices
5.0
Editorial Rating
Get Deal
On Surfshark's website
2026 Editors’ Choice
Best Value VPN
VPN
Surfshark
PROMOTION: From $2.49/mo + 3 Months Free
  • Budget-friendly VPN that lets you connect unlimited devices at once, which most VPNs cap at 10 or fewer
  • 4,500+ servers across 100 countries with proven fast speeds, even on distant connections
  • Includes a built-in ad and tracker blocker, so you get cleaner browsing without a separate tool

Author Details
Krishi Chowdhary specializes in digital privacy, cybersecurity, and consumer technology. He has written extensively on online privacy tools and broader cybersecurity topics, including online scams, data breaches, age verification, and emerging digital threats. Krishi believes technology reporting should empower readers, not confuse them, and is committed to making even the most technical subjects easy to understand without compromising on accuracy or depth. His work has appeared in leading technology publications, including CNET, ExpressVPN, and TechRadar, where he has covered topics ranging from cybersecurity incidents and privacy product announcements to artificial intelligence and major technology news

Citations

[1] Federal Trade Commission’s Proposed Enforcement Policy Statement Regarding Personalized Pricing