Manage the Regulatory Risk of Personalized Pricing

Access this content by contacting one of our representatives for assistance.

Author(s): Donnafay MacDonald

Retailers have long used dynamic pricing to balance demand and inventory, but digital commerce, loyalty programs, apps, and customer-data platforms now make it possible to personalize pricing based on individual behavioral and profile data. This shift has made personalized pricing a new regulatory flashpoint: Maryland, New Jersey, and Connecticut have already restricted or placed guardrails on personalized and surveillance pricing, the FTC proposed disclosure rules in August 2026, and the EU already mandates disclosure.

Accountability for personalized pricing falls to the CIO, who must ensure data visibility (explaining what customer data drives a price), architecture control (consistent delivery across channels), and compliance configuration (knowing where personalization is permitted, restricted, or prohibited).

The CIO's job is not to judge whether a price is fair, but to prove that pricing decisions use permitted data, follow applicable jurisdictional rules, leave an auditable record, can be explained to a human, and can be stopped when necessary. This means setting rules for how prices are calculated and what data may be used, tracking each pricing decision so it can be explained, and keeping human control to review, question, and reverse decisions.

Because requirements are taking effect now across countries and states while other proposals remain unsettled, retailers should not wait for a single federal rule. Instead, they should map their pricing landscape, set limits on data use, classify and record each pricing decision, and assign clear ownership and intervention rights so any challenged price can be explained and reversed quickly.