On August 19, 2026, the Federal Trade Commission issued a proposed enforcement policy statement regarding personalized pricing, Matter No. P034101, and opened it for public comment. Comments close September 18, 2026, at 11:59 p.m. EDT — a 30-day window that is, as of this writing, roughly three weeks from expiring.

The operative sentence is short, and it is worth reading before anything else:

“Where consumers reasonably expect that prices for a product or service will not vary based on their personal data, businesses that engage in personalized pricing should clearly and conspicuously disclose not just that the price is personalized, but also the basis for that personalization and the types of data on which the personalization is based. The failure to make these disclosures is likely to constitute an unfair or deceptive act or practice in violation of Section 5.”

That is a three-element disclosure test, stated as a likelihood of liability, published by an agency that says in the next sentence that it “intends to deploy enforcement resources in a manner consistent with this conclusion.” Chairman Andrew Ferguson’s accompanying quote is blunter: “The FTC does not have the legal authority to ban personalized pricing in all circumstances, but businesses that fail to tell consumers how their personal data is being used to set a price may be in violation of the FTC Act.”

What follows is what that document actually is, what it is not, and what a pricing or privacy function should do about it before the comment window closes.

What a Proposed Enforcement Policy Statement Is — and Is Not

Precision on legal status first, because the temptation to over- or under-read this document runs in both directions.

It is not a rule. A legislative rule — the Rule Against Unfair or Deceptive Fees at 16 C.F.R. Part 464, for example — is promulgated under a specific grant of rulemaking authority, goes through APA notice and comment, is codified in the CFR, and creates independently enforceable obligations carrying civil penalties. A policy statement does none of that. The FTC says so itself, on the last page:

“This Policy Statement does not confer any rights on any person and does not operate to bind the FTC or the public. In any enforcement action, the Commission must prove the challenged act or practice violates at least one existing statutory or regulatory requirement.”

It is also proposed — the text can change after comment, and it is one cycle away from being finalized, revised, or quietly shelved.

None of that is a reason to relax, for three connected reasons.

First, Section 5 authority already exists and does not depend on this document. 15 U.S.C. § 45 has prohibited unfair or deceptive acts or practices since 1938; § 45(n) has codified the unfairness standard since 1994. The Commission could bring a personalized-pricing deception case tomorrow, cite the Deception Policy Statement and FTC v. Colgate-Palmolive, and never mention P034101. The policy statement adds no authority; it announces how existing authority will be aimed.

Second, policy statements are precisely how the Commission telegraphs enforcement. The Deception and Unfairness Policy Statements — both cited throughout P034101 — have structured four decades of FTC practice and been substantially adopted by the courts of appeals. When the Commission says it “intends to deploy enforcement resources in a manner consistent with this conclusion,” the correct reading is that a staff investigation opened next quarter will look like the document.

Third — the practical point for counsel — a published policy statement destroys the good-faith-uncertainty defense. Once the Commission has said publicly that a “specially selected” label is likely misleading because it omits material information, a respondent arguing in 2027 that the law was unclear is arguing against a document it had notice of and a chance to comment on.

The Two Theories: Deception and Unfairness Run on Different Tracks

The statement pleads in the alternative, and the two theories have materially different elements and evidentiary burdens. Analysis that collapses them will misjudge exposure.

The deception theory

Deception requires (1) a representation, omission, or practice likely to mislead; (2) evaluated from the perspective of a consumer acting reasonably in the circumstances; and (3) materiality — likely to affect the consumer’s conduct or decision. The statement applies each element, identifying both affirmative and omission variants:

“Retailers may deceive consumers in violation of Section 5 when they represent, expressly or by implication, that a price is static or widely offered when in fact it is personalized. They may similarly deceive consumers when a consumer reasonably believes that a price for a good or service is static or widely offered, and the merchant fails to disclose that the price is in fact personalized.”

Note “by implication.” No retailer says “this price is the same for everyone.” The theory is that a posted price in a market where prices customarily do not vary by person implies uniformity — which is why the statement spends its entire Background section building the factual predicate that consumers “reasonably expect the price to be the same price that anyone else browsing to that listing would see.” The Commission carves out markets where individualized pricing is the established norm: insurance and credit, which “necessarily turn on a consumer’s individualized characteristics,” and supply-demand variation including rideshare surge pricing. Whether yours is a customary-variation market is the first question in your own analysis, and it is a factual question about consumer expectations, not a legal conclusion you get to assert.

Materiality is tied to foregone consumer self-help: consumers unaware of personalization “cannot take steps to avoid the higher prices that may result from it, such as using a virtual private network or private browsing functionality, choosing a different retailer whose prices are static or widely offered… or simply declining to complete the transaction.”

A second deception variant is easy to miss: misleading consumers about the basis or effect of personalization, even where personalization is disclosed. The statement’s example is a consumer who “reasonably believe[s] that a personalized price is a discount based on their purchase history with that retailer when it is in fact a higher price based on information about their disposable income or their shopping habits with other firms.” The citations are FTC v. Standard Education Society, 302 U.S. 112 (1937) — the “specially selected” case — and Colgate-Palmolive, for the proposition that falsely framing a price as a special reduction is deceptive “even if the offered price represents the actual value of the product.” A “just for you” badge on a price that is higher because of inferred willingness to pay is the paradigm violation.

The unfairness theory

Unfairness under 15 U.S.C. § 45(n) requires substantial injury, not reasonably avoidable by consumers themselves, and not outweighed by countervailing benefits to consumers or competition. The statement walks all three:

  • Substantial injury: “The higher price paid by a consumer due to personalized pricing may be a substantial injury.” Aggregated small per-transaction overcharges are well established as substantial.
  • Not reasonably avoidable: concealment does the analytical work. “Consumers may not reasonably be able to avoid that higher price if the fact or nature of personalization of the price has been concealed” — including because they lack the information needed to modify behavior, “dispute or correct inaccurate information collected about them that is leading to higher prices, or avoid the collection of that data in the first place.”
  • Countervailing benefits: the Commission short-circuits the balancing — “Any benefits to consumers or competition from personalized pricing may also be realized without concealing the fact and nature of the personalized pricing.”

Invoking § 45(n)‘s allowance that established public policies may be “evidence to be considered,” the statement points to the FCRA adverse action notice requirement at 15 U.S.C. § 1681m(a) — which requires disclosure not just of the adverse action but of its specific basis — and to state insurance disclosure laws. The argument is structural: in markets where the law has long tolerated individualized pricing, it paired that tolerance with a duty to disclose the basis. That analogy is the intellectual core of the document, and where a comment could push back hardest — FCRA’s notice regime came from Congress, not from Section 5 unfairness.

The Commission expressly reserves the harder question: it “declines at this time to take any position on whether some personalized pricing practices are unfair even when fully disclosed to consumers.” Disclosure is a safe harbor for now, not forever.

The Disclosure Design Problem

Here the statement stops being a legal document and becomes a UX specification, and it is the part most organizations will get wrong. The required content has three elements: that the price is personalized, the basis of the personalization, and the types of data used. The statement gives adequacy and inadequacy in the same paragraph:

“Telling a consumer only that he is being shown a ‘specially selected’ price, for example, would likely be misleading because it omits important information. Conversely, a clear and conspicuous disclosure that a personalized price is based on a consumer’s estimated willingness to pay derived from data about that consumer’s previous purchases from the same retailer through the same login account—if accurate and complete—would likely be enough.”

Read the compliant example carefully. It names the inference (“estimated willingness to pay”), the derivation (“previous purchases”), and the source scope (“from the same retailer through the same login account”) — and it is conditioned on being “accurate and complete.” That is a specificity level most marketing teams have never produced about a pricing model, and it is a factual assertion about system behavior that has to survive discovery.

“Clear and conspicuous” is not a vibe; it is a body of FTC doctrine. The Commission’s .com Disclosures guidance and its “Made in USA”–era conspicuousness principles converge on the same factors: proximity to the claim qualified, prominence, absence of distracting elements, same medium, and comprehensibility to ordinary consumers. The Fees Rule and ROSCA — both cited in footnote 15 as potentially co-violated — apply a nearly identical standard before payment information is collected. Applied to a real checkout flow:

  • A privacy policy link fails. It fails on proximity (it is not at the price), on prominence (it is boilerplate footer text), and on the settled principle that material terms cannot be buried in a hyperlinked document a consumer is not required to open. A terms-of-service acceptance fails for the same reasons, plus the problem that consent to data processing is a different question from disclosure of a price attribute.
  • The disclosure has to travel with the price. Prices appear on category pages, search results, product detail pages, cart, checkout, emails, push notifications, and app widgets. Each is a separate surface. The New York statute discussed below makes this explicit — “in the same medium as, and provided on, at, or near and contemporaneous with every advertisement, display, image, offer or announcement of a price.”
  • Dark-pattern doctrine constrains the presentation. The FTC’s Bringing Dark Patterns to Light framework treats disclosures that are technically present but practically ignorable — low-contrast text, collapsed accordions, hover-only tooltips — as themselves deceptive. A disclosure engineered for minimum comprehension is worse than none, because it demonstrates intent.

The State Overlay Is the Nearer Risk

An organization reading only the federal document will misallocate its attention. A binding obligation already exists in New York.

New York’s Algorithmic Pricing Disclosure Act, N.Y. Gen. Bus. Law § 349-a, enacted as part of the 2025–2026 budget bill (S3008C), requires any business using “personalized algorithmic pricing” to make a clear and conspicuous disclosure in exactly these words: “THIS PRICE WAS SET BY AN ALGORITHM USING YOUR PERSONAL DATA.” The definitions are broad — “personal data” is “any data that identifies or could reasonably be linked, directly or indirectly, with a specific consumer or device,” carving out location data used by ride-hailing services. Insurers and regulated financial institutions are exempt. Enforcement rests with the Attorney General, who must first issue a cease-and-desist with an opportunity to cure, and may then seek injunctive relief and civil penalties of up to $1,000 per violation — with “violation” undefined, which is the entire exposure question.

The National Retail Federation challenged the Act in the Southern District of New York, arguing compelled speech and that the statute is “replete with arbitrary exemptions.” On October 8, 2025, the court denied a preliminary injunction and granted New York’s motion to dismiss, applying the deferential Zauderer standard for compelled disclosure of purely factual, uncontroversial commercial information. Enforcement began November 10, 2025, with no grace period; NRF’s appeal is pending in the Second Circuit. Attorney General Letitia James solicited complaints in a November 2025 consumer alert and on January 8, 2026 sent an information demand to Instacart regarding “recent reports of substantial price variations among shoppers.”

Two structural points follow. First, the New York disclosure is not sufficient for the FTC’s test. Section 349-a mandates a fixed sentence stating that the price is algorithmic and personal-data-driven; the FTC statement requires the basis and the data types in addition. A retailer that has implemented New York compliance has satisfied one element of three.

Second, California is the next domino, and it is worth naming the right bill. SB 259 (Wahab), the “Fair Online Pricing Act,” was the 2025 vehicle; the live 2026 measure is AB 2564, which cleared the Assembly in May 2026 and would prohibit surveillance pricing rather than merely require its disclosure. The two regimes demand different architectural responses: disclosure can be bolted onto a presentation layer, but prohibition requires the personalization to be removable from the pricing engine.

Layered on top is the state privacy law profiling and ADMT apparatus, which reaches personalized pricing directly. Colorado’s Privacy Act gives consumers an opt-out right from profiling in furtherance of decisions producing legal or similarly significant effects. California’s CCPA regulations on automated decision-making technology carry compliance obligations beginning January 1, 2027 — pre-use notice, opt-out rights, and access rights covering the logic of the decision — and pricing based on inferred consumer characteristics is the archetype of a covered use. We covered that timeline in the CCPA ADMT January 2027 deadline analysis; read against the FTC statement, the overlap is nearly total. The FTC wants the basis and data types disclosed at the point of price; the CPPA wants pre-use notice and an opt-out for the same inference. One data inventory answers both.

The Data Provenance Problem Nobody Planned For

Here is the requirement that will break implementations: you cannot disclose “the types of data on which the personalization is based” unless you can enumerate the features of your pricing model. Most pricing teams cannot. A mature dynamic-pricing system is an accreted stack of engineered features, embeddings, and third-party enrichment signals, some opaque by construction. The failure modes:

  • Purchased and brokered signals. If a vendor supplies household composition, income band, propensity scores, or device-graph identifiers into the model, “the types of data” includes those. Your disclosure obligation extends to inputs you did not collect, and the FTC has been willing to hold companies liable for downstream use of brokered data without verified consent — the theory developed in the location-data cases covered in the Kochava geolocation enforcement analysis. The statement makes the point directly: businesses that “base personalized prices on personal data of consumers without sufficiently verifying that consumers consented to the collection of those data for that purpose may violate Section 5.”
  • Learned proxies. A model given ZIP+4 and browsing depth will approximate income without anyone naming income as a feature. If the disclosure says the price is based on browsing history and the model is functionally pricing on inferred income, the disclosure is not “accurate and complete.”
  • Embedded third-party SDKs. Tracking pixels and session-replay tooling feeding personalization pipelines are a documented FTC enforcement seam, from the Hims & Hers pixel and ROSCA matter to the ad-tech surveillance theories in the Cox Media “active listening” analysis.

The remediation is unglamorous: feature lineage documentation, a model card naming every input class in consumer-comprehensible language, and vendor contract terms requiring the data supplier to represent the categories and lawful basis of what it provides and to permit their disclosure to consumers. That last term is in almost no data-enrichment contract, because until now nobody had to tell the consumer.

The Pre-September 18 Action List

  • Determine whether personalization is occurring at all. This is not rhetorical. Segment-level pricing, geographic pricing, A/B price testing, loyalty tiers, and cart-abandonment discounts sit on a spectrum, and only some are “prices set on the basis of data specific to that consumer.” Get a written, dated answer from the team that owns the pricing service, not from marketing.
  • Inventory the pricing logic surface — every code path that can produce a different price for two simultaneous shoppers, including experimentation platforms and coupon engines, which are frequently outside the pricing team’s map.
  • Classify the inputs. Every feature, grouped into consumer-comprehensible categories, with source and provenance. Flag third-party data and anything that could proxy for a protected or sensitive characteristic.
  • Assess your market’s expectation baseline and document the reasoning, because it is the first line of defense on the reasonable-consumer element.
  • Draft the disclosure and place it. Three elements, at every surface where a price appears, in the same medium, contemporaneous with the price. Test it for comprehension, not click-through.
  • Reconcile with New York now if you sell there — § 349-a is enforceable today — and with the CCPA ADMT obligations that bite January 1, 2027.
  • Decide whether to comment by September 18. Retailers with genuine customary-variation arguments, trade associations, data providers, and anyone who thinks the FCRA analogy overreaches all have concrete stakes. Comments are the only mechanism to shape the final text, and the record they build is the record a court reads later.

Conclusion

The vote authorizing the Federal Register notice was 2-0, with no dissenting or separate statements — worth stating plainly, because that is not the same thing as broad consensus. A 2-0 vote reflects a Commission operating with two sitting members. A policy statement adopted on that basis is durable exactly as long as the current Commission’s priorities are, and a differently composed Commission could revisit it without notice and comment, precisely because policy statements are not rules. That cuts both ways: it is a weaker signal of permanence than a rulemaking, and a stronger signal of near-term staff behavior than almost anything else the agency publishes.

The right posture is therefore not “wait for the final version.” The three-element disclosure test is not novel law; it is the deception framework and § 45(n) applied to a pricing practice, with Standard Education Society — a 1937 case about the words “specially selected” — supplying the direct precedent. New York already compels a narrower version of the same disclosure and has begun enforcing it. California is drafting a prohibition. The CPPA’s ADMT clock runs to January 1, 2027.

The work that satisfies all of them is the same work, and it starts with a question most organizations cannot currently answer: what, exactly, are the inputs to our prices? Firms that can answer it have a compliance project. Firms that cannot have a discovery problem.

Sources: FTC — FTC Seeks Comment on Enforcement Policy Statement Regarding Personalized Pricing (Aug. 19, 2026), FTC — Proposed Enforcement Policy Statement Regarding Personalized Pricing, Matter No. P034101 (PDF), WilmerHale — FTC Issues Proposed Policy Statement on Personalized Pricing, Hunton — FTC Proposes Enforcement Policy Statement on Personalized Pricing, Paul, Weiss — FTC Proposes Enforcement Policy Statement on Personalized Pricing, Sheppard Mullin — FTC Proposes Enforcement Policy Statement Regarding Personalized Pricing, Duane Morris — New York’s Algorithmic Pricing Disclosure Act Is in Effect, Troutman — New York Algorithmic Pricing Disclosure Act Upheld as Constitutional, NRF — NRF Asks Federal Court to Block New York Algorithmic Pricing Law, Crowell & Moring — Surveillance Pricing Update: California’s AB 2564

This article is provided for informational purposes only and does not constitute legal advice.