Surveillance Pricing: When the Price Knows Who You Are

Estimated Time to Read: 57 minutes

Bottom Line Up Front (BLUF)

Businesses can now use personal data to decide what each individual shopper pays, and federal regulators have confirmed that the tools exist and are being sold. What the public record does not yet show is how widely retailers actually use them. Instacart's price experiments and Delta Air Lines AI pricing both produced real price variation, and both companies deny that personal data drove it. Walmart has promised the opposite of surveillance pricing outright: "We price the product, not the person." Prices that move with supply, demand, inventory, and cost are ordinary market behavior, and personalized discounts can make products affordable for people who would otherwise walk away. The liberty problem is narrower: a business using a hidden profile to estimate what one particular person will tolerate, and a consumer who cannot see that it happened.

The 90th Legislature should require honesty rather than uniform prices. Texas should mandate plain-language disclosure when personal data materially affects a price, fee, discount, or offer; preserve a nonpersonalized option for consumers who decline profiling; place firm limits on using sensitive data such as precise location, health, and children's information to raise prices; extend access and deletion rights to the inferences that drive pricing; and enforce existing deceptive-trade-practices law against companies that misrepresent how a price was set. It should also close the data-broker loophole, so state and local agencies cannot purchase information they would need a warrant to compel. Texas does not need a pricing board to require honest dealing.

Table of contents

Imagine that your washing machine stops working on a Sunday evening. You open a shopping app and search for a replacement. The retailer knows that you have searched for the same model several times, that your phone recently entered one of its stores, that you live in a relatively affluent neighborhood, and that consumers exhibiting similar behavior rarely wait for a sale.

The price on your screen looks ordinary. What you cannot see is whether another customer received a lower price, a better coupon, free delivery, or a cheaper recommendation. You also cannot tell whether the difference reflects inventory and transportation costs or whether an algorithm concluded that you urgently need the appliance and are unlikely to walk away.

The first possibility is ordinary pricing. The second may be surveillance pricing.

The controversy is not simply about businesses changing prices. Prices have always changed. Airlines adjust fares as seats fill. Hotels charge more during major events. Retailers mark down excess inventory. Restaurants offer discounts during slow hours. These practices can coordinate supply and demand, reduce waste, and communicate scarcity.

Surveillance pricing introduces something different. Instead of asking what the market will bear, a business uses personal data, behavioral observations, or inferred characteristics to estimate what a particular person will bear.

That practice sits at the intersection of free enterprise, privacy, consumer protection, artificial intelligence (AI), and the Fourth Amendment. It also presents a difficult question for anyone who values both voluntary exchange and limited government: How can Texans be protected from hidden profiling without placing government in charge of private prices?

The answer begins by recognizing that not all algorithms, price changes, or personalized offers are the same.

What Surveillance Pricing Is, and What It Is Not

Surveillance pricing occurs when a business uses personal data, behavioral observations, or inferred characteristics to influence the price, fee, discount, product ranking, financing term, or offer presented to a particular consumer. The defining feature is not merely that software was involved or that two people paid different amounts. It is that information about an individual, household, device, or behavioral profile materially affected the economic treatment that person received.

Public discussion frequently treats algorithmic pricing, dynamic pricing, personalized pricing, and surveillance pricing as interchangeable. They overlap, but they describe different practices.

Algorithmic pricing is the broadest category. It simply means software recommends or establishes a price. An algorithm might implement a routine markdown schedule, calculate transportation costs, monitor publicly advertised competitor prices, or adjust for inventory. It might also personalize an offer. The involvement of artificial intelligence does not, by itself, establish that the resulting price is individualized, deceptive, or abusive.

Dynamic pricing changes a price according to conditions surrounding the transaction. Those conditions can include supply, demand, available inventory, time, season, weather, location, capacity, or the cost of providing the product. A ticket may cost more for a rivalry game. A hotel room may cost more during a convention. A rideshare trip may cost more when many passengers are competing for relatively few drivers. The price can change quickly without depending on the identity or private characteristics of the buyer. Everyone seeking the same product under the same conditions may encounter the same price.

Personalized pricing occurs when different consumers receive different prices, discounts, or economic terms. Some forms are familiar and transparent. Senior discounts, military discounts, student admission prices, loyalty rewards, negotiated business rates, retention offers, and coupons all personalize what someone pays. A personalized discount is not necessarily surveillance pricing. A customer may voluntarily present a coupon or prove eligibility for a publicly disclosed discount. The terms are visible, and the customer understands why the price differs.

Surveillance pricing is the more concerning subset. It uses information gathered or inferred about a person to determine individualized economic treatment, frequently without the person understanding that the personalization occurred. The seller is no longer merely pricing the product or responding to the market. It is attempting to price the person.

Not All Price Changes Are Equal
The technology, the market signal, and the use of personal data are separate questions.
Algorithmic pricingDynamic pricingPersonalized pricingSurveillance pricing
How it worksSoftware recommends or sets the price.The price responds to supply, demand, inventory, time, capacity, or cost.Different buyers receive different prices, discounts, or terms.Personal data or inferred traits set one buyer’s economic treatment.
ExampleAn automated inventory markdownA higher-priced ticket for a rivalry gameA senior discount or a coupon the shopper presentsAn offer tuned to a behavioral profile
Same conditions, same price for everyone?Not necessarilyYesNoNo
Does personal data drive the difference?Not necessarilyNoNot necessarilyYes
Can the buyer see why?Depends on the useGenerallyUsuallyOften not
Software sets many prices. The question is whether a hidden profile of the buyer set this one.
Texas Policy Research
Where Principle Meets Policy

These distinctions should guide any policy response. A blanket restriction on changing prices would interfere with ordinary market coordination and could eliminate beneficial discounts. A narrower response can focus on hidden data use, sensitive information, deception, and the absence of meaningful consumer choice.

How Personal Data Becomes a Price

A surveillance-pricing system can begin with information a business collects directly from its relationship with a customer. This first-party data may include purchases, searches, abandoned shopping carts, clicks, customer-service conversations, coupon use, loyalty activity, account history, location, and responses to previous offers.

A mobile application may reveal whether someone is inside or near a store. A loyalty account may show that a household purchases certain products every week. An online account may show that the customer repeatedly returns to the same page without completing the purchase. The business can supplement that information with data obtained from brokers, advertising companies, analytics providers, public records, applications, websites, and location services. These sources can reveal or support inferences about income, household composition, home ownership, employment, travel, interests, health concerns, political engagement, religious activity, and major life events.

The system does not need to know the person's legal name. A cookie, device identifier, advertising ID, loyalty number, hashed email address, or probabilistic identity match may be enough to recognize the same person or household across multiple transactions. Information described as anonymous may still be highly specific, because combining location, device, purchasing, and household information can make it possible to recognize a person even when a name has been removed.

Once the data has been matched, a model can estimate price sensitivity, urgency, the probability that the customer will leave, the likelihood that a discount is necessary, or the highest amount the consumer is predicted to accept. The model then produces an economic outcome. That outcome might be a different base price. It might also be a higher delivery fee, a personalized coupon, a less favorable financing term, free delivery for one consumer but not another, a premium product placed at the top of search results, or the decision to withhold an offer.

Two consumers may therefore see the same listed price while receiving materially different economic treatment. One receives a coupon or a cheaper recommendation. The other never learns that a better offer existed. Surveillance pricing is not limited to visible surcharges. The personalization can occur through the benefits, choices, and opportunities that are shown or withheld.

How Personal Data Becomes a Price
Personalization can change what a person pays, and what a person is shown.
1Collect
First-party data

Purchases, searches, abandoned carts, coupon use, loyalty activity, location, account history

Brokered data

Location history, public records, app and website activity, household and income inferences

2Match
Identity matching
  • Cookie
  • Device or advertising ID
  • Loyalty number
  • Hashed email
  • Probabilistic match

No legal name required. Location, device, and purchases combined can single out a person.

3Predict
Estimates
  • Price sensitivity
  • Urgency
  • Likelihood of leaving
  • Whether a discount is needed
  • The most this buyer will accept
4Treat
Changes what you pay
Base priceDelivery or service feeFinancing term
Changes what you see
Personalized coupon or free deliveryProduct rankingAn offer withheld
Two shoppers can see the same listed price and still receive different deals.
Texas Policy Research
Where Principle Meets Policy

Why Surveillance Pricing Is Difficult to Detect

Traditional comparison shopping assumes that consumers can observe the available market. A person visits several stores, compares advertised prices, considers quality, and chooses whether to purchase.

Surveillance pricing can fragment that shared marketplace. Each consumer may see a customized version shaped by account history, cookies, location, device identifiers, and behavioral predictions. The person knows what was offered but cannot see the counterfactual. The consumer does not know what someone else saw or what would have appeared without the personal profile.

Even placing two phones next to each other may not resolve the question. The devices can carry different account histories, cookies, applications, identifiers, and location records. A business may also run temporary experiments involving only a small group of users. The pricing model itself may be supplied by a third-party intermediary, and the retailer may not know, or may not be willing to explain, every variable contributing to the recommendation.

This opacity changes the traditional bargaining relationship. Sellers have always known their costs and desired margins, while buyers have retained private knowledge about their own needs and willingness to pay. Surveillance pricing can give the seller a detailed estimate of the buyer's private side of the negotiation without giving the buyer comparable visibility into the seller's method.

That informational imbalance does not automatically establish fraud or illegality. It does make personal responsibility and market competition more difficult to exercise. Consumers cannot knowingly withhold data, correct an inaccurate profile, comparison shop, or reject a practice that remains invisible.

What the Evidence Actually Shows

Concern about surveillance pricing is not based entirely on speculation. In 2024, the Federal Trade Commission (FTC) ordered eight pricing intermediaries to provide information about their use of consumer data and algorithmic pricing products. The companies advertised tools capable of combining AI with information such as location, demographics, credit history, browsing activity, and shopping behavior.

The FTC's initial findings, released in January 2025, described intermediaries with access to direct, inferred, first-party, and third-party data. According to the agency, those systems could influence the prices, promotions, and products presented to consumers.

Those findings are significant, but they should not be overstated. They demonstrate that businesses possess and market the capability to use personal information in pricing and promotional decisions. They do not prove that every retailer uses individualized prices or that every widely circulated allegation is accurate.

A credible analysis should distinguish among capability, experimentation, and confirmed practice. Capability means a technology could support individualized pricing; electronic shelf labels, loyalty systems, AI assistants, location-aware applications, and advertising profiles may all contribute to such a system, but their existence does not prove that personal data affected a price. Experimentation occurs when different consumers or groups receive different prices so a business can observe their reactions, and an experiment may be random rather than based on individual characteristics. Confirmed surveillance pricing requires evidence that personal data or an individualized inference materially affected the economic treatment a consumer received.

Price variation alone does not establish which category applies. Three recent examples show why. The FTC has since proposed an enforcement approach built on that same distinction, discussed later in this analysis.

What the Evidence Actually Shows
Capability, experimentation, and confirmed personal-data use are different levels of proof.
FTC pricing study
Orders issued 2024; initial findings January 2025

Eight intermediaries marketed tools combining AI with location, demographics, credit history, and browsing to shape prices, promotions, and product displays.

Electronic shelf labels and loyalty apps also belong here: they enable fast price changes, not proof of individualized prices.

Capability

The tools exist and are sold.

Instacart price tests
Consumer Reports investigation, 2025

Shoppers saw different prices for the same item, from the same store, at about the same time.

Instacart says test groups were assigned at random by product category and location, not personal data, and has ended the tests.

Experimentation

Different buyers see different prices so a company can study reactions.

Alleged; Delta denies
Delta AI pricing
Public scrutiny, 2025

Critics feared AI would estimate each passenger’s willingness to pay.

Delta says its pricing tool receives no personal customer data and it has never targeted individual fares.

Confirmed use

Evidence that personal data materially changed what a specific consumer paid or was offered. Price variation alone does not reach this step.

We price the product, not the person.
Walmart President and CEO John Furner, September 2026. A public commitment that can now be measured against the company’s conduct.
Texas Policy Research
Where Principle Meets Policy

Instacart: Different Prices, but Disputed Surveillance

A 2025 Consumer Reports investigation involving hundreds of shoppers found that Instacart users could be shown different prices for the same products from the same store at approximately the same time. The investigation found differences across numerous products and reported that the highest and lowest versions of a grocery basket could differ materially. Instacart subsequently ended the item-price testing program and said that shoppers purchasing from the same store would once again see the same item prices.

The episode documented price experimentation and raised serious transparency questions. Customers generally did not know that they were participating in pricing tests or that other shoppers could receive different prices.

Instacart nevertheless denied using personal information, demographics, income, or individual shopping behavior to assign those prices. It said customers were placed randomly into test groups according to product category and location. If that description is accurate, the practice was algorithmic and individualized in its result, but it was not surveillance pricing under the definition used here.

That does not resolve whether the testing should have been disclosed more prominently or whether consumers reasonably believed they were seeing a common price. It does demonstrate why different prices should not automatically be treated as proof that personal data caused the difference.

Delta: AI Pricing Without Individual Customer Data?

Delta Air Lines generated similar scrutiny after discussing its use of AI to help inform pricing decisions. Critics feared that the airline could use AI to estimate what each passenger was willing to pay.

Delta has repeatedly denied doing so. The company says it does not provide its AI pricing tool with personal information about customers and has never used, tested, or planned a fare product targeting individual passengers with prices based on their personal data.

Airfares can still vary considerably according to route, capacity, booking time, demand, fare class, and other market conditions. AI may make those calculations faster and more sophisticated. That does not necessarily convert dynamic pricing into surveillance pricing.

Delta's denials should not foreclose scrutiny, but allegations should not be presented as established facts without evidence. The relevant inquiry remains what information enters the model and whether the passenger's identity or personal circumstances influence the fare.

Walmart: Price the Product, Not the Person

As Walmart expanded electronic shelf labels and deployed its Sparky AI shopping assistant, customers and critics questioned whether those technologies could eventually support dynamic or individualized pricing.

In September 2026, Walmart President and CEO John Furner issued a public response built around a simple promise: "We price the product, not the person."

Walmart did not promise that prices would never change. Furner acknowledged that prices may rise or fall because the cost of purchasing or transporting a product changes. What the company rejected was changing a customer's price according to identity, income, shopping history, urgency, perceived willingness to pay, or the time of day. Walmart also promised that information consumers provide to Sparky will not be used to increase their prices or hide lower-priced products that meet their needs, and said employees will continue overseeing pricing while its systems are monitored and tested against those commitments.

The announcement does not establish what every retailer will do, and a corporate promise is not an industrywide rule. It nevertheless demonstrates why precision is necessary.

Electronic shelf labels have become a symbol of this debate because they allow retailers to update displayed prices rapidly from a central system. They reduce the labor required to replace paper tags, correct discrepancies between shelf and checkout prices, support faster markdowns, and help stores manage perishable inventory. They also make frequent price changes easier. But a single electronic label visible to everyone standing in an aisle still displays a common price. To personalize an in-store price, a retailer would need an additional mechanism to identify the shopper and alter the economic terms through an application, personalized coupon, digital display, account-linked checkout price, or similar system. The concern is not the label in isolation. It is the potential combination of rapid price-management systems with location-aware applications, loyalty accounts, cameras, device tracking, identity matching, and detailed behavioral profiles. Regulating the hardware as though it were itself an abusive practice would confuse technological capacity with actual conduct.

Walmart's announcement also demonstrates the potential for market accountability. Public scrutiny prompted the nation's largest retailer to draw a clear line for its customers, and that commitment can now be measured against the company's future conduct. If Walmart keeps its promise, consumers benefit. If it secretly abandons the promise, existing laws against deceptive practices may provide a more targeted remedy than broad government control of retail prices.

The principle is straightforward: Businesses should remain free to price products according to legitimate market conditions, but consumers deserve to know when a business is instead pricing the person.

Where Surveillance Pricing Could Appear

Retail is the most intuitive application. A seller could adjust prices, shipping charges, product rankings, coupons, or financing terms based on purchase history, location, device, inferred income, brand loyalty, or previous reactions to discounts.

Travel presents an especially sensitive environment because prices already change frequently and urgency can be high. Airlines, hotels, rental-car companies, and ticket platforms know when someone searched, where the person is traveling, whether the person has an account, and how often the person returned to the page. A legitimate model may respond to remaining capacity and market demand. A surveillance-pricing model could attempt to infer that a consumer is traveling for a medical emergency, a court date, or another event that makes walking away difficult.

Transportation and delivery platforms necessarily consider origin, destination, distance, driver availability, and local demand. Those factors help estimate the cost of providing the service. The concern arises if the platform also uses account history, income proxies, or previous acceptance behavior to calculate how much a specific user will tolerate.

Subscription businesses can predict which customers are likely to cancel and offer them lower renewal prices. That discount can benefit both parties by preserving a transaction that otherwise would have ended. The same system can penalize loyal or inattentive customers by reserving favorable terms for those who threaten to leave.

Financial services and insurance already use individualized information because risk differs among customers. Credit history, claims history, and collateral may be directly relevant to a transaction. The concern is not all risk-based pricing. It is the use of unrelated browsing behavior, location history, political activity, or inferred vulnerability to influence an interest rate, premium, or credit offer.

Health care presents even higher stakes. Financial information may appropriately determine eligibility for assistance or a payment plan. Browsing history, inferred illness, or apparent desperation should not become a tool for calculating the highest price a patient will accept for medicine, urgent treatment, or transportation.

Related techniques could eventually affect rents, wage offers, scholarships, tuition discounts, employment opportunities, legal-service fees, and professional payment plans. In each setting, the individual receives different economic treatment based on a profile that may be impossible to inspect.

AI Assistants Can Serve the Buyer or the Seller

Consumer-facing AI agents could become a powerful defense against exploitative pricing. An agent working faithfully for the buyer could compare hundreds of sellers, locate discounts, monitor fees, identify unfavorable contract terms, and refuse manipulative offers. Such a tool could become one of the strongest comparison-shopping technologies ever created.

The danger is that many AI shopping assistants are operated by retailers, marketplaces, advertising companies, or platforms with financial interests in the transaction. The assistant may know what the consumer purchased, what the consumer searched for, what problem needs to be solved, and how urgently the consumer needs a result. It may appear to represent the consumer while steering that person toward products, sellers, or prices that benefit the operator.

Consumers should therefore know who controls the agent, how its operator is compensated, whether paid placement affects recommendations, whether the agent favors the operator's products, and whether information disclosed in conversation can influence prices or offers. A tool presented as the consumer's assistant should not secretly convert the consumer's disclosures into leverage for the seller.

Personalized Pricing Can Benefit Consumers

The case against surveillance pricing should not ignore the potential benefits of personalization. A business may use information to identify a price-sensitive customer who will not purchase at the standard price. Offering that person a discount can produce an additional sale while giving the consumer access to a product that might otherwise be unaffordable.

Personalized discounts can reduce abandoned purchases, expand access, reward loyalty, and help businesses cover fixed costs without reducing the standard price for every customer. Revenue-management systems can also reduce waste by moving inventory that would otherwise expire or remain unused.

The Cato Institute has argued that broad prohibitions could capture beneficial practices such as loyalty rewards, retention offers, happy hours, and individualized bargaining. The Washington Legal Foundation has similarly argued that prohibiting personalized grocery prices could prevent businesses from offering below-market discounts to price-sensitive consumers.

Those objections deserve serious consideration. A rule requiring every person to receive exactly the same price could eliminate discounts without preventing businesses from raising their general prices. Consumers who previously received targeted savings might pay more rather than less.

Competition also constrains a seller's ability to impose a personalized surcharge. A retailer that asks substantially more than the prevailing market price risks losing the customer to a competitor. Personal data may consequently be more valuable for identifying who needs a discount than for identifying who can be charged more. But competition is not a complete answer. Its protective force depends on consumers knowing that they received an unfavorable offer, having practical alternatives, and being able to compare those alternatives. Urgency, switching costs, geographic isolation, essential needs, and market concentration can weaken the ability to walk away. A rural family with one nearby grocery store, a traveler responding to a death in the family, or a parent seeking medicine for a sick child does not necessarily inhabit the frictionless market described in an economics textbook.

The same personalization model can therefore produce two very different outcomes. It can offer a discount necessary to complete a mutually beneficial transaction, or it can identify vulnerability and capture more of the consumer's willingness to pay. That uncertainty supports transparency and choice rather than blanket price controls.

Loyalty Programs and the Price of Participation

Loyalty programs demonstrate both the value and danger of commercial data collection. Consumers may voluntarily exchange purchase information for points, discounts, personalized coupons, or convenience. Retailers can use aggregated purchasing information to anticipate demand, manage inventory, and design promotions. Nothing about that exchange is inherently illegitimate.

The relationship becomes less voluntary when joining a loyalty program is the practical price of receiving an ordinary market rate, when the terms are buried in lengthy policies, or when information collected to administer rewards is sold or repurposed for unrelated profiling.

A customer who scans a loyalty card may reasonably expect the store to remember purchases and calculate points. The customer may not expect that history to be combined with brokered location data, household characteristics, and behavioral predictions to determine how much of a discount is necessary for that individual.

Kroger's data analytics and retail-media operations illustrate how purchasing information can become an asset beyond the checkout line. That business does not prove that Kroger secretly assigns individualized shelf prices. It demonstrates that grocery transactions can support extensive data and advertising systems capable of influencing what products, promotions, and messages consumers see.

The appropriate response is not to assume wrongdoing. It is to provide a clear account of how loyalty information will be used and prevent data collected for one purpose from silently migrating into an unrelated consequential decision.

Algorithmic Collusion Is a Different Problem

Surveillance pricing concerns information about a consumer. Algorithmic collusion concerns the use of technology or shared information to weaken competition among sellers.

A business does not collude merely by using software to monitor publicly available prices. Automating that process can improve price discovery and produce faster price reductions as well as increases. The concern becomes stronger when competing firms provide current, nonpublic information to the same pricing intermediary and that intermediary uses the information to coordinate recommendations throughout the market. A common vendor can potentially become the hub connecting otherwise competing spokes.

Existing antitrust law already asks whether businesses reached an agreement, exchanged competitively sensitive information, restrained trade, or harmed competition. As Cato's analysis of automated collusion explains, those questions should not be replaced with a presumption that common software constitutes a cartel. Businesses should not be able to accomplish through a shared algorithm what they could not lawfully accomplish through direct communication, but the use of an algorithm alone should not establish conspiracy. The law should address harmful conduct rather than the mere existence of technology.

When Profiling Moves Beyond Price

The most important issue extends beyond prices. Surveillance pricing is one possible use of an infrastructure designed to observe, identify, classify, predict, and influence individuals. The same location history, purchasing profile, device identifier, or inferred characteristic can be used for advertising, employment screening, insurance, political persuasion, fraud prevention, or government investigation.

This creates a purpose problem. A person may share location with a weather application, purchasing information with a grocery store, or contact information with a retailer for a legitimate and limited reason. Once that information enters the broader commercial market, it can be combined and used for purposes the person never contemplated. Formal consent buried in a privacy policy is not necessarily informed agreement to every possible downstream use.

Data brokers make accountability more difficult because most consumers have no direct relationship with them. A person may not know which companies possess the information, where it originated, what conclusions were inferred from it, or which businesses and government agencies purchased access. Inaccurate information can follow someone through multiple systems while remaining difficult to discover or correct. Security risks compound the problem, because a dataset detailed enough to influence prices is also valuable to criminals, stalkers, foreign governments, and political operatives. Information that is never collected, or that is deleted when no longer needed, cannot later be breached, sold, subpoenaed, or repurposed.

The consequences reach well past the checkout screen. What if an insurance company concludes that attending political demonstrations indicates a higher risk of injury or property damage? What if a financial institution treats donations, news subscriptions, or controversial online speech as indicators of reputational risk? What if a travel platform charges more because location history suggests a traveler is visiting a hospital, a divorce attorney, or an addiction-treatment center? What if a person gradually loses access to discounts, credit, or digital services because an unseen model has classified that person as undesirable?

None of that requires government to announce a formal social-credit score. A similar practical result could develop through decentralized systems that share identifiers, purchase information from the same brokers, use similar risk models, or inherit one another's conclusions. Traditional credit scores are at least designed for a defined purpose, calculated within an established legal framework, and accompanied by rights to access information, dispute inaccuracies, and understand adverse decisions. A behavioral reputation assembled through commercial surveillance may have no common definition, visible number, accountable institution, or meaningful appeal. One platform's inference becomes another company's input, and the second company's decision generates data that appears to validate the original conclusion. An inaccurate judgment can quietly become self-reinforcing.

The consumer may never see a score. Instead, the judgment appears through accumulated outcomes: a higher deposit, worse financing, additional identity checks, fewer product choices, a delayed transaction, a withheld discount, or an unexplained account closure. That is why the line between pricing and permission is thin. A business does not have to issue a formal denial if it can impose a price, fee, delay, or procedural burden that makes participation practically impossible. The person technically remains eligible, but only on terms designed to drive that person away.

How easily these profiles connect depends heavily on how identity is verified online. A carefully designed digital credential can confirm a narrow fact, such as whether someone meets an age requirement, while revealing less than handing a stranger a physical identification card. A mandatory, persistent identifier linked across unrelated activities does the opposite, creating the key that allows institutions to recognize and evaluate a person everywhere.

Prices make these consequences measurable in dollars. The same infrastructure becomes far more consequential when it affects employment, credit, transportation, housing, health care, or the ability to participate in public life.

When Lawful Politics Becomes a Risk Signal

The danger is not merely that an algorithm might know someone's formal political affiliation. It is that partisan loyalty, ideological belief, religious practice, civic activity, or lawful association could become an economic variable.

Political characteristics can be inferred without asking anyone to identify as a Republican, Democrat, libertarian, conservative, progressive, or independent. Models can draw conclusions from campaign donations, voter-registration records, media subscriptions, organizational memberships, event attendance, purchasing patterns, location history, social-media activity, and relationships with other people.

The resulting inference may be wrong. A person might attend a rally as a journalist, drive a relative to a political event, visit a campaign office as a vendor, or enter a religious institution for a community program. A device might be shared among several family members. A purchase may be a gift rather than an expression of belief. An algorithm can nevertheless attach a political or ideological classification to that person, and if the classification remains secret, there may be no practical opportunity to challenge it.

The concern grows when an inference moves between systems. A political-risk label created for advertising could become a financial-risk indicator. A location record collected for navigation could become evidence of association. A consumer profile developed for pricing could later attract government attention.

Political freedom depends on the ability to speak, associate, donate, organize, worship, investigate controversial ideas, and attend public events without fear that invisible systems will impose economic consequences. A society does not need an official partisan score to chill political participation. People may change their behavior once they reasonably believe that lawful association could affect prices, employment, insurance, credit, or access to financial services.

Private businesses possess their own rights of speech and association, and in many circumstances they may choose with whom to do business. A liberty-based approach should not casually replace private judgment with government control. The most serious constitutional danger arises when government officials encourage, pressure, or reward private companies for imposing consequences that government could not lawfully impose itself. A nominally private score becomes an instrument of state power when public officials influence its criteria, demand its application, threaten companies that refuse to cooperate, or purchase the information it produces.

The objective is not to guarantee every person access to every private product on identical terms. It is to prevent an opaque surveillance apparatus from converting lawful beliefs and associations into universal economic disabilities, especially when government participates in or exploits that process.

When Government Buys What Might Otherwise Require a Warrant

Commercial surveillance becomes still more consequential when government agencies purchase access to the information it produces. Private companies now collect location, identity, purchasing, and behavioral information at a scale that government could not easily have assembled in an earlier era. Law-enforcement and intelligence agencies may purchase commercially available data rather than compel it directly from a communications provider.

In Carpenter v. United States, the Supreme Court held that the government generally must obtain a warrant before acquiring extensive historical cell-site location records from a wireless carrier. The Court declined to apply the traditional third-party doctrine mechanically to a detailed record of someone's physical movements. But Carpenter did not answer every question involving commercially available location data, advertising identifiers, or datasets purchased from brokers.

That unresolved area is frequently described as the data-broker loophole. If an agency purchases information already offered on the commercial market, it may argue that it did not compel production and therefore did not need a warrant.

The Data-Broker Loophole
Two routes to the same sensitive location, identity, or behavioral information.
Compelled from a provider
Provider

A wireless carrier or service holds location records.

Warrant application

Government seeks the records through defined legal process.

Neutral judge

Access requires a finding of probable cause.

Purchased from a broker
App or website

Collects location or behavior, often for an unrelated purpose.

Data broker

Aggregates records from many sources and sells access.

Government purchase

WarrantJudge
A payment stands in for legal process.

Where both routes end
Government holds a detailed record

Movements, habits, associations, health concerns, religious activity, or political engagement.

From the individual’s side, the intrusion is substantially the same.

Carpenter v. United States (2018)
A warrant is generally required to obtain extensive historical cell-site records from a carrier. The Court did not settle purchases of commercially available data.
Does information lose its protection merely because an intermediary put it up for sale?
Texas Policy Research
Where Principle Meets Policy

From the individual's perspective, the intrusion may be substantially the same. The government obtains a detailed account of movements, habits, associations, health concerns, religious activity, or political engagement without first demonstrating probable cause to a neutral judge.

Government should not be permitted to outsource surveillance to private companies and then purchase the results as a substitute for constitutional process. Information should not lose meaningful protection merely because an application collected it and an intermediary offered it for sale. If government would need a warrant or another defined legal process to compel sensitive information directly from a provider, purchasing substantially equivalent information from a broker should generally require comparable authorization.

Commercial and governmental surveillance cannot be treated as unrelated debates. A law that constrains businesses while providing expansive government exemptions protects only part of the individual's liberty. Government should be at least as accountable for its use of sensitive information as the businesses it regulates.

Deletion, Downstream Control, and the Right to Be Forgotten

Texas Policy Research (TPR) previously examined the right to be forgotten, which concerns an individual's ability to seek removal of information that is outdated, unnecessary, or unlawfully processed. Surveillance pricing presents a related but narrower question: Even when information was collected lawfully, how much control should someone retain over its continued storage, sale, combination, and use in consequential economic decisions?

A broad power to remove truthful information from public access can conflict with freedom of speech, public records, historical preservation, and the public's legitimate interest in information. Those concerns are less pronounced when the issue involves nonpublic behavioral information retained indefinitely by commercial entities and repurposed for transactions unrelated to the reason it was collected.

Deletion becomes particularly difficult after information has moved through brokers, advertisers, analytics companies, and commercial clients. Deleting an account with the original business may not remove copies, derived inferences, or supposedly de-identified versions held elsewhere. Meaningful control may therefore require more than deleting a single record. It can involve identifying downstream recipients, correcting inaccurate source data, limiting incompatible secondary uses, and notifying processors when a valid deletion request has been made.

The goal should not be to give government the power to rewrite history. It should be to restore a measure of individual authority over nonpublic information and the commercial profiles derived from someone's daily life.

What Texas Law Already Provides

The Texas Data Privacy and Security Act, enacted as House Bill 4 (HB 4) during the 88th Legislative Session (2023), took effect on July 1, 2024. It gives covered consumers rights to determine whether a controller processes their personal data, access that data, correct inaccuracies, delete covered data, obtain a portable copy, and opt out of certain sales, targeted advertising, and profiling. The law also imposes duties involving privacy notices, data minimization, security, purpose limitation, and consent for processing sensitive data. The Texas attorney general has exclusive enforcement authority.

These protections may reach some of the practices underlying surveillance pricing, but Texas law does not clearly prohibit surveillance pricing as a category. Coverage may depend on the business, the information involved, whether the conduct qualifies as a sale or covered form of profiling, and whether an exemption applies. Consumers may also struggle to exercise their rights when they do not know personal data affected the transaction.

The Texas Data Broker Act provides registration, disclosure, and security requirements for covered brokers. Registration can improve visibility, but it does not provide consumers with a complete map of downstream transfers or independently prevent information from being used for pricing.

The Texas Deceptive Trade Practices Act may apply when a business misrepresents a price, conceals material information, or violates an express promise about data use. Walmart's commitments illustrate the point. If a company promises not to use personal information to set prices but secretly does so, the clearest legal problem may be deception rather than the mere fact that prices differed.

During the 89th Legislative Session (2025), Senate Bill 2567 (SB 2567), authored by State Sen. Royce West (D-Dallas), proposed treating the failure to disclose the use of artificial intelligence or algorithmic pricing systems as a deceptive trade practice. It did not become law, having never received a hearing in the Senate Committee on Business and Commerce. The proposal identified a legitimate concern but defined algorithmic pricing broadly enough to reach ordinary pricing software that does not use personal information. A more precise Texas approach would trigger disclosure when personal data materially affects the price, fee, discount, ranking, financing term, or offer presented to a particular consumer.

Other States Are Experimenting With Different Rules

States are beginning to take different approaches. New York requires disclosure when a business uses a consumer's personal data in algorithmic pricing, informing the consumer that the price was set by an algorithm using personal information. The National Retail Federation (NRF) challenged that requirement as unconstitutional compelled speech, and in October 2025 a federal district court dismissed the challenge, concluding that the mandated statement was factual, uncontroversial, and reasonably related to preventing consumer deception.

Connecticut, Maryland, and New Jersey enacted different restrictions in 2026, including rules affecting online transactions, food retailers, grocery delivery services, and uses of personal information. Some preserve exceptions for discounts or uniformly available promotions, while others impose broader limits.

These laws illustrate the choices Texas lawmakers could face. A state might require disclosure, prohibit only personalized price increases, regulate particular categories of sensitive data, focus on essential goods, or prohibit personal-data-based pricing more broadly.

Each approach carries tradeoffs. A broad ban may prevent exploitative surcharges but also eliminate targeted discounts. A disclosure rule preserves choice but may become meaningless if the notice is vague or buried. An industry-specific prohibition may address the most politically salient examples while producing inconsistent rules for similar conduct elsewhere. Texas should learn from these experiments without assuming that the most restrictive law is necessarily the most protective or liberty-preserving.

The FTC's Proposed Deception Approach

In August 2026, the FTC requested public comment on a proposed enforcement policy addressing personalized pricing. The proposal focuses on businesses that represent or imply that a price is generally available while secretly using personal data to vary prices among consumers. The agency observed that consumers commonly expect prices to change according to supply and demand, not according to browsing history or purchasing behavior.

The FTC did not claim authority to prohibit every form of personalized pricing. Its proposal instead centers on whether the company's representations or omissions mislead consumers about how a displayed price was produced.

That is a sound starting point. Enforcement should focus first on hidden practices, broken promises, misleading "best price" representations, and undisclosed material uses of personal information. The government does not need to determine the correct price to determine that a company lied about how it reached that price.

A Liberty-Based Framework for Texas

A principled Texas response should protect privacy without imposing price controls.

Individual liberty requires meaningful authority over sensitive information. Texans should not be covertly sorted into different economic realities according to their movements, beliefs, health, family circumstances, or private behavior.

Personal responsibility requires consumers to compare prices, evaluate terms, decide whether discounts justify data sharing, and walk away from unfavorable transactions. But responsibility is meaningful only when material information is available. A person cannot knowingly accept or reject a pricing practice that remains concealed.

Free enterprise requires that businesses remain free to respond to demand, manage inventory, negotiate, reward loyalty, offer discounts, and experiment with pricing. Government should not determine profit margins, mandate uniform prices, or presume that every algorithm is harmful. Rules should also be technologically neutral, because older statistical systems can personalize prices while advanced AI can manage inventory without touching personal information at all.

Private property applies on both sides. Businesses have legitimate interests in their technology, customer relationships, and proprietary pricing methods. Individuals have legitimate interests in information generated by their movements, purchases, devices, and private lives. Protecting consumers does not require publication of proprietary source code, because a clear description of the information used and its economic consequences can provide transparency without exposing trade secrets.

Limited government requires narrow rules, clear definitions, and equal restraint on the state itself. Regulators should enforce representations, privacy rights, consent requirements, and prohibitions against deception. They should not receive open-ended authority to declare prices fair or unfair. That same commitment requires legal process before agencies obtain sensitive brokered information. The state should not demand privacy discipline from private companies while reserving unrestricted access to the resulting dossiers for itself.

A Liberty-Based Framework for Texas
Require honest dealing, not uniform prices.
Leave to the market
Allow
Prices that respond to supply, demand, inventory, time, capacity, and cost, and discounts consumers can see and choose.
Require of businesses
Disclose
Plain-language notice, near the transaction, when personal data materially affects a price, fee, discount, financing term, ranking, or offer.
Offer a choice
A nonpersonalized option for consumers who decline profiling, where reasonably practical.
Limit sensitive data
No use of precise location, health, biometric, religious, political, or children’s information to raise prices.
Cover inferences
Access, correction, and deletion rights reach the conclusions drawn about a person, not only the raw data.
Enforce honesty
Apply the Deceptive Trade Practices Act to false “best price” claims, hidden personalization, and broken data promises.
Require of government
Require legal process
State and local agencies obtain a warrant before buying sensitive data they would need a warrant to compel.
Not on the list
A state pricing board, uniform-price mandates, or bans on pricing software.
Texas Policy Research
Where Principle Meets Policy

What Texas Should Consider

The most defensible first step is a clear disclosure requirement when personal data materially influences a price, fee, discount, financing term, product ranking, or offer. The trigger should be the consequential use of personal information, not the mere involvement of software. The notice should appear close to the transaction and identify the general categories of information involved. It should also be specific enough to mean something, because a vague statement that information is used to "improve your experience" provides no real transparency, and consumers should not have to search through a multi-page privacy policy to discover the basic nature of the bargain.

Texans should also have access to a nonpersonalized option where reasonably practical. A consumer who declines surveillance-based personalization could receive an offer based on ordinary factors such as supply, demand, inventory, location, capacity, and cost. This would preserve dynamic pricing while allowing individuals to refuse pricing based on a personal profile.

Sensitive information should receive stronger protection. Precise geolocation, health information, biometrics, religious beliefs, political activity, sexual orientation, immigration status, and information about children should not be used to increase prices. Some categories may warrant a prohibition rather than consent because the risks of coercion, discrimination, or manipulation are unusually high.

Texas should strengthen purpose limitation so that information collected to complete a delivery, prevent fraud, administer loyalty points, verify age, or provide customer service does not silently become an input for estimating maximum willingness to pay.

Access and correction rights should address consequential inferences as well as raw data. An algorithmic conclusion that someone is affluent, desperate, politically risky, unlikely to compare prices, or insensitive to fees may affect the consumer more than the underlying records used to generate it.

Valid deletion requests should follow information downstream within reasonable technical and legal limits. Businesses should remain able to retain records necessary for security, accounting, fraud prevention, contractual obligations, and legal claims. Those exceptions should not become a justification for indefinite commercial profiling.

Texas could clarify that materially misleading claims about a uniform, ordinary, lowest, or "best" price violate the Deceptive Trade Practices Act when a business secretly uses personal data to individualize the offer.

Auditing and recordkeeping can support enforcement without requiring disclosure of proprietary models. A business using personalized pricing could document the categories of information used, the stated purpose, consumer disclosures, testing procedures, and safeguards against unlawful discrimination.

Consumer-facing AI assistants should disclose conflicts of interest. Users should know whether an assistant accepts paid placement, favors its operator's products, receives compensation from sellers, or permits conversational information to affect prices and recommendations.

Finally, Texas should close the government data-broker loophole. State and local agencies should generally obtain a warrant or other legally required process before purchasing sensitive information that would require comparable authorization if compelled directly from a provider. Vendor contracts should be public. Searches should be logged. Retention should be limited. Emergency exceptions should be narrow. Individuals should have remedies when agencies intentionally evade applicable constitutional or statutory safeguards.

Price the Product, Not the Person

The future of surveillance pricing may not look like a digital shelf label flashing a higher number when an affluent customer enters the aisle. It will probably be subtler.

One shopper receives a coupon. Another pays a delivery fee. A third sees premium products first. A fourth receives unfavorable financing. Someone else never learns that a lower-cost option was available. Each person may believe he or she is participating in an ordinary marketplace while an invisible system decides which version of the market to reveal.

Not every personalized offer is abusive. The liberty concern begins when observation becomes undisclosed leverage. It becomes more serious when the resulting profiles move beyond pricing into credit, employment, insurance, transportation, identity verification, and access to essential services. It becomes still more serious when lawful political or religious activity becomes a hidden risk signal. And it becomes a constitutional concern when government agencies can purchase the same dossiers without the legal process that direct collection would require.

The dividing line is clear enough to state plainly. Businesses should remain free to price products according to supply, demand, inventory, cost, and competition. They should not secretly calculate what a particular person can be made to surrender by exploiting a dossier assembled from that person's movements, purchases, searches, relationships, beliefs, or moments of need.

Texas need not choose between innovation and privacy. It need not impose uniform prices to require honest dealing. It need not reject digital identity or data-driven commerce to insist on voluntary participation, limited disclosure, and constitutional government access.

The proper objective is narrower and more durable: preserve voluntary exchange, require honesty about individualized economic treatment, give Texans meaningful control over sensitive information, protect beneficial discounts and market competition, and prevent government from using commercial intermediaries to circumvent constitutional safeguards.

The central question is not merely whether two consumers paid different prices. It is whether one side of the transaction secretly knew nearly everything about the other and used that knowledge to decide how much money, privacy, opportunity, and bargaining power the other person could be made to surrender.


Support Our Work

Texas Policy Research relies on generous donors across Texas. If you found this helpful, please consider supporting our efforts.

Donate Today

Stay in the Loop

Subscribe for occasional emails with new research, event details, and ways to engage with Texas policy.

Subscribe for Updates