- Algorithmic pricing is not illegal anywhere. Two separate bodies of law govern it, and most write ups blur them into one.
- Pricing aimed at competitors is an antitrust question. Pricing aimed at an individual shopper is a consumer protection question.
- California AB 325 took effect on 1 January 2026 and defines a common pricing algorithm as one used by two or more persons that uses competitor data.
- There is no public data carve out in that definition, which puts ordinary third party repricing tools inside the frame.
- The DOJ settlement with RealPage attacked nonpublic data sharing and anti discount features, not the use of software to set prices.
- In the EU a trader who personalises a price by automated means has to say so, and two large platforms have already changed behaviour over it.
A repricing tool is one of the first pieces of software a growing seller buys. It watches a handful of competitors, it moves your price inside a band you set, and it does at three in the morning what you would do at nine if you had the time. Nothing about that is exotic and nothing about it is illegal.
What has changed is that two regulators and one state legislature have now drawn lines around it, all within about fourteen months, and the lines are in different places because they are answering different questions. A shop that understands which question it is facing can make a sensible decision in ten minutes. A shop that treats it as one undifferentiated legal risk either does nothing and leaves money on the table, or does everything and walks into the one version that actually carries exposure.
Which law applies to you depends on who the price is aimed at
This is the distinction the coverage keeps losing. When your software looks sideways at what other sellers charge and moves your number in response, you are in competition law. When your software looks at the person in front of it and moves the number based on who they appear to be, you are in consumer protection law. Same tool category, same word on the invoice, entirely different legal machinery.
| Question | Aimed at competitors | Aimed at the shopper |
|---|---|---|
| Body of law | Antitrust and competition | Consumer protection |
| Who enforces it | DOJ, state attorneys general, private plaintiffs | FTC, EU consumer authorities |
| What triggers exposure | Shared tool plus competitor data, or coercion | Profiling a price without telling the buyer |
| Typical remedy | Injunction, conduct rules, damages | Fines, forced disclosure, behaviour change |
| Safe version | Your own data, your own model | Same price for everyone, or a clear notice |
What did the RealPage settlement actually decide?
It decided that the problem was the data, not the algorithm. The Justice Department announced on 24 November 2025 that it requires RealPage to end the sharing of competitively sensitive information and the alignment of pricing among competitors, and the terms are worth reading closely because they read like a specification for a compliant tool.
Under the settlement RealPage cannot use competitors' nonpublic information in real time pricing decisions. Model training is limited to historic data aged at least twelve months, with no active lease data. Geographic pricing effects have to operate at state level or broader rather than in narrow local markets. Features that limited price decreases or aligned competitor pricing come out. Market surveys that collected sensitive information stop, and a court appointed compliance monitor watches the result.
Read that list again as a small seller. Every restriction targets one of two things: fresh nonpublic information about what a rival is charging right now, or a mechanism that stops prices falling. Neither is a description of software recommending a price. The department framed its own position around independence: competing companies, it said, must make independent pricing decisions, and it promised continued vigorous enforcement as algorithmic and artificial intelligence tools spread. Independence is the test. The computer is not.
Why does California AB 325 matter to a shop outside California?
Because it reaches the tool rather than the seller, and the tools are national. California's amendments to the Cartwright Act took effect on 1 January 2026, and the statutory definition is unusually wide: a common pricing algorithm is any methodology that two or more persons use, where methodology is spelled out in the statute as a computer, software or other technology. What it must do with competitor data is drawn widely. Recommending a price counts. So does aligning one, stabilizing one, setting one, or otherwise influencing any price or commercial term.
Three words in that sentence do the work. Two or more persons means a tool shared across sellers, which is what every commercial repricer is. Competitor data means exactly what it says. Influence is broader than set, so a recommendation you accept counts. And there is no carve out for publicly available information, so a tool that only scrapes public listing prices is not automatically outside the definition.
What keeps an ordinary seller out of trouble is that the definition alone is not the offence. The law prohibits use or distribution of such an algorithm as part of a conspiracy to restrain trade, or where a person coerces another into adopting the recommended price. A shop running a shared repricer, setting its own floor and ceiling, with no agreement or pressure involving another seller, is not doing either of those things. The risk is not that you used the tool. It is that the tool becomes the venue for something that looks like an agreement.
A single business using a proprietary algorithm on only its own data sits outside the two or more persons definition entirely. That is the cleanest position available, and it is one of the few genuine advantages of pricing logic that lives in code you control rather than in a vendor dashboard shared with your competitors. If you build your storefront yourself, as our approach to owning the storefront code assumes, this is a design decision you get to make once.
What is surveillance pricing, and are you doing it by accident?
Surveillance pricing means setting a price for an individual using data about that individual rather than about the market. You are probably not doing it, but the boundary is closer than most sellers assume, and the answer turns on whether the shopper sees a different number because of who they are.
The Federal Trade Commission published initial findings from its surveillance pricing study on 17 January 2025, drawn from six intermediaries including Mastercard, Accenture, PROS, Bloomreach, Revionics and McKinsey. Those intermediaries worked with at least 250 clients across grocery and apparel retail. The inputs the study catalogued go a long way past the obvious: precise location, browser history, demographics, mouse movements on a webpage, products left in a shopping cart, and search and purchase activity. The chair at the time described retailers using personal information to set targeted, tailored prices down to a person's mouse movements on a webpage.
The useful boundary for a small shop is this. A discount code sent to a segment is marketing. A price that renders differently for two people loading the same product page at the same moment is personalised pricing. Between those two sit the cases people get wrong: a first time visitor banner offering ten percent off, a cart abandonment email with a better price, a loyalty tier that shows members a lower number. Those are defensible, and they are also the ones a regulator would want disclosed if the mechanism is automated and opaque.
What does Europe require that America does not?
Disclosure. A trader who personalises a price using automated decision making has to tell the consumer, and unlike the American position this is a standing obligation rather than an enforcement theory being developed.
The practical evidence sits in enforcement rather than statute. The European Commission's record of coordinated action on marketplaces and digital services shows Tinder committing, with a mid April 2024 deadline, to inform consumers clearly that discounts on premium services are personalised using automated means and to disclose the criteria used, such as a user's limited interest in premium services at the standard rate. The same record notes that Wish stopped personalised pricing techniques in the EU as of 1 June 2022, on the basis that it was not clear to consumers how they functioned or how they determined a price from personal data.
Both outcomes point the same way. The regulator did not ban the practice. It required either a plain explanation or an exit. For a seller shipping into the EU, that converts a legal question into a copy question, which is a much easier problem: if a price is personalised, say so on the page where it appears, in the shopper's language, and name the criterion.
A workable policy for a shop of one or two people
Write this down once and you will not have to think about it again until the law moves.
Set your own floor and ceiling by hand, and never let a tool move outside them. The band is where your commercial judgment lives, and it is also the single clearest piece of evidence that you priced independently.
Prefer tools that use your own sales history over tools that use rivals' current prices. If you use a competitor aware repricer anyway, which is reasonable in marketplace categories, keep it as an input to a decision rather than an automatic publisher of prices, and keep the logs. We went through how to run that kind of watching sensibly in the piece on monitoring competitor prices without building a problem.
Never discuss your pricing rules, your floors or your tool settings with a competitor, in a supplier group chat, at a trade association meeting or anywhere else. This is the oldest rule in antitrust and the algorithm does not change it. If anything, a shared tool makes such a conversation more dangerous, because the coordination becomes implementable the moment it is agreed.
Charge every shopper the same published price unless you can explain the difference in one sentence on the page. Loyalty discounts, volume breaks and time limited promotions all pass that test easily. Anything that depends on inferred characteristics of the individual does not, and the honest question is whether you would be comfortable if the buyer read the rule. The related boundary on tailoring the rest of the experience is covered in our piece on how far personalisation can go before consent becomes the issue.
Does using the same repricing tool as my competitors create liability?
On its own, no. Shared use of a tool is an element of the California definition, not an offence by itself, and the prohibitions still require a conspiracy or coercion on top of it. What the shared tool does is remove one of the defences you would otherwise have had.
Think about how a case gets built. A plaintiff who claims that four sellers in a category coordinated their prices has to explain how they did it without meeting. Parallel pricing alone has never been enough, because rational sellers in a small market reach similar prices for obvious reasons. A shared algorithm ingesting the same competitor data gives that plaintiff a mechanism to point at, and California has now made the pleading stage easier by removing the requirement to allege facts tending to exclude the possibility of independent action.
So the practical question is not whether you use a popular tool. It is whether anything in your conduct looks like an agreement. Three habits keep the answer clean. Set your own parameters rather than accepting the vendor's recommended preset, because identical settings across sellers is the pattern that gets noticed. Keep the tool advisory on your top sellers, where a human confirms the move. Retain the configuration history, so you can show that your floor was set in March for margin reasons and never touched again.
What records are worth keeping?
Enough to reconstruct why a price was what it was on a given day, which is a lower bar than it sounds and takes about ten minutes a quarter.
Keep the floor and ceiling for each product with the date you set them and a one line reason, usually landed cost plus a target margin. Keep an export of your tool's settings whenever you change them. Keep the pricing rules themselves in writing, even if the writing is a page in a shared document. If you ever move to a different repricer, keep the old settings rather than deleting them, because the gap in the record is what looks evasive later.
None of this is about preparing for litigation, which is an unlikely outcome for a small seller. It is about being able to answer a marketplace's own compliance query, a payment provider's risk review, or an acquirer's diligence questions without reconstructing a year of decisions from memory. The same discipline that protects you legally is the discipline that lets you tell whether your pricing is working, which is the reason to do it even if no regulator ever asks.
What the next twelve months probably bring
Two directions are already visible. On the competition side, California's lowered pleading standard means a Cartwright Act claim no longer has to allege facts tending to exclude the possibility of independent action, which makes an algorithmic pricing complaint cheaper to file and harder to dismiss early. Expect more filings against tool vendors than against individual sellers, because that is where the two or more persons element is easiest to plead.
On the consumer side, the FTC has moved from studying personalised pricing to proposing an enforcement framework for it, announced on 19 August 2026. A proposed policy statement is not a rule and does not bind anyone, but it tells you what the staff considers actionable, and the consistent theme across the study and the statement is inadequate transparency rather than differential pricing as such.
Neither direction threatens a shop that prices its own goods with its own data inside a band it chose. That is worth saying plainly, because the volume of legal commentary on this subject is out of all proportion to the risk carried by a seller with four hundred products and no competitors in the room. The point of understanding the rules is not to be frightened of the software. It is to know which of its settings you should never hand over. That list is short: the floor, the ceiling, and the decision to publish without looking. Keep those three in your own hands and the rest of the configuration is an operational preference rather than a legal exposure.
Independent is the operative word in that sentence, and it is a description of a decision rather than of a technology. A price you arrived at yourself, with tools you chose, on data you hold, is independent whether you reached it with a spreadsheet or a model. A price you arrived at because a shared system nudged you and your rivals toward the same number is not, and it would not have been in 1995 either.