Skip to Main Content
Publications

Maryland's Ban on Personalized Food Pricing Takes Effect October 1: What Companies Need to Know About the Protection from Predatory Pricing Act and the National Wave Behind It

Maryland's Protection from Predatory Pricing Act (PPPA) (HB 895) takes effect on October 1, making Maryland the first state in the nation to flatly prohibit – rather than merely require disclosure of – the use of consumer personal data to set individualized prices, and it aims that prohibition squarely at the food and beverage sector.

While the statute's scope is narrower than many headlines suggest, its compliance demands are not. Beginning October 1, covered companies must be able to demonstrate, on demand, that consumer personal data did not play a role in pushing up grocery prices.

Background

Since Maryland Governor Wes Moore signed the PPPA into law on April 28, 2026, the surveillance pricing landscape has shifted drastically. Connecticut and New Jersey enacted their own bans, the latter featuring a first-in-the-nation private right of action and treble damages. New York's One Fair Price Act (OFPA) sits on Governor Kathy Hochul's desk awaiting signature. At the federal level, the Federal Trade Commission (FTC) recently issued a draft enforcement policy statement on personalized pricing, signaling that surreptitious uses of personal data to set individualized prices may soon be treated as unfair and deceptive practices under Section 5 of the FTC Act (Section 5). The plaintiff's bar has also started to file surveillance pricing class actions that pair wiretapping theories with unfair or deceptive acts or practices (UDAP)/consumer protection claims.

Core Features of the PPPA

The PPPA applies to "food retailers," defined as merchants that operate a business establishment with at least 15,000 square feet and which sell food that is exempt from the state's sales and use tax, and "third-party food delivery service providers," defined as merchants that facilitate, as a consumer service, the delivery of food that is exempt from the state's sales and use tax.

The PPPA prohibits food retailers and third-party delivery service providers from: (1) engaging in "dynamic pricing" to set a higher price for tax-exempt food for a specific consumer; (2) using "personal data" to set a higher price for tax-exempt food for a single consumer; and (3) using "protected class data" to offer, advertise, or sell to a consumer to whom that data pertains where the use has the effect of withholding or denying an accommodation, advantage, or privilege accorded to others.

Dynamic pricing means "the discriminatory practice of offering or setting a personalized price for a good or service that is specific to a consumer based on the consumer's personal data, regardless of whether the seller collected or purchased the personal data." "Personal data" has the same meaning as under the state's comprehensive consumer privacy statute, the Maryland Online Data Privacy Act (MODPA), which defines the term broadly as any information that is linked or linkable to an identified or identifiable consumer. And "protected class data" means information about an individual or group of individuals that, alone or in combination, directly or by implication identifies a characteristic that is legally protected from discrimination under Maryland or federal law.

The law also provides a number of exemptions, including for loyalty and rewards programs, promotional offers, subscription-based pricing, location- and cost-based price differences, price corrections, and certain data exchanges made with consumer consent.

Enforcement of the PPPA rests exclusively with the Consumer Protection Division of the Maryland Attorney General's Office, with authority to impose the following for non-compliance: (1) civil penalties of up to $10,000 per violation and up to $25,000 per violation for repeat non-compliance; (2) disgorgement; (3) restitution; and (4) injunctive relief.

The PPPA provides a 45-day cure period running from the date the Consumer Protection Division of the Maryland Attorney General's Office issues a notice of an alleged violation to the business that will remain in effect indefinitely.

Key Takeaways

Litigation Risk

The absence of a private right of action in the PPPA should not be mistaken for the absence of litigation risk. Personalized pricing is already being litigated, just under other statutes. As one example, several putative class actions have been filed in 2026 against a major air carrier that challenge its individualized pricing practices under the federal Wiretap Act/Electronic Communications Privacy Act (ECPA), state wiretapping statutes, and state UDAP laws. The playbook is familiar to anyone who has defended claims under the California Invasion of Privacy Act (CIPA): where a tracking technology feeds a commercial decision, plaintiffs will characterize the data capture itself as actionable conduct.

Regulatory Overlap

Companies should not assume that the PPPA is the only source of legal exposure for data-driven pricing. Existing privacy and consumer protection laws, at both the state and federal levels, already provide independent grounds for regulators to challenge the same conduct. Maryland's own MODPA, in effect since October 2025, limits the collection of personal data to what is reasonably necessary and proportionate to provide a product or service requested by a consumer – a standard grocers will not satisfy if they route loyalty data into a pricing model. Attorneys general in other states have started treating personalized pricing as a purpose limitation problem under existing comprehensive consumer privacy laws, and the FTC's January 2025 surveillance pricing study supplies the factual predicate, documenting how intermediaries use location, browsing history, cart abandonment, and demographic signals to individualize prices for retail clients, including grocers.

Ripple Effect

The ripple effect is the more consequential piece. Maryland has supplied a drafting template, complete with a sectoral prohibition, size threshold, cure period, and no private right of action, that is easy for other legislatures to copy and difficult for industry players to characterize as unworkable. New York already requires an algorithmic pricing disclosure at the point of sale, and that mandate survived a First Amendment challenge in the Southern District of New York late last year on compelled commercial speech grounds. Surveillance pricing and electronic shelf label (ESL) bills remain pending in numerous states, and federal grocery pricing proposals continue to be introduced. These developments together require building out a multistate standard, not one geared for compliance with Maryland alone.

Practical Compliance Tips and Strategies

With the PPPA taking effect on October 1, covered businesses should take the following steps now to mitigate enforcement risk and ensure their pricing practices align with the statute's requirements:

  1. Audit pricing algorithms. Map every channel – in-store, online, mobile app, and third-party delivery – to identify where personal data touches the price-setting process.
  2. Evaluate loyalty program data practices. Confirm that loyalty and rewards programs offer uniform benefits to all members, rather than using member data to generate individualized pricing.
  3. Review vendor contracts for pricing software. Understand the data inputs used by third-party pricing optimization tools and how liability is allocated for statutory violations.
  4. Coordinate privacy and pricing compliance teams. MODPA and the PPPA create overlapping obligations; ensure cross-functional alignment between data privacy counsel and commercial operations.
  5. Document exemption justifications. For every pricing differential, document the legitimate business justification and map it to a specific statutory exemption before October 1 (or as soon as possible thereafter).

The Final Word

Maryland's law is a leading indicator, not an outlier. Dozens of states have introduced surveillance pricing legislation this year, and several have already enacted laws with broader scope and steeper penalties. National retailers should treat this moment as the beginning of a fragmented, multistate compliance landscape in which Maryland's sector-specific approach may prove to be the floor, not the ceiling.

How Baker Donelson Can Help

Baker Donelson's Data Privacy & Cybersecurity, Food and Beverage, and Retail teams advise food retailers, consumer packaged goods (CPG) companies, restaurant groups, and delivery platforms on pricing-technology risk and assist with applicability and gap assessments, pricing model governance, vendor contracting, loyalty program design, attorney general inquiries and class action defense. For questions or assistance in complying with the PPPA and similar surveillance pricing laws, contact David J. Oberly, Michelle Rae Heisner, Alexandra P. Moylan, CIPP/US, AIGP, or your Baker Donelson relationship attorney.

Email Disclaimer

NOTICE: The mailing of this email is not intended to create, and receipt of it does not constitute an attorney-client relationship. Anything that you send to anyone at our Firm will not be confidential or privileged unless we have agreed to represent you. If you send this email, you confirm that you have read and understand this notice.
Cancel Accept