Skip to content

Maryland surveillance pricing law: HB 895 now in force

Filip LuchianencoUpdated 6 min read

Last updated: 2026-10-02

Maryland's surveillance pricing law took effect on October 1, 2026. House Bill 895, the Protection From Predatory Pricing Act, was approved by Governor Wes Moore on April 28, 2026 as Chapter 154. It adds § 13-321 to the Maryland Consumer Protection Act and bars a food retailer or a third-party delivery service provider from using a consumer's personal data to set a higher price for tax-exempt food for that consumer. The enacted text calls the practice "dynamic pricing". The governor's signing release describes a ban on "price manipulation practices driven by the ability to instantly spike prices based on surveillance data."

What does Maryland HB 895 prohibit?

Section 13-321(b)(2) provides that a covered business "may not: (i) engage in dynamic pricing to set a higher price for food that is exempt from the sale and use tax in accordance with § 11-206(c) of the Tax-General Article for a specific consumer; or (ii) use personal data to set a higher price for food that is exempt from the sale and use tax under § 11-206(c) of the Tax-General Article for a single consumer."

Dynamic pricing is "the discriminatory practice of offering or setting a personalized price for a good or service that is specific to a consumer based on the consumer's personal data, regardless of whether the seller collected or purchased the personal data." Personal data takes the meaning in the Maryland Online Data Privacy Act, § 14-4701(w): "any information that is linked or can be reasonably linked to an identified or identifiable consumer."

Both prongs are limited to a higher price; a lower personalized price falls outside § 13-321(b)(2). Tax-exempt food under Tax-General § 11-206(c) is grocery food "for consumption off the premises", excluding "food for immediate consumption."

A second prohibition, § 13-321(c), applies to any consumer good or service: a covered business "may not use protected class data to offer, advertise, or sell" it where the use "has the effect of withholding or denying from the consumer an accommodation, an advantage, or a privilege accorded to others."

Who must comply with the Maryland surveillance pricing law?

Two kinds of merchant, per § 13-321(a):

  • A "food retailer" operates a business establishment that "has a minimum of 15,000 square feet" and sells tax-exempt food.
  • A "third-party delivery service provider" is a merchant that "facilitates as a consumer service the delivery of food that is exempt from the sales and use tax". The definition excludes a food retailer.

The prohibition in § 13-321(b)(2) names no sales channel; its text applies the same test to a shelf price, a website price and an in-app price.

Which prices fall outside the ban?

Section 13-321(b)(1) lists nine exemptions from the pricing prohibition:

  1. promotional offers, loyalty benefits, temporary discounts and retention pricing;
  2. "objective costs" such as shipping or taxes based on location;
  3. a price difference from costs or supply and demand "in different locations or geographies";
  4. a price difference from costs tied to availability or supply;
  5. a price offered "through a loyalty, membership, or rewards program in which any consumer may voluntarily enroll or consent to participate";
  6. a price offered with a subscription-based contract;
  7. a price offered "to a consumer who consents to providing personal data or other information in exchange for obtaining the price";
  8. correcting a pricing error;
  9. resetting a price after a system or network outage.

Consent in exemption 7 takes the Online Data Privacy Act meaning, § 14-4701(g): "a clear affirmative act signifying a consumer's freely given, specific, informed, and unambiguous agreement". It excludes "agreement obtained through the use of dark patterns." In an app, exemption 5 turns on a loyalty enrollment and exemption 7 on a consent. A scan records the sign-up and consent screens as steps in the app's flow.

What changed between the introduced bill and the enacted law?

The chaptered text marks each amendment made between first reader and enactment:

  • Dynamic pricing was defined in the first reader as "varying the prices of consumer goods or services within a business day based on demand or other factors"; that text was struck (page 2).
  • "Surveillance data", defined around "sensors, cameras, device tracking, biometric monitoring", was replaced by the Online Data Privacy Act definition of personal data (page 4).
  • The words "or a group of consumers" were struck from prong (ii), and "higher" and the tax-exempt food limit were added (page 5).
  • Proposed § 13-322, a disclosure duty for every merchant ("THIS PRICE WAS SET BY AN ALGORITHM OR BY USING YOUR PERSONAL DATA"), was struck (pages 6–7).
  • Labor and Employment § 4-406, which barred a food retailer from changes that diminish employee rights under an existing collective bargaining agreement unless agreed with the employees' representative, was struck (page 9), as was the emergency clause (page 10).

How is HB 895 enforced, and what are the penalties?

Before acting, the Consumer Protection Division of the Office of the Attorney General (§ 13-101(e)) "shall issue a notice of violation" and give the merchant "45 days after the notice of violation is received to cure the violation"; a cure within that period bars an enforcement action (§ 13-321(d)). The subsection sets no expiry date for the cure.

Under § 13-410, a merchant is subject to "a fine not exceeding $10,000 for each violation" and "$25,000 for each subsequent violation" of the same kind. Section 13-321(e) states it does not "authorize a private right of action", and the act excludes § 13-321 from the private action in § 13-408 and the misdemeanor penalty in § 13-411.

Attorney General Anthony G. Brown's bill review letter of April 23, 2026 states that the right-to-cure requirement "would fundamentally weaken enforcement", adding that a prohibited dynamic pricing practice "is embedded in proprietary systems specifically not designed to be examined from the outside." The fiscal and policy note records the Office of the Attorney General's estimate of "one assistant Attorney General and one technologist", about $325,000 a year, to enforce the act.

How does Maryland compare with Connecticut's surveillance pricing law?

Connecticut enacted a broader ban in section 11 of Public Act 26-130, approved June 4, 2026. Connecticut's separate precise geolocation sale ban took effect the same day as Maryland's law.

Maryland HB 895 (Ch. 154 of 2026) Connecticut PA 26-130, § 11
In force 2026-10-01 2027-07-01
Who is barred Food retailers of 15,000+ sq ft; third-party delivery service providers Retail sellers, including retail food establishments; third-party delivery services
Goods Tax-exempt food Consumer goods and services
Conduct A higher price for a single consumer based on personal data A customized price for "a consumer or group of consumers" based on personal data collected by technology
Disclosure duty Struck from the bill "THIS PRICE WAS INCREASED USING YOUR PERSONAL DATA" for online surveillance-priced offers by any person doing business in the state
Enforcer Consumer Protection Division, after a 45-day cure Attorney General, under CUTPA
Penalty Up to $10,000 per violation, $25,000 per repeat (§ 13-410) Up to $5,000 per willful violation (§ 42-110o)
Private right of action Excluded, § 13-321(e) Excluded, § 11(e)

What does an app's network traffic show about personalized pricing?

A December 9, 2025 Consumer Reports and Groundwork Collaborative investigation split 437 volunteers into groups that each shopped identical Instacart baskets at the same time, and found that "some grocery prices differed by as much as 23 percent per item from one Instacart customer to the next." Instacart told CR the tests were "randomized" and denied using personal data to set prices; CR wrote that its "sample of volunteers would need to be larger" to test for a link to demographic data. By December 22, 2025 Instacart had ended item price tests, stating they "were never based on supply or demand, personal data, demographics, or individual shopping behavior." The tests predate HB 895, whose definition turns on whether a price is "based on the consumer's personal data".

Side-by-side sessions show that two customers saw different prices. Why they differ is decided by pricing logic on the server. An app capture records the inputs: which personal data the app sent, to which host, in the same session as a cart or price request. Whether the server used that data to raise the price is outside what a capture shows; pricing-system records and discovery establish that.

When I scan a grocery or delivery app, the report lists the SDKs found in the binary, the declared permissions, and the consent and loyalty screens. It also lists the requests recorded on the test device (precise location, device and advertising identifiers, account and loyalty IDs, browsing events), each with the receiving host and whether it was sent before or after consent. SDK presence in a binary shows the code is in the app, and only a capture shows that data was sent, so the report keeps the two apart: every static finding cites its file and line; every traffic finding cites its capture. What a scan checks and the limits of a scan are on the methodology page.

I run these investigations for lawyers and for researchers working with lawyers, on one app or in bulk. Sign up for a CanITrustThat account to run your own research, let us run an investigation for you, or browse the scanned apps.

App privacy law, applied to real apps.

Posts on new laws, fines and studies, and teardowns of the apps those laws apply to.

How we use your address: privacy notice. Prefer a feed reader? Use the RSS feed.