AI Price Fixing and Discrimination with Recommendations for Retailers

Next year will likely bring more lawmaking surrounding artificial intelligence algorithms used to set consumer pricing. Two themes are emerging: price fixing and price discrimination.

AI price fixing uses algorithms to coordinate pricing, which is raising increased scrutiny in the U.S. and Europe. Companies provide competitively sensitive data to third-party providers that analyze it to recommend prices for participating companies, leading to artificially inflated prices and reducing competition.

After over a year of litigation, the Department of Justice (DOJ) recently filed a proposed settlement with a revenue management software company, related to its algorithmic rental pricing software. State AGs continue to litigate against participating companies, and lawmakers have introduced bills to ban algorithmic price fixing. California has passed laws to restrict the use of common pricing algorithms, and regulators in the EU and UK are also focusing on algorithmic collusion. 

Regulation challenges include the argument that antitrust laws may have loopholes that make AI-driven pricing hard to prosecute; distinguishing collusion from companies’ legitimate responses to market conditions; and AI complexities creating difficulty proving violations.

AI price discrimination uses algorithms to set personalized prices for products or services based on the individual consumer’s behavior, demographics or perceived willingness to pay. The process is often hidden, making it hard to know who pays what. That raises fairness concerns (algorithms might exploit vulnerable groups and charge them more), prompting legal scrutiny and proposed regulations. 

The FTC is investigating AI’s role in price discrimination, while recently passed regulations and laws in California aim to ban using personal data for discriminatory pricing or make it easier to sue over algorithmic pricing. New York has enacted several price discrimination laws requiring algorithmic pricing disclosure and prohibiting gender-based pricing. 

Recommendations for retailers

While it is perfectly legal to test prices and adjust them to market conditions, retailers should be careful when reviewing and adopting AI pricing tools. The recent proposed settlement from the DOJ highlights some best practices for using these tools: 

  • Confirm that the AI tools train on publicly available pricing data or aggregated data, not the non-public and sensitive pricing strategies of competitors. 
  • Ensure that the AI tools allow prices to be lowered as well as increased within user-defined price ranges. 
  • Keep humans in the loop and check that users can reject or override price suggestions. 

In addition, businesses may consider the following best practices to lessen the risks of allegations of unlawful AI price discrimination:

  • The AI tools should not adjust pricing dynamically based on consumer profiles or other sensitive personal information (e.g., veteran status, religious beliefs, health condition). 
  • If the AI tool adjusts pricing based on location, retailers should confirm that this reflects legitimate market conditions and business concerns, rather than historic bias. 
  • Confirm that the AI tool uses de-identified and/or aggregated data, both to train its models and during deployment, so information is not linkable to an individual. 

Map of the United States - State Privacy Laws

And Then There Were Five…

Image Credit: Free-Photos from Pixabay.

Just last summer, in July of 2021, Colorado joined California and Virginia, and became the third U.S. state with a comprehensive consumer privacy law. The Colorado Privacy Act is set to take effect in July 2023.

Hot on its heels, and within just two months of each other, first Utah in March of 2022, now Connecticut in May of 2022, passed privacy bills which will become effective in 2023.

So far, California remains the only state which allows for a private right of action in connection with its privacy bill. For more information, please see our comparison of the current U.S. state consumer privacy laws below.

For our unofficial redline of the CPRA, click here.

Follow these links for the official text of the CPRA, CPA, CTDPA, UCPA, and VCDPA.

To view and download a PDF version of this chart, click here.

Banner for PrivSec Global: A Global Live Stream Experience. 22-23 September 2021. The Largest Data Protection, Privacy and Security Event of 2021. Businesspeople smiling in the background of the banner.

Metaverse Law Speaks at PrivSec Global

On September 23, 2021 attorney Lily Li spoke at PrivSec Global: The Largest Data Protection, Privacy and Security Event of 2021. The Global Live Stream Experience was a two day event from September 22 to September 23, 2021.

The topic of discussion was “Why Most CCPA Cases Will Fail: Five Hurdles Plaintiffs Must Clear.” For more details on the topic and to watch the presentation on-demand, click here.

Cell phone with image of lock on the screen.

Reasonable Security: Implementing Appropriate Safeguards in the Remote Workplace

Photo by Franck on Unsplash

In 2020, with large portions of the global workforce abruptly sent home indefinitely, IT departments nationwide scurried to equip workers of unprepared companies to work remotely.

This presented an issue. Many businesses, particularly small businesses, barely have the minimum network defenses set up to prevent hacks and attacks in the centralized office. When suddenly everyone must become their own IT manager at home, there are even greater variances between secure practices, enforcement, and accountability.

“Reasonable Security” Requirements under CCPA/CPRA and Other Laws

Under the California Consumer Privacy Act (CCPA), the implementation of “reasonable security” is a defense against a consumer’s private right of action to sue for data breach. A consumer who suffers an unauthorized exfiltration, theft, or disclosure of personal information can only seek redress if (1) the personal information was not encrypted or redacted, or (2) the business otherwise failed its duty to implement reasonable security. See Cal. Civ. Code § 1798.150.

Theoretically, this means that a business that has implemented security measures—but nevertheless suffers a breach—may be insulated from liability if the security measures could be considered reasonable measures to protect data. Therefore, while reasonable security is not technically an affirmative obligation under the CCPA, the reduced risk of consumer liability made reasonable security a de facto requirement.

However, under the recently passed California Privacy Rights Act (CPRA), the implementation of reasonable security is now an affirmative obligation. Under revised Cal. Civ. Code § 1798.100, any business that collects a consumer’s personal information shall implement reasonable security procedures and practices to protect personal information. See our CPRA unofficial redlines.

Read More
social network patents

Facebook, Patents, and Privacy: Social Media Innovations to Mine Personal Data

Social Media Patents & Privacy Data

[©2016. Published in GPSOLO, Vol. 37, No. 5, September/October 2020, by the American Bar Association. Reproduced with permission. All rights reserved. This information or any portion thereof may not be copied or disseminated in any form or by any means or stored in an electronic database or retrieval system without the express written consent of the American Bar Association or the copyright holder]

* Updated November 25 to include references to CPRA/ Prop24.

The episode “Nosedive” of the television series Black Mirror envisions a society built on social credit scores. In this dystopia, all social media networks have converged into one platform—think Facebook, TikTok, Yelp, and Equifax combined.

This umbrella social platform allows users to rate each other on a five-point scale after each social interaction. Those with a high score gain access to job opportunities, favorable zip codes, and even high-status relationships. Those with a low score have the social ladder kicked out from under them, leading to a downward cycle of estrangement—and in the case of Black Mirror’s protagonist, jail time.

While the society in “Nosedive” seems far-fetched, is the technology behind it plausible?

Facebook Patents That Impact Privacy

According to Facebook’s patents, the answer is a resounding “yes.”

In a series of filings spanning almost a decade, Facebook has obtained several patents that allow social media platforms to track, identify, and classify individuals in new and innovative ways. Below are just few.

Tracking individuals via dust. U.S. Patent No. 9485423B2, “associating cameras with users and objects in a social networking system” (filed September 16, 2010, patented June 25, 2013), allows social media networks to identify an individual’s friends and relationships by correlating users across the same camera. To do so, an algorithm analyzes the metadata of a photo to find a camera’s “signature.”

Read More
1 2 3