Surveillance Pricing: When Competition Law meets Privacy
#Governance #AI #Privacy
Your Pricing Algorithm Is a Privacy and Competition Problem
Dynamic pricing, personalized pricing, and shared revenue management tools create competition exposure that most companies haven’t mapped — and the privacy dimensions make it worse.
The Governance Gap describes AI as a systematic extraction engine — not intelligence in any meaningful sense, but the capture, recombination, and redeployment of personal and confidential data at unprecedented scale. Pricing algorithms are a case study in that extraction. They ingest personal information — browsing behaviour, purchase history, location, device characteristics — and convert it into a pricing decision optimized for the seller. The individual whose data drives the price has no visibility into the mechanism and no ability to challenge it.
That is the Privacy theme from the positioning paper: individual autonomy under pressure from inference, dependency, and decisions that people cannot challenge. It is also, as of the 2022–2024 Competition Act amendments, a competition law problem.
The Bureau’s Algorithmic Pricing Priority
In November 2025, the Competition Bureau concluded its investigation into algorithmic pricing in Canada’s rental housing market. Revenue management tools from RealPage and Yardi—software that ingests market data and recommends rent levels—drew scrutiny after the U.S. Department of Justice pursued RealPage for facilitating price coordination among landlords. The Bureau found Canadian adoption had not yet reached anticompetitive thresholds. But it issued compliance guidance, signalled continued monitoring, and made clear that algorithmic pricing is a permanent enforcement priority.
Two months later, the Bureau published its What We Heard report from a public consultation drawing more than 100 submissions. The Bureau’s own discussion paper distinguishes two categories. Dynamic pricing adjusts prices based on market conditions — supply, demand, competitor behaviour, time of day. Personalized pricing adjusts prices based on individual consumer characteristics. More than 60 companies in Canada offer pricing algorithm services. The competitive and privacy risks of each category diverge sharply.
Shared Algorithm as Hub-and-Spoke
The most significant competition risk does not require a company to be dominant. It requires only that competitors use the same tool.
When multiple firms in a market subscribe to the same pricing algorithm — and that algorithm ingests competitor data as an input to its recommendations — the result can be tacit price coordination without any direct communication between the firms. The algorithm is the hub, the subscribing competitors are the spokes, and the pricing recommendations transmit coordination effects that would be illegal if achieved through a phone call.
This is the Sovereignty theme from The Governance Gap at the organizational level: dependence on third-party-controlled infrastructure. The positioning paper warns of businesses becoming vassals of dominant platforms through involuntary transfer of proprietary knowledge. A pricing vendor that pools competitive data across subscribing clients and returns coordinated recommendations is exactly that mechanism — except the transfer is of pricing intelligence, not just data.
Under the amended Competition Act, this arrangement is civilly reviewable. Section 90.1 now applies to vertical agreements where any part has a significant purpose of preventing or lessening competition. A subscription agreement between a business and a pricing vendor is a vertical agreement. If the algorithm’s design produces coordinated pricing outcomes, the agreement that enables it is exposed. And since June 2025, a competitor or affected party can bring this claim directly to the Tribunal.
The companies at risk here are not tech giants. They are property management firms, hotel operators, regional retailers, and any business that subscribes to a third-party pricing optimization tool operating in a concentrated market.
Surveillance Pricing: Extraction in Action
Personalized pricing — what consultation respondents called “surveillance pricing” — is the AI theme’s extraction logic applied to consumer transactions. The data inputs that drive personalized pricing are personal information under PIPEDA: browsing behaviour, purchase history, location, inferred demographics. The output is a price tailored to what the algorithm calculates a specific individual will pay. The individual is the raw material. The pricing decision is the extraction.
The Data Provenance questions from the positioning paper apply directly. Where did the pricing data originate? Under what terms was it collected? What authority permits its use for individualized price discrimination? What obligations attach? If a company’s privacy notice does not disclose that it uses personal information to determine individualized pricing, the company faces a consent problem under PIPEDA and a misleading representation problem under the Competition Act. A notice that describes data collection for “improving your experience” without disclosing that personalization includes adjusting the price you see creates a misleading general impression — regardless of how carefully the underlying terms are drafted.
The competition exposure adds a second layer. Personalized pricing used to target a competitor’s customers with selectively lower prices—then restored once those customers are captured—raises predatory pricing concerns. A dominant firm using its data advantage to price-discriminate in ways that exclude competitors engages abuse-of-dominance provisions, now requiring only one of anti-competitive intent or effect.
The Bureau’s consultation respondents were explicit about the transparency problem. Algorithmic pricing systems operate as black boxes. Consumers do not know they are seeing different prices. Competitors cannot detect targeting. And regulators cannot monitor compliance when the pricing mechanism is opaque.
AI-Washing: The Authenticity Problem
The positioning paper’s Authenticity theme addresses the erosion of trust through synthetic content. A parallel exists in corporate AI disclosures. A company that claims its pricing algorithm is “fair,” “transparent,” or “unbiased” is making a representation subject to the deceptive marketing provisions. The 2024 anti-greenwashing amendments require “adequate and proper substantiation” for environmental representations (s. 74.01(1)(b.2)). The same logic extends: an AI fairness claim without documentation is an unsubstantiated representation. AI-washing is greenwashing’s younger sibling. The Bureau’s AI and competition consultation has already flagged deceptive marketing through AI-generated content as an enforcement concern.
Manitoba Moves Ahead; Bill C-36 Impacts
Manitoba’s Bill 49 is in force; it deems the use of personalized algorithmic pricing to increase prices to a specific consumer without consent is an unfair business practice. "Personalized algorithmic pricing" is defined as using an algorithm or automated processing to set, recommend, or vary a price offered to a specific consumer based on data about that consumer—browsing and purchase history, habits, spending behaviour, demographics, socio-economic status, and location —collected with or without consent.
Manitoba created a consent gate under consumer protection law rather than privacy law, which puts it outside the OPC's mandate and inside a regulator with summary-conviction teeth. A national retailer running one pricing engine across the country now needs Manitoba-specific consent capture or Manitoba-specific suppression. The application of this law is cross-border; the consumer's provincial residence is what matters, not where the business is. Clients running dynamic pricing, loyalty-linked offers, or willingness-to-pay modelling should be told the exposure is live now, not in 2028.
Bill C-36, the Protecting Privacy and Consumer Data Act, tabled 15 June 2026, proposes repealing and replacing PIPEDA. It addresses automated decision-making and surveillance-pricing risk without banning the practice; the drafting deliberately preserves loyalty-programme and promotional discounting. Press reporting suggests the rules are unlikely to bind before 2028.
Intersections: Compliance Gaps Companies Miss
Most organizations that deploy pricing algorithms have reviewed them for privacy compliance — or at least believe they have. Fewer have reviewed them for competition compliance. Almost none have assessed the intersection: whether the privacy notice’s description of the algorithm’s data inputs survives a deceptive marketing challenge, whether the vendor agreement creates s. 90.1 exposure, or whether the algorithm’s outputs produce coordinated effects in a concentrated market.
The Bureau has been explicit about what it expects: compliance programs that extend to algorithmic governance — vendor data source diligence, logging of inputs and outputs, monitoring of pricing outcomes, and escalation paths when outcomes suggest coordinated effects. That is a privacy program architecture repurposed for competition compliance. The convergence is structural, not incidental.
In Part 3, we examine what a converged compliance architecture looks like in practice — the Governance and Ethics themes applied to organizations that can no longer afford to run these programs in silos.
About the Author
Constantine Karbaliotis is the principal of Privacy
• Legal™ (privacylegal.ca), a Canadian privacy, AI governance, and cybersecurity law practice. He is the author of
The Governance Gap: AI, Privacy, and the Accountability Imperative, the positioning paper that anchors
The Privacy Briefing series.
© 2026 Privacy • Legal™ | All rights reserved.
Recent Posts





