Why the privacy debate keeps arresting the wrong suspect

The oldest idea in economics, now with a compute budget

There is a persistent belief that the great data scandal of our age is theft: that somewhere in a server farm, your browsing history is being bundled and sold to a stranger. It is a comforting story, because it has a villain, a crime, and a plausible remedy. It is also mostly beside the point.

The more interesting thing being done with your data is not sales. It is an estimation. Firms are using it to answer a single question that has haunted commerce since the invention of the marketplace: what is the absolute maximum this particular person would have handed over before walking away?

Economists have a dull name for the answer (willingness to pay) and an even duller name for the practice of extracting it (first-degree price discrimination). Textbooks have described it for over a century as a theoretical curiosity, the sort of thing that could only work if a seller were omniscient. The seller has since acquired a phone in your pocket, a record of your searches, your device model, your location at 2 a.m., and a machine learning budget. Curiosity has become a product category.

The number they are actually hunting

Suppose a flight is priced at 6,000 rupees and you would have paid 9,000. Congratulations: you have just captured 3,000 rupees of what economists call consumer surplus. It is not money in your bank account. It is the invisible discount you enjoy because sellers historically could not read minds and therefore had to quote everyone the same number.

Consumer surplus is the entire consumer benefit of a competitive market, expressed as a figure. It is also, viewed from the other side of the table, a rounding error waiting to be collected.

Personalised pricing is simply the industrial project of converting that 3,000 rupees from your surplus into somebody's revenue. Nothing is stolen. No data leaves the building. The privacy policy is honoured to the letter. You are merely quoted 8,900 instead of 6,000, and you accept, because it is still less than 9,000, and because you have no way of knowing that the passenger in the next seat paid 5,400.

Case study: Delta, an algorithm, and a very carefully worded denial

In July 2025, Delta Air Lines gave the clearest public account of this ambition anyone has yet managed, on an earnings call, to investors, voluntarily.

Delta's president, Glen Hauenstein, described the airline's partnership with an AI pricing firm called Fetcherr as a full reengineering of how the company prices. The system had been switched on across roughly 3 percent of Delta's domestic network, with a stated target of 20 percent by the end of that year. Investors, understandably, were delighted.

Three United States senators were less so. In a letter dated 21 July 2025, Ruben Gallego, Mark Warner and Richard Blumenthal warned that individualised pricing would likely push fares up to each consumer's personal "pain point." The phrase is worth pausing on. It is not a metaphor. In a model of this kind, the pain point is the operative variable.

Delta's response was a small masterpiece of the genre. The airline stated that no fare product it had ever used, was testing, or planned to use targeted customers with individualised prices based on personal data, and that its ticket pricing never takes personal data into account. Aggregated demand, competitive fares, route performance, fuel costs: all fine. Individual data: never.

This may be entirely true. It is also a sentence engineered to survive contact with a legislative committee. The whole weight of the defence rests on the boundary between "aggregated" and "individualised," and nobody outside the company can audit where that boundary sits, or how narrow a segment must become before an aggregate of one is reached. Senator Gallego observed that Delta appeared to be telling investors one thing and the public another. He was being generous. The company told both audiences the truth, in two different dialects.

The Indian edition, in which the tell is your phone

India got the cruder version first. In January 2025, following a run of consumer complaints that identical rides were being quoted at higher fares on iPhones than on Android handsets, the Central Consumer Protection Authority issued notices to Ola and Uber. The Consumer Affairs Minister described it as a prima facie unfair trade practice. Both companies denied setting prices by phone manufacturers, and offered to help clear up any misunderstanding.

Take the denials at face value. The episode still teaches something useful: consumers can only detect this when the segmentation is clumsy enough to be visible. Phone model is a crude proxy for income, and crude proxies get caught, because two friends on a train can compare screens. The sophisticated version does not require a proxy anyone can spot.

The law is standing guard at the wrong door

Here is where the joke lands.

India's Digital Personal Data Protection Act was operationalised by Rules notified on 13 November 2025, with full compliance required by 13 May 2027 and penalties reaching 250 crore rupees. It is a serious statute. It governs notice, consent, purpose limitation, retention, breach reporting and children's data.

Every one of those obligations regulates the collection and handling of information. Not one of them regulates the price you are quoted as a result. A firm may obtain your consent in itemised plain language, store your data lawfully, delete it on schedule, and in the interim use it to charge you the most you will tolerate. That is not a loophole. It is the design. Data protection law asks whether the seller was permitted to know. It does not ask what the seller did with the knowing.

The United States is at least having the argument out loud. The Federal Trade Commission's 2025 study found that intermediaries routinely use location, browsing patterns and demographics to set individual prices. In April 2026 the agency opened rulemaking touching personalised pricing disclosure, and on 19 August 2026 it proposed an enforcement policy warning that undisclosed personalised pricing may be unfair or deceptive. Individual states moved faster: New Jersey banned personalised algorithmic pricing for grocery and delivery platforms in July 2026, with Maryland and Connecticut measures arriving in October.

Notice what nearly all of it converges on. Disclosure. The proposed cure is a notice informing you that the number on your screen was derived from an estimate of your desperation. One assumes it will appear next to the cookie banner, and be dismissed with equal care.

In defence of the accused, briefly

Price discrimination is not automatically robbery. Student concessions, off-peak fares and coupons are all price discrimination, and they generally widen access rather than restrict it. Some travellers genuinely receive cheaper seats when a system can identify who would otherwise walk away.

The meaningful distinction is not personalised versus uniform. It is self-selected versus inferred. A student discount requires you to present an ID and claim a category; you know the ladder exists and where you stand on it. An inferred price asks nothing of you and tells you nothing. And willingness to pay is not a clean measure of wealth or indifference. It also measures urgency. The person booking a one-way fare at 2 a.m. is frequently not a relaxed executive with an expense account. Charging the most to those least able to postpone is an efficient market outcome and a fairly ugly social one.

What a serious rule would look like

Not a ban, which would be unenforceable, and not a disclosure, which would be decorative. The workable demand is a published price ladder: a requirement that any firm using personal data as a pricing input must periodically publish the distribution of prices actually charged for an identical good within the same window.

Not your price. The spread. Once the range is visible, the information asymmetry that makes the entire model profitable begins to collapse, because personalised pricing only works for as long as you believe your quote is the price, rather than an opening bid addressed specifically to you.

Your data is quite safe. It was never the target. You were.