Blog
New Jersey Signs Surveillance Pricing Law as South Korea Fines Apple and TikTok for Lacking a Legal Basis to Process Data
July 28, 2026
Want to receive these privacy recaps in your inbox each week? Subscribe here.
New Jersey’s governor signed the Fair Price Protection Act, banning personal-data-based pricing of groceries and making the state the third to enact a surveillance pricing law. Meanwhile, South Korea’s PIPC fined TikTok and Apple for collecting and using personal information without a valid legal basis.
Keep reading for the analysis and takeaways.
United States
New Jersey Governor Signs Surveillance Pricing Law
The New Jersey legislature passed, and the governor signed, A4085, the Fair Price Protection Act. The law prohibits:
- Using any pricing method, algorithmic or manual, that varies the price of groceries based on personal data
- Pricing groceries using data gathered through cameras, sensors, biometric monitoring, or device tracking
- Reusing personal data collected to justify a permitted price difference for any other purpose without the consumer’s consent
- Deploying new electronic shelf labels, for a 1-year moratorium
There are exceptions. Companies can charge different prices due to reasonable costs like delivery distance or fulfillment cost, as long as the price isn’t changed more than once in a 24-hour period. They can offer eligibility-based discounts (teacher or veteran pricing) if the criteria are publicly disclosed and offered uniformly to anyone who qualifies. And they can offer loyalty programs with personalized pricing benefits, as long as enrollment is voluntary, all members get the same benefits under the same terms, benefits are disclosed and made available to the Division of Consumer Affairs within 14 days of a request, and terms and data practices are publicly disclosed.
The law primarily takes effect August 1, 2027. The electronic shelf label moratorium takes effect February 1, 2027. An electronic shelf label study takes effect immediately.
Takeaway
New Jersey is the third state to enact a surveillance pricing law, after Maryland and Connecticut, with a fourth, New York, pending the governor’s signature. New Jersey’s law is narrower in scope than the others, applying only to groceries and foodstuffs and exempting restaurants and sellers of prepared food or items for immediate consumption. New York, if signed, will apply to all goods and services universally. Maryland will apply its ban to tax-exempt food items sold by large-format retailers and third-party food delivery providers, but will also impose disclosure obligations on any merchant using dynamic pricing or personal data to set a price, regardless of category. Connecticut’s ban applies to retail sellers of tangible personal property generally.
But within its scope, New Jersey goes further than any other state. It’s the only state imposing an electronic shelf label moratorium, the only one to ban any personal-data-based grocery price variation rather than just algorithmic pricing, and the only one to explicitly bar reusing pricing-related personal data without consent, though more general purpose-limitation rules in other states’ comprehensive privacy laws may already cover that use case, as seen in California’s recent surveillance pricing sweep.
World
South Korea Fines Apple and TikTok for Lacking a Legal Basis for Processing
South Korea’s Personal Information Protection Commission (PIPC) fined TikTok KRW 10.3 billion and Apple Distribution International KRW 252 million, both for collecting and using personal information without a legal basis.
The PIPC found that TikTok failed to sufficiently notify users, so that they could clearly recognize it at sign-up, of its collection of users’ activity from third-party websites and apps, and effectively forced users to consent to that practice as a condition of using the service. The PIPC found that Apple collected and used voice recordings and transcribed text from Siri for voice recognition and improving search results without obtaining separate consent. Apple started obtaining consent for service improvement use in October 2019, but the PIPC found it kept using the transcripts without establishing a separate lawful basis.
Takeaway
Many international privacy laws, including South Korea’s Personal Information Protection Act (PIPA), share principles and requirements with the GDPR, but enforcement nuances matter. The TikTok decision reinforces an existing PIPC position, already applied to Google and Meta: an advertising platform tracking the off-service behavior of its own registered users can’t assign consent responsibility to participating websites and apps. The platform itself must establish a valid basis for its processing.
The GDPR doesn’t let a platform disclaim responsibility either, but the EDPB has stated that the joint controller first involved with the data subject should collect consent for the relevant processing, and that an original consent may be relied upon by multiple joint controllers if all are named, purposes are specified, and separate choices are given for genuinely separate purposes. Publishers and social platforms can be treated as joint controllers across the chain from pixel collection through ad delivery and reporting, as long as purposes and means are jointly determined.
South Korea and the EU have operationalized similar principles from different angles. Korean enforcement focuses on the platform’s own obligation to get valid consent from registered users whose off-service behavior it collects and links to their accounts for targeted advertising; the PIPC rejected platforms’ arguments that participating sites and apps should bear that responsibility in the Google and Meta cases, upheld by the Seoul Administrative Court. The Korean decisions don’t conclusively establish that a platform must always obtain duplicative consent where a publisher already has valid consent covering the platform’s activities, but unlike EU authorities, the PIPC hasn’t yet clearly endorsed publisher-collected consent as sufficient in that situation, at least based on public materials. It’s a difference in enforcement posture and legal certainty rather than a settled substantive difference, but one worth recognizing.
A LITTLE MORE PRIVACY, IF YOU PLEASE
- Data Brokers Must Begin Processing California Delete Act DROP Requests by August 1
- Garante Fines Utility Suppliers for Data Use Transparency Violations
- CNIL Publishes FAQs to Supplement Recent Email Pixel Guidance
- Does consent banner performance vary by device in 2026?
A Little Privacy, Please weekly recaps are provided for general, informational purposes only, do not constitute legal advice, and should not be relied upon for legal decision-making. Please consult an attorney to determine how legal updates may impact you or your business.
Latest Blog Posts
New Jersey Signs Surveillance Pricing Law as South Korea Fines Apple and TikTok for Lacking a Legal Basis to Process Data
July 28, 2026New Jersey signs surveillance pricing law banning personal-data-based grocery...
Pennsylvania Court Lets Pixel-Tracking Wiretap Claims Proceed as EDPB Orders Belgian DPA to Rule on noyb Cookie-Banner Complaint
July 22, 2026PA court holds Meta Pixel is a wiretap device...
SCOTUS Lets Texas App Store Accountability Act Stand as CNIL Clarifies Geolocation Consent Rules for Mobile Apps
July 15, 2026SCOTUS allows enforcement of the Texas App Store Accountability...
Latest White Papers
Connecting Legal & Marketing Teams on Consent and Preferences
February 4, 2025Break down data silos and unlock better collaboration. Marketing...
Navigating Sensitive Data in the U.S.
February 4, 2025Download our comprehensive guide to learn how different states...
Enterprise Guide To Cookie management & Tracker List Curation
July 1, 2024How to review the tracking tech on your websites...