Summary
The FTC’s proposed enforcement policy statement on personalized pricing highlights a governance problem extending far beyond pricing itself. Organizations may properly collect, secure, classify, and retain personal data, yet create new regulatory exposure when that information is subsequently used for a materially different purpose.
AI makes this problem more consequential because existing data can generate new inferences, influence automated decisions, and produce consumer outcomes never contemplated when the information was originally collected.
This Cyber Brief examines purpose drift and introduces two important governance principles: Collection Authority ≠ Use Authority and New Purpose → New Governance Question. It argues that modern data governance must track not only where information originates and moves, but why it is being used, who authorized new purposes, what decisions those uses influence, what disclosures are required, and what evidence demonstrates accountability.
The larger lesson is that regulatory risk may emerge long after data collection—when an enterprise decides to do something new with information it already possesses.
A company collects customer data for legitimate business purposes.
Browsing history.
Purchase behavior.
Location.
Device information.
Customer preferences.
Perhaps demographic or behavioral information.
The data is properly collected.
It is stored securely.
Access is controlled.
Retention requirements are documented.
Privacy notices exist.
The organization may conclude that the data is governed.
Then someone discovers another use for it.
An analytics platform can estimate how much an individual customer might be willing to pay.
An algorithm can use that estimate to adjust the price the customer sees.
Nothing was necessarily stolen.
No database was breached.
No attacker entered the environment.
The cybersecurity controls may have worked exactly as designed.
And yet the organization may have created an entirely different kind of regulatory risk.
That is the governance problem emerging from the Federal Trade Commission’s proposed enforcement policy statement on personalized pricing.
The FTC is warning businesses that using personal data to determine individualized prices without appropriate disclosure can potentially constitute an unfair or deceptive practice.
The larger lesson reaches far beyond personalized pricing.
Data governance cannot stop at how information is collected and protected.
Organizations also need to govern what happens when someone decides to use that information for something new.
The Data May Not Have Changed
Consider the underlying governance problem.
A retailer has customer purchase histories.
Those records may have originally been collected to complete transactions, manage accounts, provide customer service, prevent fraud or understand purchasing patterns.
Later, the organization develops a new capability.
An algorithm analyzes that same information to estimate an individual customer’s willingness to pay.
The data has not necessarily changed.
The governance context has.
That distinction matters.
Organizations frequently govern data according to familiar questions:
What data do we collect?
Where is it stored?
Who can access it?
How long do we retain it?
Is it encrypted?
Can it be shared?
What privacy requirements apply?
Those remain essential questions.
But they are incomplete.
There is another question:
What are we allowed to do with it now?
That is a purpose question.
And purpose can change much faster than data.
The FTC Is Focusing on Personalized Pricing
The FTC describes personalized pricing as the use of personal data to set prices according to what a business believes an individual consumer is willing to spend.
The Commission’s proposed enforcement policy statement does not attempt to prohibit all personalized pricing.
Instead, it focuses heavily on transparency and consumer expectations.
Where consumers reasonably expect that a price will not vary according to their personal data, the FTC says businesses engaging in personalized pricing should clearly and conspicuously disclose that the price is personalized, explain the basis for the personalization, and identify the types of data being used.
Failure to make those disclosures, according to the proposed statement, is likely to constitute an unfair or deceptive practice under Section 5 of the FTC Act.
That creates an important governance distinction.
The regulatory question is not simply:
Did you have permission to possess the data?
It may also become:
Was this particular use of the data governed appropriately?
Those are very different questions.
Collection Authority Is Not Use Authority
This distinction should become increasingly important in enterprise data governance.
Organizations often treat lawful or authorized collection as though it creates broad authority over subsequent use.
But data can migrate through an enterprise.
Marketing uses information collected by commerce systems.
AI teams train models using operational records.
Analytics groups combine previously separate datasets.
Customer-service transcripts become inputs to behavioral analysis.
Location data becomes a signal for pricing or targeting.
Historical transactions become AI context.
Data originally collected for one purpose acquires another.
That suggests a governance principle:
Collection Authority ≠ Use Authority
The fact that an organization legitimately possesses information does not automatically answer whether every subsequent use is appropriate, disclosed, expected, contractually permissible or legally defensible.
The governance system therefore needs to follow the data beyond collection.
Purpose Drift Is the Hidden Risk
We already understand scope creep in technology projects.
Data has its own version.
Call it purpose drift.
Purpose drift occurs when information collected, generated or acquired for one purpose begins being used for another without corresponding governance review.
It can happen gradually.
A dataset is available.
Someone discovers that it contains useful signals.
A team builds an experiment.
The experiment becomes a pilot.
The pilot performs well.
The capability is integrated into an application.
The application becomes operational.
At no point does anyone necessarily stop and ask whether the new use materially changes the organization’s obligations.
That progression might look like:
Data Collected → Original Purpose → New Use → Algorithmic Decision → Consumer Outcome
But governance needs additional steps:
Data Collected → Original Purpose → Proposed New Use → Governance Review → Authorization → Algorithmic Decision → Consumer Outcome → Disclosure → Evidence
The difference is not bureaucracy.
It is accountability.
AI Makes Purpose Drift Easier
This problem is becoming more consequential because AI dramatically expands what organizations can infer from existing data.
Historically, the value of a dataset might have been relatively closely tied to the reason it was collected.
AI weakens that relationship.
A collection of customer interactions may reveal sentiment.
Purchase histories may predict financial behavior.
Browsing patterns may suggest urgency.
Location information may reveal routines.
Support conversations may expose vulnerability.
Transaction histories may help estimate willingness to pay.
Individually mundane data points can become powerful when combined.
The enterprise therefore needs to govern not only the data itself, but the inferences produced from it.
That introduces another layer:
Raw Data → Combined Data → Inference → Decision → Outcome
The inference may be more consequential than any individual field used to produce it.
A company may never explicitly collect a field labeled:
Maximum Price This Customer Will Pay
An AI system may infer it.
Governance still needs to account for the result.
The Algorithm Does Not Eliminate Accountability
Personalized pricing also illustrates a broader problem emerging across AI governance.
Organizations sometimes treat algorithmic outcomes as though responsibility belongs somewhere inside the model.
The system determined the price.
The model identified the customer.
The algorithm produced the recommendation.
But algorithms do not possess organizational accountability.
Someone authorized the system.
Someone selected the data.
Someone approved the use case.
Someone established the business objective.
Someone decided whether disclosure was necessary.
Someone deployed the capability.
Someone benefits economically from the outcome.
That creates a governance chain:
Data → Purpose → Model → Decision → Consumer Outcome → Accountability
The more automated the decision becomes, the more important that chain becomes.
Automation can remove humans from individual transactions.
It cannot remove organizational responsibility for the system producing them.
Data Lineage Needs a Purpose Layer
Traditional data lineage helps organizations understand where information originated and how it moved through systems.
That remains important.
But the FTC’s personalized-pricing proposal points toward something broader.
Organizations increasingly need purpose lineage.
Data lineage asks:
Where did this data come from?
Where did it move?
How was it transformed?
Which systems consumed it?
Purpose lineage asks:
Why was it originally collected?
What uses were originally authorized?
When did the purpose change?
Who approved the new use?
What disclosures accompanied that change?
What decisions now depend upon the data?
What outcomes does the new use create?
Together, those concepts provide a richer governance model:
Data Origin → Original Purpose → Transformation → New Purpose → Authorization → Decision → Outcome
That is considerably more useful for AI-era governance than simply knowing which database supplied a field.
The Evidence Problem Comes Next
Imagine the FTC asks an organization to explain how personal information came to influence an individualized price.
Could the organization reconstruct the decision?
It might need to demonstrate:
What data was collected.
Why it was originally collected.
What representations were made to consumers.
When the new pricing use case was proposed.
Which personal information the pricing system used.
What inferences were generated.
Who reviewed the use case.
Which legal and governance requirements were considered.
Who approved deployment.
What disclosures consumers received.
How the algorithm influenced the price.
What monitoring occurred after deployment.
What consumers ultimately experienced.
That produces an evidentiary chain:
Data Collected → Original Purpose → New Use → Authorization → Algorithmic Decision → Consumer Outcome → Disclosure → Evidence
If those records do not exist, the organization may find itself reconstructing governance after the regulator arrives.
That is precisely when evidence becomes expensive.
A Data Catalog Is Not Enough
Many organizations have invested heavily in data catalogs.
They know where important datasets exist.
They assign owners.
Define classifications.
Record schemas.
Track lineage.
Document quality.
Those capabilities are valuable.
But knowing that a dataset exists is not the same as governing what the enterprise is doing with it.
A mature data-governance system should increasingly be able to answer:
What is this data?
Where did it originate?
Who owns it?
Who can access it?
Why are we using it?
What decisions does it influence?
What models consume it?
What inferences are produced from it?
What outcomes result?
What restrictions apply to secondary use?
When does a new purpose require review?
That moves data governance from inventory toward accountability.
New Use Should Be a Governance Trigger
One practical implication follows directly from the FTC development.
Organizations should treat material new use of personal data as a governance event.
Not every analytical query requires executive approval.
But consequential secondary uses should trigger review.
The workflow might be:

Can the organization demonstrate the entire decision?
That is purpose governance.
This Is Not Just a Privacy Department Problem
It would be easy to classify the FTC’s proposal as a privacy issue.
It certainly has privacy implications.
But the governance problem is broader.
Personalized pricing can involve:
Data governance.
AI governance.
Consumer protection.
Legal compliance.
Marketing.
Pricing strategy.
Product management.
Enterprise architecture.
Model risk.
Reputation.
Executive oversight.
The use case crosses organizational boundaries.
That means no single control function may see the entire chain.
The data team knows the dataset.
The AI team knows the model.
Marketing knows the business objective.
Legal knows the regulatory standard.
Technology knows the architecture.
Privacy knows the disclosure.
Leadership owns the outcome.
Governance is what connects them.
The Board Does Not Need to Approve Pricing Algorithms
As with other governance issues, board oversight should not become operational management.
Directors do not need to approve individual datasets or pricing models.
They should understand whether management has established a system for governing consequential uses of customer data.
Useful questions include:
Does management know which AI and analytics systems use personal data to make consequential decisions?
Are secondary uses of personal data subject to review?
Can management distinguish original collection purposes from subsequent uses?
Are significant algorithmic inferences governed?
Who has authority to approve a materially new use?
Are consumer disclosures aligned with actual data practices?
Can management reconstruct how personal data influenced a consequential consumer outcome?
Those are oversight questions.
They test whether data governance is functioning as an enterprise capability rather than merely a privacy inventory.
Test the Purpose Chain
Organizations can examine this risk now.
Select a consequential AI, analytics or personalization use case.
Choose one important input dataset.
Then trace it backward.
Where did the data originate?
Why was it collected?
What was the consumer told?
What was originally authorized?
When did the current use begin?
Who proposed it?
Who reviewed it?
Who approved it?
What model or algorithm consumes it?
What inference does the system produce?
What decision does that inference influence?
What outcome does the consumer experience?
What disclosure explains the practice?
What evidence proves the process?
Then ask:
Would the person who originally provided the data reasonably recognize this as one of the purposes for which it is now being used?
That question will not resolve every legal issue.
But it may reveal where governance review needs to begin.
The Governance Takeaway
The FTC’s proposed personalized-pricing policy is still a proposal.
But the governance signal is already useful.
Data risk does not end when information is securely collected.
It continues throughout the information lifecycle.
And in an AI-enabled enterprise, the most consequential risk may emerge long after collection—when existing information acquires a new purpose.
That changes the governance model.
Organizations need to move beyond:
What data do we have?
Toward:
Why are we using it now?
The governing principle is straightforward:
New Purpose → New Governance Question
When data changes purpose, the organization should determine whether the new use changes its obligations, disclosures, controls, decision authority or risk.
And it should preserve evidence of that determination.
Because the future enforcement question may not be whether the organization protected the data.
It may be whether the organization can explain what it decided to do with it.
The data may have been governed.
Was its new purpose?



