Clean rooms are emerging as a primary data collaboration strategy as companies prepare for the deprecation of third-party cookies and Apple's App Tracking Transparency opt-in framework. The term encompasses a wide range of data-matching and audience-building practices, but IAB Tech Lab has released draft standards for industry comment to bring greater consistency to what "clean room" actually means in practice. Using a clean room does not create a privacy safe harbor — obligations depend on what the partner does with data, what purposes are served, and whether activation for targeted advertising versus aggregate analytics is involved. The setup requires months of effort and significant investment, and the business case remains experimental for many companies still figuring out whether it will scale. The Supreme Court heard oral argument in Google and Twitter cases centered on Section 230 immunity for user-generated content and platform content moderation. The justices appeared largely skeptical of narrowing congressional intent on the statute, suggesting immunity is likely to remain intact. But even if Section 230 is unchanged, the underlying questions about how platforms use personal data for personalization, algorithmic decision-making, and AI-driven engagement will continue to drive regulatory and legislative scrutiny through other channels — including emerging AI-specific requirements and state privacy laws that address data protection impact assessments. California's CPRA enforcement window opens July 1, at which point all CPRA modifications to the original CCPA become actionable by both the California Privacy Protection Agency and the Attorney General's office. Virginia's privacy law is already in effect. Early enforcement is expected to target low-hanging fruit: privacy policy disclosures, opt-out scope and prominence, and ad tech transparency notices. Against this backdrop, the broader question of what it means to be "compliant" is inherently dynamic — no company considers its privacy work finished because data uses, products, and regulations continuously evolve, and the real goal is a structured, adaptive compliance program capable of responding as the regulatory scaffolding continues to take shape.
IAB clean rooms, Section 230, California CPRA enforcement
- AI PrivacyCCPA / CPRAPrivacy Regulations
- Episode 2
- February 22, 2023
Stream this episode on
Summary
Transcript
**Jonathan:** Hey, Alysa. Welcome. You know, I'm in I'm in your patch here in DC this week. **Alysa:** Welcome to DC. We I'd say we brought great weather for you, but it's a little gray outside today. **Jonathan:** Yeah. It's nice, though. It's nice, though. It's it's a little warmer than I thought. **Alysa:** It is, we've got cherry blossoms blooming and it is February, so not sure whether to be excited about that or disturbed. **Jonathan:** Yeah, I know. So look, what's going on in the world of privacy? I'm hearing a ton about clean rooms. IAB just released its standards. We've got the Supreme Court, some Supreme Court cases we'd love to talk about. And then, you know, we talked a little last week about the California regulators out in public and what they were talking about. I'd love to dig in a little deeper on that, you think the enforcement actions will be or the areas of focus for them. But let's start with clean rooms. The IAB released standards, it seems like everyone's talking about clean rooms lately. What are the need to know there? **Alysa:** Yeah, well, first, the fact that clean rooms are just hot. It is a booming business area. And if we think about why, why are clean rooms of such interest? We've got getting ready for the deprecation of third party cookies by Google. We have Apple's change in its ATT framework that moved to opt in. And so you have a lot of companies with their first party data now wondering how do they have kind of that next generation of improved personalized targeted advertising that's going to actually convert in a successful way? And so clean rooms have popped up as a result. Now I use the maybe lowercase clean rooms because we have seen so many different versions of data matching essentially and to create audiences by different companies using the term clean rooms and privacy safe and a lot of that terminology. But the practices by companies really vary. And so it puts a lot of burden on those using clean rooms with those different partners and vendors to figure out what's actually happening. Are these tools that the companies can use to analyze the data? Are there combinations of data? What is that partner who's offering the clean room? What do they do with the data? Do they have any of their own use? And so those questions are really important to drill down so you know what your privacy obligations are. Because you hear the word clean room, and it has such a nice pristine, fresh sound to it that you must be in privacy safe land. And that's how they often are advertised. But absent really knowing what's happening and absent a standard, it's a little bit of the Wild West. And so you have IAB Tech Lab, which is the industry body on a lot of best practices and industry standards just released for comment. So they're not final. They're asking for industry comment on essentially standards for clean rooms and how one would describe and how they should function. And so I would put it out there. If you're in the clean room business or you want to use clean rooms, to take a look at IAB Tech Lab's draft standards and give some thought, we'll certainly see what the final version looks like. But that's generally the direction that I think is worth taking into account as you examine your own practices on that front. And also just because you're using a clean room, can't help not put this aside, just because you're using a clean room does not mean you're out of scope of your privacy obligations, that there absolutely are privacy obligations. It matters what the partner's doing. It matters what purposes you're using the clean room and what's happening to that data. So really drill down on that and work with your privacy team to get the answers. **Jonathan:** Some of the classic use cases we've been seeing there, which firstly, is people are storing data in multi clouds. And so there's an idea that you need to combine what's in these different clouds so you can have a full understanding. The other classic use case is a consumer goods company and a retailer. You need to come together so they can understand the full customer journey. And the question I had for you, Alysa, is it seems like there are a lot of analytics use cases, but can you use the output of a clean room or the output of that analysis and actually advertise to that segment of people that you've created? Are they there yet, is that something we're figuring out? **Alysa:** Well, I think we're figuring out. That's certainly one of the use cases and intents that I've seen, And you can do that. You need to do that in a way that does take into account your privacy obligations. And those obligations may differ based on whether you're using it for this audience activation targeted marketing strategy versus perhaps aggregate data analytics. So it just what you're doing and why you're doing it matters. So that's the legal side. Now on the business side, what's going to work and what's going to take off? I think that's to be determined, and whether that can be done in a scalable way so that the monetary investment in that is really worth it. I mean, takes a lot to set up a clean room for a company. And it's a multi month effort to even see if this is going to work out. So I describe this as a lot of experimentation. And some experiments work and some don't. But you have to do it either way to figure out what's the path forward. **Jonathan:** Gotcha. And over here at Ketch, we're obsessed with this idea of permission data. The data that you have, always understanding what you can do with it, what you can't do with it, and that includes how you send it to a clean room, what you do with that. And so these integrations with clean rooms like Habu are super important. We'll set our second topic, seeing a lot of buzz with some Supreme Court cases that are here today. Can you give us a quick snapshot of what's happening there? I'm seeing Google in the news there. **Alysa:** There's a couple of interesting things. Yeah, so we had a Google case yesterday, oral argument, the Supreme Court, Twitter case today, I believe. And really the word is content moderation, which comes up a lot and often intersects with privacy in some interesting ways. A number of the state attorneys general in some of their criticism of big tech, content moderation is one of those issues. And ultimately it goes to this concept of should tech platforms have immunity from the content that appears on their platforms, such as user generated content under Section 230. That has been kind of for many, many years now. That's allowed the internet to prosper. And it has protected tech platforms from being directly sued by companies in relation to the content posted on their platform. So yesterday at oral argument, I think the main takeaway is that the Supreme Court justices by and large seem pretty skeptical that they should weigh in and change a congressional intent on the statute scope and to remove the immunity. We'll find out when the ultimate decision is issued but it seems reading the tea leaves that immunity is probably going to stay and it makes you wonder whether the criticism of tech platforms and being able to personalize and drive engagement, that has a lot to do with content moderation, but it also has a lot to do with how personal information is used. And so I think that topic doesn't go away, the scrutiny doesn't go away. I think we still get into are there ethical uses of data, algorithmic decision making, proper uses of AI and what new laws may ultimately affect some of those obligations, even if immunity itself is not taken away. **Jonathan:** I love this idea of kind of where privacy is going as we start to think about AI and how to remove bias out of AI. We should put a pin in that and talk about it next week. That'll be a good one. So last week, we talked about the California regulators, and they were kind of out in force publicly, and their consumer forward messaging. One of the things I heard kind of since then is that they're thinking through enforcement actions that the envelopes are licked and stamped already almost, and July, June, maybe we should expect some letters to go out. Where do you think they'll focus? **Alysa:** Well, let's talk about where we stand today, right? So we have January one twenty twenty three has come and passed, so we have Virginia's privacy law, which is already in effect and potentially enforceable. We have California CCPA so that's maybe version one point zero which the California Attorney General's Office has the power to continue to enforce under its original set of regulations. Before privacy day, I think we mentioned there are a slew of investigations currently pending. So what happens July first is under the CPRA statute, all of those modifications to CCPA one point zero, suddenly those do become enforceable. And that enforcement period applies for acts and practices July one forward. So when we talk about July two, that really goes to the possibility of either the CPPA or the California Attorney General's Office being able to enforce companies who are not yet in compliance with CPRA. Now from the business side, see a lot of companies really scrambling to make sure that their practices are up to date, even as these draft final regulations are just percolating through. So I think there's a lot of catch up happening and yet there probably will be enforcement letters sent out July second. I think they're probably going to go after more low hanging fruit issues. For example, there are notice obligations, privacy policy disclosures that have to be said in certain ways and that's a pretty easy thing to look at companies privacy policies and say have they been updated to account for these new obligations. And we saw that with CCPA so that would be my sense. I think the opt outs and the scope of opt outs also are going to be a big issue. I think prominent notices not just the privacy policies on the ad tech side are also going to be a big issue. So yes, I think maybe the bottom line is, I think we will see enforcement. I think July second letters very likely that those will go out. Stacy Schessler from the California Attorney General's Office mentioned that at the California Privacy Law Summit a couple weeks ago, so we are waiting for that. **Jonathan:** One of the things I've been dying to ask you, and thanks for that, I saw a stat yesterday that asked UK based companies how compliant they thought they were with GDPR. And what I was surprised by is that half of the respondents said, Yeah, we're partially compliant. And I thought, privacy that kind of a movable feast where you can never actually say we're good and you're always working towards something? How do companies think about that? It seems to constantly evolve. Is there a place where you just kind of feel good about it? How do you advise clients there? **Alysa:** It's such a challenge. It's one bite of the elephant at a time in some ways. I don't know any company that feels like their work is done. And I think that has to be the case because we're talking about data which is the fabric of so many companies and there's always new uses. There's always new products, new services that there's new modeling. So I don't think you're ever done. I think the focus is do you have structure? Have you created the framework, the program that's continuing to be dynamic and responsive? And right now we're in scaffolding mode because all of that structure is some of it's new by these new laws and are still getting interpreted or still getting figured out How do we operationalize some of this? So I think we are in, I don't know, building mode and there's a lot of work to be done. I don't know a lot of companies who are very diligently and in good faith working to set up their compliance programs, but there is still a lot more work to be done. **Jonathan:** Gotcha. Thanks, Alysa. As always, we appreciate you. **Alysa:** Oh, it's fun.
Next step
See permissioning infrastructure in action
Walk through the platform with a Ketch architect, or launch the free CMP today.
Get started in less than 5 min