This episode covers three topics following the Possible conference for marketers and ad tech players: clean room legal frameworks, new state privacy laws in Montana and Tennessee, and Senator Schumer's emerging AI regulatory framework. On clean rooms, the conversation clarifies a persistent misconception: entering data into a clean room does not create a privacy-free zone. Legal analysis must focus on the specific purposes for which the clean room is being used, what actually happens to the data inside it, and the contractual relationships with the clean room provider and any collaborating parties. Ensuring the clean room is properly classified as a service provider — rather than a co-controller or third party — requires confirming that data processing agreements are in place and that the provider is not independently using or enriching client data. The classification can change depending on whether the clean room combines data from multiple first and third parties, which can affect what privacy obligations apply. On the state law front, Montana and Tennessee (with Indiana also noted) have passed comprehensive privacy laws awaiting governor signatures. All follow the Virginia model rather than the California model: no private right of action, narrower scope, and effective dates well into the future. The discussion notes the significance of conservative-leaning states embracing comprehensive privacy legislation, framing privacy as a bipartisan consumer protection value. The California Chamber of Commerce lawsuit challenging the California Privacy Protection Agency's authority is touched on briefly — with a clear message to practitioners: do not slow down compliance programs in anticipation of a litigation-driven delay. New York’s pending bill, which would include a private right of action, is flagged as a higher-stakes development to watch. The episode’s centerpiece is Senator Schumer’s four-part AI governance framework: assessment of intended audience and purpose, transparency into data inputs, visibility into the model’s internal workings, and scrutiny of outputs for bias. This parallels what FTC Commissioner Bedoya has been signaling at IAPP. The key insight developed in the discussion is that ethics is not a post-hoc filter applied only at the output stage — it must be embedded across the entire AI value chain from the outset. The ChatGPT French language example is used to illustrate how thoughtful documentation of inputs can enable beneficial surprises while also guarding against harmful ones. Waiting until outputs are produced to ask ethical questions is too late; the more durable approach is to interrogate intended use cases, sensitive domains, and foreseeable downstream consequences before a model is ever deployed.
Clean room legal reality, Montana and Tennessee privacy laws
- AI GovernanceState Privacy LawsFTC Enforcement
- Episode 11
- April 27, 2023
Stream this episode on
Summary
Transcript
**Jonathan:** Hey, Lisa. How are you? **Alysa:** Hey there. Hello. Good to see you. **Jonathan:** Great to see you. Happy to talk about privacy. What's going on? **Alysa:** Yeah. A lot going on. So last week, we're at the Possible conference, ton of marketers, ton of ad tech players, ton of agencies. I mean, you could not talk about AI. It was just kind of everywhere. So I wanted to get your thoughts on that. I loved Schumer's framework on kind of the four pieces and things that he's thinking about when you think about AI regulation. I'd love to tie that to some of what FTC Commissioner Bedoya was saying when we were at IAPP. I think it seems to be a little broader. More stakes. And last week I talked to Fred at Harvard about clean rooms and we promised to get the legal perspective. Maybe you can check some of the things that he was saying. **Jonathan:** Yeah, yeah, no totally. Well let's start with clean rooms then. I mean, one of the things I talked to Fred about was just the name Clean Room. Kind of what is it? And there's a lot of confusion about it. At Hub, they seem to have settled on this idea of data collaboration platform. As people kind of think through what clean rooms do and what they don't do, what collaboration platforms do or don't do, what's your kind of practical advice there? **Alysa:** Well, one, these are all good questions. I usually have clients come to me with, we're using a clean room, and sometimes there's a presumption that anything that happens in the clean room means it's safe, privacy laws don't apply, anything can happen in the clean room, kind of it's this special vacuum. And that's not the case, right? So usually what we're doing is breaking down, what are you doing, right? What problems are you trying to solve in the clean room? And often there's a number of different things they are doing with that clean room. So isolating, what are the purposes? That's really important for the legal analysis. What's actually happening in the clean room, right? Clean rooms provide just a lot of tools and a lot of capabilities. It doesn't mean that you're using all of those tools and capabilities. So, that's really important. And then, what are the relationships, right? What contract terms do you have in place? What is the clean room? What's the relationship to the clean room and the clean room's role? Sometimes some clean rooms also provide their own data and that's an important legal factor to consider in assessing what the obligations are. So, all of those types of issues are ones that from the lawyer perspective, we like to break down and have a really good factual understanding. **Jonathan:** Gotcha. What else is — so for a lawyer who's negotiating a clean room contract between two parties or looking at vendors, what's some good practical advice for them? **Alysa:** So you want to have privacy terms with the clean room and you want to determine — usually, you want them to be your service provider. You don't want them to be doing something else with your data, right? They are the set of tools for you. So, you need to confirm that you've got the right set of privacy terms in place, that's one. And that's just a data processing agreement, sometimes the clean room has one even posted on their website. But two, what is happening? So, if there are some instances where personal data from a first party and a third party are combined, and that combination of data, depending on the facts, may essentially disqualify the clean room from being considered a service provider for that functionality. And so, that, you know, business has a way of doing things and what's gonna work best for the clients. These are new legal restrictions, so there's a little bit of a delay in reacting to these new legal restrictions. And so, what we're seeing are clean rooms responding to that. So, well, at the end of the day, it's making sure what data is being used and shared and collaborated with, and what is happening to that data in the clean room, and making sure you understand that so you know at the end of the day, do we have opt outs? No opt outs? Do privacy laws even apply? Maybe the data is aggregated, you use federated learning, for example, and that can be super helpful. **Jonathan:** Thanks Alysa, super helpful. So more states, maybe there's something in the water, but like Montana, Tennessee now on the governor's desk. Anything interesting about those two? Anything different? **Alysa:** Well, I know for certainly a lot of companies it's a headache in the sense of we have more states. Does that mean new requirements? Are there changes from type of privacy infrastructure that companies are already building? And I think for the most part, the safe answer is no. These are three red states, and I think that's interesting because privacy is part of consumer protection law, and you don't typically see more conservative states regulate in the consumer protection area in a very specific way. And so, what this tells me is privacy is a value, it is important, and important enough that there are comprehensive privacy laws in these states as soon as they're signed by the governor. So, I think that's interesting. They fit within the lines though of the other Virginia type model, even a little bit more narrow than Connecticut. There's no private right of action. The effective dates are down the path, right? It's not a twenty twenty three type of issue. **Jonathan:** Gotcha. Yeah, I forgot about Indiana. That was the first state there. Thanks for mentioning that. So, nothing interesting, but it is a bipartisan issue, privacy. But it's narrow in scope without the private right of action. Would you say there's a ton of overlap between what's out there already? Generally a little conservative? **Alysa:** No, I think like I said, it fits within the lines, very similar. We don't yet have the issue of a state passing a totally different model that doesn't play well from an operational perspective with the other states that have laws on the books. That's a helpful thing. We're watching bills, you know, being just contested in various state legislatures that would be entirely different. New York, for example, they've got a bill that has a private right of action for a comprehensive privacy law. That type of risk factor ups the ante if that were to move forward. So things we're definitely watching. **Jonathan:** Gotcha. And the California Chamber of Commerce suing the California Privacy Protection Agency. Is there anything to that? Is there merit there? You think there'll be a delay in the enforcement date? **Alysa:** Well, here's the thing with litigation. It'll be interesting, but I don't think we will — you can't bank on a clear answer that slows down any of the compliance obligations you're doing. Litigation can be a long windy path, and so for now, you just kind of have to have heads down and keep building your compliance program and hope maybe you get some more time after July, but I would not count on it. **Jonathan:** Well AI, I love Schumer's kind of four part framework. To summarize that real quick, there was almost an assessment stage, right? A little like who's the intended audience of the AI? Who's working on the model? And then there was something on data inputs, of course, and then the inner workings of the model. What is it doing? Give us some transparency there. And then fourthly, the outputs and are they biased basically, which as we know FTC Commissioner Bedoya was talking about already having regulation for. What were your thoughts on that framework? I mean, me, on the first piece, on the assessment, I know we're already doing assessments for automated decision making. Is there enough room there for innovation? **Alysa:** What he's not saying is — the model has to do what you said it was going to do. Look, it's an emerging topic and I think it's really helpful to have different perspectives come at it and maybe they use different labels or names. At the end of the day, what the emphasis is, is really understanding the inputs, not have it be this entire black box. Understand what is happening internally and then what are the outputs and what are the purposes? Because that could be really important to know if you've over indexed, for example, on your inputs to a certain population or certain set of attributes that — but if your intent is for the output to really broadly apply those insights, to extrapolate that, then you probably do have some biases. There's some unevenness. And the push here by Schumer, by what we've seen in the state laws when it comes to data protection impact assessments, is having a very frank and detailed conversation between those doing the legal analysis and the privacy analysis with the engineers and the data scientists who are putting in. And often, sometimes you're coming from different directions that there's not a clear connection, so not a common factual understanding. And that's really, I think, the push from all of these different efforts, Schumer's and the state laws to drive those conversations. **Jonathan:** Gotcha. So for example, this small worry I had that looks a little unfounded now. I love Bedoya's example of ChatGPT being designed for English language searches as an example. But some French got in there, and it was a happy accident. Because of that French getting in there, found out ChatGPT is a great translation engine. And I thought, what a great happy accident! Doing the assessment upfront doesn't stop innovation like that. It helps you document the intention a little bit, right? Is it fair to say that? So, me, the worry that this is too prescriptive almost doesn't necessarily have to be that way. **Alysa:** I agree with that. I think prescriptive is thou shall not do it. That's not what we are hearing. What we are hearing comes down to do a risk assessment, meaning really understand what is happening and why are you using it so that you can determine, right? Oh, you had this input that actually impacted that translation capability. That required factually knowing that you had French language put in. And if you were thoughtfully doing that, you were more likely to have a common understanding. That was a beautiful oops. But there can be other potentially more harmful, emphasis based on data that comes in and how you're using it going out. So I think that was really one of the key points to support innovation, but being thoughtful in terms of how you're looking, how you're using it. And then the other theme that we haven't talked about is just really ethics. And that's really — that's I think where you get into not prescriptive, like don't do this, but I think ethically there probably are gonna be lines to draw, right, ethically for the business that they don't wanna be connected to certain types of usage. And that goes to how they are doing their AI capabilities. So, I think that's where we may see some laws that identify a certain set of categories, right, that are off the table or that if you're going to do those, that requires extra belt and suspenders, right? Think of just like AI in medical technology, right, in managing the brain and how you think. Those could have such serious impacts that I think the ethics really come into play. Minority Report obviously comes to mind, right? How are you using law enforcement in the legal system? So I think that's really — it's yes on the data, but the use cases and foreseeable use cases are just as important. **Jonathan:** Oh, you handle that in the assessment upfront. Yeah, love that because it's, for a while there, I was thinking, well, you handle the ethics because you're looking at the outputs and you're making sure they're not biased, but actually what you're saying is we should be looking at ethics earlier. Should we even be asking this question? Is this an area that we want to dig in? And is it a sensitive domain or whatnot? And it's just the ethics piece is across this whole AI value chain, not just on the outputs. Because it's too late. The toothpaste is out of the tube at the end, right? It's really at the beginning of the journey being very intentional. It can allow for innovation in the beautiful oops type moments, but I think you have to know and anticipate some of the foreseeable outcomes that could raise some ethical quandaries. **Alysa:** Gotcha. Thanks, Alysa. We'll keep watching it. I'm sure it's not a fad that'll go away. **Jonathan:** No. I hundred percent agree with that. Well, good to chat with you too. Have a good week.
Next step
See permissioning infrastructure in action
Walk through the platform with a Ketch architect, or launch the free CMP today.
Get started in less than 5 min