Home Privacy Fun Fact About Clean Rooms: Data Security Isn’t A Given

Fun Fact About Clean Rooms: Data Security Isn’t A Given

SHARE:
data clean rooms (hero size)

Data clean rooms are magic. All you have to do is put your data inside, press a button, and it comes out matched, privacy safe and secure on the other side.

Just kidding.

Advertisers need to do their due diligence on potential clean room partners before working together, including (and especially) finding out how secure the platform is.

Because once data has been exposed, linked or enriched by another data set, “you can’t walk that back,” said Devon DeBlasio, VP of product marketing at InfoSum, speaking at an IAB Tech Lab Rearc privacy event in New York City last week.

Toothpaste doesn’t go back in the tube.

Somebody call security

Some of the potential security threats in a data clean room environment are the commingling of data, information leakage and “publisher ad observation.”

If, for example, a publisher knows which ads an advertiser is planning to serve, it could observe and log the first-party IDs associated with its own visitors who were also shown the ads. Then the publisher could look up the plaintext PII match keys for those identifiers and – voila! – the data has been exposed.

But not all threats are nefariously motivated, said Bosko Milekic, chief product officer at data collaboration platform Optable.

For example, say a media company owns and operates its own SSP or an advertiser has its own DSP. There’s nothing wrong with that, Milekic said, but even seemingly benign internal data sharing between them can be a form of “collusion” that leads to privacy and security problems, including data transfer through unsecured channels.

In order for data clean rooms to be considered secure, according to the IAB Tech Lab’s new technical standard for data clean room interoperability (which was released for public comment last week), the rooms have to check three important boxes.

  1. All PII must be encrypted and never shared directly with any party.
  2. No participant should be able to learn anything about the identity of people who aren’t in their own contributed data set.
  3. No one involved should be able to learn anything about anyone in the overlapping audience.

Miss any of these steps, and a clean room can’t really call itself a clean room.

Always ask

But the devil is in those details, and there are a lot of other things for advertisers to consider before partnering with a data clean room.

For example (deep breath):

How does the clean room access data? Can the data stay put, or will it have to be streamed into another platform? Do you have to change the format of your data before sharing it? Are there controls for data governance and encryption? How granular are the controls? Is there a time limit for how long the clean room has access to the data? Will the data flows be audited? What queries can you run on the platform, and is there a specific query language? What type of liability do you have in case of a data breach, and whose responsibility is it? What happens if there’s a breach involving matched data?

“This gets very complicated,” DeBlasio said, “but these are very important questions to ask.”

And we’re not done.

Don’t forget to ask about which privacy-enhancing technologies (PETs) the data clean room uses, said Rachel Blum, principal architect and field CTO at Snowflake.

Some PETs are more privacy-enhancing than others, depending on the use case and the advertiser’s own risk tolerance. And PETs aren’t static. The “level” of privacy can be dialed up or down based on qualitative thresholds, and there’s usually a trade-off between privacy and accuracy.

A data breach is a headache no one wants, but implementing a PET that’s so strong you can’t do anything practical is also a problem.

“It’s important to consider what you’re interested in implementing and what risks you’re looking at,” Blum said. “You also need to be able to actually perform the activity.”

Must Read

TV Manufacturer Telly Touts Programmatic Home Screen Ads

Telly, the startup that gives away free smart TVs in exchange for data and ad exposure, is making its home screen ads available for brands to buy programmatically – and pushing for industry standards to help attract more spend. 

AI Is Helping L’Oréal Brainstorm Unique Ways To Reach Male Audiences

L’Oréal adopted creative AI platform Springboards to generate creative ideas that led to a collaborative, ongoing ideation process.

AdExchanger's Big Story podcast with journalistic insights on advertising, marketing and ad tech

Google Had Its Day In Court. Now, It’s Amazon’s Turn

Google won’t have to break up its ads business after being declared an online monopolist. Meanwhile, Amazon faces a lawsuit from the FTC alleging that it charged advertisers more than necessary for ecommerce ads.

Privacy! Commerce! Connected TV! Read all about it. Subscribe to AdExchanger Newsletters

The FTC’s Amazon Lawsuit Is Ad Tech’s History Of Opacity Repeating Itself

Buy-side experts said it’s another example of a Big Tech platform taking advantage of the lack of transparency built into programmatic ad auctions. And they’re not optimistic change is coming.

How The Fin Tech Clearco Finances Ecommerce Startups (Without Losing Its Shirt)

This week, the Commerce Media Newsletter catches up with a startup from outside the world of data-driven advertising, but with an interesting position when it comes to ecommerce advertising. That’s Clearco, a Canadian fin tech company founded in 2015.

LOS ANGELES, CALIFORNIA - APRIL 26: Halo Collar CMO Seth Solomons attends a Celebration to Shine a Light On Dog Safety With Halo Collar on April 26, 2022 in Los Angeles, California. (Photo by Stefanie Keenan/Getty Images for Halo Collar)

How Halo Collar Uses Data And Incrementality To Raise Both Awareness And Sales

Halo Collar, a dog collar brand with direct-to-consumer origins, is preparing for its retail expansion by honing its first-party data strategy and incrementality measurement.