RatedWithAI

RatedWithAI

Accessibility scanner

Privacy LawSeptember 8, 2026

Your Retail Media Network Is a CCPA Sale. The Clean Room Does Not Fix It.

Nobody wired money for the data, so the privacy notice says the company does not sell personal information. CPRA added the word "sharing" to close precisely that gap — and the AI audience model sitting between the loyalty database and the CTV ad break is the thing it was written about.

Sharing
Triggers the same opt-out as a sale — no payment required
$7,500
Per intentional violation, multiplied across an audience file
Inferences
Model-derived segments are personal information, not anonymous output

Sale, Sharing, and the Distinction That Does Not Help You

Original CCPA regulated the "sale" of personal information, and the ad-tech industry spent two years arguing that a data flow with no invoice attached was not one. CPRA answered by adding a parallel defined term. Sharing means disclosing personal information to a third party for cross-context behavioural advertising, whether or not for monetary or other valuable consideration.

A retail media network is the textbook case. The retailer holds first-party purchase data. A brand wants to reach the households that bought a competing product. Whatever the contract calls it — a media buy, a co-operative marketing programme, an audience activation — the retailer is disclosing information about identified consumers so a third party can advertise to them somewhere else. That is sharing, and sharing carries the same "Do Not Sell or Share My Personal Information" obligation as a sale.

Where the AI Layer Changes the Analysis

The modelling step is often presented as the thing that removes the privacy problem: no raw records leave, only a model and its outputs. CCPA's definition of personal information forecloses that argument in one clause. Inferences drawn from personal information to create a profile reflecting a consumer's preferences, characteristics, predispositions and behaviour are themselves personal information.

IN SCOPE
Loyalty and purchase history
SKU-level transactions tied to a member ID — the input to nearly every retail media segment
IN SCOPE
AI-derived audience segments
"Likely expecting a child", "switched brands in the last 90 days", propensity scores attached to a household
IN SCOPE
ACR viewing data from smart TVs
Automatic content recognition logs of what was on screen, matched to an advertising identifier
IN SCOPE
Hashed email used for identity resolution
A hashed identifier is pseudonymous, not anonymous — it exists to re-identify the same person elsewhere
IN SCOPE
IP-derived household graph
Linking a phone, a TV and a laptop into one household for frequency capping and targeting
OUT
Aggregate campaign reporting
Reach and frequency at a level where no individual is reasonably identifiable, with re-identification contractually and technically prevented

The recurring engineering mistake is treating the segment as a derivative artefact that inherits none of the source data's status. It inherits all of it. A propensity score is an inference about a named household, and moving it into an ad platform is a disclosure of personal information about that household.

What a Clean Room Actually Buys You

Clean rooms are genuinely useful, and they are consistently oversold internally as a compliance answer. The distinction that matters is between the two things a clean room can be used for.

Measurement and attribution — defensible

A brand asks whether people exposed to a campaign bought more. The output is an aggregate lift number. Here the clean room operator can plausibly sit as a service provider processing on documented instructions, with no individual-level output leaving. This is the use case the architecture was designed for.

Audience building and activation — still sharing

A brand builds a segment inside the clean room and pushes it to a DSP for targeting. No raw records moved, and it makes no difference: the purpose is cross-context behavioural advertising and the result is an addressable set of real households. The opt-out obligation attaches to the purpose, not to the file transfer method.

The service provider contract is the pivot

CCPA's service provider exception requires contractual terms prohibiting the recipient from retaining, using or disclosing the data for any purpose other than performing the specified service, and from combining it with data from other sources. Most clean room and DSP contracts contain a permission to enrich or to improve the vendor's own models. That single clause converts a service provider into a third party and the transfer into a sale.

Enrichment permissions are the audit finding

Read every downstream contract for the words 'improve our services', 'aggregate with other customers' data', or 'develop models'. Any of them, unqualified, means you have been sharing under CCPA while telling consumers you were not.

Connected TV: Two Statutes, Not One

CTV inventory is where a retail media programme most often walks into a regime its privacy team was not scoping for. Automatic content recognition — the TV identifying what is on its own screen — produces a viewing history, and viewing history is regulated separately from general personal information.

  • CCPA sensitive PI limits. Viewing data that supports an inference about health, religion or sexual orientation puts you in the sensitive category, which carries a separate "Limit the Use of My Sensitive Personal Information" right and a purpose limitation on inferring characteristics.
  • Video privacy statutes. The federal VPPA and several state analogues attach consent requirements to disclosing what a person watched. These are older, stricter, and come with statutory damages and a private right of action — which is what makes them the litigation risk rather than the regulatory one.
  • No browser, no signal. A CTV app cannot receive Global Privacy Control. That does not create an exemption; it means the account-level opt-out is the one that has to be honoured, and that your identity graph has to carry the flag across identifier spaces.
  • Household, not individual. One television, several people, one opt-out. The conservative and operationally simpler answer is to suppress the household, because the alternative is defending a claim that you kept targeting someone who exercised a right.

The Opt-Out Has to Reach the Model

The most common real-world failure is not a missing opt-out link. It is an opt-out that is recorded correctly, honoured on the website, and never propagated into the pipeline that builds the audience file. Trace the flag through each hop:

1. Capture
  • Footer link present on every page, not only the privacy policy
  • GPC processed as a valid opt-out on first request, without requiring an account
  • In-app and in-store opt-out paths recorded into the same store as web
  • Loyalty programme sign-up captures the notice at collection before the first data flow
2. Propagation
  • Opt-out flag joined to every identifier the consumer maps to — hashed email, member ID, device IDs, household graph node
  • Suppression applied at segment build time, not only at activation
  • Downstream platforms receive the opt-out via a documented signal, and receipt is logged
  • Clean room queries exclude opted-out records before the model runs
3. Model hygiene
  • Training sets are reconstructible, so an opted-out cohort can be removed and the model retrained
  • Retraining cadence short enough that removal is a scheduled job, not a rebuild project
  • Existing inferences about a deleting consumer are deleted, not merely detached from the profile
  • Seed-audience uploads carry an expiry, so a stale seed cannot resurrect an opted-out household
4. Evidence
  • Timestamped log showing opt-out received, propagated and confirmed downstream
  • Contract register recording which counterparties are service providers and which are third parties
  • Annual review of enrichment and model-improvement clauses in every ad-tech contract
  • Privacy notice that names sharing explicitly rather than denying a sale

Frequently Asked Questions

We only share hashed emails. Isn't that de-identified?

No. Hashing is pseudonymisation, and the entire purpose of sending a hashed email to a platform is to match the same person on the other side. CCPA's de-identification standard requires that the information cannot reasonably be linked to a consumer and that you take measures to prevent re-identification — a deterministic identifier built to enable matching fails both limbs. Treat hashed identifiers as personal information in every audit.

The brand, not the retailer, decides the targeting. Who owes the opt-out?

Both, for different things. The retailer is the business that collected the data and owes the notice at collection, the opt-out mechanism and the suppression. The brand is a business in its own right for the data it receives and the profiles it builds, and it cannot rely on the retailer's compliance as a defence for its own processing. In practice the contract should allocate suppression duties explicitly, because the failure mode is each side assuming the other filtered the file.

Does a financial incentive through a loyalty programme let us use the data for advertising?

A loyalty programme can offer a price difference in exchange for data, but CCPA requires a separate financial incentive notice, opt-in consent to the incentive, a good-faith estimate of the value of the data, and a right to withdraw at any time. What it does not do is override the sharing opt-out: a member who joined the programme and later opted out of sharing has to be suppressed from advertising audiences while remaining in the programme.

Our media partner says their contract makes them a service provider. Is that enough?

Only if the terms actually meet the statutory requirements and the conduct matches. A service provider must be prohibited from retaining, using or disclosing the personal information for any purpose other than the specified service, and from combining it with information received from other sources. A platform that uses the data to improve its own targeting models across advertisers is a third party regardless of the label on the agreement, and regulators look at the processing, not the heading.

How far back does a deletion request reach into our models?

Deletion covers the personal information you collected and the inferences you drew, which includes segment membership and scores. Whether the model itself must be retrained is unsettled and fact-dependent, but the FTC has ordered algorithmic disgorgement where a model was built on data collected unlawfully, and California regulators have referenced the same remedy. The defensible posture is to be able to remove a cohort and retrain, which is an architecture decision made long before the request arrives.

Audit the Purpose, Then the Pipe

Every defensible retail media and CTV programme answers two questions in order. What is the purpose of this data flow — measurement or targeting? And can a consumer's opt-out actually reach every place their identifier lives, including the model that was trained before they exercised it?

A clean room is an answer to a security question. It has never been an answer to the purpose question, and the purpose question is the one CCPA asks first.