A Clean Room Is Not a Loophole
The clean room was sold to marketing as the privacy-safe replacement for the cookie: your first-party list never leaves, theirs never leaves, and a model meets in the middle. It is a genuinely better architecture. It is not an exemption — and the California definition it has to survive does not mention money at all.
The word is "share", and it was added on purpose
Under the original CCPA, a lot of adtech argued its way out of "sell" by pointing at the absence of consideration. California closed that with a second verb. Share means disclosing a consumer's personal information to a third party for cross-context behavioral advertising, whether or not for monetary or other valuable consideration. The opt-out right attaches to both verbs, which is why the mandated link reads "Do Not Sell or Share My Personal Information".
A clean-room audience build is, in plain description, the use of your customer list to target advertising on someone else's inventory across a context your customer did not come to you through. That is the paradigm case the second verb was written for. The enclave changes the security posture; it does not change the purpose, and purpose is what the definition turns on.
Three architectures, three different answers
"Clean room" describes a family of arrangements, and they do not all land in the same place. Work out which one you have bought before writing a word of your privacy notice.
Vendor processes only on your instructions
SERVICE PROVIDER PATHA measurement or modelling vendor that uses your data solely to perform services for you, under a contract with the required CCPA restrictions, and that is barred from retaining, using or disclosing the data for its own purposes.
This is the only configuration that avoids the opt-out analysis, and it is fragile: the moment the vendor combines your data with another client's for its own product, the exemption is gone and the contract will not save it.
Match with a platform that also uses the result
SHAREYou upload hashed identifiers, the platform matches them to its own users and activates a segment. The platform is running the match for its advertising business as well as yours.
This is a share for cross-context behavioral advertising. It requires the opt-out link, honouring of opt-out preference signals, and disclosure in the notice at collection — and it requires the opt-out to suppress the segment, not just the next upload.
Model trained inside, weights or segments exported
DEPENDS ON THE OUTPUTThe enclave produces something durable — a lookalike model, a propensity score, a set of weights — that outlives the session and gets used later.
Ask whether the artefact can single out a person. A score attached to an identifier is personal information wearing a decimal point. A genuinely aggregate coefficient may not be, but you have to be able to show the difference rather than assert it.
The opt-out has to reach the pipeline, not the tag
Most sites implement the opt-out where it is easiest to see: the consent banner drops the advertising tags and the page stops firing pixels. A clean-room flow is server-side and batch, so it survives that entirely. The consumer sees a banner confirming their choice while a nightly job keeps posting their hashed email into an audience.
The opt-out has to be recorded as a durable attribute
Not a cookie. A cookie-scoped preference is lost on the next device and was never visible to the warehouse job that builds the upload.
Global Privacy Control counts as a request
An opt-out preference signal has to be treated as a valid opt-out of sale and sharing for that consumer, which means the front end has to write it somewhere the back end reads.
Suppression must cover the segment already uploaded
Removing someone from tomorrow's file leaves them inside today's audience. The flow needs an active deletion or suppression call, and someone has to verify it landed.
A model already trained is its own question
You cannot usually untrain a person out of a propensity model. That is an argument for training on data you are permitted to use rather than on everything, and for retention limits that force periodic rebuilds.
Authorised agents send these in bulk
Opt-outs increasingly arrive from agents on behalf of many consumers at once. A manual suppression process that works for three requests a month will not survive three thousand.
"Deidentified" and "aggregate" are defined terms
The most common escape attempt in a clean-room deck is the claim that the output is deidentified or aggregated and therefore out of scope. Both words have statutory definitions. Deidentified information must not reasonably be capable of being associated with a particular consumer, and to rely on the exclusion a business must take reasonable measures to prevent reidentification, publicly commit to maintaining the data in deidentified form, and contractually oblige recipients to do the same. Aggregate consumer information describes a group and is not linkable back to a member of it. An audience built so that an ad can be served to specific people fails both tests by design — the targeting is the reidentification.
Sensitive categories get in through the back door
A first-party list that looks innocuous can carry sensitive personal information into the match without anyone choosing to send it. Purchase history from a pharmacy category, a membership tied to a religious organisation, precise geolocation from a mobile SDK, a product line whose customers are overwhelmingly one demographic — each can support an inference in a category with its own limit-use right. The safe move is to enumerate what is in the upload field by field before the first sync, rather than discovering it in an inquiry response. An inference is personal information too, and a model that produces one has produced data you now hold.
What a regulator can check without asking you anything
California's public enforcement in this area has repeatedly turned on mechanisms a stranger can test from a browser: whether the opt-out link exists and works, whether the Global Privacy Control signal is honoured, whether the notice at collection describes what is actually happening. None of that requires a subpoena, and none of it is about intent. Before you worry about the enclave's cryptography, confirm that the link in your footer is reachable by keyboard, announces itself to a screen reader, and leads to a flow that finishes — because that is the part that gets tested first.
Does your "Do Not Sell or Share" link actually work?
The opt-out mechanism is the most-tested surface in California privacy enforcement, and it fails in boring ways: a footer link with no accessible name, a modal that traps keyboard focus, a toggle with no label a screen reader can read. Scan the page free and see what an investigator — or a consumer using a keyboard — would find.
Scan Your Privacy Page for Free →Frequently Asked Questions
We do not sell data. Money never changes hands. Does CCPA still apply?
Yes, because the definition that matters here is not 'sell'. California added 'share', which covers disclosing personal information to a third party for cross-context behavioral advertising whether or not anything of value is exchanged. That definition was written for exactly this arrangement: you provide the audience, the platform provides the reach, and no invoice describes it as a data sale.
The identifiers are hashed. Is hashed email personal information?
Treat it as personal information. A hash that is used to match one person's record to the same person's record on another system is, by construction, an identifier capable of being associated with a particular consumer. The whole value of the pipeline depends on the hash identifying someone; you cannot claim in a privacy notice that it does not.
Our clean-room vendor says nothing leaves the enclave, so there is no disclosure.
The architecture is a good control, not a legal conclusion. Ask what leaves: a match rate, a segment membership flag, a model, a set of weights, or an activation push into an ad account. If the output allows the other party to act on your consumers differently from other consumers, personal information has been made available for their benefit, which is what the statute addresses. Design the output, not just the enclave.
Does an opt-out have to reach the clean room?
Yes, and this is where most implementations fail. An opt-out of sale or sharing must propagate to every downstream flow, including the segment already uploaded, the model already trained on it, and the next scheduled refresh. Suppression on the next sync but not on the live segment leaves the consumer in an audience they opted out of.
Can we call the model output deidentified or aggregate and stop worrying?
Only if it actually meets the statutory standard, which is not a vibe. Deidentified information must not reasonably be capable of being associated with a consumer, and the business must take reasonable measures to prevent reidentification, publicly commit to keeping it deidentified, and contractually bind recipients to the same. An audience segment that is targeted at individuals is not aggregate consumer information, no matter how many people are in it.
Do the automated decision-making rules reach audience models?
Possibly, depending on what the model decides. The California rules on automated decision-making technology are aimed at decisions producing legal or similarly significant effects — credit, housing, employment, essential goods. Ordinary product advertising generally sits outside that, but a model that gates a price, a financial offer or access to a service is not ordinary advertising and should be assessed on its own.