

Request a live demo
Want to see what else data clean rooms can do? Have a specific use case in mind? Let us show you.

Most attribution setups involving a walled garden or other closed platform start from an assumption: that a brand can send identifiable customer data to the platform, and the platform will handle it appropriately. A brand shares hashed emails or device IDs with the platform, which matches those against ad exposure and returns a report showing which campaigns actually drove conversions. That's the mechanism behind a last-touch model, crediting the final ad seen before purchase. Multi-touch attribution works differently: several publishers each send their own log-level exposure data to a separate measurement partner, who runs the model that spreads credit across those exposures. For the rest of this piece, we'll refer to whoever holds the exposure data as the publisher, in keeping with how the brand/publisher pairing is described elsewhere in clean room terminology. This piece focuses on the simpler case: one advertiser, one publisher, tracing conversions back to a single exposure source.
That assumption breaks down for a large and growing set of advertisers, and not only because of cookie deprecation and the signal loss it's already causing. Healthcare companies, health plans, and pharmaceutical brands are often legally prevented from sending identifiable customer data to a platform unless that platform is willing to sign a business associate agreement (BAA) or an equivalent data protection commitment. Many platforms won't. When that happens, standard attribution becomes unavailable.
This is most acute in walled garden environments like major social platforms and authenticated streaming platforms, where the platform itself holds the exposure data and expects identifiable data in return to complete the match. Open web attribution generally doesn't face this problem today, since DSPs typically already send exposure logs directly to advertisers, agencies, or measurement partners. That's outside the scope of this piece.
Where the standard model fails
Consider a regulated retailer in a category like eyewear or healthcare-adjacent retail, selling prescription products that count as protected health information under HIPAA. The retailer wants to know whether its campaigns on a major social platform are driving purchases and what return on ad spend those campaigns are generating, the same question any advertiser would ask. To answer it the usual way, the retailer would need to send hashed customer emails to the platform so exposure and conversion data can be matched, a common setup among brands chasing closed-loop attribution from walled garden platforms.
In some cases, the platform won't sign a BAA. Without one, sending that data would violate HIPAA. The retailer is left with a real measurement need and no compliant way to meet it through the platform's standard attribution tools.
The same constraint shows up wherever the exposure side of the equation sits with a platform unwilling or unable to take on that liability. And it isn't specific to social platforms. A regulated advertiser trying to match conversions against exposure on a streaming or CTV publisher runs into the identical problem, since the constraint comes from the advertiser's own data, regardless of which channel is doing the exposing.
Matching data without exposing it
Data clean rooms change what has to be shared in order to measure. Instead of the brand sending conversion data to the publisher, or the publisher sending exposure data to the brand, both parties bring their data into a neutral, encrypted environment. The match between exposure and conversion happens inside that environment, and what comes out is an aggregated report, such as the share of conversions attributed to each touchpoint and the timing between exposure and conversion, not a dataset either party could use on its own.
This is where it's worth being specific about the protection a clean room actually offers. Party-to-party protection, which is standard across data clean rooms in advertising generally, stops the brand and the publisher from seeing each other's raw data. That solves the problem between the two commercial parties. It doesn't, on its own, address what the clean room operator itself can see.
Operator-level protection comes from how the clean room itself is built. Some clean rooms rely only on policy and access controls to enforce party-to-party protection between the brand and the publisher, without doing anything to change what the operator itself can see. Others build the environment on confidential computing, meaning the underlying architecture keeps the data encrypted even while it's being processed, not just at rest or in transit. In that kind of environment, the operator running the clean room cannot access the raw inputs either, because the infrastructure itself was built without a path for anyone to do so.
For a regulated advertiser deciding whether attribution can be done compliantly at all, this is usually the distinction that matters most: party-to-party protection keeps the brand and the publisher separated from each other, but it's the clean room's underlying architecture, specifically whether confidential computing is part of it, that determines whether a third party running the infrastructure represents a new point of exposure.
Does this just introduce a new compliance problem?
It's a fair question, and worth answering directly rather than assuming the clean room label settles it. Running attribution inside a clean room does introduce a new party: whoever operates that environment. The answer comes down to the architecture point above. If the operator built the environment on confidential computing, there's no path for it to access the raw inputs, so it isn't a new point of exposure. If it didn't, the advertiser has effectively swapped one exposure point for another rather than closing the gap.
Beyond the architecture: why independence matters too
Compliance is one reason to care about the operator. Independence is a second, related one. Several of the largest clean room providers are owned by holding companies that also own media agencies: InfoSum joined WPP's GroupM in 2025, and LiveRamp has agreed to be acquired by Publicis Groupe, a deal expected to close before the end of 2026. When the entity measuring a campaign's closed-loop performance has a commercial relationship with the media side of that same campaign, the measurement carries a structural conflict of interest, regardless of how the technology performs.
That's a reason to weigh operator independence alongside operator-level data protection for any advertiser, and it becomes a harder requirement rather than a preference for a regulated advertiser already navigating a narrower set of compliant options. Both questions come down to the same underlying concern: who, besides the advertiser and the publisher, has access or influence over the result.
Decentriq is one of the few clean room providers built natively on confidential computing that has also stayed independent of that consolidation, which is the combination this piece has been arguing matters most for this use case.
What to look for
Advertisers evaluating a clean room provider for this kind of use case, regulated or not, should ask a few questions directly:
- Does the provider rely on confidential computing for operator-level protection, or only on the access controls standard to policy-based clean rooms?
- Can the provider point to independent verification, such as hardware attestation or third-party audits, rather than asking the advertiser to take its word for it?
- Is the operator independent of the media platforms and agencies involved in the campaign being measured?
The answers determine whether attribution is genuinely available and compliant, or only appears to be until the review starts, a question that matters most for a regulated advertiser but isn't exclusive to one.
Where this fits
Compliant attribution is one piece of a broader measurement picture. It sits alongside conversion lift, cross-media reach and frequency, and other clean room measurement use cases that share the same underlying requirement: getting a real answer about campaign performance without requiring either party to give up control of their data.
Want to see how this works for a specific setup? Request a demo.
References
Request a live demo
Want to see what else data clean rooms can do? Have a specific use case in mind? Let us show you.

Related content
Subscribe to Decentriq
Stay connected with Decentriq. Receive email notifications about industry news and product updates.


