A new white paper from Germany’s digital industry association BVDW examines Data Clean Rooms through the lens of the EU General Data Protection Regulation. Although developed for the German programmatic advertising market, its findings point to a much wider European challenge: privacy-enhancing technology can reduce data exposure, but it does not resolve questions of legal responsibility, consent, security and governance. For organisations operating under the GDPR, the decisive issue is no longer simply whether data can be combined securely, but whether the entire collaboration remains controllable and accountable.
Across Europe, organisations face a growing tension. First-party data is becoming increasingly important for advertising, customer intelligence and data-driven business models, while privacy regulation places strict conditions on how personal information can be combined, analysed and reused. Data Clean Rooms, or DCRs, have emerged as one technological response. They provide controlled environments in which publishers, advertisers and other partners can match and analyse datasets without directly exposing the underlying raw data to one another.
Germany’s Bundesverband Digitale Wirtschaft (BVDW) has now examined the implications in a white paper entitled Data Protection Considerations of Use Cases for Data Clean Rooms. The BVDW is the German Association for the Digital Economy and represents more than 600 companies ranging from digital businesses and agencies to publishers. The paper was produced through its Programmatic Advertising Ecosystem activities and is intended primarily as industry guidance. It is therefore important to distinguish its role clearly: the BVDW is not a European regulator and the white paper is not legally binding guidance.
Its relevance beyond Germany nevertheless comes from the framework used for the analysis. The authors assess Data Clean Room scenarios against the EU General Data Protection Regulation, including questions of legal basis, joint controllership, processing on behalf of another organisation, security obligations and potential Data Protection Impact Assessments. These are not specifically German concepts. They form part of the common GDPR framework governing data processing across the European Union and European Economic Area.
The paper can therefore be read as a German industry contribution to a much broader European debate.
A “clean” environment does not automatically mean compliant processing
At first sight, the concept appears straightforward. Two or more organisations place pseudonymised datasets in a secure and neutral environment. The data can be matched or analysed without either party receiving the other organisation’s raw customer information. Results may then be returned as statistics, audience segments or identifiers for an agreed purpose.
But the BVDW warns against treating the technology itself as a compliance guarantee. Whether processing complies with the GDPR depends on the actual purpose, data flow and allocation of roles between the participating organisations. The same technical platform can therefore support very different regulatory situations. A statistical analysis designed only to determine whether two customer populations overlap is fundamentally different from identifying specific users and targeting them with personalised advertising.
The white paper illustrates this through five scenarios: potential analysis, Audience Insights, retargeting, Lookalike Audiences calculated within the Data Clean Room and Lookalike Audiences generated outside the DCR on the infrastructure of one of the parties. Read together, they reveal a clear pattern: the closer a use case moves from aggregated analysis towards individual profiling and activation, the greater the requirements surrounding legal basis, consent, transparency and responsibility.
For purely statistical analysis, a carefully assessed legitimate interest may under certain circumstances be considered. In advertising scenarios involving individual targeting, consent becomes considerably more important. For European organisations, this distinction is critical. Risk is not determined simply by how much data is processed, but by what organisations intend to learn about individuals and what they subsequently intend to do with those conclusions.
Pseudonymisation reduces exposure, not necessarily responsibility
One of the most important points in the paper concerns terminology that is frequently misunderstood in technical discussions. Data Clean Rooms commonly process hashed email addresses, customer numbers or other pseudonymous identifiers. That does not automatically make those datasets anonymous.
Where an organisation can realistically reconnect a pseudonymous identifier with an individual, the data can remain personal data for GDPR purposes. A company that hashes the email addresses in its own CRM system, for example, may still know exactly which customer stands behind each original value. Pseudonymisation therefore reduces exposure and can be a valuable security measure, but it does not make purpose limitation, data minimisation, transparency or security obligations disappear.
The legal picture becomes more complex where the parties have different abilities to identify the individuals concerned. One organisation may retain the original customer relationship, while another receives only pseudonymous values or aggregated outputs and has no realistic means of re-identification. The BVDW paper discusses this as an area in which the legal analysis is not entirely settled. This makes documentation particularly important: organisations should be able to explain what each participant receives, what each participant can realistically identify and how the data moves through the process.
For European security leaders, this has an important implication: technical separation and legal responsibility do not always follow the same boundaries.
Who decides may matter more than who hosts the system
A central part of the white paper deals with joint controllership under Article 26 GDPR. In simplified terms, organisations may become joint controllers where they jointly determine the purposes and means of processing personal data.
The paper stresses that joint responsibility does not require two parties to exercise precisely the same amount of control. Their decisions may complement one another. Nor is it necessarily decisive that both organisations can directly access the same personal data. What matters is how their contributions interact and whether the relevant processing operation depends on the involvement of both parties.
Activation scenarios make this particularly visible. An advertiser may contribute a customer list and define the campaign objective. A publisher contributes its own user base and the environment in which advertising is displayed. The DCR performs the matching or creates the relevant segment. None of these contributions alone produces the final targeting operation.
This is why the paper sees strong arguments for joint controllership in scenarios such as retargeting and certain forms of Lookalike Audience activation. At the same time, joint controllership does not make each party responsible for everything. A publisher remains responsible for aspects associated with its own user profiles and advertising delivery, while an advertiser remains responsible for its own customer data. Responsibility overlaps where the joint process itself takes place – for example during matching, segment creation or target-group selection.
The distinction matters because a Joint Controller Agreement cannot simply be used to define the legal reality away. According to the paper, such an agreement follows from an existing situation of joint responsibility; it does not create or eliminate that responsibility. Data transfers still require an appropriate legal basis, affected individuals must receive the necessary information and responsibilities for GDPR obligations must be allocated transparently.
For European companies building multi-party data ecosystems, the message is highly practical: contracts need to describe the processing that actually takes place rather than the processing model the parties would prefer to have.
Privacy by Design becomes part of security architecture
The white paper becomes particularly relevant to the security community when it moves from legal classification to implementation. Many privacy requirements cannot be enforced effectively through policies and contractual clauses alone. They need to be reflected in the technical architecture.
The BVDW recommends minimising the amount of directly identifying information used, applying pseudonymisation – potentially at several stages – and limiting outputs to aggregated or statistical information wherever the use case allows it. Data Clean Rooms can also impose technical restrictions on queries, such as minimum cohort sizes, to reduce the possibility that a user narrows an analysis until individuals become identifiable.
Consent should likewise become part of the technical workflow. The paper recommends connecting DCR processing with existing Consent Management Platforms so that only authorised identifiers enter relevant processes. If an individual withdraws consent, the architecture should be capable of removing or blocking the corresponding identifier for subsequent matching.
This turns the familiar concept of Privacy by Design into something more operational: compliance becomes a system property. Consent status, permitted purposes, export restrictions and access rights are no longer merely documented in policies; they increasingly have to be enforced by technology.
For CISOs, data protection officers and security architects, this creates a much closer connection between privacy governance and technical security design.
The Data Clean Room itself becomes a high-value security environment
The term “Clean Room” can also create a misleading sense of safety. Even when data is pseudonymised, combining large volumes of information from several organisations can create an attractive target for attackers and insiders.
The BVDW therefore stresses that GDPR security requirements continue to apply. It recommends security audits of DCR providers, appropriate encryption and strict access controls. Particularly sensitive operations, such as exporting information from the protected environment, should be restricted to a small number of authorised users.
This significantly widens the security assessment. Organisations need to understand who can add a new dataset, launch a matching process, modify processing parameters or generate an export. Privileged access should be traceable. Technical restrictions should reflect the purpose agreed between the parties. And when a processing purpose ends, organisations should be capable of demonstrating that information has been deleted, returned or blocked as required.
A Data Clean Room should therefore be viewed not simply as a privacy tool but as a cross-organisational trust zone. Identity and access management, privileged-user controls, audit logs, encryption and governance become as important as the matching technology itself.
The legal architecture must reflect the technical architecture
The BVDW paper accordingly places considerable emphasis on contractual arrangements. Where organisations qualify as joint controllers, their agreement should define the common processing purposes, technologies involved, information obligations, handling of data-subject rights and what happens to information when the cooperation ends.
The DCR provider itself will often be treated as a processor if it merely supplies the infrastructure and processes information according to the parties’ instructions. In those circumstances, Article 28 GDPR agreements should cover the relevant datasets, processing purposes, confidentiality, security obligations, audit rights and support with data-subject requests.
The structure becomes more complex when advertising agencies or further technology providers participate. An agency may operate on behalf of an advertiser, while other service providers may become processors or subprocessors. The apparent simplicity of the Data Clean Room can therefore conceal a much more complicated network of legal and operational relationships.
This is one of the broader lessons for European data ecosystems: technical integration is often faster than governance integration. Verifying a platform provider’s encryption or certification is not enough if access privileges, contractual responsibilities and actual data flows do not align.
AI will extend the governance challenge
The next stage is likely to make this considerably more difficult. The white paper already examines Lookalike Audiences, where existing user data can be used to identify other individuals with similar characteristics. Such profiling may require a Data Protection Impact Assessment where data is combined and new predictions about individuals are created. The BVDW identifies risks such as discrimination and lack of transparency that should be considered as part of that assessment.
But the current paper deliberately stops short of fully analysing the next generation of AI-driven Data Clean Rooms. Future systems may move beyond matching identical identifiers between two datasets. AI-based analysis could identify patterns across several datasets and multiple partners, allowing organisations to generate joint insights without sharing the raw information from which those insights were derived.
That development changes the security question again. Organisations may need to govern not only datasets and identifiers, but also models, training processes, scoring logic and the insights derived from combined information. Controls will be needed not only around what data enters a DCR, but also around what models can learn and what conclusions are permitted to leave it.
Standardisation is becoming a European scalability issue
The BVDW identifies the current lack of standardisation as another major challenge. Technical interoperability is needed for areas such as secure identity matching, while more consistent legal approaches could simplify recurring forms of data cooperation.
At present, individual companies may need to negotiate bilateral solutions for each new collaboration. That is manageable for pilot projects but becomes problematic when Data Clean Rooms are intended to support larger ecosystems. If every partnership requires a new technical integration, a separate role assessment, individual contracts and another compliance review, scaling becomes expensive and difficult.
Standardisation therefore has a security dimension as well as an economic one. Repeatable architectures make controls easier to test. Standardised interfaces can reduce implementation inconsistencies. More consistent governance models make it easier to establish who is responsible for what.
The white paper also points to anticipated guidance from the European Data Protection Board on anonymisation and pseudonymisation. Greater clarity in this area could become particularly important for determining when pseudonymised information remains personal data for individual participants and how responsibility should consequently be allocated.
Sven Wegholz of Publicis Media Germany, who leads the BVDW’s Data Clean Rooms Lab, summarises the underlying principle: successful Data Clean Room projects are those in which privacy is considered from the beginning and where all participating organisations develop a common understanding of the legal requirements before the collaboration is implemented.
A German paper with a wider European message
The significance of the BVDW white paper should therefore be understood carefully. It is neither an EU policy document nor regulatory guidance for the whole of Europe. It is an industry paper developed in Germany, primarily for the programmatic advertising market.
But the regulatory questions on which it is based are European.
The GDPR makes purpose, legal basis, transparency, security and accountability central to the processing of personal data. Data Clean Rooms do not remove those requirements; they change the technological environment in which companies have to fulfil them. This is why the paper has relevance beyond the German advertising industry.
The strategic question for European organisations is no longer simply whether data can be combined without exchanging raw records. The more important question is whether the resulting cooperation remains controllable: Can the parties establish which information is being processed, for what purpose, on what legal basis, by whom, under which access rights and with which permitted outputs?
That creates a more meaningful benchmark for Data Clean Rooms.
Their quality should not be measured by how much data they can connect, but by how effectively they enable collaboration without sacrificing accountability, traceability and control.
The technology can create the protected environment.
European compliance and security depend on the governance built around it.
At a glance: 10 key points for European organisations
- A Data Clean Room is not a compliance certificate. Technical isolation does not automatically make processing GDPR-compliant.
- The purpose of processing determines much of the risk. Aggregated analysis and individual advertising activation require different assessments.
- Pseudonymisation is not the same as anonymisation. Hashed identifiers may still constitute personal data.
- European relevance comes from the GDPR. The BVDW is a German industry association, but the legal principles examined in the paper apply across the EU/EEA GDPR framework.
- Joint controllership depends on the real processing model. Organisations do not need identical influence or identical access to become jointly responsible.
- Contracts must follow reality. A Joint Controller Agreement documents responsibilities; it cannot remove joint responsibility where it already exists.
- Privacy by Design requires technical enforcement. Data minimisation, consent status, cohort limits, purpose restrictions and export controls should be built into DCR architecture.
- The Clean Room itself needs protection. Large combined datasets require strong encryption, privileged-access controls, auditing and tightly controlled export functions.
- AI will increase the governance burden. Models, profiling, scoring and derived insights will become additional security and compliance objects.
- Standardisation will determine scalability. Common technical interfaces and clearer governance models will be necessary if Data Clean Rooms are to move from individual projects to wider European data ecosystems.




