Retail Media and Shopper Data Toolkit: Data Rights, Clean Rooms, Measurement, and Consent
By Casey Scott McKay ·
A supermarket knows what a household eats, when it runs out, and a great deal it was never told. Retailers have discovered that this information is worth more sold to brands than the groceries are worth sold to shoppers. This toolkit assembles the working material for practitioners advising retailers, brands, agencies, and the technology businesses that connect them. It covers the data rights position, the consent and opt-out architecture that state privacy statutes now impose, and the sensitive category inferences that turn a loyalty programme into a regulatory problem. It works through clean room arrangements, their technical controls, and the differencing attacks that defeat naive aggregation thresholds. It closes with measurement and attribution claims, supplier and brand terms including the own-label firewall, clause language, and the failures that recur.
IP and Technology > Privacy Data Security | Toolkit | Published 9 June 2025 - Updated 20 March 2026 | Casey Scott McKay - marksy.us
Summary. A retailer knows what a household buys, and has discovered that the knowledge is worth more than the margin on the goods. This toolkit covers the data rights position in shopper and loyalty data, the consent and opt-out architecture state statutes impose, the clean room arrangements that let retailers and brands combine data without transferring it, measurement and attribution claims as advertising claims, sensitive category inference, and the supplier and brand terms that allocate all of it.
Keywords: retail media · shopper data · loyalty programmes · clean rooms · data collaboration · measurement and attribution · incrementality · sensitive inference · consumer rights requests · supplier terms · onsite and offsite advertising · in-store media · sale and sharing · opt-out signals · closed loop measurement · audience segments
Start Here
Retail media is an advertising business built on a dataset the retailer assembled for a different purpose, and every problem in the practice comes from that mismatch.
The data was collected to run a shop. Transaction records exist because somebody had to be charged. Loyalty records exist because the retailer wanted repeat custom. Neither was collected with an advertising business in mind, and the notices given at the time say so.
The inference is more sensitive than the record. A basket does not say "pregnant", "diabetic", "in recovery", or "recently bereaved". It permits all four to be inferred with uncomfortable accuracy, and state privacy statutes increasingly treat inferences about sensitive categories as sensitive data regardless of how they were derived.
The counterparties are competitors. A retailer serves many brands, each of which competes with the others, and each of which wants insight the others do not have. A brand supplying a retailer is also giving it data. The confidentiality architecture matters as much as the privacy architecture.
And the product being sold is measurement. Retail media's advantage over other advertising is closed loop attribution — the retailer can see the exposure and the purchase. That claim is the product, and it is an advertising claim about advertising, subject to the ordinary substantiation rules.
Four questions organise the work.
What rights exist in the data, and what does the notice permit?
What must be offered to consumers, and how is it operationalised?
How may retailer and brand data be combined without transferring either?
And what is being claimed about performance, and what proves it?
See The Aisle Is an Advertising Network for the doctrinal treatment, Building a Retail Media or Shopper Data Business for the sequence, and the Retail Media and Shopper Data Checklist for the working list.
Part one: rights in shopper data
Nobody owns the facts. A transaction record is a fact about a purchase, and facts are not property — Feist Publications, Inc. v. Rural Telephone Service Co.. A compilation attracts thin protection in its selection and arrangement under 17 U.S.C. § 103, and nothing in the underlying data.
So the position is contractual and regulatory. Access control, terms of service, loyalty programme terms, supplier agreements, and the statutory obligations that attach to personal data. See Selling Something You Cannot Own.
Trade secret protection under 18 U.S.C. § 1836 covers the derived assets — segments, models, and methodologies — where reasonable measures are taken, per Rockwell Graphic Systems, Inc. v. DEV Industries, Inc..
The four data pools each have different constraints. Transaction data, generated at the till and tied to a payment instrument or a loyalty identifier. Loyalty data, with a programme relationship and a consent record. Onsite behavioural data from the retailer's own website and application. And offsite data, obtained from partners, publishers, and identity resolution providers, whose provenance the retailer inherits.
Provenance discipline is the recurring weakness. A retailer that buys audience data does not know how it was collected, and a chain of contractual assurances is not the same as evidence. Where the resulting product is sold to brands with representations about compliance, the retailer has assumed the risk of somebody else's collection practice.
The notice given at collection is the binding constraint, and most loyalty notices were written to describe a discount scheme. A retailer building an advertising business on a decade-old notice should assume the notice does not cover it and should refresh rather than reinterpret.
Contractual restrictions on supplier data matter too: a brand supplying sell-through or promotional data to a retailer usually restricts its use, and retail media products built on that data may exceed the restriction.
Part two: consent, sale and sharing, and consumer rights
State comprehensive privacy statutes reshaped this business, and the reshaping is not finished.
"Sale" is defined broadly in several statutes to include disclosure for monetary or other valuable consideration, which reaches arrangements a retailer would not describe as selling data.
"Sharing" for cross-context behavioural advertising is a separate defined activity in some statutes, with its own opt-out, specifically aimed at the practice retail media depends on.
Opt-out rights must be honoured operationally, not merely offered. That means a mechanism that reaches every downstream recipient, a suppression process that actually suppresses, and a record showing it worked.
Universal opt-out signals must be recognised where the statute requires it, which is an engineering obligation rather than a policy one.
Sensitive data requires more. Several statutes require opt-in consent, or an explicit right to limit use, for sensitive categories — health, sexual orientation, religion, precise geolocation, and, critically, inferences that reveal any of them. A basket-derived pregnancy or health inference is squarely within scope in several jurisdictions.
Consumer rights requests — access, deletion, correction, portability, and opt-out — must be fulfilled across the retail media stack, including in the clean room, in audience segments already distributed, and at partners. A deletion that removes a record from the transaction system and leaves the segment intact is not a deletion.
Children's data is a separate regime with a separate risk profile, and a retailer selling children's products has an obvious exposure. See Building for Someone Who Cannot Consent.
Marketing channel rules run alongside: consent records for calls and texts, and email requirements. See Permission to Reach Someone.
Enforcement authority sits with state attorneys general and, federally, with the deception and unfairness authority in 15 U.S.C. § 45, which has been used against data practices that exceeded what the notice described.
Build the programme rather than the policy. See Building a Privacy Compliance Program for a Consumer Brand and the Privacy and Marketing Data Toolkit.
Part three: clean rooms and data collaboration
The clean room is the sector's characteristic structure and it is widely misunderstood.
What it is. A controlled environment in which a retailer's data and a brand's data are matched and analysed without either party obtaining the other's records. Outputs are aggregate, and query types are constrained.
What it is not. It is not anonymisation, and it is not a legal safe harbour. A clean room that permits queries returning small cells, or that permits repeated queries whose differences reveal individuals, leaks. The technical controls are the compliance measure and they have to be specified.
The controls that matter. Minimum aggregation thresholds on every output. Query allow-lists. Rate limiting and differential query controls to prevent reconstruction by subtraction. Logging of every query and its output. No raw record export. Defined roles and named users. Independent review of the configuration.
The matching layer is where the privacy exposure concentrates: identifiers are hashed and matched, and hashed identifiers of stable values are pseudonymous rather than anonymous. Treat matched data as personal data.
Contractual architecture. Who operates the room, who may query, what query types are permitted, what outputs may leave, what each party may do with the outputs, how long anything persists, and what happens on termination.
Competition sensitivity. A clean room serving several competing brands within one retailer's data can produce outputs that inform pricing or promotional behaviour. Keep outputs backward-looking, aggregated, and non-attributable, and route the design through a competition review. The controls are the same ones described in the Competitive Intelligence and Benchmarking Toolkit.
Consumer rights must reach into the room. A deletion request has to remove the individual from the matched population and from any persisted output that could identify them.
And the vendor operating the room is a processor with the ordinary obligations, plus a technical role that makes its configuration part of the compliance position rather than an implementation detail. See the Data Licensing Checklist.
Part four: measurement, attribution, and the claims problem
Retail media sells measurement, and measurement claims are advertising claims.
The claims that recur. Return on advertising spend. Incrementality — sales that would not have occurred without the advertising. Reach and frequency. New-to-brand buyers. Halo effects across categories. Store visits attributed to online exposure.
Attribution methodology is a choice, not a fact. Last-touch, multi-touch, and modelled attribution produce different numbers from the same events, and a platform that reports the most favourable methodology without disclosing it is making a claim that requires substantiation.
Incrementality requires a control group. A claim of incremental sales without a holdout or a geographic control is an assertion, not a measurement, and a brand that later runs a proper test will discover the difference.
Marking your own homework is the structural problem. The retailer sells the advertising, measures the outcome, and reports the result. Independent verification, or at minimum a documented and disclosed methodology with the brand's ability to run its own tests, is what makes the claim defensible.
The legal exposure is real. 15 U.S.C. § 45 reaches deceptive performance claims made to business customers as well as consumers, and 15 U.S.C. § 1125(a) gives a competing retail media network a false advertising claim, with standing analysed under Lexmark International, Inc. v. Static Control Components, Inc.. The literal falsity and implied deception framework is set out in False Advertising Under the Lanham Act.
Contract remedies matter more in practice. Brands increasingly negotiate measurement warranties, audit rights, and make-good obligations, and a network that resists them is telling the brand something.
Third-party verification is becoming an expectation, as it did in digital advertising a decade earlier.
And disclose the methodology. A reported number with a stated methodology and a stated limitation is defensible. The same number presented as a fact is not.
Part five: supplier and brand terms
The commercial agreements in this sector do several jobs at once and are frequently drafted for only one of them.
The advertising insertion order covers placement, price, and delivery, and says nothing about data.
The data rights layer should be separate and explicit: what data the brand supplies, what the retailer may do with it, what the brand receives back, in what form, at what granularity, and what it may do with that.
Aggregate versus granular output is the negotiation. Brands want customer-level insight; retailers want to keep the customer relationship and cannot lawfully hand over identified shopper records without a basis. The workable answer is aggregated segments and modelled outputs, with granularity floors specified.
Exclusivity and category restrictions — whether a brand's insights may inform the retailer's own-label products — is the sharpest commercial issue in the sector and is frequently unaddressed. A brand supplying data to a retailer that also competes with it through own label is exposed, and should say so in the contract.
Confidentiality between brands must be structural rather than promised, since the retailer holds data from competitors in one system.
Trading terms and media spend interact in a way that attracts regulatory attention in some jurisdictions, where a supplier's media commitment is effectively a condition of shelf space.
Audit rights over measurement, over data handling, and over the clean room configuration.
Termination. What happens to segments already built, models already trained, and outputs already delivered.
And privacy flow-down. The brand is frequently a controller in its own right for what it receives, and the allocation of consumer rights obligations between retailer and brand should be express rather than assumed.
Clause bank
Data use grant (brand to retailer). Brand grants Retailer a non-exclusive licence to use Brand Data solely to: (a) deliver and measure the Campaigns; and (b) produce Aggregated Insights in accordance with the Output Standard. Retailer shall not use Brand Data to develop, position, price, or promote any Retailer own-brand product, and shall not disclose Brand Data or any output derived from it to any third party, including any other supplier. Retailer shall maintain technical separation between Brand Data and the data of other suppliers, and shall provide a description of those controls on request.
Output standard for a clean room. No output may be released from the Environment unless it: (a) aggregates no fewer than [N] distinct households, with no single household contributing more than [X] per cent of any reported metric; (b) is produced by a Permitted Query listed in Schedule [A]; (c) has passed the automated small-cell suppression check; and (d) has been logged with the query, the requester, the timestamp, and the output. No raw or record-level data may be exported. The Operator shall apply rate limiting and differential query controls sufficient to prevent reconstruction of suppressed cells by repeated or differenced queries, and shall report any suspected reconstruction attempt to both parties within [24] hours.
Measurement methodology disclosure. Retailer shall provide, with each Campaign report: the attribution model applied; the lookback window; the definition of each reported metric; the treatment of organic and non-exposed purchases; and any modelling applied. Where Retailer reports an incrementality metric, it shall state the control methodology used and shall make the control design available to Brand. Brand may, at its own cost and on [notice], conduct an independent holdout test within the Campaign, and Retailer shall implement the agreed holdout and shall not exclude the holdout population from reporting.
Consumer rights flow-through. On receipt of a verified consumer request, Retailer shall within [the statutory period]: suppress the individual from all active audiences; instruct each downstream recipient listed in Schedule [B] to do the same and obtain confirmation; remove the individual from the matched population in the Environment; and, for a deletion request, delete the individual's records and re-derive any persisted output that would otherwise reflect them. Retailer shall maintain a record of each request and each step taken, and shall provide it to Brand on request in respect of any Brand Data affected.
Sensitive inference restriction. Neither party shall create, use, or disclose any segment, model output, or targeting criterion that is derived from purchase behaviour and that reveals or is intended to reveal: health status or condition, pregnancy, sexual orientation, religious belief, immigration status, or substance use, except where the individual has provided the consent required by applicable law and that consent is recorded. Each party shall maintain a prohibited-inference list and shall review new segments against it before activation.
Own-label firewall. Retailer shall procure that no individual engaged in the development, sourcing, pricing, or marketing of Retailer own-brand products in the [Category] has access to Brand Data or to any non-aggregated output derived from it. Retailer shall maintain a list of individuals with access, shall review it quarterly, and shall make it available to Brand's auditor under confidentiality. Breach of this clause entitles Brand to terminate the Agreement immediately and to require deletion of Brand Data.
Part six: the in-store and offsite layers
Onsite advertising — sponsored listings and display on the retailer's own site and application — is the easiest layer legally, because the retailer controls the surface and the data stays inside.
Offsite advertising uses retailer audiences on third-party inventory, which requires transferring or matching identifiers outside the retailer's environment. That is the activity most likely to constitute a sale or a sharing under state statutes, and the opt-out obligations attach.
In-store retail media is the newest and least settled layer. Digital screens, shelf-edge displays, and audio are broadcast media and raise no personal data question by themselves. Cameras that measure attention, dwell, or demographics do, and where the processing produces a biometric identifier a statutory written-consent regime may apply, with statutory damages. See Your Face as Data and the Biometric Data Checklist.
Store-level notice is hard to do well. A sign at the entrance is the usual approach and is a weak basis for anything requiring consent. Where the technology needs consent, the technology probably needs redesigning.
Connected television and streaming audio extend the audience further and add the platform's own terms and measurement standards.
Identity resolution providers sit underneath the offsite layer and are the point at which provenance becomes opaque. Diligence them, contract for representations, and understand that the representations are only as good as the counterparty.
Marketplaces and third-party sellers add another party whose data practices the retailer inherits reputationally if not legally. See the Marketplace and Platform Liability Toolkit.
And influencer and creator activity funded through retail media budgets carries its own disclosure obligations. See Endorsements, Influencers, and the Law of Paid Praise and Building an Influencer and Endorsement Compliance Program.
Worked scenarios
A notice that does not reach the business. A grocery chain launches a retail media network using loyalty data collected under a notice written in 2013 describing "offers and rewards". A state attorney general asks how the advertising business is disclosed. The retailer's position is that the notice permits "marketing", which is true and insufficient, because the activity includes sharing identifiers with third-party platforms and constructing audiences from inferred characteristics. The remediation is a refreshed notice, a properly operationalised opt-out, and a sensitive-inference prohibition list — all of which were cheaper before launch.
A clean room that leaks by subtraction. A brand runs a series of queries in a retailer's clean room, each aggregated above the threshold, whose differences isolate a single high-value household segment down to a handful of shoppers. The controls prevented small-cell outputs and did not prevent differencing. Nobody acted maliciously; an analyst was being thorough. The configuration change that prevents it is standard and was not specified in the contract.
An incrementality claim that does not survive a holdout. A network reports a return on advertising spend of eight to one. The brand runs its own geographic holdout and measures incremental lift closer to one and a half to one. The difference is attribution methodology: the network credited purchases by shoppers who would have bought anyway. Nothing was fabricated and the reported number was indefensible as presented. The disclosure clause in the bank above would have made the difference visible from the start.
An own-label overlap. A brand supplies detailed category data to a retailer as part of a media partnership. Eighteen months later the retailer launches an own-label product positioned precisely against the brand's strongest segment. The brand cannot prove the data was used and cannot prove it was not. The firewall clause, with an access list and an audit right, is what turns an unprovable suspicion into a verifiable position — and its absence is why this dispute usually ends in a quiet reduction of the brand's data sharing rather than in litigation.
Failures that recur
A retail media business built on a loyalty notice written for a discount scheme.
Opt-outs offered but not operationalised through to downstream recipients and existing segments.
Universal opt-out signals unrecognised, which is an engineering failure with a regulatory consequence.
Sensitive inferences created by default because nobody built a prohibited-inference list.
Deletion that removes the record and leaves the segment.
A clean room with small-cell suppression and no differencing controls.
Matched hashed identifiers treated as anonymous.
Attribution methodology undisclosed, then discovered by a brand running its own test.
Incrementality claimed with no control group.
Brand data informing own-label development with no firewall and no access list.
Identity resolution provenance accepted on a warranty with no diligence behind it.
And in-store attention measurement deployed without considering whether the processing creates a biometric identifier.
Part seven: governance and operating model
Retail media businesses grow faster than their governance, and the gap is where the problems live.
Name an owner for the data position who sits between the commercial team selling the advertising and the privacy function writing the notices. Without one, the commercial team ships products the notice does not cover and the privacy function discovers them from a press release.
Put a review gate in the product process. Every new audience segment, every new measurement product, every new offsite activation, and every new data partner reviewed before launch against the notice, the statutes, and the supplier agreements.
Maintain a prohibited-inference list and test every segment against it before activation. This is a technical control, not a policy statement, and it should run automatically.
Maintain a segment register: what each segment is, how it is derived, which data it uses, which notice covers it, which brands may access it, and when it was last reviewed.
Maintain a downstream recipient list so that an opt-out or deletion can actually be propagated. A retailer that cannot list its downstream recipients cannot honour a request.
Audit the clean room configuration independently, at least annually, and specifically test differencing and reconstruction rather than only small-cell suppression.
Audit measurement by re-running a sample of campaign reports from raw events, and by supporting brand-run holdouts rather than resisting them.
Train the commercial team on what may be promised. Most misdescription in this sector originates in a sales deck rather than in a contract.
And report to the board. Retail media is now material revenue at many retailers, and its regulatory profile is materially different from grocery retail. The board should know what the business is doing with the loyalty data it acquired for a different purpose.
Part eight: diligence in a retail media transaction
Whether the matter is an acquisition, an investment, a retailer selecting a technology partner, or a brand assessing a network, the same questions apply.
Notice coverage. The notices in force when each data pool was collected, and whether they cover the current activity. Expect the oldest and largest pool to be covered by the weakest notice.
Consent and opt-out operation. Not the policy — the mechanism. Test a request end to end and see whether the individual disappears from an active segment.
Downstream recipients. The actual list, with contracts, and evidence that suppression instructions have been issued and confirmed.
Sensitive inference exposure. The segment register, tested against the categories the applicable statutes treat as sensitive.
Clean room configuration. Thresholds, query controls, differencing protections, logging, and the independent review if one exists.
Measurement substantiation. The methodology documents, the definitions, and whether any incrementality claim rests on a control group. Re-run one campaign report from raw events.
Supplier terms. Whether brand data is used within the limits granted, and whether any own-label activity has touched it.
Identity resolution provenance. The chain behind any purchased audience data, and the strength of the representations relied on.
Biometric exposure. Any in-store technology performing identification or demographic estimation, and the notice and release position.
Children's data. Whether the retailer sells children's products and how age is handled.
Open regulatory matters, attorney general inquiries, and consumer class actions.
And quantify. The cost of refreshing notices and re-consenting; the cost of rebuilding segments without prohibited inferences; the exposure from any biometric collection point; and the revenue at risk if a measurement claim cannot be substantiated.
Part nine: the brand's side
Most writing about retail media is addressed to retailers. Brands are the paying customers and their position deserves its own treatment.
Understand what you are giving. Every campaign supplies the retailer with information about which products, which promotions, and which audiences the brand values. Over time that is a map of the brand's strategy, held by a party that may compete through own label.
Negotiate the firewall. An access list, a quarterly review, and an audit right converts an unprovable suspicion into a verifiable position. Retailers resist it and accept it when a large enough brand insists.
Negotiate measurement transparency. Methodology disclosure, metric definitions, lookback windows, and the right to run a holdout. A network unwilling to support an independent holdout is telling the brand something about its numbers.
Do not accept last-touch attribution as incrementality. They are different questions and the difference is usually a large multiple.
Compare networks on a common basis. Each retailer reports differently, and a brand allocating budget on reported returns without normalising methodology is allocating on the basis of who reports most generously.
Watch the trading interaction. Where media commitment becomes a condition of range or shelf space, the arrangement raises questions beyond intellectual property, and the brand should document how the commitment was arrived at.
Address data return. What the brand receives back, at what granularity, and what it may do with it — including whether it may use retailer-derived insight in its dealings with other retailers, which retailers routinely prohibit and brands routinely assume.
Address privacy allocation. The brand is frequently a controller for what it receives, with its own consumer rights obligations, and the contract should say who does what.
And keep the substantiation. A brand repeating a retailer's performance claim in its own marketing has adopted the claim, and the retailer's methodology is now the brand's substantiation.
Part ten: where this is going
Statutory convergence, slowly. More states, broader sensitive category definitions, and a steady expansion of what counts as sharing. A programme built to the strictest current standard will need less rebuilding than one built to the median.
Inference regulation specifically. The clearest regulatory direction of travel is toward treating derived characteristics as equivalent to collected ones, which removes the argument that a basket-derived health inference is different from a stated one.
Measurement standardisation. Digital advertising went through this and retail media will: common definitions, third-party verification, and industry standards that a network must meet to be bought at scale.
In-store measurement expansion, with the biometric question becoming the sector's largest single financial exposure exactly as it has at stadium turnstiles.
Consolidation of clean room infrastructure, which concentrates the configuration risk in a small number of vendors whose settings become de facto industry practice.
And retailer own-label growth, which sharpens the firewall question every year and which will eventually produce the dispute that sets the expectation for the sector.
The practitioners who will be useful are the ones who treat this as a data governance practice with an advertising overlay, rather than as an advertising practice with a privacy appendix. The obligations attach to the data, they run for as long as the data is held, and they reach every downstream party the retailer has ever sent an identifier to.
The segment review, in practice
Segment creation is where compliance either happens or does not, and a workable review takes about fifteen minutes per segment.
What is the segment? A one-line description in plain words, as a regulator would read it. "Households likely to be managing type two diabetes" is a different sentence from "sugar-substitute repeat purchasers", and the first is what the segment actually is.
What data derives it? Every input, with the pool it came from and the notice covering that pool.
Does it reveal a sensitive category? Not "was it intended to" — does it. Test against the prohibited-inference list, and against the categories the applicable statutes name.
Could a reasonable consumer be surprised? The most reliable predictor of regulatory trouble in this sector is whether the shopper would be startled to learn the segment exists.
Who can access it? Which brands, which internal teams, and whether anybody on the own-label side is on the list.
How is it suppressed? The mechanism by which an opt-out or deletion removes an individual from this specific segment, tested rather than assumed.
How long does it persist? And is it re-derived or static, because a static segment built two years ago will contain people who have since opted out.
Who approved it, and when? Recorded, because the review is only evidence if it leaves a trace.
A retailer that runs this on every segment will decline a small number and will fix a larger number, and will have a defensible position on all of them. One that does not will have a segment library nobody can describe, which is the position most networks are actually in.
Two documents worth keeping current
The segment register. One row per segment: description in plain words, derivation, source pools and their notices, sensitivity assessment, access list, suppression mechanism, persistence, approval date and approver. It is the document a regulator asks for and the one that makes every other control auditable.
The downstream recipient map. One row per recipient: identity, what they receive, in what form, under which contract, with what suppression obligation, and the date suppression instructions were last confirmed. Without it, an opt-out cannot be honoured and a deletion cannot be certified — which means the compliance position rests on a promise nobody can verify.
The three-day test
The quickest diagnostic on a retail media business takes three days. Pick the largest revenue-generating audience segment and ask for five things.
The plain-language description of what the segment actually identifies. The notice in force when each contributing data pool was collected, and whether it discloses this activity. The list of every downstream recipient that has received the segment or an identifier from it. The record of an opt-out request propagating through to that segment and those recipients, with confirmations. And the sensitivity assessment showing the segment was tested against the prohibited-inference list before activation.
A network that produces all five has a defensible position and will survive an attorney general inquiry. A network that produces two has the ordinary position and a year of work ahead. A network that produces none is running an advertising business on a grocery notice, which is the most common finding in the sector and the one that will not survive the next few years of statutory expansion.
One paragraph to remember
Retail media is a data governance practice wearing an advertising costume. Nobody owns the shopper data, so the position rests on the notice given at collection, the consent and opt-out machinery that actually works, and the contracts with brands and downstream recipients. Build a prohibited-inference list and run it automatically; specify clean room controls that defeat differencing rather than only small cells; disclose attribution methodology and support brand-run holdouts; firewall brand data from own-label development with an access list and an audit right; and never build a segment you would not be willing to describe, in one plain sentence, to the shopper it identifies.
A note on the pregnancy example
Every discussion of this subject reaches for the same illustration: the retailer that inferred a pregnancy from a purchase pattern and revealed it to the household before the household intended. The example is a decade old and still the best one available, for a reason worth stating.
Nothing unlawful was alleged. The inference was accurate. The targeting worked. The system did precisely what it was built to do, and the consequence was a story that has followed the sector ever since.
Which is the point. In retail media the compliance question and the reputational question are usually the same question, arriving in different order. The segment that a regulator would question is almost always the segment a journalist would write about, and both are almost always the segment a shopper would be startled by. A practitioner who tests every proposal against that intuition, before testing it against the statute, will be right more often than the statute alone would make them.
Key Authorities at a Glance
Data rights. Feist Publications, Inc. v. Rural Telephone Service Co.; 17 U.S.C. § 103; 18 U.S.C. § 1836 and 18 U.S.C. § 1839 with Rockwell Graphic Systems, Inc. v. DEV Industries, Inc.; 18 U.S.C. § 1030 with Van Buren v. United States and hiQ Labs, Inc. v. LinkedIn Corp..
Consumer protection and advertising. 15 U.S.C. § 45 for deception and unfairness; 15 U.S.C. § 1125(a) for false advertising, with standing under Lexmark International, Inc. v. Static Control Components, Inc. and the substantiation framework discussed in False Advertising Under the Lanham Act; 15 U.S.C. § 1117 for remedies.
Privacy statutes. State comprehensive privacy statutes define sale, sharing, sensitive data, and consumer rights, and impose universal opt-out recognition — see State Privacy Opt-Out Signals. Biometric statutes impose written notice and release before collection, with the standing analysis of Rosenbach v. Six Flags Entertainment Corp.. Children's data is separately regulated under 16 C.F.R. § 312. Marketing channels engage 47 U.S.C. § 227 and 15 U.S.C. § 7704.
Contract formation. Loyalty and site terms must be formed enforceably; see Terms That Actually Bind.
Trademark. Keyword and listing disputes arise across retail media surfaces — 15 U.S.C. § 1114 and 15 U.S.C. § 1125, with the keyword analysis in Buying a Competitor's Name.
| Authority | Governs | Practical consequence | | --- | --- | --- | | Feist | Facts | Shopper data is contractual, not owned | | State privacy statutes | Sale and sharing | Offsite activation triggers opt-outs | | Sensitive data provisions | Inferences | Basket-derived health inference is in scope | | Biometric statutes | Identifiers | In-store cameras may need written release | | Rosenbach | Standing | Technical violation suffices | | 15 U.S.C. § 45 | Deception | Measurement claims need substantiation | | Lexmark | Standing | Competing networks can sue | | 16 C.F.R. § 312 | Children's data | Separate regime, higher risk | | 47 U.S.C. § 227 | Calls and texts | Consent records required | | 18 U.S.C. § 1836 | Trade secrets | Segments and models | | Van Buren | Computer access | Contract claims do more work | | 15 U.S.C. § 1125 | Keyword and listing use | Marks on retail media surfaces |
Related Documents
The triad
- The Aisle Is an Advertising Network: Retail Media, Shopper Data, and the Rights Inside a Basket
- Building a Retail Media or Shopper Data Business
- Retail Media and Shopper Data Checklist
Privacy and consent
- Building a Privacy Compliance Program for a Consumer Brand
- Privacy and Marketing Data Toolkit
- Your Face as Data: Biometric Privacy Statutes and the Written Consent Requirement
- Biometric Data Checklist
- Building a Biometric Compliance Program
- Building for Someone Who Cannot Consent: COPPA, Age Signals, and the New Design Duties
- Permission to Reach Someone: The TCPA, CAN-SPAM, and the Consent Records Nobody Keeps
Data rights and collaboration
- Selling Something You Cannot Own
- Data Licensing Checklist
- Competitive Intelligence and Benchmarking Toolkit
- Who Owns the Data: Scraping, Databases, and the Limits of Ownership
- Data Collection and Scraping Risk Checklist
Advertising and claims
- False Advertising Under the Lanham Act
- Endorsements, Influencers, and the Law of Paid Praise
- Building an Influencer and Endorsement Compliance Program
- Buying a Competitor's Name: Keyword Advertising and the Death of Initial Interest Confusion
- Whose Campaign Is It? Advertising Agencies, Creative Services, and the Work Nobody Assigned
Platforms, partners, and adjacent practice
- Marketplace and Platform Liability Toolkit
- Online Brand Protection Toolkit
- Channel Partner IP Checklist
- Travel, Hospitality, and Loyalty Programme Brand Toolkit
- Terms That Actually Bind
- Running a Data Breach Response
Marksy is not a law firm. This toolkit is provided for general informational purposes and does not constitute legal advice. State privacy statutes, sensitive data definitions, opt-out signal requirements, and biometric regimes vary by jurisdiction and change frequently. Clause language is illustrative and must be adapted to the arrangement. Nothing here creates an attorney-client relationship. Consult qualified privacy and advertising counsel before relying on any position described here.