Privacy-First Measurement: Server-Side Tagging, Consent Mode and Conversion APIsFirst-party data, modeling and clean rooms · Lesson 13 of 14
Modeled conversions, aggregated measurement and data clean rooms
Video lecture
Modeled conversions, aggregated measurement and data clean rooms
The narrated lecture is in production
Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.
Chapters
Transcript of the narration, chapter by chapter.
0:00 Modeled measurement and clean rooms
Even the best, fully compliant tracking setup won't see every conversion. Some people decline consent, some switch devices, some use apps that don't share data. So platforms fill the gaps with models, and you need to know how to read those numbers honestly. In this lecture you'll learn the types of modeled measurement, how to judge them, and how data clean rooms let companies analyze combined data without sharing raw personal data.
0:31 Why it matters
Why does this matter? Because modeled numbers are now part of almost every report you'll read, and people who can't tell estimates from observations make overconfident decisions. Here's an analogy. Election night coverage shows counted votes and projected results. Projections are useful and usually right, but everyone knows they're projections, and when the final count arrives, it wins. Modeled conversions are projections. Lift tests are the final count. Clean rooms are like secure counting centers where parties can combine ballots without seeing each other's raw papers.
1:08 Six kinds
You'll meet six kinds of estimate. Google Ads conversion modeling under Consent Mode estimates conversions from people who declined. GA4 behavioral modeling estimates unconsented users' activity. Platforms model conversions lost to browsers, Apple's tracking prompt and cross-device journeys. App measurement uses privacy frameworks like Apple's SKAdNetwork and AdAttributionKit. Marketing mix models estimate channel contributions from aggregated data. And lift studies estimate causal effects with randomized holdouts.
1:37 Judging modeled numbers
How do you judge modeled numbers? Three checks. Direction and scale: do they move sensibly when consent rates or traffic change? Reconciliation: do platform totals, including modeled conversions, stay within a known band of your backend orders? And experiments: lift tests are the referee. If modeled attribution and a well-designed lift test disagree, trust the lift test. And always label modeled numbers in reports, so nobody mistakes an estimate for an observation.
2:08 Data clean rooms
Now data clean rooms. A clean room lets two or more parties analyze combined data, say your purchases and a platform's or retailer's ad exposure data, without either side seeing the other's raw, individual-level records. Queries return only aggregated results, above minimum thresholds, and often with extra protections. It's a way to answer questions like did people who saw these ads buy more, without handing over customer lists.
2:38 Simple example: UK home goods (illustrative)
Here's a simple worked example. A UK home-goods retailer sees Google Ads report one thousand conversions for the month, including modeled ones. Their backend shows nine hundred and fifty orders attributable to paid search clicks by their own matching, and their reconciliation band says Google should be within eighty to one hundred and twenty percent of that. One thousand is within the band, so they accept it for steering. But when a Conversion Lift study later estimates that only seventy percent of Google's reported conversions were incremental, they apply that factor to planning. Three numbers, three purposes, all labeled. The numbers are illustrative.
3:23 Examples (check current)
Examples, and check current names because this market moves fast. Google's Ads Data Hub lets you analyze Google and YouTube campaign data with your own data in BigQuery. Amazon Marketing Cloud does the same for Amazon Ads. Cloud and independent clean rooms, from providers like Snowflake, AWS, LiveRamp and InfoSum, power publisher and retailer collaborations. And many retailers, including large grocery and marketplace groups in the Gulf and the UK, offer clean room access to brands buying their retail media.
3:58 Uses and limits
What are they good for? Reach and frequency across channels, overlap between your customers and a platform's audience, incremental sales from retail media, and audience planning without swapping lists. The limits: thresholds hide small segments, setup needs data engineering, each clean room usually covers one partner, and contracts must define purposes, retention and allowed outputs.
4:22 Privacy-enhancing technologies
Clean rooms use privacy-enhancing technologies. Aggregation thresholds. Differential privacy, which adds calibrated noise so no individual can be singled out. Secure multi-party computation. And trusted execution environments, hardware that processes data in isolation, which Google uses for confidential matching. These reduce risk. But they don't replace a lawful basis, transparency, and using data only for the purposes people were told about.
4:49 Example: UK snack brand (illustrative)
Here's an illustrative example. A UK snack brand buys retail media from a grocer. Through the grocer's clean room, it measures in aggregate whether exposed shoppers bought more than matched unexposed shoppers, and how many were new to the brand. The results feed the brand's mix model as priors. No raw loyalty data ever leaves the grocer. The lesson includes a clean-room style SQL pattern for this kind of aggregated overlap, with one warning: exposed versus unexposed isn't causal unless groups are randomized or carefully matched.
5:26 Mistakes + try this now
Common mistakes here. Presenting modeled numbers as if they were observed. Assuming a clean room makes any use of data lawful. Comparing exposed and unexposed customers and calling the difference incremental. Building a one-off clean room analysis with no repeatable process. And never reconciling platform totals with the backend. Try this now: take your latest marketing report and mark every number with one of three labels: observed, modeled, or experimental. If you can't label one, find out before the next meeting.
6:01 Quick self-check
Quick self-check. In a retailer's clean room, shoppers who saw your ads bought your brand at twice the rate of shoppers who didn't. Your manager wants to announce that the ads doubled sales. Should they? Pause. Not yet. The retailer's ad system probably showed your ads to people already likely to buy your brand, so the comparison is biased. To claim a causal lift, you need randomized holdouts or carefully matched groups. Present the result as exposed shoppers bought more, and propose a proper lift design for next campaign.
6:40 Watch me do it: first clean-room analysis (illustrative)
Watch me do it. Let's walk through a first clean room analysis for an illustrative UAE snack brand buying retail media from a grocery chain. Step one, the question: did shoppers exposed to our on-site ads buy the brand more in the following two weeks than similar unexposed shoppers? Step two, the contract: the retailer's clean room lets us upload our own campaign list, and outputs only aggregates above a minimum count. Step three, the design: instead of comparing all exposed with all unexposed, we ask the retailer to match unexposed shoppers on past category purchases and store region, which reduces selection bias. Step four, the query: exposed purchasers, matched-control purchasers, and new-to-brand counts, grouped by campaign. Step five, the result: exposed shoppers bought at a higher rate than matched controls, and a meaningful share were new to the brand. Step six, the caveat, written right on the slide: matched comparison, not randomized; for a causal estimate, next quarter we'll request a holdout. Step seven, we feed the result into our marketing mix model as a prior for retail media. Every number is labeled for what it is.
8:02 Recap and next step
Recap. Modeled measurement fills real gaps. Label it, sanity-check it, reconcile it with the backend, and let lift tests referee. Clean rooms enable aggregated collaboration without raw data sharing, backed by privacy-enhancing technologies, but they don't make any use lawful by themselves. Your next step: mark which numbers in your reports include modeled data, set your expected reconciliation band, and pick one clean room or lift test that would validate them.
When you cannot observe, you estimate — carefully
Even a perfect, consent-compliant stack will not observe every conversion. Platforms and analysts fill the gap with modeled and aggregated measurement. Understanding what these are — and are not — is essential for honest reporting.
Types of modeling you will meet
| Type | What it estimates | Where |
|---|---|---|
| Consent Mode conversion modeling | Ad conversions from users who denied consent, using cookieless pings and consented patterns | Google Ads |
| GA4 behavioral modeling | Sessions/users/events for unconsented users | GA4 (Blended identity) |
| Platform conversion modeling | Conversions lost to browser limits, ATT, cross-device | Google Ads, Meta, TikTok |
| Aggregated app measurement | Install and in-app conversions via privacy frameworks | Apple SKAdNetwork / AdAttributionKit; Android privacy features |
| Marketing mix models | Channel contributions from aggregated time series | Your own models (Meridian, Robyn) |
| Lift studies | Causal effect via randomized holdouts | Platforms and your own geo tests |
Good practice: label modeled numbers as such, know which reports include them, and never present modeled user-level details as facts.
How to judge modeled numbers
- Direction and scale checks: modeled conversions should move sensibly with consent rates and traffic.
- Backend reconciliation: platform totals including modeled conversions should stay within a known band of backend orders.
- Experiments: lift tests are the arbiter; if modeled attribution and lift disagree, trust well-designed lift.
Data clean rooms
A data clean room lets two or more parties analyze combined data (for example, your customer purchases and a platform's or retailer's ad exposure data) without either side seeing the other's raw, user-level data. Queries return only aggregated results above privacy thresholds; many add noise or restrict joins.
Common offerings (check current names and availability):
- Google Ads Data Hub — analyze Google/YouTube campaign data with your first-party data in BigQuery, aggregated outputs.
- Amazon Marketing Cloud — Amazon Ads exposure data with advertiser data.
- Cloud and independent clean rooms — for example Snowflake Data Clean Rooms, AWS Clean Rooms, LiveRamp and InfoSum — used for publisher–advertiser and retailer media collaborations.
- Retail media clean rooms — many retailers (including large Gulf and UK grocery and marketplace groups) offer clean-room access to their shopper data for brands buying their media.
Use cases: reach and frequency across channels, overlap between your customers and a platform's audience, incremental sales from retail media, audience planning without sharing raw lists.
Limits: aggregation thresholds hide small segments; set-up needs data engineering; each clean room is typically specific to one partner; contracts must define purposes, retention and outputs.
Privacy-enhancing technologies (PETs)
Clean rooms often combine techniques: aggregation thresholds, differential privacy (adding calibrated noise), secure multi-party computation, and trusted execution environments (hardware-isolated processing, as in Google's confidential matching). PETs reduce risk; they do not replace a lawful basis, transparency, and purpose limitation.
Worked example: a UK FMCG brand and retail media
A snack brand buys retail media from a UK grocer. Through the grocer's clean room, the brand measures (in aggregate) whether exposed shoppers bought more than matched unexposed shoppers, and how many were new to the brand. Results feed the brand's MMM as priors. No raw loyalty data leaves the grocer.
Hands-on: an aggregated overlap query pattern (clean-room style SQL)
-- Runs inside a clean room: both tables are visible only to the query engine.
-- Output is aggregated and suppressed below a minimum count.
SELECT
a.campaign_id,
COUNT(DISTINCT a.user_key) AS exposed_users,
COUNT(DISTINCT IF(p.user_key IS NOT NULL, a.user_key, NULL)) AS exposed_purchasers,
SAFE_DIVIDE(COUNT(DISTINCT IF(p.user_key IS NOT NULL, a.user_key, NULL)),
COUNT(DISTINCT a.user_key)) AS purchase_rate
FROM partner.ad_exposures a
LEFT JOIN advertiser.purchases p
ON a.user_key = p.user_key AND p.purchase_date BETWEEN a.exposure_date AND DATE_ADD(a.exposure_date, INTERVAL 14 DAY)
GROUP BY a.campaign_id
HAVING COUNT(DISTINCT a.user_key) >= 50; -- illustrative threshold; clean rooms enforce their ownRemember: exposed vs unexposed comparisons are not causal unless groups are randomized or carefully matched — use lift designs where possible.
Pitfalls
- Reporting modeled conversions as observed.
- Assuming clean rooms make any use lawful.
- Comparing exposed and unexposed users as if randomized.
- Building one-off clean-room analyzes with no repeatable process.
How to measure success
Clear labeling of modeled vs observed in reports, reconciliation bands respected, lift tests validating modeled attribution, and clean-room analyzes that change budget decisions.
Key takeaways
- Modeled measurement fills gaps (Consent Mode, GA4, platform modeling, app frameworks, MMM, lift) — label it clearly.
- Judge modeled numbers by direction checks, backend reconciliation and experiments.
- Data clean rooms enable aggregated joint analysis without sharing raw user data.
- PETs (thresholds, differential privacy, MPC, TEEs) reduce risk but don't replace lawful basis and purpose limits.
- Exposed vs unexposed comparisons aren't causal unless randomized or carefully matched.
Check your understanding
Quick questions to lock in the lesson. They don’t count towards your certificate.
Put it into practice
Mark which numbers in your current reports include modeled data, write the reconciliation band you expect versus backend orders, and identify one clean-room or lift test that would validate them.
Enrol for free to save your progress
Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.