A Health Audience Data Contract Checklist for Marketers
Contract questions for marketers buying health audience data: permitted use, deletion, audit rights, subprocessors, and measurement. Not legal advice.
The short answer
Due diligence tells you what a health data vendor says about its data. The contract determines what the vendor must actually do. Marketers are rarely the ones drafting data agreements, but they know how the data will be used, which means they know which terms matter. This checklist helps marketers bring the right questions to counsel. It is not legal advice.
Permitted use
- Which uses are allowed: targeting, suppression, measurement, modeling, analytics?
- Which channels and partners may receive the data?
- May the data be combined with other data sets, and under what conditions?
- Are there restrictions on specific conditions or populations?
If the plan includes measurement, confirm it is permitted. Contracts that allow targeting but not measurement are common.
Data handling
- How is the data delivered, stored, and transmitted?
- What security standards apply?
- Who at the brand or agency may access it?
- When must the data be deleted, and how is deletion confirmed?
Individual rights
- How are opt-outs and deletion requests passed to you, and how quickly must you act?
- Who is responsible for honoring them in downstream systems?
Subprocessors and partners
- Does the vendor use subprocessors or upstream suppliers?
- Will you be notified if they change?
- Do upstream restrictions flow down to you?
Transparency and audit
- May you review methodology documentation?
- Do you have audit rights, and what triggers them?
- Will the vendor notify you of material changes to sources or methods?
Measurement and outcomes
- May segment performance be measured and reported?
- May results be shared with other partners, such as an agency or measurement vendor?
- Who owns the resulting analysis?
Liability and incidents
- What happens if the data was collected improperly?
- What are the vendor's obligations if there is a breach?
- The FTC's Health Breach Notification Rule may apply to certain health data holders.
Turning due diligence into terms
| Due diligence finding | Contract term to request |
|---|---|
| Vendor described sources | Warranty that sources match description, with change notice |
| Vendor described refresh cadence | Minimum refresh commitment |
| Vendor described opt-out handling | Maximum time to propagate opt-outs |
| Vendor claimed accuracy | Right to validate, remedy if materially lower |
See provenance questions and consent, permission, and fitness for use for the upstream work.
Practical takeaway
Before contract review, write one page describing exactly how the data will be used in the campaign and measurement. Give it to counsel with this checklist. It makes review faster and reduces the chance of a gap between plan and contract.
Sources
External guidance and platform documentation change. Links were current at publication; check them again before relying on them for a decision.
Editorial note. Analysis and frameworks are the author's own and do not represent Acxiom or any current or former employer, client, or named platform. Examples labeled hypothetical or illustrative are not results from real campaigns. Nothing here is legal, regulatory, or medical advice.
New pharma programmatic breakdowns, occasionally
One email when I publish something worth reading. Benchmarks, measurement teardowns, and case studies with the caveats attached. No cadence promises, no reselling your address.
Unsubscribe any time. See the privacy policy.
Working through this decision on a real plan?
I work on health and pharma data, identity, and activation, after five years running HCP and DTC programmatic agency-side. Happy to talk through how this applies to your situation.