Consent, Permission, and Fitness for Use Are Not the Same Thing
A three-gate model for health data in pharma marketing that separates legal permission, contractual permission, and whether a use fits the brand's standards.
The short answer
A common question in pharma media is "are we allowed to use this data?" The question sounds like it has one answer. It has at least three. Data can be legally permissible, contractually permitted, and still inappropriate for the brand. Treating any single signal as universal approval leads to problems.
The three gates
Gate 1: Legal permission
Is the use allowed under applicable law? This depends on the type of data, who holds it, where the individual lives, and what they were told. Federal rules include HIPAA for covered entities and the FTC's authority over unfair or deceptive practices, including the Health Breach Notification Rule. Several states have consumer health data laws with their own consent requirements. This gate belongs to counsel.
Gate 2: Contractual permission
Does the contract with the data provider allow this specific use? Contracts often limit data to certain purposes, such as targeting but not measurement, or prohibit combining it with other data. Upstream contracts can also restrict what the provider can license. This gate belongs to procurement and counsel together.
Gate 3: Fitness for use
Even when the first two gates pass, would the brand be comfortable if patients, clinicians, or regulators saw exactly how the data was used? Is the data accurate enough for the purpose? Could the use cause harm, such as revealing a condition to others on a shared device? This gate belongs to the brand, privacy, and media teams.
How the gates interact
| Legal | Contract | Fitness | Decision |
|---|---|---|---|
| Yes | Yes | Yes | Proceed |
| Yes | Yes | No | Do not proceed or change the use |
| Yes | No | Any | Renegotiate or do not proceed |
| No | Any | Any | Do not proceed |
The third row is common. A use can be legal and still prohibited by contract. The second row is the one teams skip, because once legal and contract say yes, it feels like the question is answered.
Questions for the fitness gate
- Would a reasonable patient expect their data to be used this way?
- Is the data accurate enough that errors will not cause harm or embarrassment?
- Could the ad reveal sensitive information to someone other than the intended person?
- Does the use match the brand's published privacy commitments?
The NIST Privacy Framework offers a structured way to think about privacy risk beyond legal compliance.
Document the decision
Record each gate's answer, who made it, and when. If the data or use changes, revisit all three. This record is also useful in data contract reviews and provenance checks.
Practical takeaway
Replace "are we allowed?" with three separate questions in your approval process, each with a named owner. Do not proceed until all three have a documented yes.
Sources
- FTC, Health Breach Notification Rule: The Basics for Business
- NIST Privacy Framework
- HHS, HIPAA for Professionals
External guidance and platform documentation change. Links were current at publication; check them again before relying on them for a decision.
Editorial note. Analysis and frameworks are the author's own and do not represent Acxiom or any current or former employer, client, or named platform. Examples labeled hypothetical or illustrative are not results from real campaigns. Nothing here is legal, regulatory, or medical advice.
New pharma programmatic breakdowns, occasionally
One email when I publish something worth reading. Benchmarks, measurement teardowns, and case studies with the caveats attached. No cadence promises, no reselling your address.
Unsubscribe any time. See the privacy policy.
Working through this decision on a real plan?
I work on health and pharma data, identity, and activation, after five years running HCP and DTC programmatic agency-side. Happy to talk through how this applies to your situation.