What Log-Level Data Should a Pharma Advertiser Request?
Minimum log-level data field sets by use case for pharma programmatic, plus a review of fields you should not collect for privacy reasons.
The short answer
Log-level data is the record of each impression your campaign bought: when it was served, where, at what price, and with what outcome. It lets advertisers verify delivery, reconcile fees, analyze performance, and feed measurement. In pharma, log-level data also carries privacy obligations. The right request asks for what each use needs and nothing more.
Minimum fields by use case
Delivery verification
- Timestamp
- Campaign, line item, and creative IDs
- Domain or app bundle
- Placement or ad unit
- Device type
- Deal ID if applicable
Fee reconciliation
- Everything above, plus
- Clearing price
- DSP fees by type
- Data fees
- Currency
See DSP fee transparency.
Supply path analysis
- Seller ID
- Exchange
- SupplyChain object nodes where available
See ads.txt, sellers.json, and schain.
Performance analysis
- Viewability and completion indicators
- Invalid traffic flags
- Click and conversion events
Measurement
- Identifiers needed by your measurement partner, delivered through their approved privacy method
Fields to question
Log-level data can include fields you do not need and should not hold, especially in health contexts:
- Precise location data. Rarely needed for pharma analysis and can be sensitive.
- Raw device identifiers. Needed only if your measurement partner requires them through a privacy-reviewed process.
- IP addresses. Often not needed once other quality checks are done.
- Contextual signals that reveal health information about an individual.
HHS guidance on online tracking technologies and the NIST Privacy Framework both support collecting only what you need.
Delivery and retention
Agree on:
- Format and delivery method, such as daily files to a secure cloud bucket.
- Retention period, both at the vendor and on your side.
- Access controls, including who can view the data.
- Deletion, when the purpose is complete.
Start small
Log-level files are large. Many teams request everything and then never use it. Start with one use case, such as fee reconciliation, and add fields as new uses arise.
Practical takeaway
Write a one-page log-level data request listing each use case, the fields it needs, the fields you are deliberately excluding, delivery method, and retention period. Have your privacy team review it before sending.
Sources
- HHS, Use of Online Tracking Technologies by HIPAA Covered Entities
- NIST Privacy Framework
- IAB Tech Lab, sellers.json
External guidance and platform documentation change. Links were current at publication; check them again before relying on them for a decision.
Editorial note. Analysis and frameworks are the author's own and do not represent Acxiom or any current or former employer, client, or named platform. Examples labeled hypothetical or illustrative are not results from real campaigns. Nothing here is legal, regulatory, or medical advice.
New pharma programmatic breakdowns, occasionally
One email when I publish something worth reading. Benchmarks, measurement teardowns, and case studies with the caveats attached. No cadence promises, no reselling your address.
Unsubscribe any time. See the privacy policy.
Working through this decision on a real plan?
I work on health and pharma data, identity, and activation, after five years running HCP and DTC programmatic agency-side. Happy to talk through how this applies to your situation.