Trust, Verified: Four Guiding Principles for Building a Defensible Health-Adjacent Data Partnership for TV Advertising

By Andy Dale, General Counsel & Chief Privacy Officer, OpenAP

and Ben Chapman, General Counsel & Chief Privacy Officer, Swoop
Often, health-adjacent data deals are built to pass a compliance review, not to survive one five years from now. As we built our own partnership between OpenAP, the audience infrastructure behind data-driven television, and Swoop, one of the largest data providers in health advertising, we set out to answer a harder question: could we build a deal that is extensible, dynamic and pragmatically compliant so that it could survive shifts in the law?
Privacy law in the U.S. is moving quickly. In just a handful of years, the landscape has transformed from a small handful of comprehensive state privacy regimes to an increasingly complex patchwork of over twenty state laws. That’s on top of a growing stack of sector-specific laws that single out “sensitive personal information” categories like health, location, biometric, and information about children, for special treatment. For example, Washington’s My Health My Data Act contains a definition of “consumer health data” that goes beyond HIPAA’s covered-entity perimeter, giving it much wider applicability to businesses of all kinds. Connecticut and Nevada have passed amendments adding health-data provisions to their state privacy laws. And on the horizon is another game-changing law: New York’s recently re-introduced Health Information Privacy Act, which layers its own consent, sale, and advertising restrictions on top of a sweeping definition of “regulated health information.”
Despite the increased regulatory environment, spending on health-related advertising has seen consistent gains in the past few years. Health-focused advertisers spent over $7 billion on linear TV in 2025, pharma alone accounts for 13% of total linear ad spend, and digital placements in the category are on pace for an estimated $26.2 billion in 2026. The money and the regulatory complexity are both increasing at once, which means the partnerships behind that spend need to be built for durability, not just for today’s checklist.
When the business teams at OpenAP and Swoop proposed a new data partnership for TV advertising, we each came to the table with very different profiles, business drivers, and risk surface area. And yet today, it’s one of the most successful partner models in our industry. What does it take to stand up a partnership purpose-built to withstand regulatory complexity and commercial need? Here are four guiding principles we’d give any peer General Counsel or Chief Privacy Officer sitting where we sat a year ago.
1. Do the diligence all the way, not the version that fits in a questionnaire.
We’ve all seen due diligence treated as a checkbox exercise: spreadsheets exchanged, very little follow-up, discussion or deeper investigation. We didn’t stop there.
Swoop opened up the parts of its operation that data providers so often keep generic in a security questionnaire: the actual sources of its underlying data, the lawful basis on which each source flows in, the chain of custody from procurement to audience, and, most importantly, the de-identification methodology and HIPAA standards behind it. We worked through the statistical approach, the expert-determination logic, the re-identification risk thresholds, and the controls that prevent linkage back to an individual downstream. Together, we talked through what gets stripped, what gets generalized, what gets suppressed and why, and we evaluated how Swoop’s approach would fare under state privacy law frameworks. We identified specific states we or our advertisers and publishers might want suppressed, and how to effectuate that.
OpenAP, in turn, walked Swoop through its campaign data flows, the state suppression requirements of its publisher customers, the different integrations used to access Swoop’s data, and the possible use cases for Swoop’s data. We listened to one another’s compliance concerns and considered the actions each party might be able to take or influence to ensure we were both satisfied that privacy protections would remain in place for the data throughout the campaign journey.
We also shared third-party evaluations with each other ranging from SOC2 audits, to insight into our product and legal positioning, and shared overviews of our respective industry compliance activities like participation in the Network Advertising Initiative (NAI) and Future of Privacy Forum (FPF). Sharing audit reporting is commonplace, but we went a step further and contextualized our work.
The awareness that each party was committed to compliance and staying close to a shifting legal landscape is invaluable context for durable relationships. These conversations required trust and a healthy dose of vulnerability, but they are exactly the ones worth having, because they’re the ones that protect both companies later.
2. Put risk on the party that can actually manage it.
Once diligence has been done transparently and collaboratively, the contract itself is a lot easier to negotiate because each side knows what it can actually stand behind.
For example, Swoop is the only party positioned to represent the lawfulness of its data sources and the integrity of its de-identification process, so those representations sit with Swoop. OpenAP is the only party positioned to govern use restrictions inside its own environment and the incident protocols for what happens if something goes wrong downstream, so those obligations sit with OpenAP. Neither of us signed up for a representation we couldn’t honestly stand behind.
This isn’t always the case in negotiations. Sometimes parties are too focused on “winning” the reps/warranties or getting the better end of a deal to the detriment of a lasting partnership. We worked hard to find the lasting solution.
3. Let the facts build the architecture and let the contract follow.
The reason this structure holds up for all forms of TV advertising, streaming and programmatic activation and not just linear, isn’t the paperwork, it’s the underlying solution design.
Audiences built through Swoop use de-identified information, and Swoop’s audience-build safeguards are designed to eliminate the risk of revealing, identifying, or inferring any individual’s health status or condition. Encrypted third-party algorithms transform Swoop’s data into already-existing online IDs without ever connecting health information to that ID, in Swoop’s environment or anywhere else.
That audience, built by Swoop and activated through OpenAP’s identity framework for programmatic campaigns, arrives already rendered into a health-agnostic, general audience of online IDs, at which point OpenAP manages the outbound data flow and any consumer privacy requests that follow. That outbound flow is enabled by OpenAP’s infrastructure built to honor consumer privacy obligations.
The contract documents that architecture; it doesn’t substitute for it. The strongest privacy posture is the one where the controls would still hold even if the contract disappeared.
4. Expect this to get more complicated, not less, and plan for that.
Finally, don’t be afraid to lean into the complexity and take the time to understand the rapid evolution taking place. Life in this industry is not getting simpler; it’s becoming more complex and rigorous. Health advertising can serve useful ends, but doing it ethically and in a way that protects individual privacy is a challenge that should be embraced.
While there are increased complexities in this deal, the key principles and contract solutions are not unique to television advertising or to health-adjacent data. It’s the same test any two companies should apply before either sign: can each side transparently stand behind what it’s promising? And would the underlying controls still hold if the contract disappeared tomorrow? If the answer to either question is no, the deal isn’t ready, no matter how good the diligence questionnaire looks coming back.
The more companies that build partnerships this way, the more the whole ecosystem’s use of health-data for advertising can hold up to scrutiny, not just any one deal.
Ben Chapman

Ben Chapman is the General Counsel and Chief Privacy Officer at Swoop. He focused his legal career in ad tech, advertising, privacy law and compliance, and complex data and technology licensing. Prior to joining Swoop, Ben served as Deputy General Counsel for Real Chemistry, and prior to that as Senior Counsel for Publicis Groupe Re:Sources, supporting companies under the Publicis Media division. Ben ensures that Swoop remains at the forefront of AI and digital audience engagement in a privacy enhancing and compliant way. Ben holds a J.D. from Boston College Law School and a B.A. from Virginia Commonwealth University.
ABOUT SWOOP
Swoop improves patient outcomes by connecting the signals that drive earlier diagnosis, better treatment decisions, and sustained adherence. The integrated, privacy-by-design platform enables life sciences companies to drive measurable patient and commercial outcomes with actionable intelligence — spanning patient and HCP audience targeting, community engagement, AI-powered web solutions, coordinated omnichannel activation, and prescription fulfillment. Swoop is a member of the NAI. For more information, visit www.swoop.com.
ANDY DALE

Andy Dale is General Counsel and Chief Privacy Officer of OpenAP, the technology company powering the data-driven video workflow of the future. Prior to OpenAP, Andy was the General Counsel & Chief Privacy Officer at Alyce, a B2B gifting and engagement platform, General Counsel & VP of Global Privacy at SessionM, which was acquired Mastercard in 2019, and VP Legal & Data Protection Officer at dataxu, an adtech company which was acquired by Roku. He is an active speaker, writer and advisor in the marketing/advertising tech space. Together with Pedro Pavon from Meta, Andy hosts the popular podcast “The Data Protection Breakfast Club” and runs a series of adtech roundtables with industry General Counsels and privacy lawyers. Andy has also served as an in-house lawyer at TD Ameritrade, worked in a corporate law firm and clerked for a judge in Baltimore. He received his BA from Colgate University, his JD from University of Baltimore and holds the IAPP’s CIPP/US and CIPP/E certifications.
ABOUT OPENAP
OpenAP is a technology company powering the data-driven video workflow of the future. Rooted in our mission of bringing simplicity and scale to audience-based advertising, our Open Audience Platform powers a more streamlined audience creation, planning, buying and measurement process for TV, spanning data-driven linear, programmatic and streaming channels. We make it easier for buyers to work across multiple publishers and platforms, while bringing transparency and consistency to how identity is resolved across every stage of the campaign. Our technology is open and interoperable, allowing publishers, agencies, brands and to harness operational efficiencies to scale. For more information, visit www.openap.tv and follow @OpenAPTV on LinkedIn.