Clean room query rules compared: AWS requires same rule type across tables; most restrictive applies.; Snowflake needs column approval and enforces MIN_GROUP_SIZE=5 in policies.; Google Ads Data Hub aggregates results by user group and filters rows silently.
Image: AdTech Market Guide

Platform Comparisons

Part of Advertising clean rooms

Comparing query restrictions across clean room products

Compare AWS Clean Rooms, Snowflake Data Clean Rooms and Ads Data Hub by query route, join limits and output controls.

Compare the query shape each product permits with the output controls that apply. The documented restrictions differ across AWS Clean Rooms, Snowflake Data Clean Rooms and Google Ads Data Hub.

ProductQuery routeDocumented output restrictions
AWS Clean RoomsAggregation, list or custom rules on configured tables; custom SQL is SELECT-only.The same rule type must apply across referenced tables, and the most restrictive controls apply. An example requires 150 distinct identifier values per output row.
Snowflake Data Clean RoomsOfferings expose specified columns; free-form SQL can be enabled alongside templates.Source and offering policies apply. The MIN_GROUP_SIZE_POLICY example sets MIN_GROUP_SIZE to 5; activation requires column approval.
Google Ads Data HubCustom analysis can join first-party data uploaded to BigQuery with Google event-level campaign data.Results are aggregated in a group of users; underlying data cannot be inspected. Privacy checks can filter rows without notice.

AWS: establish the rule type

An analysis rule is an account-level control on a configured table; without a rule, the table cannot be queried. A query can reference only tables with the same rule type, and AWS applies the more restrictive controls across all referenced tables.

Aggregation rules support COUNT, SUM and AVG over optional dimensions. Their query structure includes SELECT and FROM, with INNER JOIN, WHERE, GROUP BY, HAVING and ORDER BY clauses; a rule can require a direct or transitive join to a configured table owned by the member who can query.

Custom rules allow SELECT-only SQL, including window functions, OUTER JOIN, CTEs and subqueries. Data owners can approve specific analysis templates or allow query-provider accounts to create queries; custom rules also support differential privacy, minimum aggregation thresholds and comparison controls.

AWS's output-constraint example sets limits of 100 and 150 distinct identifier values on two collaborators' tables. A query using both tables needs at least 150 distinct identifier values in each output row, and the output does not indicate when results have been removed by the constraint.

Snowflake: inspect the offering and policy

A data offering is a live view of source data and exposes only the columns listed in its specification. Any Snowflake policies applied to the source data remain active in the offering.

Free-form queries can be enabled with allowed_analyses: template_and_freeform_sql; only columns listed under schema_and_template_policies are available. Providers can associate policies with offering columns, and changes to linked policies affect datasets immediately.

Snowflake's example MIN_GROUP_SIZE_POLICY sets MIN_GROUP_SIZE to 5. Source-data policies are enforced even when they are not shown in freeform_sql_column_policies.

Activation uses a dedicated template, and each data provider must approve activation at the column level. The offering limits activation to designated runners and templates; results are written to a table in the target account rather than returned to the query runner. Activating to another Snowflake account requires Enterprise Edition.

Ads Data Hub: privacy checks

Google Ads Data Hub supports custom analysis. First-party data can be uploaded to BigQuery and joined with Google's event-level campaign data; results are aggregated in a group of users, and the underlying data cannot be inspected.

When privacy checks are triggered, rows can be filtered without notice. Some checks compare results with historical results and may trigger if results have not changed appropriately between jobs.

Choose with one sample specification

Start with the required output: AWS applies the most restrictive relevant table controls, Snowflake activation depends on approved columns, and Google Ads Data Hub aggregates results by user groups and may filter rows through privacy checks. Then match the required query shape and fields to the AWS rule type and Snowflake offering.

Platform Trade-offs in Query Flexibility and Control

  • AWS Clean Rooms
  • Snowflake Data Clean Rooms
  • Google Ads Data Hub

More from Platform Comparisons