AMC on AWS Clean Rooms: requirements, setup and data rules

In short: AMC on AWS Clean Rooms is an AMC variant where your first-party data stays in your AWS environment. You create an AWS Clean Rooms collaboration, bring event and identity data there, and send aggregated results to your S3 bucket. Amazon recommends this route over the direct AMC data upload.

What is it?

AMC uses the collaboration feature of AWS Clean Rooms. A collaboration is a secured logical boundary in which one member, for example an advertiser, can run SQL queries on configured tables of other members. AWS Entity Resolution handles the matching of audience identifiers.

The core point according to Amazon: hashed PII and event signals do not have to be moved into AMC, they stay in your AWS environment. The aggregated results of the joint analysis go to an S3 destination of your choice.

The benefits according to Amazon

  • No identity or event signal mobility: you do not share or move your own hashed PII into AMC.
  • Easier: signal refresh and processing policies apply automatically when you work with Amazon Ads signals.
  • Audience creation with the privacy-enhancing techniques of AWS Clean Rooms.
  • Access to all AMC features and bespoke solutions through the AMC console.

Requirements

The setup is aimed at the AMC account administrator and the administrator of your AWS account. You get AMC access if you are eligible to onboard or already an AMC customer. For onboarding Amazon lists:

  • an executed Amazon DSP Master Service Agreement (planned to be replaced by a standalone AMC agreement),
  • planned campaigns, or campaigns that ran in the last 28 days,
  • the DSP advertiser IDs and, where applicable, Sponsored Ads IDs for your instance,
  • a SQL-capable person who can work with the supported commands of the AWS Clean Rooms SQL reference.
  • On the AWS side: an AWS account with administrator permissions, an administrator user for Clean Rooms, IAM roles for the collaboration members and a service role to read your data.

This list is in the documentation for AMC on AWS Clean Rooms. For AMC access in general Amazon has widened eligibility (October 2024 through partners, September 2025 directly for sponsored ads advertisers, see the AMC timeline). You also need authenticated access to the Amazon Ads API (a Login with Amazon app and API access) to create ID mapping tables and to use AMC programmatically. Amazon points out that you may need to involve your security, legal or IT teams.

Data rules for the upload

  • Dataset names are unique; only lowercase letters and digits are allowed, no spaces, no special characters, no uppercase. Duplicate names cause an error.
  • Event tables must not contain PII. Third-party (3P) identifiers are not hashed.
  • Consent data goes in fixed columns (tcf, gpp, amz_user_data_consent, amz_ad_storage_consent, country) of type string. For the two amz_ columns only the value GRANTED counts as consent.
  • For data with user IDs consent is checked per row; rows without sufficient consent are excluded from the query.

When is this variant worth it?

Amazon itself writes that the direct AMC data upload is possible, but that the two routes through AWS Clean Rooms (event data and identity data) are recommended. If you already hold customer data in AWS and do not want to copy it into AMC, that is a reason for this variant.

Our assessment, not Amazon's statement: the effort sits in AWS (roles, Glue catalogue, Entity Resolution). Without AWS know-how in the team the direct upload with hashed data is the shorter path, at the price that the data lives in AMC.

Step by step

  1. Clear the requirements. Provide AMC access, an AWS account with administrator, IAM roles and Amazon Ads API access.
  2. Create the instance. Create an instance with POST /amc/instances using acrBacked: true and awsAccountId, without s3BucketName (otherwise error 400).
  3. Join the collaboration. Accept the collaboration in AWS Clean Rooms and specify the S3 bucket for results.
  4. Prepare the data. Follow the dataset naming, consent column and PII rules.
  5. Upload event and identity data. Bring event data and identity data into the collaboration, then run queries in AMC.

Frequently asked questions

Do I have to upload my customer data to AMC?

No, with AMC on AWS Clean Rooms hashed PII and event signals stay in your AWS environment. Only the aggregated results go to your S3 destination.

Why does creating the instance fail with error 400?

For an ACR-backed instance the request must not contain s3BucketName. The bucket is specified later, when joining the collaboration.

Sources: Amazon Ads API: AMC on AWS Clean Rooms, Overview · Requirements for AMC-AWS Clean Rooms set up · Set up a collaboration instance · Data upload essentials (retrieved 2026-10-09)

Keep reading: Schema reference · AMC without DSP · AMC timeline