Artifact GuideUSContract Classification Workflow

US CCPA Contract Classification Workflow

Classify each recipient from actual processing and contract terms as a service provider, contractor, or third party; a label alone does not prevent a disclosure from being a sale or sharing.

A service-provider label is not enough. Section 7051 requires a compliant written contract, and the recipient must operate within that role.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
3

Structured answer sets in this page tree.

Primary sources
2

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Under the California Consumer Privacy Act (CCPA), classify a recipient from the data flow, purpose, relationship, and written agreement. A service provider or contractor processes personal information for limited and specified business purposes under a section 7051 contract. A is outside those roles and, when a business sells or shares personal information with it, needs a section 7053 agreement. The Civil Code and California Privacy Protection Agency (CPPA) regulations control the role; the classification record below is practical evidence for applying them.

Section 1

How should the classification decision run?

Start with the service being performed and every use, disclosure, retention, combination, and subcontracting path. A service provider processes personal information on behalf of the business; a contractor receives personal information for a business purpose. Account servicing, payment processing, storage, contextual advertising, and analytics can fit those roles when the purpose, use, and contract meet the statute and regulations.

A person providing cross-context behavioral advertising is a for that service, even if the same person acts as a service provider for a different permitted service. For example, a social-media company may provide non-personalized advertising based on aggregate or demographic information as a service provider, but it cannot use the business's customer email list to identify its users for cross-context targeting under that role.

Then test the written agreement. A section 7051 contract must identify specific business purposes, prohibit sale or sharing, restrict use to those purposes and the direct business relationship, require the same level of privacy protection, support consumer requests and applicable audits, risk assessments, and ADMT duties, give the business monitoring and remediation rights, require notice if the recipient can no longer comply, and flow the restrictions to subcontractors.

  • Data owner: map the personal information, source, purpose, recipient, onward recipients, retention, and consumer groups.
  • Procurement or legal: select the role for each service, not once for the entire vendor relationship.
  • Privacy: decide whether each transfer is a sale, sharing, disclosure for a business purpose, consumer-directed disclosure, merger or acquisition transfer, or separate collection by the recipient.
  • Control owner: block the transfer or route it through notice and opt-out controls if the intended exclusion from sale or sharing is not supported.
Section 2

What changes when the recipient is a third party?

A is not converted into a service provider by adding restrictions after the fact. When a business sells or shares personal information with a third party, section 7053 requires an agreement identifying the limited and specified purposes, limiting use to those purposes, requiring CCPA-level privacy protection, allowing the business to check and remediate use, and requiring notice if the third party can no longer comply.

The business must separately address the consumer-facing consequences of a sale or sharing: notice, request methods, opt-out preference signals, suppression, and forwarding applicable opt-out requests. A compliant third-party agreement governs the recipient's use; it does not eliminate the sale-or-sharing classification. Without a section 7053 contract, the may not collect, use, process, retain, sell, or share the personal information the business made available.

  • Identify each limited purpose and prohibit unrelated reuse.
  • Require the to apply CCPA-level protection and comply with forwarded opt-out requests.
  • Give the business rights to check compliance, stop unauthorized use, and obtain remediation evidence.
  • Keep the third-party contract analysis separate from the business's notice and opt-out analysis.
Section 3

What should the classification record contain?

Keep one record per service and data flow. It should show the facts used to select the role, the contract version and clauses relied on, any sale-or-sharing analysis, the systems and data covered, the owner, and the reassessment trigger. Record exceptions and open questions instead of forcing an uncertain relationship into a preferred label.

For a service provider or contractor, retain evidence that the business exercises its contractual monitoring rights. For a contractor, retain the required certification that it understands and will follow the statutory restrictions. The regulations identify due diligence and enforcement of contract terms as relevant to whether the business had reason to believe the recipient was violating the CCPA.

  • Scope: legal entity, service, purpose, data categories, sources, consumers, systems, retention, recipients, and subprocessors.
  • Decision: role by service, sale-or-sharing result, contract section, reviewer, approval date, and unresolved assumptions.
  • Controls: request cooperation, audit or testing rights, compliance notice, remediation, security, assessment support, and subcontractor flow-down.
  • Evidence: signed agreement and effective date, data-flow map, recipient documentation, configuration, assessment or test results, issues, remediation, approval, and next review date.
Primary sources

References and citations

leginfo.legislature.ca.gov
Referenced sections
  • Binding statutory definitions of business, business purpose, contractor, cross-context behavioral advertising, service provider, sale, sharing, and third party.
Related guides

Explore more topics

California Data Brokers: CCPA, Registration, and DROP Duties
Decide whether a CCPA business is also a California data broker and track registration, privacy metrics, DROP deletion, vendor, and audit duties.
CCPA Consumer Rights Workflow: Requests, Clocks, and Evidence
Route CCPA requests by right, apply the correct verification and response rule, coordinate downstream action, and retain a clear decision record.
CCPA Dark Patterns: Rules, Examples, and Review Checklist
Check a CCPA privacy interface for clear language, symmetrical choices, unnecessary steps, and other designs that can invalidate consent.
CCPA Deadlines and Compliance Calendar
Track CCPA request clocks, annual duties, DROP dates, and phased 2026-2030 deadlines for risk assessments, ADMT, and cybersecurity audits.
CCPA Do Not Sell or Share Guide
Classify CCPA sales and sharing, provide valid opt-out methods, honor preference signals, stop disclosures within 15 business days, and notify recipients.
CCPA Do Not Sell or Share: Implementation and Testing
Implement CCPA sale-or-sharing opt-outs across links, GPC, consent state, ad tech, recipients, confirmation, privacy disclosures, and evidence.
CCPA Do Not Sell or Share: Scope and Implementation
Determine whether a transfer is a CCPA sale or sharing, provide the required opt-out path, honor preference signals, and propagate the choice.
CCPA DSAR Workflow: Intake, Verification, and Response
Run CCPA data-subject requests from intake through verification, search, exception review, downstream action, response, and retained evidence.
CCPA Financial Incentives: Notice, Consent, and Data Value
Assess a loyalty, discount, payment, or service program under the CCPA and document notice, opt-in, withdrawal, and data-value requirements.
CCPA Global Privacy Control (GPC): team obligations and technical implementation
Implement Global Privacy Control as a CCPA sale and sharing opt-out across browsers, devices, known accounts, and relevant downstream systems.
CCPA Minors: Opt-In Rules for Consumers Under 16
Apply the CCPA's under-13 parent authorization and age-13-to-15 consumer opt-in rules for sale or sharing of personal information.
CCPA Notice at Collection: Timing, Content, and Examples
Place a CCPA notice where consumers encounter it before collection and disclose categories, purposes, retention, sale or sharing, and required links.
CCPA Opt-Out Signal Workflow: Detect, Apply, and Test GPC
Process CCPA opt-out preference signals across browsers, devices, profiles, accounts, offline data, conflicts, recipients, and confirmation controls.
CCPA Penalties and Fines: Current Amounts
See current CCPA fines, civil penalties, security-breach damages, adjustment rules, and the facts needed before estimating exposure.
CCPA Personal and Sensitive Information Categories
Classify personal and sensitive personal information under the current CCPA, including exclusions and the duties each category can trigger.
CCPA Privacy Policy Template: Required Content and Review
Draft and maintain a CCPA privacy policy covering data practices, rights, request methods, GPC handling, minors, contacts, and the last-updated date.
CCPA Risk Assessments, Cybersecurity Audits, and ADMT
Apply California's regulations effective January 1, 2026 for risk-assessment triggers, phased cybersecurity audits, ADMT rights, evidence, reviews, and CPPA submissions.
CCPA vs CPRA: What Changed and Which Rules Apply
Compare the original CCPA with the CPRA amendments and learn why current California privacy work must use the CCPA as amended, not two separate laws.
CCPA vs GDPR: Scope, Rights, Duties, and Evidence
Compare the California CCPA and EU GDPR by scope, roles, legal basis, rights, advertising transfers, contracts, security, deadlines, and enforcement.
Does the CCPA apply to my business? Threshold guide
Apply the CCPA revenue, data-volume, and sale-or-sharing revenue thresholds, then check California nexus, control, joint ventures, roles, and exemptions.
US CCPA Applicability Test Guide
Apply the CCPA entity-by-entity: test California nexus, for-profit control, current thresholds, related-entity routes, exemptions, and processing roles.
US CCPA Compliance Checklist
A verifiable CCPA checklist for scope, data mapping, notices, rights, opt-outs, contracts, retention, security, risk assessments, audits, ADMT, and evidence.
US CCPA Compliance Guide
Build a CCPA operating model for entity scope, data mapping, notices, rights, opt-outs, contracts, retention, security, assessments, audits, ADMT, and evidence.
US CCPA Dark Patterns Guide
Review CCPA privacy interfaces for plain language, symmetry, minimal steps, neutral presentation, valid consent, and reliable opt-out operation.
US CCPA Data Broker Crossover Guide
Test whether a CCPA business is also a California data broker, then assign registration, metrics, DROP, deletion, downstream, and audit duties.
US CCPA DSAR Verification Guide
Verify CCPA know, delete, correct, and ADMT-access requests with request-specific, secure, minimized methods without adding friction to opt-outs.
US CCPA Enforcement and Penalties Guide
Understand CPPA investigations, Attorney General civil actions, CCPA administrative orders, current penalties, and the limited security-breach private action.
US CCPA Financial Incentives Guide
Decide whether a CCPA financial-incentive rule applies, then document the notice, data-value method, opt-in, withdrawal, and nondiscrimination checks.
US CCPA GPC Signal Guide
Implement Global Privacy Control under the CCPA across browsers, devices, accounts, ad technology, downstream recipients, and consumer notices.
US CCPA Minors Guide
Apply the CCPA opt-in rules for selling or sharing personal information of consumers under 16, including age bands, authorization, notices, and evidence.
US CCPA Notice at collection Guide
Build a CCPA Notice at Collection for online and offline collection points, including categories, purposes, sale or sharing, retention, links, and change control.
US CCPA Personal and Sensitive PI Categories Guide
Classify CCPA personal information and sensitive personal information, apply exclusions, and map each category to notices, rights, retention, security, sale, and sharing.
US CCPA Privacy Law FAQ
Direct answers on CCPA scope, rights, notices, opt-outs, GPC, minors, sensitive information, financial incentives, and data brokers.
US CCPA Privacy Notices and Disclosures Guide
Choose and maintain each CCPA consumer notice: privacy policy, collection, sale or sharing, sensitive-information limits, financial incentives, and ADMT.
US CCPA Privacy Policy Guide
Build and maintain a CCPA privacy policy covering online and offline practices, 12-month disclosures, consumer rights, request methods, and annual updates.
US CCPA Requirements Guide
Plain-language CCPA requirements covering scope, minimization, notices, rights, opt-outs, contracts, security, records, risk assessments, audits, and ADMT.
US CCPA Scope and Thresholds Guide
CCPA scope and threshold reference covering the current $26,625,000 revenue threshold, the 100,000-consumer-or-household test, related entities, and exemptions.
US CCPA Service Provider Contractor and Third Party Contracts Guide
Classify CCPA recipients and check the distinct contract terms for service providers, contractors, and third parties before disclosing personal information.
US CCPA Service Provider Contractor Contracts Guide
Check CCPA service-provider and contractor agreements for specific purposes, use restrictions, consumer-request support, subcontractors, and remediation.
US CCPA Thresholds Guide
Apply the CCPA business thresholds per legal entity, including the 2025 CPI-adjusted revenue amount, volume and sale-or-sharing tests, and control routes.
What must a CCPA privacy policy include?
A practical guide to CCPA privacy-policy content, placement, annual updates, consumer rights, request methods, and supporting evidence.
What must CCPA service-provider contracts include?
Required CCPA contract terms, role checks, subcontractor flow-downs, oversight rights, and evidence for service providers and contractors.
What should teams do about consumer request verification under the CCPA?
Choose a proportionate CCPA verification method for know, delete, and correct requests without collecting unnecessary identity data.
When does the CCPA require risk assessments or cyber audits?
CCPA triggers, deadlines, evidence, retention, and submission duties for risk assessments and annual cybersecurity audits.