Classify each recipient from actual processing and contract terms as a service provider, contractor, or third party; a label alone does not prevent a disclosure from being a sale or sharing.
A service-provider label is not enough. Section 7051 requires a compliant written contract, and the recipient must operate within that role.
Under the California Consumer Privacy Act (CCPA), classify a recipient from the data flow, purpose, relationship, and written agreement. A service provider or contractor processes personal information for limited and specified business purposes under a section 7051 contract. A is outside those roles and, when a business sells or shares personal information with it, needs a section 7053 agreement. The Civil Code and California Privacy Protection Agency (CPPA) regulations control the role; the classification record below is practical evidence for applying them.
1
Section 1
How should the classification decision run?
Start with the service being performed and every use, disclosure, retention, combination, and subcontracting path. A service provider processes personal information on behalf of the business; a contractor receives personal information for a business purpose. Account servicing, payment processing, storage, contextual advertising, and analytics can fit those roles when the purpose, use, and contract meet the statute and regulations.
A person providing cross-context behavioral advertising is a for that service, even if the same person acts as a service provider for a different permitted service. For example, a social-media company may provide non-personalized advertising based on aggregate or demographic information as a service provider, but it cannot use the business's customer email list to identify its users for cross-context targeting under that role.
Then test the written agreement. A section 7051 contract must identify specific business purposes, prohibit sale or sharing, restrict use to those purposes and the direct business relationship, require the same level of privacy protection, support consumer requests and applicable audits, risk assessments, and ADMT duties, give the business monitoring and remediation rights, require notice if the recipient can no longer comply, and flow the restrictions to subcontractors.
Data owner: map the personal information, source, purpose, recipient, onward recipients, retention, and consumer groups.
Procurement or legal: select the role for each service, not once for the entire vendor relationship.
Privacy: decide whether each transfer is a sale, sharing, disclosure for a business purpose, consumer-directed disclosure, merger or acquisition transfer, or separate collection by the recipient.
Control owner: block the transfer or route it through notice and opt-out controls if the intended exclusion from sale or sharing is not supported.
A is not converted into a service provider by adding restrictions after the fact. When a business sells or shares personal information with a third party, section 7053 requires an agreement identifying the limited and specified purposes, limiting use to those purposes, requiring CCPA-level privacy protection, allowing the business to check and remediate use, and requiring notice if the third party can no longer comply.
The business must separately address the consumer-facing consequences of a sale or sharing: notice, request methods, opt-out preference signals, suppression, and forwarding applicable opt-out requests. A compliant third-party agreement governs the recipient's use; it does not eliminate the sale-or-sharing classification. Without a section 7053 contract, the may not collect, use, process, retain, sell, or share the personal information the business made available.
Identify each limited purpose and prohibit unrelated reuse.
Require the to apply CCPA-level protection and comply with forwarded opt-out requests.
Give the business rights to check compliance, stop unauthorized use, and obtain remediation evidence.
Keep the third-party contract analysis separate from the business's notice and opt-out analysis.
Keep one record per service and data flow. It should show the facts used to select the role, the contract version and clauses relied on, any sale-or-sharing analysis, the systems and data covered, the owner, and the reassessment trigger. Record exceptions and open questions instead of forcing an uncertain relationship into a preferred label.
For a service provider or contractor, retain evidence that the business exercises its contractual monitoring rights. For a contractor, retain the required certification that it understands and will follow the statutory restrictions. The regulations identify due diligence and enforcement of contract terms as relevant to whether the business had reason to believe the recipient was violating the CCPA.
Scope: legal entity, service, purpose, data categories, sources, consumers, systems, retention, recipients, and subprocessors.
Decision: role by service, sale-or-sharing result, contract section, reviewer, approval date, and unresolved assumptions.
Controls: request cooperation, audit or testing rights, compliance notice, remediation, security, assessment support, and subcontractor flow-down.
Evidence: signed agreement and effective date, data-flow map, recipient documentation, configuration, assessment or test results, issues, remediation, approval, and next review date.
Binding statutory definitions of business, business purpose, contractor, cross-context behavioral advertising, service provider, sale, sharing, and third party.