What must the contract say?
Execute the contract before disclosing personal information. It must prohibit sale or sharing; identify each specific business purpose; prohibit retaining, using, or disclosing the data outside those purposes, for an unpermitted commercial purpose, or outside the direct business relationship; and address impermissible combining of data from other sources. A reference to the agreement as a whole is not specific enough.
The contract must require compliance with applicable CCPA provisions and the same level of privacy protection required of businesses. It must enable the business to handle consumer requests, allow reasonable and appropriate oversight, require notice if the vendor can no longer meet its obligations, and let the business stop and remediate unauthorized use. A or contractor that engages a subcontractor must impose a downstream contract that complies with the CCPA and section 7051.
A person without a compliant section 7051 contract is not a or contractor under the CCPA. The disclosure may then be a sale or sharing that requires consumer opt-out rights, depending on the facts. Even with compliant text, processing outside the permitted purposes or relationship can defeat the intended role.
The roles are close but not identical. A processes personal information on behalf of the business and receives it from or for the business; a contractor is a person to whom the business makes personal information available for a business purpose. Both need the statutory written restrictions and section 7051 terms. A third party has a different contract under section 7053, and sale or sharing analysis applies to the transfer.
Section 7050 permits limited uses when they remain reasonably necessary and proportionate, including the contract's specific purposes, compliant subcontracting, internal work to build or improve the quality of the service without using the original data to serve another person, and other listed operational purposes. It does not authorize the vendor to repurpose customer data for its own advertising, unrelated products, or another customer's services.
- Map each service to a specific purpose, personal-information category, consumer population, system, retention rule, and permitted disclosure.
- Separate service-provider or contractor processing from any third-party or independent use and apply the contract and consumer-choice rules for the actual role.
- Confirm consumer-request assistance, security duties, oversight rights, inability-to-comply notice, remediation, deletion or return, and subcontractor flow-downs.
What makes a vendor a CCPA or contractor?
The relationship, written contract, and actual processing must all fit the statutory role. A processes personal information on behalf of a business and receives it from or for the business. A contractor receives personal information made available for a business purpose. Both need the required written restrictions and must operate within them.
What terms must a CCPA service-provider or contractor contract include?
The contract must prohibit sale and sharing; state each limited and specific business purpose; restrict retention, use, disclosure, commercial use, use outside the direct relationship, and combining; require CCPA compliance and equivalent privacy protection; support consumer requests; permit reasonable oversight; require notice of inability to comply; allow the business to stop and remediate misuse; and bind subcontractors through compliant downstream terms.
Is calling a vendor a in a DPA enough?
No. A generic label or data-protection addendum does not establish the role. Section 7051 requires specific contract terms, and section 7050 restricts actual processing. If the contract is missing or the vendor uses the data outside the permitted purposes and relationship, the intended service-provider or contractor treatment can fail.
Can a combine or reuse business data?
Only within the CCPA's permitted purposes and restrictions. Section 7050 allows limited internal use to build or improve the quality of the services provided to the business, but the vendor cannot use the original customer data to perform services for another person. Combining data from other sources is prohibited unless the CCPA or regulations expressly permit it.
What must happen when a vendor uses a subcontractor?
The or contractor must enter a downstream contract that satisfies the CCPA and section 7051. The statutory role definitions also require notice to the business when another person is engaged to assist with processing. Keep the subcontractor identity, notice or approval record, scope, data categories, purposes, and executed flow-down terms.
How often should a business test a or contractor?
Section 7051 requires reasonable and appropriate oversight and gives examples including ongoing manual reviews, automated scans, assessments, audits, and other technical or operational testing at least once every 12 months. The exact mix depends on the service and risk, but a business should document its cadence, results, findings, and remediation.
What happens if the required contract is missing?
The recipient is not a CCPA or contractor for that disclosure. The business must classify the recipient and transfer under the rules that actually apply, including the third-party contract requirements and possible sale-or-sharing notice and opt-out duties. Put the compliant agreement in place before disclosing personal information.
Sections 7050 and 7051 establish role consequences, required contract terms, subcontractor flow-downs, and the relevance of due diligence and enforcement.
The statute defines service provider, contractor, business purpose, sale, and sharing and sets the core contractual restrictions that determine the role.