Artifact GuideUSService Provider and Contractor Contracts

US CCPA Service Provider and Contractor Contracts

A vendor is not a CCPA service provider or contractor merely because the agreement uses that label; the written terms and actual processing must satisfy the role-specific purpose, use, assistance, oversight, and remediation requirements.

Classify the vendor from the data flow and actual use, execute the required terms before disclosure, and verify that subcontractors receive equivalent restrictions.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

A vendor qualifies as a CCPA or contractor only when both the relationship and the written contract satisfy the statute and regulations. The label in an agreement is not enough. Check what personal information the vendor receives, why it processes the data, whether it acts on the business's behalf, and whether its own uses fit the CCPA limits.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

What must the contract say?

Execute the contract before disclosing personal information. It must prohibit sale or sharing; identify each specific business purpose; prohibit retaining, using, or disclosing the data outside those purposes, for an unpermitted commercial purpose, or outside the direct business relationship; and address impermissible combining of data from other sources. A reference to the agreement as a whole is not specific enough.

The contract must require compliance with applicable CCPA provisions and the same level of privacy protection required of businesses. It must enable the business to handle consumer requests, allow reasonable and appropriate oversight, require notice if the vendor can no longer meet its obligations, and let the business stop and remediate unauthorized use. A or contractor that engages a subcontractor must impose a downstream contract that complies with the CCPA and section 7051.

A person without a compliant section 7051 contract is not a or contractor under the CCPA. The disclosure may then be a sale or sharing that requires consumer opt-out rights, depending on the facts. Even with compliant text, processing outside the permitted purposes or relationship can defeat the intended role.

The roles are close but not identical. A processes personal information on behalf of the business and receives it from or for the business; a contractor is a person to whom the business makes personal information available for a business purpose. Both need the statutory written restrictions and section 7051 terms. A third party has a different contract under section 7053, and sale or sharing analysis applies to the transfer.

Section 7050 permits limited uses when they remain reasonably necessary and proportionate, including the contract's specific purposes, compliant subcontracting, internal work to build or improve the quality of the service without using the original data to serve another person, and other listed operational purposes. It does not authorize the vendor to repurpose customer data for its own advertising, unrelated products, or another customer's services.

  • Map each service to a specific purpose, personal-information category, consumer population, system, retention rule, and permitted disclosure.
  • Separate service-provider or contractor processing from any third-party or independent use and apply the contract and consumer-choice rules for the actual role.
  • Confirm consumer-request assistance, security duties, oversight rights, inability-to-comply notice, remediation, deletion or return, and subcontractor flow-downs.

What makes a vendor a CCPA or contractor?

The relationship, written contract, and actual processing must all fit the statutory role. A processes personal information on behalf of a business and receives it from or for the business. A contractor receives personal information made available for a business purpose. Both need the required written restrictions and must operate within them.

What terms must a CCPA service-provider or contractor contract include?

The contract must prohibit sale and sharing; state each limited and specific business purpose; restrict retention, use, disclosure, commercial use, use outside the direct relationship, and combining; require CCPA compliance and equivalent privacy protection; support consumer requests; permit reasonable oversight; require notice of inability to comply; allow the business to stop and remediate misuse; and bind subcontractors through compliant downstream terms.

Is calling a vendor a in a DPA enough?

No. A generic label or data-protection addendum does not establish the role. Section 7051 requires specific contract terms, and section 7050 restricts actual processing. If the contract is missing or the vendor uses the data outside the permitted purposes and relationship, the intended service-provider or contractor treatment can fail.

Can a combine or reuse business data?

Only within the CCPA's permitted purposes and restrictions. Section 7050 allows limited internal use to build or improve the quality of the services provided to the business, but the vendor cannot use the original customer data to perform services for another person. Combining data from other sources is prohibited unless the CCPA or regulations expressly permit it.

What must happen when a vendor uses a subcontractor?

The or contractor must enter a downstream contract that satisfies the CCPA and section 7051. The statutory role definitions also require notice to the business when another person is engaged to assist with processing. Keep the subcontractor identity, notice or approval record, scope, data categories, purposes, and executed flow-down terms.

How often should a business test a or contractor?

Section 7051 requires reasonable and appropriate oversight and gives examples including ongoing manual reviews, automated scans, assessments, audits, and other technical or operational testing at least once every 12 months. The exact mix depends on the service and risk, but a business should document its cadence, results, findings, and remediation.

What happens if the required contract is missing?

The recipient is not a CCPA or contractor for that disclosure. The business must classify the recipient and transfer under the rules that actually apply, including the third-party contract requirements and possible sale-or-sharing notice and opt-out duties. Put the compliant agreement in place before disclosing personal information.

Citations
Question 2

What evidence should teams keep for Service Provider and Contractor Contracts under the US CCPA?

Keep a role assessment for each vendor, the signed agreement and amendments, the specific-purpose schedule, data-flow record, security review, subcontractor list, and evidence that the vendor can support consumer requests. Record which systems and personal-information categories are in scope and which vendor uses are prohibited.

Use the contract's oversight rights and keep evidence. Preserve due-diligence results, audit or test reports, issue notices, remediation evidence, deletion confirmations, and any notice that the vendor can no longer meet its obligations. Section 7051 says reasonable steps may include manual reviews, automated scans, assessments, audits, or other technical and operational testing; the appropriate method depends on the relationship and risk.

  • Contract evidence: executed terms, incorporated schedules, purpose descriptions, prohibited uses, request assistance, oversight, notice, and remediation rights.
  • Operational evidence: data inventory, transfer diagram, access list, retention and deletion settings, security assessment, and request test.
  • Downstream evidence: current subcontractor register, approval or notice records, and compliant flow-down terms.
Citations
Question 3

Which mistakes create risk when handling Service Provider and Contractor Contracts under the US CCPA?

A data-protection addendum does not prove service-provider or contractor status. Reassess the role when the vendor adds a product feature, combines customer data, uses data for its own advertising or model training, changes retention, or adds a subcontractor.

A business that never enforces the contract or exercises its audit and testing rights may have difficulty relying on the statutory defense that it had no reason to believe the vendor intended to violate the CCPA. Record the review cadence and follow through on identified misuse.

  • Do not describe the purpose by pointing to the whole agreement or using a generic label.
  • Do not allow independent commercial use, sale, sharing, or unapproved combining through a side document or product setting.
  • Do not assume a subcontractor inherits restrictions unless the required downstream contract exists.
Citations
Primary sources

References and citations

leginfo.legislature.ca.gov
Referenced sections
  • The statute defines service provider, contractor, business purpose, sale, and sharing and sets the core contractual restrictions that determine the role.
Related guides

Explore more topics

California Data Brokers: CCPA, Registration, and DROP Duties
Decide whether a CCPA business is also a California data broker and track registration, privacy metrics, DROP deletion, vendor, and audit duties.
CCPA Consumer Rights Workflow: Requests, Clocks, and Evidence
Route CCPA requests by right, apply the correct verification and response rule, coordinate downstream action, and retain a clear decision record.
CCPA Contract Classification: Service Provider or Third Party?
Classify CCPA recipients from their actual processing and contracts, then document the clauses, restrictions, monitoring, and opt-out consequences.
CCPA Dark Patterns: Rules, Examples, and Review Checklist
Check a CCPA privacy interface for clear language, symmetrical choices, unnecessary steps, and other designs that can invalidate consent.
CCPA Deadlines and Compliance Calendar
Track CCPA request clocks, annual duties, DROP dates, and phased 2026-2030 deadlines for risk assessments, ADMT, and cybersecurity audits.
CCPA Do Not Sell or Share Guide
Classify CCPA sales and sharing, provide valid opt-out methods, honor preference signals, stop disclosures within 15 business days, and notify recipients.
CCPA Do Not Sell or Share: Implementation and Testing
Implement CCPA sale-or-sharing opt-outs across links, GPC, consent state, ad tech, recipients, confirmation, privacy disclosures, and evidence.
CCPA Do Not Sell or Share: Scope and Implementation
Determine whether a transfer is a CCPA sale or sharing, provide the required opt-out path, honor preference signals, and propagate the choice.
CCPA DSAR Workflow: Intake, Verification, and Response
Run CCPA data-subject requests from intake through verification, search, exception review, downstream action, response, and retained evidence.
CCPA Financial Incentives: Notice, Consent, and Data Value
Assess a loyalty, discount, payment, or service program under the CCPA and document notice, opt-in, withdrawal, and data-value requirements.
CCPA Global Privacy Control (GPC): team obligations and technical implementation
Implement Global Privacy Control as a CCPA sale and sharing opt-out across browsers, devices, known accounts, and relevant downstream systems.
CCPA Minors: Opt-In Rules for Consumers Under 16
Apply the CCPA's under-13 parent authorization and age-13-to-15 consumer opt-in rules for sale or sharing of personal information.
CCPA Notice at Collection: Timing, Content, and Examples
Place a CCPA notice where consumers encounter it before collection and disclose categories, purposes, retention, sale or sharing, and required links.
CCPA Opt-Out Signal Workflow: Detect, Apply, and Test GPC
Process CCPA opt-out preference signals across browsers, devices, profiles, accounts, offline data, conflicts, recipients, and confirmation controls.
CCPA Penalties and Fines: Current Amounts
See current CCPA fines, civil penalties, security-breach damages, adjustment rules, and the facts needed before estimating exposure.
CCPA Personal and Sensitive Information Categories
Classify personal and sensitive personal information under the current CCPA, including exclusions and the duties each category can trigger.
CCPA Privacy Policy Template: Required Content and Review
Draft and maintain a CCPA privacy policy covering data practices, rights, request methods, GPC handling, minors, contacts, and the last-updated date.
CCPA Risk Assessments, Cybersecurity Audits, and ADMT
Apply California's regulations effective January 1, 2026 for risk-assessment triggers, phased cybersecurity audits, ADMT rights, evidence, reviews, and CPPA submissions.
CCPA vs CPRA: What Changed and Which Rules Apply
Compare the original CCPA with the CPRA amendments and learn why current California privacy work must use the CCPA as amended, not two separate laws.
CCPA vs GDPR: Scope, Rights, Duties, and Evidence
Compare the California CCPA and EU GDPR by scope, roles, legal basis, rights, advertising transfers, contracts, security, deadlines, and enforcement.
Does the CCPA apply to my business? Threshold guide
Apply the CCPA revenue, data-volume, and sale-or-sharing revenue thresholds, then check California nexus, control, joint ventures, roles, and exemptions.
US CCPA Applicability Test Guide
Apply the CCPA entity-by-entity: test California nexus, for-profit control, current thresholds, related-entity routes, exemptions, and processing roles.
US CCPA Compliance Checklist
A verifiable CCPA checklist for scope, data mapping, notices, rights, opt-outs, contracts, retention, security, risk assessments, audits, ADMT, and evidence.
US CCPA Compliance Guide
Build a CCPA operating model for entity scope, data mapping, notices, rights, opt-outs, contracts, retention, security, assessments, audits, ADMT, and evidence.
US CCPA Dark Patterns Guide
Review CCPA privacy interfaces for plain language, symmetry, minimal steps, neutral presentation, valid consent, and reliable opt-out operation.
US CCPA Data Broker Crossover Guide
Test whether a CCPA business is also a California data broker, then assign registration, metrics, DROP, deletion, downstream, and audit duties.
US CCPA DSAR Verification Guide
Verify CCPA know, delete, correct, and ADMT-access requests with request-specific, secure, minimized methods without adding friction to opt-outs.
US CCPA Enforcement and Penalties Guide
Understand CPPA investigations, Attorney General civil actions, CCPA administrative orders, current penalties, and the limited security-breach private action.
US CCPA Financial Incentives Guide
Decide whether a CCPA financial-incentive rule applies, then document the notice, data-value method, opt-in, withdrawal, and nondiscrimination checks.
US CCPA GPC Signal Guide
Implement Global Privacy Control under the CCPA across browsers, devices, accounts, ad technology, downstream recipients, and consumer notices.
US CCPA Minors Guide
Apply the CCPA opt-in rules for selling or sharing personal information of consumers under 16, including age bands, authorization, notices, and evidence.
US CCPA Notice at collection Guide
Build a CCPA Notice at Collection for online and offline collection points, including categories, purposes, sale or sharing, retention, links, and change control.
US CCPA Personal and Sensitive PI Categories Guide
Classify CCPA personal information and sensitive personal information, apply exclusions, and map each category to notices, rights, retention, security, sale, and sharing.
US CCPA Privacy Law FAQ
Direct answers on CCPA scope, rights, notices, opt-outs, GPC, minors, sensitive information, financial incentives, and data brokers.
US CCPA Privacy Notices and Disclosures Guide
Choose and maintain each CCPA consumer notice: privacy policy, collection, sale or sharing, sensitive-information limits, financial incentives, and ADMT.
US CCPA Privacy Policy Guide
Build and maintain a CCPA privacy policy covering online and offline practices, 12-month disclosures, consumer rights, request methods, and annual updates.
US CCPA Requirements Guide
Plain-language CCPA requirements covering scope, minimization, notices, rights, opt-outs, contracts, security, records, risk assessments, audits, and ADMT.
US CCPA Scope and Thresholds Guide
CCPA scope and threshold reference covering the current $26,625,000 revenue threshold, the 100,000-consumer-or-household test, related entities, and exemptions.
US CCPA Service Provider Contractor and Third Party Contracts Guide
Classify CCPA recipients and check the distinct contract terms for service providers, contractors, and third parties before disclosing personal information.
US CCPA Service Provider Contractor Contracts Guide
Check CCPA service-provider and contractor agreements for specific purposes, use restrictions, consumer-request support, subcontractors, and remediation.
US CCPA Thresholds Guide
Apply the CCPA business thresholds per legal entity, including the 2025 CPI-adjusted revenue amount, volume and sale-or-sharing tests, and control routes.
What must a CCPA privacy policy include?
A practical guide to CCPA privacy-policy content, placement, annual updates, consumer rights, request methods, and supporting evidence.
What should teams do about consumer request verification under the CCPA?
Choose a proportionate CCPA verification method for know, delete, and correct requests without collecting unnecessary identity data.
When does the CCPA require risk assessments or cyber audits?
CCPA triggers, deadlines, evidence, retention, and submission duties for risk assessments and annual cybersecurity audits.