Artifact GuideUSService Provider Contractor and Third Party Contracts

US CCPA Service Provider Contractor and Third Party Contracts

Match the written agreement to the recipient role, limited and specified purposes, use and combination restrictions, consumer-request cooperation, security, oversight, notification, remediation, and subcontractor duties.

Ground decisions in the consolidated CCPA statute and the regulations effective through January 1, 2026; preserve the trigger, owner, evidence, deadline, and reassessment condition for each control.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Classify each recipient from its contract and actual processing. A processes personal information for a business under a compliant written contract; a receives information under the statute's certification and contract conditions; and a is outside those restricted roles. The classification controls permitted uses, consumer-right cooperation, oversight, and whether a disclosure may be a sale or sharing.

Section 1

Contract requirements for service providers and contractors

Start by confirming whether the vendor is a or under the CCPA. For those roles, the contract must prohibit selling or sharing personal information, identify the specific business purpose, restrict use to that purpose, require compliance with the CCPA and these regulations, and give the business the right to take reasonable and appropriate steps to check compliance and stop or remediate unauthorized use.

The contract must also require the recipient to notify the business if it can no longer meet its obligations, allow reasonable and appropriate compliance checks and remediation, and require help with consumer requests. Any subcontractor must be bound by a contract that provides the same level of privacy protection. Under the regulations effective January 1, 2026, service providers and contractors must also supply facts and evidence needed for the business's applicable cybersecurity audit and risk assessment, and assist with verifiable consumer requests to access ADMT.

  • Confirm the recipient's actual collection, use, combination, disclosure, and subcontracting before selecting a role.
  • Describe the specific business purpose and the personal information covered; a generic reference to the services agreement is insufficient.
  • Add the role-specific restrictions on selling, sharing, retaining, using, disclosing, and combining personal information.
  • Include consumer-request assistance, compliance-check, notice, and remediation terms, and document applicable security, subcontractor, cybersecurity-audit, risk-assessment, and ADMT-access duties.
Section 2

How to tell service providers, contractors, and third parties apart

A processes personal information for a business under a written contract; a receives personal information made available by the business under the required certification and contract restrictions. Both roles are limited to business purposes and the direct business relationship. A is a person that is not the business with which the consumer intentionally interacts in the current interaction, a qualifying service provider, or a contractor.

A third-party contract must identify the limited and specified purposes, require compliance and the same level of privacy protection, permit reasonable and appropriate compliance checks, require notice if the recipient can no longer comply, and allow the business to stop and remediate unauthorized use. A without a section 7053 contract may not collect, use, process, retain, sell, or share the personal information the business made available. A compliant contract does not remove a sale or sharing from the consumer's opt-out right.

  • Treat the contract and actual processing as one classification test; neither can cure the other by itself.
  • Map whether the recipient acts only for the business, interacts directly with the consumer, or uses information for its own purposes.
  • Identify any sale or sharing and connect it to notices, opt-out methods, GPC, and downstream instructions.
  • Reclassify before adding a new purpose, data source, customer, advertising use, or subcontractor.
Section 3

What teams should check before relying on a contract structure

A or may use personal information for specified regulatory purposes, including the contract's business purposes, compliant subcontracting, certain internal service improvement, security and fraud prevention, and other uses allowed by the regulations. For example, an email provider may analyze interactions to improve the email service, but may not reuse the original customer list to market for another business. Each use must remain reasonably necessary and proportionate and within the applicable restrictions.

Combining personal information from different businesses or from the recipient's own consumer interactions is restricted, subject to specific regulatory exceptions. Cross-context behavioral advertising for another person does not fit the service-provider or role.

  • Check whether a cloud, analytics, advertising, identity, or AI provider trains, profiles, or improves services using the business's personal information.
  • Check whether instructions for deletion, correction, access, opt-out, and limitation can reach the recipient and its subcontractors.
  • Check whether the business has a practical right and process to stop unauthorized use, not only a paper audit clause. Section 7051 gives examples of ongoing manual reviews, automated scans, and internal or third-party testing at least once every 12 months.
  • Escalate mixed roles and multi-customer data uses rather than assigning one label to the entire vendor relationship.
Section 4

How should teams operationalize Service Provider Contractor and Third Party Contracts with proportionate controls?

Create a recipient record that links the data flow, role analysis, signed agreement, clause map, subprocessors, rights-response method, compliance checks, and reassessment triggers. Procurement should not approve access to personal information until the role and required terms match.

When monitoring finds unauthorized use, apply the contractual stop-and-remediate process and reassess whether past or future disclosures are sale or sharing. Preserve the finding, notice, containment instruction, deletion or correction evidence, affected consumers and flows, reclassification decision, and closure approval.

  • Map the recipient, data, source, purpose, consumer relationship, combinations, disclosures, and subcontractors.
  • Classify each processing role and identify sale or sharing consequences.
  • Review every required clause against the signed agreement and record its location.
  • Test consumer-request cooperation and remediation, then schedule review for material changes.
Primary sources

References and citations

cppa.ca.gov
Referenced sections
  • Sections 7050-7053 define permitted service-provider and contractor uses, third-party restrictions, and the required contract terms for each recipient role.
"A service provider or contractor shall not retain, use, or disclose personal information collected pursuant to its written contract with the business except for the following purposes, provided that the retention, use, or disclosure is reasonably necessary and proportionate for those purposes."
Related guides

Explore more topics

California Data Brokers: CCPA, Registration, and DROP Duties
Decide whether a CCPA business is also a California data broker and track registration, privacy metrics, DROP deletion, vendor, and audit duties.
CCPA Consumer Rights Workflow: Requests, Clocks, and Evidence
Route CCPA requests by right, apply the correct verification and response rule, coordinate downstream action, and retain a clear decision record.
CCPA Contract Classification: Service Provider or Third Party?
Classify CCPA recipients from their actual processing and contracts, then document the clauses, restrictions, monitoring, and opt-out consequences.
CCPA Dark Patterns: Rules, Examples, and Review Checklist
Check a CCPA privacy interface for clear language, symmetrical choices, unnecessary steps, and other designs that can invalidate consent.
CCPA Deadlines and Compliance Calendar
Track CCPA request clocks, annual duties, DROP dates, and phased 2026-2030 deadlines for risk assessments, ADMT, and cybersecurity audits.
CCPA Do Not Sell or Share Guide
Classify CCPA sales and sharing, provide valid opt-out methods, honor preference signals, stop disclosures within 15 business days, and notify recipients.
CCPA Do Not Sell or Share: Implementation and Testing
Implement CCPA sale-or-sharing opt-outs across links, GPC, consent state, ad tech, recipients, confirmation, privacy disclosures, and evidence.
CCPA Do Not Sell or Share: Scope and Implementation
Determine whether a transfer is a CCPA sale or sharing, provide the required opt-out path, honor preference signals, and propagate the choice.
CCPA DSAR Workflow: Intake, Verification, and Response
Run CCPA data-subject requests from intake through verification, search, exception review, downstream action, response, and retained evidence.
CCPA Financial Incentives: Notice, Consent, and Data Value
Assess a loyalty, discount, payment, or service program under the CCPA and document notice, opt-in, withdrawal, and data-value requirements.
CCPA Global Privacy Control (GPC): team obligations and technical implementation
Implement Global Privacy Control as a CCPA sale and sharing opt-out across browsers, devices, known accounts, and relevant downstream systems.
CCPA Minors: Opt-In Rules for Consumers Under 16
Apply the CCPA's under-13 parent authorization and age-13-to-15 consumer opt-in rules for sale or sharing of personal information.
CCPA Notice at Collection: Timing, Content, and Examples
Place a CCPA notice where consumers encounter it before collection and disclose categories, purposes, retention, sale or sharing, and required links.
CCPA Opt-Out Signal Workflow: Detect, Apply, and Test GPC
Process CCPA opt-out preference signals across browsers, devices, profiles, accounts, offline data, conflicts, recipients, and confirmation controls.
CCPA Penalties and Fines: Current Amounts
See current CCPA fines, civil penalties, security-breach damages, adjustment rules, and the facts needed before estimating exposure.
CCPA Personal and Sensitive Information Categories
Classify personal and sensitive personal information under the current CCPA, including exclusions and the duties each category can trigger.
CCPA Privacy Policy Template: Required Content and Review
Draft and maintain a CCPA privacy policy covering data practices, rights, request methods, GPC handling, minors, contacts, and the last-updated date.
CCPA Risk Assessments, Cybersecurity Audits, and ADMT
Apply California's regulations effective January 1, 2026 for risk-assessment triggers, phased cybersecurity audits, ADMT rights, evidence, reviews, and CPPA submissions.
CCPA vs CPRA: What Changed and Which Rules Apply
Compare the original CCPA with the CPRA amendments and learn why current California privacy work must use the CCPA as amended, not two separate laws.
CCPA vs GDPR: Scope, Rights, Duties, and Evidence
Compare the California CCPA and EU GDPR by scope, roles, legal basis, rights, advertising transfers, contracts, security, deadlines, and enforcement.
Does the CCPA apply to my business? Threshold guide
Apply the CCPA revenue, data-volume, and sale-or-sharing revenue thresholds, then check California nexus, control, joint ventures, roles, and exemptions.
US CCPA Applicability Test Guide
Apply the CCPA entity-by-entity: test California nexus, for-profit control, current thresholds, related-entity routes, exemptions, and processing roles.
US CCPA Compliance Checklist
A verifiable CCPA checklist for scope, data mapping, notices, rights, opt-outs, contracts, retention, security, risk assessments, audits, ADMT, and evidence.
US CCPA Compliance Guide
Build a CCPA operating model for entity scope, data mapping, notices, rights, opt-outs, contracts, retention, security, assessments, audits, ADMT, and evidence.
US CCPA Dark Patterns Guide
Review CCPA privacy interfaces for plain language, symmetry, minimal steps, neutral presentation, valid consent, and reliable opt-out operation.
US CCPA Data Broker Crossover Guide
Test whether a CCPA business is also a California data broker, then assign registration, metrics, DROP, deletion, downstream, and audit duties.
US CCPA DSAR Verification Guide
Verify CCPA know, delete, correct, and ADMT-access requests with request-specific, secure, minimized methods without adding friction to opt-outs.
US CCPA Enforcement and Penalties Guide
Understand CPPA investigations, Attorney General civil actions, CCPA administrative orders, current penalties, and the limited security-breach private action.
US CCPA Financial Incentives Guide
Decide whether a CCPA financial-incentive rule applies, then document the notice, data-value method, opt-in, withdrawal, and nondiscrimination checks.
US CCPA GPC Signal Guide
Implement Global Privacy Control under the CCPA across browsers, devices, accounts, ad technology, downstream recipients, and consumer notices.
US CCPA Minors Guide
Apply the CCPA opt-in rules for selling or sharing personal information of consumers under 16, including age bands, authorization, notices, and evidence.
US CCPA Notice at collection Guide
Build a CCPA Notice at Collection for online and offline collection points, including categories, purposes, sale or sharing, retention, links, and change control.
US CCPA Personal and Sensitive PI Categories Guide
Classify CCPA personal information and sensitive personal information, apply exclusions, and map each category to notices, rights, retention, security, sale, and sharing.
US CCPA Privacy Law FAQ
Direct answers on CCPA scope, rights, notices, opt-outs, GPC, minors, sensitive information, financial incentives, and data brokers.
US CCPA Privacy Notices and Disclosures Guide
Choose and maintain each CCPA consumer notice: privacy policy, collection, sale or sharing, sensitive-information limits, financial incentives, and ADMT.
US CCPA Privacy Policy Guide
Build and maintain a CCPA privacy policy covering online and offline practices, 12-month disclosures, consumer rights, request methods, and annual updates.
US CCPA Requirements Guide
Plain-language CCPA requirements covering scope, minimization, notices, rights, opt-outs, contracts, security, records, risk assessments, audits, and ADMT.
US CCPA Scope and Thresholds Guide
CCPA scope and threshold reference covering the current $26,625,000 revenue threshold, the 100,000-consumer-or-household test, related entities, and exemptions.
US CCPA Service Provider Contractor Contracts Guide
Check CCPA service-provider and contractor agreements for specific purposes, use restrictions, consumer-request support, subcontractors, and remediation.
US CCPA Thresholds Guide
Apply the CCPA business thresholds per legal entity, including the 2025 CPI-adjusted revenue amount, volume and sale-or-sharing tests, and control routes.
What must a CCPA privacy policy include?
A practical guide to CCPA privacy-policy content, placement, annual updates, consumer rights, request methods, and supporting evidence.
What must CCPA service-provider contracts include?
Required CCPA contract terms, role checks, subcontractor flow-downs, oversight rights, and evidence for service providers and contractors.
What should teams do about consumer request verification under the CCPA?
Choose a proportionate CCPA verification method for know, delete, and correct requests without collecting unnecessary identity data.
When does the CCPA require risk assessments or cyber audits?
CCPA triggers, deadlines, evidence, retention, and submission duties for risk assessments and annual cybersecurity audits.