- Official California statute defining the written-contract restrictions for service providers and contractors.
"for a business purpose pursuant to a written contract, provided that the contract prohibits the person from:"
Use the required written terms and actual processing limits to preserve service-provider or contractor status, including specified purposes, prohibited uses, assistance, oversight, notification, and remediation rights.
Ground decisions in the consolidated CCPA statute and the regulations effective through January 1, 2026; preserve the trigger, owner, evidence, deadline, and reassessment condition for each control.
Structured answer sets in this page tree.
Cited legal and guidance references.
Under the California Consumer Privacy Act (CCPA), a vendor is not a CCPA merely because the agreement uses that label. The written contract and actual processing must meet the statutory conditions and the California Privacy Protection Agency (CPPA) regulations. The clause map, ownership, and test records below are practical evidence for applying those binding rules.
Start by deciding whether the recipient processes personal information on the business's behalf as a service provider or receives it for a business purpose as a contractor. Examples can include account servicing, customer support, payment processing, storage, contextual advertising, or analytics performed for the business. The label is not enough: a recipient providing is a third party for that service, and one vendor can hold different roles for different services.
Under , the contract must identify each specific business purpose rather than refer generally to the agreement. It must prohibit selling or sharing the data; prohibit retention, use, or disclosure outside those purposes except where the CCPA permits it; prohibit use outside the direct business relationship; and control combinations with data from another person or the recipient's own consumer interaction.
The agreement must also require compliance with applicable CCPA obligations and the same level of privacy protection, assistance with consumer requests, notice if the recipient can no longer comply, reasonable and appropriate compliance checks by the business, and authority to stop and remediate unauthorized use. Separately, service providers and contractors must cooperate with applicable cybersecurity audits and risk assessments and assist with verifiable consumer requests to access ADMT. Every subcontractor in the processing chain needs a contract that imposes the same requirements.
Ownership should sit with the team that can approve vendor terms, manage procurement, and enforce contract follow-up, with privacy/legal review for ambiguous cases.
Evidence should show the signed contract and effective date, role analysis by service and data flow, clause map, specific business purposes, covered personal-information categories, subcontractor chain, security commitments, request-response procedure, compliance checks, findings, and any remediation. A contract clause map should cite the executed section rather than a draft, template, or unsigned data-processing addendum.
A compliant contract does not protect a role that the actual processing contradicts. If the vendor uses the information for another person's services, , or an unrelated independent purpose, reclassify the flow and assess sale or sharing.
The regulations allow limited uses beyond the stated contract purpose, including compliant subcontracting, internal improvement of the services provided to the business, security and fraud prevention, and specified statutory purposes. For example, an email provider may analyze engagement to improve its email service, but it may not use the business's original customer list to market for another business. A shipping provider may learn from incomplete addresses to improve delivery, but may not compile client addresses to advertise or sell to data brokers. These permissions remain bounded by necessity, proportionality, direct-relationship, and combination restrictions.
Use a contract clause map that cites the executed section for each requirement and pairs it with operational evidence. A clause is incomplete if the business has no owner or process to use the promised audit, notice, request, or remediation right.
Before onboarding and renewal, compare the agreement with current processing and subprocessor facts, recent rights requests, security findings, unauthorized-use incidents, and any notice from the vendor that it can no longer comply. identifies ongoing reviews, automated scans, assessments, audits, or other technical and operational testing at least once every 12 months as examples of reasonable compliance checks; the business should select and document checks that fit the processing risk.
This US CCPA guide turns Service Provider Contractor Contracts into owners, evidence requests, review checkpoints, and reusable operating records in Sorena.
Turn Service Provider Contractor Contracts into scoped questions, evidence fields, and review tasks.
Use Research Copilot to answer follow-up questions with cited source material.
Review scope, evidence, owners, and the next compliance actions with Sorena.
"for a business purpose pursuant to a written contract, provided that the contract prohibits the person from:"
"The contract required by the CCPA for service providers and contractors shall"
"A service provider or contractor that subcontracts with another person in providing services to the business"