Artifact GuideUSContract Terms

US CPRA Contract Terms

Use this guide to resolve Contract Terms under the CCPA as amended by the CPRA, including the trigger, required action, deadline, owner, and evidence.

Apply the cited California statute and regulations to the actual entity, data flow, system, and recipient role; escalate unresolved legal interpretation.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
6

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Classify the recipient before drafting. CCPA contract terms differ for service providers and contractors versus third parties, and the actual processing must stay within the written purpose. A label such as 'processor' or 'vendor' does not create a California role when the agreement or conduct fails the statutory and regulatory tests.

Section 1

What should teams decide about Contract Terms under the US CPRA?

For a or contractor, state the specific business purpose and prohibit selling or sharing the personal information, retaining, using, or disclosing it outside that purpose or the direct business relationship, and combining it with personal information received from other businesses or collected from the recipient's own consumer interactions, subject to the statutory and regulatory exceptions. Name the service and permitted use, such as sending the business's customer emails or delivering its orders; generic descriptions such as 'business services' or 'as needed' do not identify a specific purpose.

Require compliance with the CCPA and regulations, the same level of privacy protection, notice if the recipient can no longer meet its obligations, and cooperation with consumer requests. Preserve the business's rights to take reasonable and appropriate steps to verify compliant use and to stop and remediate unauthorized use. If the recipient uses a subcontractor, require a contract that imposes the same applicable restrictions.

For a third party receiving personal information through sale or sharing, identify the limited and specified purpose, restrict use to that purpose, require the same level of protection, and include the monitoring, notice, and remediation rights. The business must also transmit applicable consumer opt-out instructions. Contract terms do not cure a disclosure made without the required notice or consumer choice.

  • Define whether the vendor is a , contractor, or third party before drafting the contract.
  • For service providers and contractors, include the statutory use restrictions and every applicable requirement in regulation section 7051, including cooperation with requests and downstream-contract duties.
  • For third parties, state the limited and specified purpose, require use only for that purpose, require compliance with applicable CCPA sections and regulations, preserve monitoring and remediation rights, and require notice if the third party can no longer meet its obligations.
  • Attach the cited rule, the owner, and the evidence field before approving the control.
  • Escalate uncertainty when the facts depend on service-provider status, contractor status, third-party sharing, sale or sharing opt-outs, subcontractors, or missing audit and remediation rights.
Section 2

Who should own the terms, and what evidence proves they operate?

Procurement should prevent the disclosure until the role decision and required terms are approved. Privacy or legal should approve the purpose, role, restrictions, exceptions, and transfer instructions. The business owner should confirm that actual use matches the contract, and security or assurance teams should operate the assessment and remediation rights. A contract that is never checked against actual processing may also weaken the statutory defense that the business had no reason to believe a third party would violate the CCPA.

Retain the signed agreement and amendments, role rationale, data and purpose schedule, subprocessors, consumer-request instructions, opt-out transmissions, assessments or audits, noncompliance notices, remediation, and termination or deletion evidence. A clause library without an executed agreement is not evidence that the disclosure qualifies.

  • Before signature: record the recipient role, specific purpose, data categories, source, permitted uses, and whether sale, sharing, or cross-context behavioral advertising occurs.
  • At onboarding: record systems, access, subprocessors, retention and deletion instructions, request-routing contacts, and opt-out propagation.
  • During service: exercise and retain evidence of reasonable and appropriate monitoring. Depending on the processing, this may include ongoing manual reviews, automated scans, or regular internal or third-party assessments, audits, or other technical and operational testing at least once every 12 months; act on noncompliance.
  • At change or exit: reassess the role and purpose, amend the agreement before expanded processing, and retain return, deletion, or lawful-retention evidence.
Section 3

Which edge cases should teams check before relying on a Contract Terms decision?

Most CPRA contract-term mistakes happen at the boundary between , contractor, third party, sale, sharing, subcontractor, and direct-business-relationship terminology.

Reassess before a material change to the data, purpose, interface, vendor, recipient role, system logic, or source text.

  • Check whether the rule changes because the recipient is a , contractor, third party, subcontractor, advertising partner, or a business using personal information outside the written contract.
  • Separate binding law, regulator guidance, consultation material, standards, and enforcement commentary in the evidence record.
  • Do not rely on a previous answer if the data categories, user interface, vendor role, or contractual flow changed.
  • Track unresolved assumptions in an open-questions section and route legal interpretation points for review.
Section 4

How should teams operationalize Contract Terms with proportionate controls?

Use a clause matrix that maps each statutory and regulatory requirement to the executed section, affected data flow, owner, and evidence. Pair it with a role decision that explains why the recipient qualifies and how actual processing stays within the written purpose.

Reopen the review when the recipient adds a purpose, combines data, starts advertising activity, changes subprocessors, receives consumer opt-out instructions, cannot meet a request, or reports that it can no longer comply.

  • Block disclosure until the role and executed terms are recorded.
  • Test the agreement against actual data flows and recipient uses, not only the vendor's description.
  • Transmit deletion, correction, and opt-out instructions through an owned process and retain completion evidence.
  • Treat processing outside a compliant contract as a new role and sale-or-sharing analysis rather than a contract exception.
Primary sources

References and citations

cppa.ca.gov
Referenced sections
  • Binding current regulations for implementing contract clauses in service-provider, contractor, and third-party workflows.
"Contract Requirements for Service Providers and Contractors"
leginfo.legislature.ca.gov
Referenced sections
  • Operational source for mapping contract records to statutory purposes, same-level-protection clauses, audit rights, and remediation rights.
"notify the business if it makes a determination that it can no longer meet its obligations"
leginfo.legislature.ca.gov
Referenced sections
  • Operational source for checking whether a recipient fits the service-provider or contractor role before relying on CPRA contract terms.
"A person to whom the business makes available a consumer’s personal information for a business purpose"
leginfo.legislature.ca.gov
Referenced sections
  • Supports CPRA contract-term edge cases by tying third-party liability defenses to written contracts and same-level protection.
"requires the third party to provide the same level of protection"
cppa.ca.gov
Referenced sections
  • CPPA regulations source for evidence of specific business purposes, use limits, audit rights, notice duties, and remediation rights in service-provider and contractor contracts.
"The business purpose(s) shall not be described in generic terms"
cppa.ca.gov
Referenced sections
  • Boundary and edge-case support for this artifact page.
"The CPRA amended the CCPA by adding additional consumer privacy rights and obligations for businesses"
Related guides

Explore more topics

California CCPA and CPRA Applicability Test
Decide whether the CCPA as amended by the CPRA applies, using California nexus, current business thresholds, related-entity rules, and data-specific exemptions.
California CCPA and CPRA Compliance Checklist
A California CCPA/CPRA implementation checklist covering scope, notices, rights, opt-outs, vendor contracts, retention, security, and 2026 regulations.
California CCPA/CPRA Deadlines and Compliance Calendar
Track California CCPA and CPRA request clocks, phased 2026 regulation deadlines, recurring metrics, and separate Delete Act dates.
California CCPA/CPRA Penalties, Fines, and Private Damages
Understand current California CCPA and CPRA fine caps, who enforces them, the limited private action for security breaches, and the evidence to preserve.
California CPRA FAQ
Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
California CPRA Requirements Guide
California CCPA/CPRA requirements for covered businesses: notices, rights, opt-outs, data-use limits, contracts, security, and phased 2026 rules.
California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide
Apply the separate California trigger tests, duties, phase-in dates, evidence, and consumer rights for risk assessments, cybersecurity audits, and ADMT.
California Data Broker Deletion Workflow Guide
California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
California Data Broker Registry and DROP Guide
California Delete Act guide to data-broker scope, annual registration, DROP processing from August 1, 2026, deletion, opt-out fallback, metrics, and audits.
California Delete Act data broker registry and DROP guide
California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
CCPA vs CPRA: What Changed in California Privacy Law
Compare the original CCPA with the CPRA amendments, including scope thresholds, new rights, contracts, retention, enforcement, and implementation steps.
CPPA Regulations Tracker | CCPA and CPRA
Track the in-force 2023 and 2026 CCPA regulations, their legal status, affected processing, and phased risk, audit, and ADMT deadlines.
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ
US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
CPRA vs Colorado Privacy Act: Practical Comparison
Compare California and Colorado privacy law on scope, consumer rights, opt-outs, sensitive data, contracts, assessments, and enforcement.
CPRA vs Virginia VCDPA: Practical Comparison
Compare California and Virginia privacy law on scope, rights, sale, advertising, sensitive data, contracts, assessments, and enforcement.
US CPRA Compliance Guide
Build a CCPA/CPRA compliance program for scope, notices, consumer rights, opt-outs, vendor contracts, retention, security, and phased 2026 duties.
US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
US CPRA Contracts Contractors and Service Providers Guide
Classify CCPA recipients as service providers, contractors, or third parties and apply the correct purpose limits, contracts, and consumer instructions.
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
US CPRA Cyber Audit Readiness Workflow Guide
US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
US CPRA Risk Assessment Intake Workflow Guide
Screen the six CPPA risk-assessment triggers, record exceptions and evidence, hold covered launches for approval, and track review and submission dates.
US CPRA Risk Assessment Template Guide
US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
US CPRA Risk Assessments and Cybersecurity Audits Guide
Apply the separate CPPA trigger tests for processing-level risk assessments and entity-level annual cybersecurity audits, with phase-in dates and evidence.
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.
What counts as sharing under the California CPRA?
How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.
What should teams do about ADMT under the US CPRA?
Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.
What should teams do about Contract Terms under the US CPRA?
Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.
What should teams do about Correction Rights under the US CPRA?
Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.
What should teams do about Cybersecurity Audits under the US CPRA?
US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about retention under the California CPRA?
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
What should teams do about Sensitive Personal Information Limits under the US CPRA?
US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
When is a CPRA risk assessment required?
When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.