- Binding current regulations on service-provider, contractor, and third-party boundaries.
"Contract Requirements for Third Parties"
Use this guide to resolve Contracts Contractors and Service Providers under the CCPA as amended by the CPRA, including the trigger, required action, deadline, owner, and evidence.
Apply the cited California statute and regulations to the actual entity, data flow, system, and recipient role; escalate unresolved legal interpretation.
Structured answer sets in this page tree.
Cited legal and guidance references.
A recipient is a service provider or only when both the relationship and the written agreement satisfy the CCPA rules. Classify the actual processing before disclosure. If the recipient does not qualify, analyze it as a third party and determine whether the disclosure is a sale or sharing that requires notice, opt-out handling, and third-party terms.
A service provider processes personal information on behalf of a business under a written contract. A is a person to whom the business makes personal information available for a business purpose under a qualifying written contract and certification. Both roles are subject to purpose, use, disclosure, sale, sharing, combination, and direct-business-relationship restrictions.
A person without a contract that complies with regulation section 7051 is not a service provider or for that processing. The same is true when the recipient provides cross-context behavioral advertising services to the business. Contextual advertising based on the page's subject or aggregated demographics can fit a service relationship when the other tests are met; using the business's customer list to identify those people on another platform for cross-context behavioral advertising cannot. If a recipient uses personal information outside the contract, the business and recipient must analyze the consequences under the sale, sharing, and third-party rules.
Subcontracting does not remove the restrictions. A service provider or must bind a subcontractor to a CCPA-compliant agreement and follow the business's contract requirements for engaging it. The original recipient remains responsible for using the data only within permitted purposes.
The business owner describes the service and actual uses; privacy or legal classifies the recipient; procurement secures the terms before disclosure; and data, product, and security teams enforce instructions and monitoring. No single contract label should replace that cross-functional decision.
Keep a role memorandum or intake record, executed agreement, data-flow diagram, purpose and category schedule, subcontractor list, opt-out and consumer-request instructions, assessment results, incidents, remediation, and deletion or return evidence. Review the role when the service, purpose, data, advertising activity, or recipient's own use changes.
A recipient can have different roles for different processing. Classify each data flow and purpose instead of assigning one permanent label to the company. A compliant service-provider relationship for hosting does not automatically cover the recipient's advertising or product-development uses.
Internal use to improve the quality of services is limited by the regulations and does not permit building or modifying household or consumer profiles for another business or cleaning or augmenting data acquired from another source. For example, an email provider may analyze interactions to improve its email service but may not reuse the original customer list to send another business's marketing; a shipping provider may use delivery experience to identify faulty addresses but may not compile client addresses for advertising or sale to data brokers. Security and fraud-prevention uses also remain subject to the stated purpose and legal limits.
Disclosures directed by the consumer or intentional consumer interactions with a third party may fall outside sale or sharing definitions when statutory conditions are met. Record the consumer action and the recipient identity rather than assuming every integration qualifies.
Use a recipient register with one row per purpose and data flow. Record the California role, sale or sharing result, contract section, consumer-choice dependency, systems, subcontractors, retention, request route, assurance evidence, and review trigger.
When the recipient cannot comply, stop the affected disclosure or use, investigate the scope, preserve evidence, remediate the data and contract position, and reassess notices and consumer instructions. The CCPA contract right to remediate must be usable in practice.
This US CPRA guide turns Contracts Contractors and Service Providers into owners, evidence requests, review checkpoints, and reusable operating records in Sorena.
Turn Contracts Contractors and Service Providers into scoped questions, evidence fields, and review tasks.
Use Research Copilot to answer follow-up questions with cited source material.
Review scope, evidence, owners, and the next compliance actions with Sorena.
"Contract Requirements for Third Parties"
"take reasonable and appropriate steps to stop and remediate unauthorized use"
"A person who processes personal information on behalf of a business"
"shall have a contract with the subcontractor that complies with the CCPA"
"Organizations should not assume implementation of these Privacy Framework activities or outcomes means that they have met the"