Artifact GuideUSContracts Contractors and Service Providers

US CPRA Contracts Contractors and Service Providers

Use this guide to resolve Contracts Contractors and Service Providers under the CCPA as amended by the CPRA, including the trigger, required action, deadline, owner, and evidence.

Apply the cited California statute and regulations to the actual entity, data flow, system, and recipient role; escalate unresolved legal interpretation.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

A recipient is a service provider or only when both the relationship and the written agreement satisfy the CCPA rules. Classify the actual processing before disclosure. If the recipient does not qualify, analyze it as a third party and determine whether the disclosure is a sale or sharing that requires notice, opt-out handling, and third-party terms.

Section 1

What should teams decide about Contracts Contractors and Service Providers under the US CPRA?

A service provider processes personal information on behalf of a business under a written contract. A is a person to whom the business makes personal information available for a business purpose under a qualifying written contract and certification. Both roles are subject to purpose, use, disclosure, sale, sharing, combination, and direct-business-relationship restrictions.

A person without a contract that complies with regulation section 7051 is not a service provider or for that processing. The same is true when the recipient provides cross-context behavioral advertising services to the business. Contextual advertising based on the page's subject or aggregated demographics can fit a service relationship when the other tests are met; using the business's customer list to identify those people on another platform for cross-context behavioral advertising cannot. If a recipient uses personal information outside the contract, the business and recipient must analyze the consequences under the sale, sharing, and third-party rules.

Subcontracting does not remove the restrictions. A service provider or must bind a subcontractor to a CCPA-compliant agreement and follow the business's contract requirements for engaging it. The original recipient remains responsible for using the data only within permitted purposes.

  • Service provider: record the business, service, specific business purpose, data categories, permitted internal uses, and prohibited uses.
  • : record the business-purpose disclosure, written certification, purpose and use limits, and the same operational controls required for the relationship.
  • Third party: record the limited and specified purpose, sale or sharing status, consumer-choice instructions, same-level-protection terms, and remediation rights.
  • Subcontractor: record authorization or notice, data and purpose, executed downstream terms, request handling, deletion, and monitoring evidence.
Section 2

How should teams make and prove the role decision?

The business owner describes the service and actual uses; privacy or legal classifies the recipient; procurement secures the terms before disclosure; and data, product, and security teams enforce instructions and monitoring. No single contract label should replace that cross-functional decision.

Keep a role memorandum or intake record, executed agreement, data-flow diagram, purpose and category schedule, subcontractor list, opt-out and consumer-request instructions, assessment results, incidents, remediation, and deletion or return evidence. Review the role when the service, purpose, data, advertising activity, or recipient's own use changes.

  • Ask who determines the purposes and means of the recipient's processing and whether the recipient uses the information for its own commercial purposes.
  • Compare every actual use with the specific business purpose in the signed agreement.
  • Check whether the recipient combines the information with data from other businesses or its own consumer interactions and whether a regulatory exception applies.
  • Document how deletion, correction, opt-out, access, security, and subcontractor instructions reach the systems that hold the information.
Section 3

What edge cases should teams check before relying on the decision?

A recipient can have different roles for different processing. Classify each data flow and purpose instead of assigning one permanent label to the company. A compliant service-provider relationship for hosting does not automatically cover the recipient's advertising or product-development uses.

Internal use to improve the quality of services is limited by the regulations and does not permit building or modifying household or consumer profiles for another business or cleaning or augmenting data acquired from another source. For example, an email provider may analyze interactions to improve its email service but may not reuse the original customer list to send another business's marketing; a shipping provider may use delivery experience to identify faulty addresses but may not compile client addresses for advertising or sale to data brokers. Security and fraud-prevention uses also remain subject to the stated purpose and legal limits.

Disclosures directed by the consumer or intentional consumer interactions with a third party may fall outside sale or sharing definitions when statutory conditions are met. Record the consumer action and the recipient identity rather than assuming every integration qualifies.

  • Check whether the rule changes because the recipient is a service provider, , third party, subcontractor, advertising partner, or a business using personal information outside the written contract.
  • Separate binding law, regulator guidance, consultation material, standards, and enforcement commentary in the evidence record.
  • Do not rely on a previous answer if the data categories, user interface, vendor role, or contractual flow changed.
  • Track unresolved assumptions in an open-questions section and route legal interpretation points for review.
Section 4

How should teams operationalize the decision with proportionate controls?

Use a recipient register with one row per purpose and data flow. Record the California role, sale or sharing result, contract section, consumer-choice dependency, systems, subcontractors, retention, request route, assurance evidence, and review trigger.

When the recipient cannot comply, stop the affected disclosure or use, investigate the scope, preserve evidence, remediate the data and contract position, and reassess notices and consumer instructions. The CCPA contract right to remediate must be usable in practice.

  • Before disclosure: complete the role, sale-or-sharing, notice, consumer-choice, and contract reviews.
  • At onboarding: configure data access, permitted purposes, retention, request instructions, subcontractors, and monitoring.
  • During service: compare actual use with the contract and investigate deviations or inability-to-comply notices.
  • At termination: revoke access and retain verified return, deletion, or documented lawful-retention evidence.
Primary sources

References and citations

leginfo.legislature.ca.gov
Referenced sections
  • Operational source for mapping service-provider and contractor contracts to statutory purposes, monitoring rights, notice, and remediation.
"take reasonable and appropriate steps to stop and remediate unauthorized use"
leginfo.legislature.ca.gov
Referenced sections
  • Supports CPRA contractor and service-provider role analysis by defining permitted processing and use restrictions.
"A person who processes personal information on behalf of a business"
cppa.ca.gov
Referenced sections
  • Operational source for service-provider and contractor contract clauses, subcontractor requirements, and audit evidence.
"shall have a contract with the subcontractor that complies with the CCPA"
nist.gov
Referenced sections
  • NIST privacy framework crosswalk background for operational privacy governance evidence; CPRA sources control the contract requirements.
"Organizations should not assume implementation of these Privacy Framework activities or outcomes means that they have met the"
Related guides

Explore more topics

California CCPA and CPRA Applicability Test
Decide whether the CCPA as amended by the CPRA applies, using California nexus, current business thresholds, related-entity rules, and data-specific exemptions.
California CCPA and CPRA Compliance Checklist
A California CCPA/CPRA implementation checklist covering scope, notices, rights, opt-outs, vendor contracts, retention, security, and 2026 regulations.
California CCPA/CPRA Deadlines and Compliance Calendar
Track California CCPA and CPRA request clocks, phased 2026 regulation deadlines, recurring metrics, and separate Delete Act dates.
California CCPA/CPRA Penalties, Fines, and Private Damages
Understand current California CCPA and CPRA fine caps, who enforces them, the limited private action for security breaches, and the evidence to preserve.
California CPRA FAQ
Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
California CPRA Requirements Guide
California CCPA/CPRA requirements for covered businesses: notices, rights, opt-outs, data-use limits, contracts, security, and phased 2026 rules.
California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide
Apply the separate California trigger tests, duties, phase-in dates, evidence, and consumer rights for risk assessments, cybersecurity audits, and ADMT.
California Data Broker Deletion Workflow Guide
California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
California Data Broker Registry and DROP Guide
California Delete Act guide to data-broker scope, annual registration, DROP processing from August 1, 2026, deletion, opt-out fallback, metrics, and audits.
California Delete Act data broker registry and DROP guide
California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
CCPA vs CPRA: What Changed in California Privacy Law
Compare the original CCPA with the CPRA amendments, including scope thresholds, new rights, contracts, retention, enforcement, and implementation steps.
CPPA Regulations Tracker | CCPA and CPRA
Track the in-force 2023 and 2026 CCPA regulations, their legal status, affected processing, and phased risk, audit, and ADMT deadlines.
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ
US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
CPRA vs Colorado Privacy Act: Practical Comparison
Compare California and Colorado privacy law on scope, consumer rights, opt-outs, sensitive data, contracts, assessments, and enforcement.
CPRA vs Virginia VCDPA: Practical Comparison
Compare California and Virginia privacy law on scope, rights, sale, advertising, sensitive data, contracts, assessments, and enforcement.
US CPRA Compliance Guide
Build a CCPA/CPRA compliance program for scope, notices, consumer rights, opt-outs, vendor contracts, retention, security, and phased 2026 duties.
US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
US CPRA Contract Terms Guide
Required CCPA/CPRA contract terms for service providers, contractors, and third parties, with role tests, clause checks, and evidence.
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
US CPRA Cyber Audit Readiness Workflow Guide
US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
US CPRA Risk Assessment Intake Workflow Guide
Screen the six CPPA risk-assessment triggers, record exceptions and evidence, hold covered launches for approval, and track review and submission dates.
US CPRA Risk Assessment Template Guide
US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
US CPRA Risk Assessments and Cybersecurity Audits Guide
Apply the separate CPPA trigger tests for processing-level risk assessments and entity-level annual cybersecurity audits, with phase-in dates and evidence.
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.
What counts as sharing under the California CPRA?
How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.
What should teams do about ADMT under the US CPRA?
Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.
What should teams do about Contract Terms under the US CPRA?
Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.
What should teams do about Correction Rights under the US CPRA?
Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.
What should teams do about Cybersecurity Audits under the US CPRA?
US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about retention under the California CPRA?
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
What should teams do about Sensitive Personal Information Limits under the US CPRA?
US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
When is a CPRA risk assessment required?
When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.