Artifact GuideUSContract Terms

US CPRA Contract Terms

Classify each recipient as a service provider, contractor, or third party, then use the contract terms required for that role before making personal information available.

Apply the cited California statute and regulations to the actual entity, data flow, system, and recipient role; escalate unresolved legal interpretation.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

This page explains when California privacy law requires recipient contract terms, how the terms differ for service providers, contractors, and third parties, and what procurement, privacy, legal, security, and product teams should verify.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

What should teams do about Contract Terms under the US CPRA?

Classify the recipient from the actual data flow, not its job title or the agreement's label. A processes personal information for a business under a written contract; a receives information for a business purpose and makes the required certification; a is a recipient that does not qualify for an applicable exclusion. If the arrangement does not meet the service-provider or contractor requirements, a disclosure may be a sale or sharing unless another statutory exception applies.

A service-provider or contract must identify specific business purposes, prohibit sale or sharing, restrict retention, use, and disclosure outside those purposes and the direct business relationship, restrict combining data except as allowed, require compliance with the CCPA, allow monitoring, require notice if the recipient can no longer comply, and let the business stop and remediate unauthorized use. It must also require assistance with consumer requests and, where applicable, cybersecurity audits and risk assessments.

A third-party contract for sold or shared information must identify limited and specified purposes, require the to comply with the CCPA and provide the same level of privacy protection, allow reasonable steps to verify compliant use, require notice if the third party can no longer comply, and give the business the right to stop and remediate unauthorized use. A third party without a section 7053-compliant contract may not collect, use, process, retain, sell, or share the personal information the business made available.

Execute the correct contract before making personal information available. If a or uses a subcontractor for the business purpose, the subcontract must bind that recipient to the same CCPA requirements. Due diligence and enforcement matter after signature: the regulations say that never enforcing the contract or exercising audit and test rights can affect whether the business may claim it lacked reason to believe the recipient intended a violating use.

  • Map the recipient role, data categories, transfer purpose, sale or sharing analysis, and permitted uses before selecting a template.
  • Write specific purposes; generic descriptions such as "business operations" do not establish the required limits.
  • Name the contract owner, recipient control owner, consumer-request contact, notice route for inability to comply, and stop-and-remediate procedure.
  • Reassess the role and amend the agreement before the data, purpose, subcontracting, or recipient behavior changes.
Citations
California Civil Code section 1798.140

Statutory CPRA definitions source for service-provider, contractor, and third-party contract restrictions on retaining, using, or disclosing personal information.

Question 2

What evidence should teams keep for Contract Terms under the US CPRA?

Keep the executed agreement and effective date, role analysis, data-flow record, data categories, specific purposes, sale or sharing analysis, subcontractor notices and terms, consumer-right assistance procedure, compliance notices, monitoring or audit evidence, remediation records, and approval trail. Link each contract obligation to the system and team that can carry it out.

For monitoring, retain the review scope, evidence requested, finding, recipient response, remediation owner, due date, retest, and closure decision. When the recipient says it can no longer comply, record when notice arrived, which data and systems are affected, whether transfers stopped, what data was returned or deleted, and how remediation was verified.

  • Source URL and quote used for the decision.
  • Scope notes, data-flow and system references, role mapping, contract version, effective date, and approved purposes.
  • Subcontractor chain, request-assistance test, monitoring record, exception notes, remediation evidence, and next review date.
Citations
California Civil Code section 1798.140

Statutory CPRA definitions source for service-provider, contractor, and third-party contract restrictions on retaining, using, or disclosing personal information.

Question 3

Which mistakes create risk when handling Contract Terms under the US CPRA?

Common failures include relying on the word "processor" without meeting California's role tests, describing purposes generically, omitting the right to stop and remediate unauthorized use, allowing combination of data beyond the regulatory conditions, failing to flow terms to subcontractors, or leaving consumer-request assistance and compliance monitoring undefined.

  • Using a service-provider template for a recipient whose actual use makes it a .
  • Listing a broad purpose that does not limit how the recipient may use, retain, or disclose the data.
  • Signing required terms without monitoring compliance or acting when the recipient reports it can no longer comply.
Citations
California Civil Code section 1798.140

Statutory CPRA definitions source for service-provider, contractor, and third-party contract restrictions on retaining, using, or disclosing personal information.

Primary sources

References and citations

leginfo.legislature.ca.gov
Referenced sections
  • Statutory CPRA source for requiring businesses that sell, share, or disclose personal information to bind recipients by contract.
"A business that sells or shares a consumer’s personal information"
leginfo.legislature.ca.gov
Referenced sections
  • Statutory CPRA definitions source for service-provider, contractor, and third-party contract restrictions on retaining, using, or disclosing personal information.
"prohibits the person from retaining, using, or disclosing the personal information"
cppa.ca.gov
Referenced sections
  • CPPA FAQ confirms that the CPRA amended the CCPA and added consumer privacy rights and business obligations.
"additional consumer privacy rights and obligations for businesses"
Related guides

Explore more topics

California CCPA and CPRA Applicability Test
Decide whether the CCPA as amended by the CPRA applies, using California nexus, current business thresholds, related-entity rules, and data-specific exemptions.
California CCPA and CPRA Compliance Checklist
A California CCPA/CPRA implementation checklist covering scope, notices, rights, opt-outs, vendor contracts, retention, security, and 2026 regulations.
California CCPA/CPRA Deadlines and Compliance Calendar
Track California CCPA and CPRA request clocks, phased 2026 regulation deadlines, recurring metrics, and separate Delete Act dates.
California CCPA/CPRA Penalties, Fines, and Private Damages
Understand current California CCPA and CPRA fine caps, who enforces them, the limited private action for security breaches, and the evidence to preserve.
California CPRA FAQ
Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
California CPRA Requirements Guide
California CCPA/CPRA requirements for covered businesses: notices, rights, opt-outs, data-use limits, contracts, security, and phased 2026 rules.
California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide
Apply the separate California trigger tests, duties, phase-in dates, evidence, and consumer rights for risk assessments, cybersecurity audits, and ADMT.
California Data Broker Deletion Workflow Guide
California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
California Data Broker Registry and DROP Guide
California Delete Act guide to data-broker scope, annual registration, DROP processing from August 1, 2026, deletion, opt-out fallback, metrics, and audits.
California Delete Act data broker registry and DROP guide
California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
CCPA vs CPRA: What Changed in California Privacy Law
Compare the original CCPA with the CPRA amendments, including scope thresholds, new rights, contracts, retention, enforcement, and implementation steps.
CPPA Regulations Tracker | CCPA and CPRA
Track the in-force 2023 and 2026 CCPA regulations, their legal status, affected processing, and phased risk, audit, and ADMT deadlines.
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ
US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
CPRA vs Colorado Privacy Act: Practical Comparison
Compare California and Colorado privacy law on scope, consumer rights, opt-outs, sensitive data, contracts, assessments, and enforcement.
CPRA vs Virginia VCDPA: Practical Comparison
Compare California and Virginia privacy law on scope, rights, sale, advertising, sensitive data, contracts, assessments, and enforcement.
US CPRA Compliance Guide
Build a CCPA/CPRA compliance program for scope, notices, consumer rights, opt-outs, vendor contracts, retention, security, and phased 2026 duties.
US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
US CPRA Contract Terms Guide
Required CCPA/CPRA contract terms for service providers, contractors, and third parties, with role tests, clause checks, and evidence.
US CPRA Contracts Contractors and Service Providers Guide
Classify CCPA recipients as service providers, contractors, or third parties and apply the correct purpose limits, contracts, and consumer instructions.
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
US CPRA Cyber Audit Readiness Workflow Guide
US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
US CPRA Risk Assessment Intake Workflow Guide
Screen the six CPPA risk-assessment triggers, record exceptions and evidence, hold covered launches for approval, and track review and submission dates.
US CPRA Risk Assessment Template Guide
US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
US CPRA Risk Assessments and Cybersecurity Audits Guide
Apply the separate CPPA trigger tests for processing-level risk assessments and entity-level annual cybersecurity audits, with phase-in dates and evidence.
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.
What counts as sharing under the California CPRA?
How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.
What should teams do about ADMT under the US CPRA?
Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.
What should teams do about Correction Rights under the US CPRA?
Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.
What should teams do about Cybersecurity Audits under the US CPRA?
US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about retention under the California CPRA?
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
What should teams do about Sensitive Personal Information Limits under the US CPRA?
US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
When is a CPRA risk assessment required?
When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.