US State Law California, USA

CCPA Service Provider Agreements: Required Contract Terms

The contract clauses that keep a vendor a service provider instead of a third party under the CCPA: mandatory terms, contractor vs. third party, and audit duties.

Regulation

Cal. Civ. Code 1798.100(d), 1798.140(ag)-(ai); CCPA Regulations 7050-7053

Max Penalty

$2,500 per violation; $7,500 per intentional violation (an unpapered disclosure can be charged as an unauthorized sale)

Enforcing Authority

California Privacy Protection Agency (CPPA) and California Attorney General

Official Source

cppa.ca.gov

Executive Summary

  • Under the CCPA, every disclosure of personal information to another entity is a sale or share unless a compliant contract makes the recipient a service provider or contractor.
  • Required terms (Regulations 7051): purpose limitation to specified services, prohibitions on selling/sharing and on combining data across customers, CCPA-compliance commitments, notification of inability to comply, and the business's right to monitor and remediate.
  • Service providers and contractors differ mainly in paperwork: contractors additionally certify their restrictions and permit business oversight; both are distinct from third parties, to whom disclosures are sales/shares requiring opt-out rights.
  • Ad-tech vendors generally cannot qualify as service providers for cross-context behavioral advertising; that processing is 'sharing' no matter what the contract says.
  • The DoorDash action shows the failure mode: disclosing customer data to a marketing co-op without qualifying contracts was an unauthorized sale, and downstream resale multiplied the harm.

The CCPA’s vendor rule is binary and unforgiving: a recipient of personal information is either papered as a service provider or contractor, or every byte you send them is a sale. DoorDash learned the corollary in 2024, joining a marketing cooperative without qualifying contracts made the disclosures unauthorized sales, and the data was resold downstream where no contract could reach it. Vendor contracting is therefore not procurement hygiene; it is the difference between processing and selling.

ProvisionsCiv. Code 1798.100(d), 1798.140(ag)-(ai); Regs 7050-7053
RuleNo compliant contract = disclosure is a sale/share
RegulatorCPPA
Regulations textCCPA Regulations (CPPA)

Building the contract program

Inventory recipients, not contracts. Start from network reality: every domain your sites and apps transmit personal information to, every SFTP feed, every reverse-ETL sync. Then match each recipient to paper. Orphan flows, tags added by marketing, SDKs bundled by developers, are the normal finding, and each is an unpapered disclosure.

Use a three-bucket taxonomy. (1) Service providers/contractors with full 7051 terms; (2) third parties you knowingly sell/share to, wired into your opt-out propagation; (3) prohibited recipients to remove. Ad-tech mostly lands in bucket 2 regardless of contract labels.

Handle the GDPR overlap once. The 7051 terms map closely onto GDPR Article 28 processor clauses (purpose limitation, confidentiality, sub-processing controls, deletion, audit). A combined DPA with a California annex, no-sale/no-share covenants, combination prohibition, CCPA definitions, satisfies both and avoids clause drift across regimes.

Write the operational clauses tightly. Deletion turnaround (days, not “promptly”), opt-out propagation mechanics, breach notice windows aligned to your own obligations, audit rights you will actually exercise, and termination-plus-deletion on non-compliance. The DSAR intake guide covers the request-cascade plumbing these clauses feed.

Verify annually. Attestations, SOC 2 review where relevant, and a technical crawl of your properties to catch new endpoints. Diligence is what converts your contract into a defense under Regulation 7051(c).

The other states’ processor rules (Virginia-lineage DPA requirements) are similar enough that one national template works; differences are covered in the multi-state strategy guide. To find the unpapered flows first, run a free scan and diff the third-party endpoints against your vendor list.

Frequently Asked Questions

What clauses must the contract contain?

Per Regulation 7051: identify the specific business purposes and services; prohibit selling or sharing the data; prohibit retention, use, or disclosure outside the contract or the CCPA's permitted purposes; prohibit combining the data with data from other sources (with narrow exceptions); require CCPA compliance and same-level protection; require notification if the provider can no longer comply; and grant the business rights to take reasonable steps to stop unauthorized use. Missing terms mean the recipient is a third party by definition.

What's the difference between a service provider, contractor, and third party?

Service providers process on the business's behalf under a 1798.140(ag) contract. Contractors (1798.140(ai)) receive data for a business purpose under similar terms plus a written certification of their restrictions. Everyone else is a third party (1798.140(ai)), and giving them personal information is a sale or share triggering opt-out obligations. The classification is functional: a perfect contract cannot save a vendor that in practice uses your data for its own purposes.

Can our ad-tech vendors be service providers?

Only for limited functions (measurement on your own data, non-personalized ad serving). Providing personal information for cross-context behavioral advertising is 'sharing' by statutory definition and cannot be contracted around, the CPPA has said explicitly that a business cannot avoid opt-out obligations by labeling ad-tech partners service providers. Map each ad vendor's actual data use; most DSPs, data co-ops, and audience platforms are third parties.

What diligence and monitoring does the CCPA expect?

Regulation 7051(c) makes reliance on a contract reasonable only if the business conducts appropriate diligence: audits, questionnaires, or technical verification proportional to risk. If you never verify, you may not be able to claim the good-faith defense when a provider misuses data. Annual attestations plus scanning your own properties for unexpected vendor endpoints is the pragmatic floor.

What happens when a deletion or opt-out request arrives?

Deletion requests cascade: the business must direct service providers and contractors to delete, and they must comply and flow the instruction to their subprocessors. Opt-outs of sale/sharing must be forwarded to third parties to whom data was sold or shared. Contracts should hard-wire these turnaround times (the statute's 15-business-day opt-out window leaves little slack for manual processes).

Regulatory Crosswalk

CCPAGDPR Art. 28State processor contracts

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.