skip to content

Under the CCPA, what must a business's written contract with a service provider contain, and what follows if the contract falls short?

level: middleimportance: should knowfreq 33%

answer

  1. the contract makes the role
  2. specific purpose, not 'the agreement'
  3. no selling, sharing or combining
  4. audit, notify, stop and remediate
  5. 11 CCR 7051(a), ten terms

basics

~20 s

Under the CCPA, the contract must confine the service provider to specific business purposes, bar selling, sharing and outside use, bind it to the CCPA, and grant audit and remediation rights (11 CCR 7051); without it, the vendor is not a service provider.

solid answer

~50 s

Civil Code 1798.140(ag) defines a service provider by its **written contract**, and 1798.100(d) and 11 CCR 7051(a) list the terms. The contract must **prohibit selling or sharing** the data; name the **specific business purposes**, not "the services under the agreement"; forbid retaining, using or disclosing it for any other purpose or **outside the direct relationship**, including combining it with other sources except as the law permits; bind the vendor to the CCPA with the **same level of privacy protection**; give the business the right to **check compliance** and to **stop and remediate** unauthorised use; require the vendor to **notify** the business if it can no longer comply; and make it help with **consumer requests**. Subcontractors need matching contracts (7051(b)). Under 7050(e), a vendor without a compliant contract is **not a service provider**, and handing it data may be a sale or sharing.

go deeper

for a junior

Recall that the CCPA makes service-provider status depend on a written contract with specific prohibitions and business purposes.

for a middle

Explain the main 7051(a) terms: specific purposes, no selling or sharing, no use outside the relationship, audit rights and request assistance.

for a senior

Show how you would spot a data flow to a vendor with no compliant contract and what that does to the flow's legal character.

for a principal

Decide how vendor contracts, the data inventory and data-sharing reviews stay in step as the vendor estate grows.

## Why the contract matters Under the CCPA as amended by the CPRA, a **service provider** is not a label a vendor chooses; it is a status the **contract** creates. Civil Code **1798.140(ag)(1)** defines it as a person that processes personal information on behalf of a business and receives it for a business purpose *pursuant to a written contract* that prohibits specified uses. Civil Code **1798.100(d)** separately requires a business that discloses personal information to a service provider or contractor for a business purpose to enter into an agreement with certain terms. The CPPA regulations at 11 CCR **7051** turn both into a checklist. ## The required terms 11 CCR 7051(a) requires the contract to: 1. **Prohibit selling or sharing** the personal information collected under the contract. 2. **Identify the specific business purposes** and state that the business discloses the data only for those limited and specified purposes. Generic wording, such as a reference to the whole contract, is not enough. 3. Prohibit retaining, using or disclosing the data **for any purpose other than** those business purposes, except as the CCPA and regulations permit. 4. Prohibit doing so for any **commercial purpose** other than those business purposes, unless expressly permitted. 5. Prohibit doing so **outside the direct business relationship**, including **combining** it with personal information from other sources or its own consumer interactions, unless expressly permitted. 6. Require compliance with the CCPA and the **same level of privacy protection** the law requires of businesses. 7. Grant the business the right to take **reasonable and appropriate steps** to ensure compliant use, such as manual reviews, automated scans, and assessments, audits or testing at least once every 12 months. 8. Require the vendor to **notify the business** if it determines it can no longer meet its obligations. 9. Grant the business the right, on notice, to **stop and remediate** unauthorised use. 10. Require the vendor to **enable the business to comply with consumer requests**, or require the business to pass requests on with the information needed. ## What the vendor may still do The prohibitions have regulated exceptions. Under 11 CCR **7050(a)** a service provider may also use the data to engage a compliant subcontractor, for **internal use to build or improve the quality of its services** to that business (so long as it does not use the data to perform services for another person), to detect and prevent security incidents and fraud, and for the purposes in Civil Code 1798.145(a)(1)-(7). The regulation's example: an email service may learn from engagement data to improve its service for everyone, but may not use one client's email list to send another client's marketing. ## Subcontractors A service provider that engages another person to help process the data must **notify the business** and bind that person by a written contract meeting the same requirements (1798.140(ag)(2); 7051(b)). The chain is only as good as its weakest contract. ## Due diligence after signing Signing is not the end of the duty. 11 CCR **7051(c)** says whether the business conducts **due diligence** factors into whether it had reason to believe the vendor was misusing data. A business that never enforces the contract or uses its audit rights **might not be able to rely** on the defence that it had no reason to believe the vendor would violate the law. | Contract state | Result under the CCPA | |---|---| | All 7051(a) terms present and enforced | vendor is a service provider; disclosure is for a business purpose | | Terms present, never checked | status stands, but the business's defence weakens (7051(c)) | | Required terms missing | vendor is **not** a service provider (7050(e)) | ## When the contract falls short 11 CCR **7050(e)**: a person without a contract that complies with 7051(a) **is not a service provider or a contractor**. The regulation's example spells out the consequence: disclosing personal information to that person **may be considered a sale or sharing**, which carries the consumer's right to opt out. How the opt-out then works is a separate subject; the point here is that a missing clause changes the legal character of an ordinary data flow. ## Engineering consequences - The data inventory should record, per recipient, whether a compliant contract exists and which business purposes it names. - Data sent to a vendor should match the named purposes; a support-ticket vendor has no need for full purchase history. - Deletion and correction must propagate, because the contract must let the business meet consumer requests (7051(a)(10); Civil Code 1798.130(a)(3)(A)). - A new use by the vendor, such as a new product line, is a contract change, not a configuration toggle.

  • Under the CCPA regulations, an email-delivery vendor wants to use your customer list to improve its product for all clients. Can the contract allow it?
    Partly. 11 CCR 7050(a)(3) lets a service provider use the data internally to **build or improve the quality of its services**, even if the contract does not list that purpose, but it may **not** use the data to perform services for another person. Analysing engagement to improve delivery is allowed; mailing your list for another client is not.
  • Under the CCPA regulations, must a business audit its service providers?
    The contract must **grant** the right to take reasonable and appropriate steps, with assessments at least every 12 months as an example (7051(a)(7)). Using the right is not spelled out as mandatory, but 7051(c) warns that a business that never enforces or audits may lose the defence that it had no reason to suspect misuse.

saying these in an interview costs you the question

  • Describing the purpose as 'services under the master agreement' is specific enough.
  • A service provider may freely combine client data across its customers.
  • Subcontractors are covered automatically by the prime vendor's contract.
  • Once signed, the business has no reason ever to check the vendor.
  • A vendor is a service provider whenever it follows instructions, contract or not.