skip to content

Under the CCPA, what makes an advertising or analytics vendor a service provider rather than a third party, and why can't cross-context advertising qualify?

level: seniorimportance: must knowfreq 46%

answer

  1. not a third party by definition
  2. a written contract with prohibitions
  3. specific business purposes
  4. no cross-context advertising
  5. no compliant contract, no carve-out

basics

~20 s

Under Civil Code 1798.140(ag), a service provider processes personal information for a business purpose under a written contract barring sale, sharing and other uses; 11 CCR 7050(b) makes a vendor providing cross-context behavioural advertising a third party.

solid answer

~50 s

'Third party' in Civil Code `1798.140(ai)` excludes service providers and contractors, so a disclosure to one is neither a sale nor sharing. A **service provider** (`1798.140(ag)`) processes personal information on the business's behalf for a **business purpose** under a **written contract** that prohibits selling or sharing it, using it outside the specified purposes or the direct relationship, and combining it with other data except as permitted. The CCPA regulations (11 CCR 7051(a)) spell out the contract, including purposes described specifically rather than by reference to the whole agreement. Two limits decide advertising cases. Business purposes include advertising and marketing **except cross-context behavioural advertising** (`1798.140(e)(6)`), and 7050(b) says a vendor providing it is a **third party** for that service. And under 7050(e), a vendor without a compliant contract is not a service provider at all, so disclosing to it may be a sale or sharing.

go deeper

for a junior

Recall that service providers and contractors are not third parties, so disclosures to them under a proper contract are not sales or sharing.

for a middle

Explain the contract prohibitions in 1798.140(ag), the specific-purpose requirement in 11 CCR 7051, and why a missing contract turns a vendor into a third party.

for a senior

Classify a tag and vendor inventory: which flows fit a service-provider contract, which are cross-context advertising and therefore third-party, and what diligence supports each.

for a principal

Decide which advertising capabilities to keep inside service-provider arrangements and which to accept as third-party sharing behind the opt-out.

## Why the label matters Under the CCPA as amended by the CPRA, both 'sale' and 'sharing' require a disclosure to a **third party**. Civil Code `1798.140(ai)` defines a third party as anyone who is **not** the business the consumer intentionally interacts with, a **service provider** or a **contractor**. So a vendor that qualifies as a service provider sits outside both definitions, and the business owes no opt-out for that flow. 11 CCR 7026(f)(1) confirms that collection by a service provider or contractor under a compliant contract is not a sale or sharing. ## The statutory definition `1798.140(ag)(1)`: a service provider is a person that **processes personal information on behalf of a business** and receives it **for a business purpose** under a **written contract** that prohibits it from: 1. **Selling or sharing** the personal information; 2. Retaining, using or disclosing it for any purpose **other than the business purposes specified** in the contract, including any other commercial purpose; 3. Retaining, using or disclosing it **outside the direct business relationship** with the business; 4. **Combining** it with personal information from other sources or its own interactions, except for business purposes the regulations permit. The contract may let the business monitor compliance, including assessments or audits at least once every 12 months. Sub-processors must be notified to the business and bound by the same terms (`1798.140(ag)(2)`). A **contractor** (`1798.140(j)`) has near-identical conditions and must also **certify** that it understands and will comply with them. ## The contract the regulations require 11 CCR 7051(a) lists the terms. Among them: - prohibit selling or sharing; - identify the **specific** business purposes; a generic reference to 'the services under this agreement' is not enough; - prohibit use for other purposes, other commercial purposes, or outside the direct relationship, including combining the data with other sources; - require compliance with the CCPA and the same level of privacy protection; - grant the business rights to ensure proper use and to stop and remediate unauthorised use; - require the vendor to notify the business if it can no longer meet its obligations, and to help it comply with consumer requests. Under 7050(e), a person **without** a contract that complies with 7051(a) **is not a service provider or contractor**, and a disclosure to it may be a sale or sharing that needs the opt-out. ## Where advertising falls | Vendor activity for the business | Service provider possible? | Source | |---|---|---| | Measuring the site's own audience, for the site only | Yes, with a compliant contract | `1798.140(e)(5)` | | Contextual ads, such as ads on recipe pages for cookware | Yes | 7050(b) example | | Nonpersonalised ads from aggregated or demographic segments | Yes | 7050(b) example | | Matching the business's customer emails to target those users on the vendor's platform | No: cross-context behavioural advertising | 7050(b) example | | Retargeting the site's visitors across other sites and apps | No: third party for that service | 7050(b), `1798.140(e)(6)` | `1798.140(e)(6)` makes 'advertising and marketing services, except for cross-context behavioural advertising' a business purpose, and bars service providers from combining opted-out consumers' data with other data for advertising. 11 CCR 7050(b) closes the loop: **a person who contracts to provide cross-context behavioural advertising is a third party**, not a service provider, with respect to that service. ## What a service provider may still do 11 CCR 7050(a) lets a service provider use the data for the contracted purposes, for sub-processors that meet the same requirements, to **build or improve the quality of its own services** as long as it does not use the data to perform services for another person, and to detect security incidents and fraud. The regulation's examples draw the line: an email vendor may learn from engagement to improve its product for everyone, but may not use one client's list to send another client's emails. ## Due diligence 11 CCR 7051(c) makes enforcement part of the defence. A business that never exercises its audit rights or enforces the contract may be unable to claim it had no reason to believe the vendor was misusing the data. ## Interview answer in one line A vendor is a service provider when a compliant written contract confines it to specified business purposes, and it stays one only while it keeps to them; cross-context behavioural advertising can never be one of those purposes.

  • An analytics vendor's contract says it may use client data 'as described in the agreement'. Is that enough?
    No. 11 CCR 7051(a)(2) requires the contract to identify the specific business purposes and says they shall not be described in generic terms, such as by referencing the entire contract generally. Without a compliant contract, 7050(e) says the vendor is not a service provider, so disclosures to it may be sales or sharing.
  • Can the business rely on the contract alone if the vendor misuses the data?
    Only if it had no actual knowledge or reason to believe the vendor intended a violation, under Civil Code 1798.145(i). 11 CCR 7051(c) adds that a business that never enforces the contract or uses its audit rights may be unable to claim it had no reason to believe.

saying these in an interview costs you the question

  • Calls any vendor with a signed contract a service provider
  • Believes a vendor can be a service provider for cross-context behavioural advertising
  • Thinks a generic 'as described in the agreement' purpose clause suffices
  • Assumes a disclosure to a vendor without a compliant contract is harmless
  • Believes a service provider may reuse one client's data to serve another