CCPA Service Provider: Definition, Contracts, and Restrictions

A CCPA service provider is a person or entity that processes personal information on behalf of a California business under a written contract that restricts how the data can be used. The classification matters for one reason above all others: data disclosed to a qualifying service provider is not a “sale” or a “share” under California privacy law, so the transfer does not trigger a consumer’s right to opt out. Whether a vendor actually qualifies depends almost entirely on the contract. Miss a required clause, and the same vendor becomes a third party by default, turning routine data transfers into sales that need consumer opt-outs.

Who Qualifies

Under the California Consumer Privacy Act as amended by the California Privacy Rights Act, a service provider is any person that processes personal information on behalf of a business and receives that information for a business purpose under a written contract.1California Legislative Information. California Civil Code 1798.140 – Definitions The contract must prohibit the service provider from selling or sharing the data, using it outside the direct business relationship, or combining it with data from other sources.

“Business purpose” is defined broadly enough to cover most operational outsourcing. The enumerated categories include auditing and ad measurement, security, debugging, short-term transient use, performing services such as payment processing and customer support, advertising and marketing (with an important exception for cross-context behavioral advertising), internal research, and quality assurance.2California Privacy Protection Agency. California Consumer Privacy Act of 2018 – Full Text If the reason data is being sent to the vendor fits one of those categories and the contract meets every statutory requirement, the vendor qualifies.

The practical test is whether the entity acts as an extension of the business or pursues its own interests with the data. A cloud host storing customer records, a payment processor handling transactions, or an analytics firm running reports for a single client are classic examples. The moment the vendor uses the data to benefit another client, build its own consumer profiles, or sell insights, the service provider relationship breaks down.

Service Provider vs. Contractor vs. Third Party

The CPRA created a second trusted-partner category called a “contractor,” and mixing the two up leads to drafting errors. A service provider processes personal information on behalf of a business. A contractor is a person to whom the business makes personal information available for a business purpose.1California Legislative Information. California Civil Code 1798.140 – Definitions The line rests on the nature of the engagement. Service providers tend to perform data-centric processing like hosting, analytics, and payment handling. Contractors provide less data-centric services where access to personal information is incidental.

Both categories carry nearly identical contractual restrictions: no selling or sharing, no use outside the direct business relationship, no combining with other data. The differences are procedural. A contractor’s contract must include a certification that the contractor understands and will comply with the restrictions; the statute does not impose that certification requirement on service providers. For contractors, the contract must permit the business to monitor compliance. For service providers, monitoring is framed as permissive, using “may” rather than mandatory language.

A “third party” is anyone who is not the business itself, a service provider, or a contractor. Disclosing personal information to a third party for monetary or other valuable consideration is a “sale.” Disclosing it for cross-context behavioral advertising is a “share.” Both trigger consumer opt-out rights. The service provider and contractor classifications exist to carve out a space for legitimate operational outsourcing that does not require consumer consent for every data transfer.

The Contract Requirements That Make or Break the Status

Without a contract that hits every statutory requirement, the vendor on the other end of the transfer is a third party by default, and the disclosure looks like a sale. California law imposes two overlapping layers: one set built into the service provider definition itself, and another set that applies to any business disclosing personal information to a service provider.

Prohibitions Required by the Definition

The contract must prohibit the service provider from four specific activities:1California Legislative Information. California Civil Code 1798.140 – Definitions

  • Selling or sharing the personal information it receives from the business.
  • Retaining, using, or disclosing the data for any purpose other than the business purposes specified in the contract, including any separate commercial purpose.
  • Retaining, using, or disclosing the data outside the direct business relationship with the disclosing business.
  • Combining data received from one business with data received from another person or collected from its own consumer interactions, except in narrow circumstances defined by regulation.

If any of these four prohibitions is missing, the entity does not meet the statutory definition of a service provider.

Additional Provisions Required When Disclosing Data

A separate statute requires the business disclosing personal information to include five more provisions:3California Legislative Information. California Civil Code 1798.100 – General Duties of Businesses That Collect Personal Information

  • Personal information is disclosed only for limited and specified purposes.
  • The service provider must comply with all applicable CCPA obligations and provide the same level of privacy protection the statute requires.
  • The business has the right to take reasonable steps to ensure the service provider handles data consistently with the business’s own legal obligations.
  • The service provider must notify the business if it determines it can no longer meet its obligations under the statute.
  • The business has the right, upon notice, to take reasonable steps to stop and fix any unauthorized use of personal information.

Missing any of these clauses won’t strip the entity of its service provider status, which depends on the definitional requirements above. But it does put the business itself out of compliance with its own disclosure obligations.

Why the Classification Matters: The Sale and Share Exception

The CCPA defines a “sale” as disclosing personal information to a third party for monetary or other valuable consideration, and defines “sharing” as disclosing it to a third party for cross-context behavioral advertising. Both definitions hinge on the phrase “third party.” The statute explicitly excludes service providers and contractors from the definition of “third party.”4California Legislative Information. California Civil Code 1798.140 – Definitions

Mechanically, that means if the vendor qualifies as a service provider, it is not a third party, so the disclosure cannot be a sale or a share. The business does not have to offer consumers an opt-out for the transfer. It does not need to include the transfer in its “Do Not Sell or Share My Personal Information” disclosures. Payments, cloud storage, and analytics run without consumer intervention.

The protection evaporates the moment the contract or the conduct falls short. If a company labels a partner as a service provider but the agreement lacks the required prohibition on commingling, or the partner is using the data for its own marketing, the entity is a third party again. Every consumer whose information was transferred without an opt-out opportunity represents a separate potential violation. Most compliance failures happen here: companies treat the service provider label as a status they assign rather than a legal conclusion that depends on ongoing contractual and behavioral compliance.

What Service Providers Cannot Do With the Data

The restrictions built into the definition are not just contract boilerplate. They set the boundaries of what the vendor can actually do with the data day to day.

No Commingling

A service provider cannot mix personal information received from one business with data received from a different business or data the provider collects from its own consumer interactions.1California Legislative Information. California Civil Code 1798.140 – Definitions For analytics providers and advertising technology companies that serve multiple clients, this requires strict data silos. Client A’s consumer data cannot be used to improve models for Client B, and a business’s customer data cannot be enriched with information the provider collected independently.

Narrow exceptions exist for business purposes defined in CPPA regulations, but the default is separation. Companies that built their value proposition on aggregating data across clients need to rethink their architecture or accept that they are not operating as service providers.

No Cross-Context Behavioral Advertising

The statute carves cross-context behavioral advertising out of the permissible business purposes for which a service provider can use data. Cross-context behavioral advertising means targeting ads to a consumer based on personal information gathered from that consumer’s activity across different businesses or websites.4California Legislative Information. California Civil Code 1798.140 – Definitions A service provider can help a business run its own advertising and marketing, but it cannot use the data it receives to track consumers across other clients’ platforms and serve targeted ads based on that cross-platform profile.

An ad tech company that receives data from a retailer under a service provider agreement and then uses that data to target ads on an unrelated news site has crossed the line. The transfer is no longer protected, and the business that disclosed the data may be treated as having “shared” personal information for cross-context behavioral advertising without proper consumer consent.

Consumer Rights Requests and Sub-Processors

Service providers do not interact directly with consumers for CCPA purposes. If a consumer submits a deletion, access, or correction request to a service provider, the provider can redirect them to the business. The obligation runs through the business.5California Legislative Information. California Civil Code 1798.105 – Consumers Right to Delete Personal Information

Behind the scenes, cooperation duties are substantial. When a business receives a verified deletion request, the service provider must, at the business’s direction, delete the consumer’s personal information from its systems or enable the business to do so. The service provider must also notify its own sub-processors to delete the data, and notify any other service providers, contractors, or third parties that may have accessed the information through it. Similar cooperation duties apply to access and correction requests: the provider must make personal information in its possession available to the business and correct inaccurate information at the business’s direction.6California Privacy Protection Agency. California Consumer Privacy Act Regulations

When a service provider brings in its own vendors, it must notify the business of that engagement, and the sub-processor must be bound by a written contract imposing the same restrictions that apply to the service provider itself.1California Legislative Information. California Civil Code 1798.140 – Definitions This flows down through every layer of the processing chain. Personal information should never reach an entity that is not bound by the full set of service provider restrictions, no matter how many links exist.

Penalties When the Status Fails

Service providers face direct enforcement. The CCPA applies its civil penalty provisions to “any business, service provider, contractor, or other person” that violates the law.7California Legislative Information. California Civil Code 1798.199.90 – Civil Penalties A service provider that ignores its contractual restrictions can be sued directly by the Attorney General, not just dropped by the business.

The base statutory penalties are $2,500 per violation and $7,500 per intentional violation or violation involving the personal information of a consumer under 16, adjusted for inflation.8California Privacy Protection Agency. California Privacy Protection Agency Announces 2025 Increases for CCPA Fines and Penalties Because they are assessed per violation, a service provider that misuses data affecting thousands of consumers faces liability that scales quickly.

A business that disclosed data to a service provider is not automatically liable for the service provider’s violations, provided the business did not have actual knowledge or reason to believe the service provider intended to violate the law at the time of disclosure. That shield depends on the business having done its contractual homework. A contract missing required provisions, or a business that ignores red flags about a provider’s practices, weakens the argument that the business had no reason to suspect problems.