Under the California Consumer Privacy Act, a company that processes personal information for a California business qualifies as a service provider only if it operates under a written contract that meets specific requirements: the contract must identify the business purposes for processing, bar the vendor from selling, sharing, or repurposing the data, require the same level of privacy protection the business itself must provide, and flow those same restrictions down to any subcontractor. Miss any of these terms and the vendor loses service provider status, which turns a routine data transfer into a disclosure to a third party and exposes both sides to enforcement by the California Privacy Protection Agency.
Who Counts as a Service Provider
A service provider is a company that processes personal information on behalf of a business and receives that information from or on behalf of the business for a specified business purpose under a written contract.1California Legislative Information. California Civil Code 1798.140 – Definitions The written contract is not a formality. Without it, the receiving company cannot claim service provider status at all, and the transfer of data may be treated as a sale or disclosure to a third party, which carries far heavier obligations for both sides.
Some vendors assume that a signed master services agreement is enough. It isn’t, unless that agreement contains the CCPA-specific terms discussed below.
What the Contract Must Contain
The CPPA’s implementing regulations set out the terms every service provider agreement must include. The contract cannot describe business purposes in generic terms like “to perform services under this agreement.” It has to name each specific business purpose for which the vendor will process personal information.2California Privacy Protection Agency. California Consumer Privacy Act Regulations
Beyond that specificity requirement, the agreement must:
- Prohibit the service provider from selling or sharing any personal information collected under the contract.
- Prohibit retention, use, or disclosure of the data for any purpose beyond the specific business purposes listed.
- Prohibit use of the data outside the direct business relationship, meaning the vendor cannot build an independent commercial product from a client’s data.
- Prohibit combining the data with information the vendor receives from other sources or collects through its own consumer interactions, unless a statutory exception applies.
- Require the vendor to provide the same level of privacy protection the CCPA requires of the business itself.
- Require the vendor to notify the business if it determines it can no longer meet its obligations under the law.
- Give the business the right, on receiving that notice, to take reasonable steps to stop and remediate any unauthorized use.
- Address consumer rights requests, either by enabling the business to comply directly or by requiring the service provider to handle specified requests itself.
Missing any of these terms puts the vendor’s legal status at risk.2California Privacy Protection Agency. California Consumer Privacy Act Regulations If the agreement falls short, the entity can be reclassified as a third party, which triggers consumer opt-out rights, potential “Do Not Sell” link obligations, and significantly greater regulatory exposure for the business that hired it.
Permitted Uses of the Data
Even with the right contract in place, a service provider’s use of personal information is limited to business purposes that are reasonably necessary and proportionate to why the data was originally collected. The statute recognizes categories including:
- Account and order management, transaction processing, payment processing, and identity verification.
- Customer service, advertising or marketing services, and analytic services provided on behalf of the business.
- Auditing activities tied to current consumer interactions, such as counting ad impressions and verifying ad placement quality.
- Detecting security incidents and protecting against fraudulent or illegal activity.
- Internal research for technological development and testing, provided it improves the existing service and does not produce consumer profiling beyond the contract’s scope.
These purposes are limited to serving the business that disclosed the data.1California Legislative Information. California Civil Code 1798.140 – Definitions A service provider running fraud detection for Client A cannot fold Client A’s data into its own proprietary fraud model. A marketing analytics vendor cannot enrich a client’s customer list with its own audience data. The data-isolation rule is where many vendors quietly fall out of compliance.
Helping the Business Respond to Consumer Requests
When a California consumer submits a request to access, delete, or correct their personal information, the business must respond within 45 days of receiving a verifiable request. That deadline can be extended once by another 45 days when reasonably necessary, if the consumer is notified within the initial period.3California Legislative Information. California Civil Code 1798.130
Service providers are obligated to help meet those deadlines. The cooperation is not optional and not a best-efforts commitment. The regulations require the contract to either enable the business to comply directly or require the vendor to handle specified requests itself.2California Privacy Protection Agency. California Consumer Privacy Act Regulations In practice, that means the vendor needs to be able to locate, produce, correct, or delete a specific consumer’s data across every active system it runs, on demand.
Retention and Deletion
A service provider cannot hold personal information indefinitely just because a contract once authorized its collection. Retention must be reasonably necessary and proportionate to the purpose for which the data was collected, and the vendor’s practices need to match the retention periods the business has disclosed to consumers.2California Privacy Protection Agency. California Consumer Privacy Act Regulations
When a consumer exercises the right to delete, the business must permanently erase, deidentify, or aggregate the personal information from its existing systems. Service providers and contractors have to do the same on their end. If personal information sits on archived or backup systems, compliance can be delayed until that system is restored to active use or is next accessed for a sale, disclosure, or commercial purpose.2California Privacy Protection Agency. California Consumer Privacy Act Regulations That backup exception is narrower than many vendors read it. Backup data cannot live there forever. The clock simply restarts when the backup becomes active again.
Subcontractors Get the Same Rules
When a service provider hires another company to help process personal information, that subcontractor does not get a lighter set of restrictions. The service provider must notify the business of the arrangement and enter into a written contract with the sub-processor that imposes the same obligations the service provider operates under.1California Legislative Information. California Civil Code 1798.140 – Definitions The same flow-down duty applies if the sub-processor engages yet another company below it.
The service provider remains responsible for the sub-processor’s compliance. A cloud provider subcontracting to a data center operator subcontracting to a managed services firm creates three layers of obligation, and a failure at any layer can cascade upward. Businesses negotiating these agreements often insist on visibility into the sub-processor chain and a right to approve new subcontractors before data is transferred to them.
Service Provider or Contractor
The CPRA added a second category called a “contractor,” which faces nearly identical restrictions. A service provider processes personal information received “from or on behalf of” the business; a contractor is a company to which a business “makes available” personal information.1California Legislative Information. California Civil Code 1798.140 – Definitions Two contract differences follow:
- A contractor’s agreement must include a certification stating that the contractor understands and will comply with the restrictions. Service provider contracts do not require this certification.1California Legislative Information. California Civil Code 1798.140 – Definitions
- Contractor agreements must permit the business to monitor compliance through measures like audits, automated scans, or assessments at least once every 12 months. For service providers, the same monitoring right is permissive rather than mandatory.1California Legislative Information. California Civil Code 1798.140 – Definitions
A company that doesn’t clearly fit one category tends to default toward the stricter contractor requirements. When the classification is ambiguous, including the certification clause and mandatory audit rights costs nothing and avoids a dispute later.
What Noncompliance Costs
The California Privacy Protection Agency has primary authority to enforce the CCPA through administrative actions against businesses, service providers, contractors, and any other person that violates the law.4California Legislative Information. California Civil Code 1798.199.40 – Agency Functions
The base statutory fines are up to $2,500 per violation, or $7,500 per intentional violation and for violations involving personal information of consumers the violator knows are under 16.5California Legislative Information. California Civil Code 1798.155 – Administrative Enforcement Those amounts are adjusted periodically for inflation. As of January 1, 2025, the adjusted amounts are $2,663 per violation and $7,988 per intentional violation or violation involving a minor’s data.6California Privacy Protection Agency. 2025 Increases for CCPA Fines and Penalties Fines are assessed per violation, so a single failure affecting thousands of consumers can produce enormous aggregate liability.
Service providers should also read their contracts for indemnification. A vendor’s security lapse or unauthorized data use can trigger regulatory action against the business that hired it, and those costs typically flow back through the contract to the vendor that caused them.