Topic guide

Vendor and service-provider contracts

When a vendor touches personal information for you, California and federal law dictate what the contract must say. Missing terms can turn a routine vendor relationship into a "sale."

Last reviewed

In short

  • Under the CCPA, whether a vendor is a service provider, contractor or third party depends largely on the contract.
  • A vendor without a contract containing the terms required by 11 CCR § 7051(a) is not a service provider or contractor, and disclosing data to it may be a sale or sharing.
  • Every contract that discloses personal information to a nonaffiliated third party must require reasonable security.
  • HIPAA requires a business associate agreement with specific terms before a vendor handles protected health information.

Classify the vendor

RoleDefinitionSource
Service providerProcesses personal information on behalf of the business, under a written contract with required restrictions.Civ. Code § 1798.140(ag)
ContractorReceives personal information from the business for a business purpose, under a written contract with parallel restrictions.§ 1798.140(j)
Third partyAnyone who isn't the business the consumer is dealing with, a service provider or a contractor.§ 1798.140(ai)

An advertising vendor that provides cross-context behavioral advertising is a third party, not a service provider, for those services (11 CCR § 7050(b)). Disclosing data to it is usually "sharing," which triggers opt-out rights.

Required terms for service providers and contractors

The contract must (11 CCR § 7051(a); Civ. Code § 1798.100(d)):

  1. prohibit selling or sharing the personal information;
  2. identify the specific business purposes. They "shall not be described in generic terms, such as referencing the entire contract generally";
  3. prohibit retaining, using or disclosing the information for any other purpose;
  4. prohibit using it outside the direct business relationship, including combining it with information from other sources, except as the regulations allow;
  5. require CCPA compliance and the same level of privacy protection, including helping with consumer requests and maintaining reasonable security;
  6. give the business the right to take reasonable and appropriate steps to ensure compliance, such as audits or testing at least once every 12 months;
  7. require the vendor to notify the business if it can no longer meet its obligations;
  8. give the business the right to stop and remediate unauthorized use; and
  9. require the vendor to enable the business to comply with consumer requests.

Why it matters: "A person who does not have a contract that complies with section 7051, subsection (a), is not a service provider or a contractor under the CCPA." Disclosing data to that person "may be considered a sale or sharing" that requires an opt-out (11 CCR § 7050(e)). Missing contracts were cited in CalPrivacy's Honda and Tractor Supply decisions and the Attorney General's Healthline settlement.

Two more points from the regulations:

  • Subcontractors need the same contract terms (11 CCR § 7051(b)).
  • Use your rights. A business that never enforces the contract or exercises its audit rights may lose the argument that it had no reason to believe the vendor would violate the law (11 CCR § 7051(c)).
  • New in 2026: service providers and contractors must cooperate with the business's cybersecurity audits and risk assessments, and must not misrepresent facts to the auditor (11 CCR § 7050(h)).

Contracts with third parties

If you sell or share personal information with a third party, the contract must identify specific purposes, limit use to them, require CCPA compliance (including honoring opt-outs you pass along), give you rights to take reasonable steps to ensure compliance and to stop unauthorized use, and require notice if the third party can no longer comply (11 CCR § 7053(a)). A third party without such a contract may not collect, use, sell or share the information (11 CCR § 7052(a)).

Reasonable-security clauses

Separately from the CCPA, a business that discloses personal information about California residents to a nonaffiliated third party under a contract "shall require by contract" that the third party maintain reasonable security appropriate to the nature of the information (Civ. Code § 1798.81.5(c)). See Security.

HIPAA business associate agreements

A covered entity may give protected health information to a business associate only with written assurances that meet 45 CFR § 164.504(e). Business associates need the same kind of agreement with their own subcontractors (§ 164.502(e)). The agreement must, among other things:

  • set the permitted uses and disclosures, and prohibit others;
  • require appropriate safeguards and compliance with the Security Rule for electronic information (§ 164.314(a));
  • require reporting of unauthorized uses and disclosures, security incidents and breaches;
  • flow the same restrictions down to subcontractors;
  • support patients' rights of access, amendment and accounting of disclosures;
  • make books and records available to HHS;
  • at termination, return or destroy the information if feasible, and otherwise extend the protections; and
  • allow termination for material breach.

Under California's medical privacy law, providers may disclose medical information to vendors that provide billing, claims management, medical data processing or other administrative services, but the vendor may not further disclose it in violation of the law (Civ. Code § 56.10(c)(3)).

Checklist

  • Inventory vendors that receive personal information, and classify each as service provider, contractor or third party.Civ. Code § 1798.140(ag), (j), (ai)
  • Confirm each service provider or contractor contract has all nine § 7051(a) terms, with specific purposes.11 CCR § 7051(a)
  • Fix contracts that are missing terms, or treat the disclosure as a sale or sharing.11 CCR § 7050(e)
  • Add audit and testing rights, and actually use them.11 CCR § 7051(a)(6), (c)
  • Require cooperation with your cybersecurity audits and risk assessments.11 CCR § 7050(h)
  • Require subcontractor flow-down terms.11 CCR § 7051(b); 45 CFR § 164.504(e)
  • Use § 7053 contracts for any sale or sharing with third parties.11 CCR § 7053
  • Include a reasonable-security clause in every contract that discloses personal information.Civ. Code § 1798.81.5(c)
  • Sign complete business associate agreements before any vendor handles protected health information.45 CFR §§ 164.504(e), 164.314(a)
  • Include return-or-delete terms and proof of deletion at the end of every contract.45 CFR § 164.504(e)(2)(ii)(J); best practice under the CCPA

Related guides

Official sources