Getting the CCPA service provider classification wrong is how a routine vendor relationship becomes a sale of personal information. California law recognizes three roles for the parties you share data with — service provider, contractor and third party — and the difference between them lives almost entirely in the contract you signed.
This guide sets out what each role means under section 1798.140, what the contract has to say, and the practical test for deciding which one a vendor is.

CCPA service provider, contractor and third party
| Role | Definition in outline | What it turns on |
|---|---|---|
| Service provider | A person that processes personal information on behalf of a business, under a written contract | Processing on your behalf, with the required contract terms |
| Contractor | A person to whom the business makes personal information available for a business purpose, under a written contract | Making data available for a business purpose, plus a certification of understanding |
| Third party | A person who is not the business the consumer interacts with, nor a service provider or contractor of it | The residual category — what you are if the contract terms are missing |
Read the third row twice. A CCPA service provider is a status the contract creates, not one a vendor claims. Third party is not a status a vendor elects; it is what remains when the service provider or contractor conditions are not met. A vendor you regard as a processor, without the statutory contract terms, is a third party — and transferring personal information to a third party for anything of value is where “sale” and “sharing” analysis begins.
What a CCPA service provider contract has to contain
Both the CCPA service provider and the contractor definitions are contract-dependent, and the required terms overlap almost entirely. The agreement must:
- Prohibit selling or sharing the personal information.
- Prohibit retaining, using or disclosing it for any purpose other than the business purposes specified in the contract.
- Prohibit use outside the direct business relationship between the parties.
- Prohibit combining the personal information with information received from another person, subject to the limited exceptions the regulations allow.
- Permit the business to monitor compliance, including through measures such as audits at least once every twelve months.
The contractor definition adds one thing the service provider definition does not: a certification by the contractor that it understands the restrictions and will comply with them. It is a single clause and it is the one most often missing from an otherwise adequate agreement.
The clause people leave out
The right to monitor — including the annual audit right — reads like boilerplate and is not. Its absence is a defect in the definition itself, which means the vendor may not qualify as a service provider or contractor at all, whatever the rest of the agreement says. Reviewing a vendor file against these five points is a two-hour exercise that changes the legal characterization of every relationship it touches.
The practical test for classifying a vendor
Work through it in this order for each vendor:
- Are we giving them personal information at all? If the data never leaves your control — an on-premises tool, a fully anonymized extract — the question does not arise.
- Are they processing it on our behalf, for our purposes? If yes, CCPA service provider is the target classification.
- Are we making it available to them for a business purpose that is more than pure processing? Then contractor is the fit, and remember the certification clause.
- Do they use the data for their own purposes? Advertising networks, data enrichment services and analytics providers who improve their own models are the usual examples. That is a third party, and the transfer needs sale or sharing analysis and an opt-out route.
- Does the contract actually contain the required terms? If not, the intended classification fails regardless of the commercial understanding.
The most common error is assuming the answer at step two and never testing step five. The second most common is treating a GDPR data processing agreement as sufficient: it covers similar ground, but the CCPA terms — particularly the prohibition on combining data and the monitoring right — are not automatically present in a processor annex written for European law.
Why the classification matters commercially
Three consequences follow from the label:
- Consumer rights flow differently. Requests you receive have to reach the parties holding the data, and the mechanics differ by role.
- Sale and sharing disclosures change. Data going to a third party may require opt-out mechanisms and specific disclosures that data going to a service provider does not.
- Liability allocation changes. The statutory conditions are what let a business argue it was not selling data when it engaged a vendor.
All of which is why the vendor inventory and the contract review belong together rather than in separate workstreams. Our guide to CCPA compliance in 2026 covers the deadline ladder those obligations sit on.
Frequently asked questions
What is the difference between a CCPA service provider and a contractor?
A service provider processes personal information on the business’s behalf; a contractor is one to whom the business makes personal information available for a business purpose. The contractor’s contract must also include a certification that it understands and will comply with the restrictions.
Is a third party a bad thing?
Not inherently — some relationships genuinely are third-party ones. What matters is recognizing it, because the disclosure and opt-out obligations differ.
Does a GDPR data processing agreement satisfy the CCPA?
Not by itself. The subject matter overlaps but the specific prohibitions and the monitoring right have to be present.
Do we really need an annual audit right?
The definitions contemplate the business being able to monitor compliance, including through measures such as audits at least once every twelve months. Whether you exercise it is a separate question from whether the right exists.
What if a vendor refuses the terms?
Then the vendor is a third party, and you should treat the transfer accordingly rather than describing them internally as a processor.
Where this leaves you
Classify every vendor deliberately, and let the contract decide rather than the org chart. Run the five required terms against each agreement — no selling or sharing, purpose limitation, no use outside the relationship, no combining, and the monitoring right — add the contractor certification where the role calls for it, and treat anything that fails the test as a third party until the paper is fixed. A vendor list with roles assigned and contracts checked is the artifact that makes every later CCPA question answerable.
References
- California Civil Code § 1798.140 — the definitions of service provider, contractor and third party.
- California Privacy Protection Agency — regulations — the rules that operationalize the contract requirements.
More on US privacy compliance
- CCPA service providers and contractors — you are here
- CCPA compliance in 2026: every deadline
- Building a data protection strategy
- Records of processing activities
Vendor classification registers and contract clause sets are in the CCPA-CPRA Compliance Toolkit, or start with the free ISO templates.