Back to the hub

What is the difference between a service provider and a third party under the CCPA?

Under California Civil Code section 1798.140, a service provider processes personal information under a written contract barring it from selling the data or using it outside that contract. A third party is anyone who is not the business, a service provider, or a contractor. Sending data to a third party can be a sale.

Applies to: Businesses covered by the CCPA that send California consumers' personal information to vendors, analytics tools, advertising platforms, or any other outside company, and need to know which contracts they must sign.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Founding 30% off with code FOUNDING until 15 August 2026

Almost every business sends customer data somewhere else. Your help desk sees support tickets, your analytics tool sees behavior, your ad platform sees audiences. The CCPA does not treat those recipients the same way, and the category a recipient falls into is decided almost entirely by the contract you signed with it. Get the category wrong and a routine vendor transfer becomes a sale you never disclosed.

What is a service provider under the CCPA?

Section 1798.140(ag)(1) defines a service provider as a person that processes personal information on behalf of a business and receives that information for a business purpose under a written contract. The contract has to prohibit the service provider from four things: selling or sharing the personal information; retaining, using, or disclosing it for any purpose other than the business purposes specified in the contract; retaining, using, or disclosing it outside the direct business relationship between the two companies; and combining the personal information it receives from you with personal information it receives from other sources.

That last one catches people out. A vendor that pools your customer data with data from its other clients to improve a shared model is not acting as your service provider, whatever the contract is titled.

What is a third party?

Section 1798.140(ai) defines it by exclusion. A third party is a person who is not the business the consumer intentionally interacts with, not a service provider to that business, and not a contractor. There is no middle ground. If a vendor does not meet the service provider or contractor definition, it is a third party by default.

Section 1798.140(j)(1) covers contractors, which are recipients to whom you make personal information available for a business purpose under a written contract carrying a similar set of prohibitions. The practical difference between service providers and contractors is narrow, and both sit outside the third-party category.

Why the label decides whether you made a sale

Section 1798.140(ad)(1) defines a sale as disclosing a consumer's personal information to a third party for monetary or other valuable consideration. Section 1798.140(ah)(1) defines sharing as disclosing it to a third party for cross-context behavioral advertising, whether or not money changes hands. Both definitions turn on the phrase "third party."

So the chain runs like this. Correctly contracted service provider, no third party, no sale. Same data, same vendor, missing contract terms, and now you have disclosed personal information to a third party, which means you owe consumers a Do Not Sell or Share link and an opt-out you must honor. The contract is the control.

The five terms every agreement needs

Section 1798.100(d) applies whenever you sell personal information to a third party, share it with one, or disclose it to a service provider or contractor for a business purpose. The agreement must specify that the information is sold or disclosed only for limited and specified purposes; obligate the recipient to comply with the applicable obligations in the CCPA and provide the same level of privacy protection the law requires; grant you rights to take reasonable and appropriate steps to help ensure the recipient uses the data consistently with your own obligations; require the recipient to notify you if it determines it can no longer meet those obligations; and grant you the right, on notice, to take reasonable and appropriate steps to stop and remediate unauthorized use.

Those five terms are the floor for every recipient category. The extra prohibitions in Section 1798.140(ag)(1) are what buy you service provider status on top of that.

Next step

If you are not sure which of your vendors are service providers and which are third parties, the free 2-minute Obligation Scan checks whether the CCPA applies to you and flags the vendor contracts and disclosures it puts you on the hook for. The California privacy overview sets out the thresholds, the notice at collection page covers what you have to tell consumers upfront, and the US state privacy laws hub compares the rules across states.

Compliance checklist

  • List every outside company that receives California consumers' personal information, including analytics, support, hosting, and advertising vendors.
  • For each one, decide whether it is a service provider, a contractor under Section 1798.140(j)(1), or a third party, based on what the signed contract actually says.
  • Put the four prohibitions in Section 1798.140(ag)(1)(A) to (D) into every service provider contract: no selling or sharing, no use outside the specified business purposes, no use outside the direct business relationship, and no combining with other sources.
  • Include the five terms Section 1798.100(d) requires in every agreement with a third party, service provider, or contractor, including the duty to notify you when it can no longer meet its obligations.
  • Treat any recipient that will not sign those terms as a third party, and disclose and handle the transfer as a sale or share.

Sources

Last verified: 2026-08-14

Informational, not legal advice.