Back to the hub

Cal. Civ. Code 1798.140: service provider, contractor, or third party?

Under Cal. Civ. Code section 1798.140, a service provider processes personal information on behalf of a business under a written contract, a contractor is a person the business makes personal information available to under a similar contract, and a third party is anyone who is none of those three.

Applies to: Businesses covered by the CCPA that send California consumers' personal information to vendors, analytics tools, advertising platforms, or any other outside company, and need to know which contracts they must sign.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Almost every business sends customer data somewhere else. Your help desk sees support tickets, your analytics tool sees behavior, your ad platform sees audiences. The CCPA does not treat those recipients the same way, and the category a recipient falls into is decided almost entirely by the contract you signed with it. Get the category wrong and a routine vendor transfer becomes a sale you never disclosed.

What is a service provider under the CCPA?

Section 1798.140(ag)(1) defines a service provider as a person that processes personal information on behalf of a business and receives that information for a business purpose under a written contract. The contract has to prohibit the service provider from four things: selling or sharing the personal information; retaining, using, or disclosing it for any purpose other than the business purposes specified in the contract; retaining, using, or disclosing it outside the direct business relationship between the two companies; and combining the personal information it receives from you with personal information it receives from other sources.

That last one catches people out. A vendor that pools your customer data with data from its other clients to improve a shared model is not acting as your service provider, whatever the contract is titled.

What is a third party?

Section 1798.140(ai) defines it by exclusion. A third party is a person who is not the business the consumer intentionally interacts with, not a service provider to that business, and not a contractor. There is no middle ground. If a vendor does not meet the service provider or contractor definition, it is a third party by default.

What is a contractor, and how is it different from a service provider?

Section 1798.140(j)(1) defines a contractor as a person to whom the business makes available a consumer's personal information for a business purpose, under a written contract carrying the same four prohibitions: no selling or sharing, no retaining, using, or disclosing the information for purposes outside the contract, no retaining, using, or disclosing it outside the direct business relationship, and no combining it with personal information from other sources.

The difference between the two definitions is one verb, and it is worth reading them side by side. A service provider "processes personal information on behalf of a business" and "receives from or on behalf of the business" the consumer's personal information. A contractor is one to whom the business "makes available" the personal information.

So the distinction is about direction and purpose rather than about how strict the contract is. A vendor running a workload for you is the service provider case. A recipient you hand data to for a business purpose of your own is the contractor case. Both sit outside the third-party category, and both require a written contract to stay there.

Why the label decides whether you made a sale

Section 1798.140(ad)(1) defines a sale as disclosing a consumer's personal information to a third party for monetary or other valuable consideration. Section 1798.140(ah)(1) defines sharing as disclosing it to a third party for cross-context behavioral advertising, whether or not money changes hands. Both definitions turn on the phrase "third party."

So the chain runs like this. Correctly contracted service provider, no third party, no sale. Same data, same vendor, missing contract terms, and now you have disclosed personal information to a third party, which means you owe consumers a Do Not Sell or Share link and an opt-out you must honor. The contract is the control.

The five terms every agreement needs

Section 1798.100(d) applies whenever you sell personal information to a third party, share it with one, or disclose it to a service provider or contractor for a business purpose. The agreement must specify that the information is sold or disclosed only for limited and specified purposes; obligate the recipient to comply with the applicable obligations in the CCPA and provide the same level of privacy protection the law requires; grant you rights to take reasonable and appropriate steps to help ensure the recipient uses the data consistently with your own obligations; require the recipient to notify you if it determines it can no longer meet those obligations; and grant you the right, on notice, to take reasonable and appropriate steps to stop and remediate unauthorized use.

Those five terms are the floor for every recipient category. The extra prohibitions in Section 1798.140(ag)(1) are what buy you service provider status on top of that.

Next step

If you are not sure which of your vendors are service providers and which are third parties, the free 2-minute Obligation Scan checks whether the CCPA applies to you and flags the vendor contracts and disclosures it puts you on the hook for. The California privacy overview sets out the thresholds, the notice at collection page covers what you have to tell consumers upfront, and the US state privacy laws hub compares the rules across states.

The contract requirements the definitions add on top

The four prohibitions are the well-known part of Section 1798.140. Three further requirements sit in the same subdivisions and are missed far more often, because they are drafting obligations rather than conduct rules.

A contractor has to certify. Section 1798.140(j)(1)(B) requires the contract to include "a certification made by the contractor that the contractor understands the restrictions in subparagraph (A) and will comply with them." There is no equivalent in the service provider definition. A contract that imposes the four prohibitions on a contractor but contains no certification does not make that recipient a contractor, which means the transfer falls back into the third-party category and can be a sale.

Monitoring is mandatory for contractors and optional for service providers. Section 1798.140(j)(1)(C) says the contract "permits, subject to agreement with the contractor, the business to monitor the contractor's compliance with the contract through measures, including, but not limited to, ongoing manual reviews and automated scans and regular assessments, audits, or other technical and operational testing at least once every 12 months." The service provider definition at Section 1798.140(ag)(1)(D) uses a permissive form for the same clause: "The contract may, subject to agreement with the service provider, permit the business to monitor the service provider's compliance." Same words, different verb, different consequence. Leave the audit clause out of a contractor agreement and the status fails; leave it out of a service provider agreement and the status survives, though you lose the right.

Subprocessors have to be notified and flowed down. Section 1798.140(ag)(2) and Section 1798.140(j)(2) carry the same rule. If a service provider or contractor engages any other person to assist it in processing personal information for a business purpose on behalf of the business, or if a person it engaged engages another, "it shall notify the business of that engagement, and the engagement shall be pursuant to a written contract binding the other person to observe all the requirements set forth in paragraph (1)."

That flow-down is the clause most vendor paper omits. It means your service provider cannot quietly add a sub-vendor, and it means the same four prohibitions have to reach every layer below your direct counterparty, rather than only the company whose name is on your agreement.

The exact statutory wording of "service provider" and "third party"

Because the chain from label to sale runs through two definitions, both are worth having in front of you verbatim rather than in summary.

Section 1798.140(ag)(1) opens: "'Service provider' means a person that processes personal information on behalf of a business and that receives from or on behalf of the business consumer's personal information for a business purpose pursuant to a written contract, provided that the contract prohibits the person from:"

The four prohibitions then read:

(A) "Selling or sharing the personal information."

(B) "Retaining, using, or disclosing the personal information for any purpose other than for the business purposes specified in the contract for the business, including retaining, using, or disclosing the personal information for a commercial purpose other than the business purposes specified in the contract with the business, or as otherwise permitted by this title."

(C) "Retaining, using, or disclosing the information outside of the direct business relationship between the service provider and the business."

(D) "Combining the personal information that the service provider receives from, or on behalf of, the business with personal information that it receives from, or on behalf of, another person or persons, or collects from its own interaction with the consumer", subject to the proviso that the service provider may combine personal information to perform any business purpose as defined in the regulations adopted under Section 1798.185(a)(9), except as provided in Section 1798.140(e)(6) and in regulations adopted by the California Privacy Protection Agency.

Section 1798.140(ai) is shorter and it is a pure exclusion: "'Third party' means a person who is not any of the following: (1) The business with whom the consumer intentionally interacts and that collects personal information from the consumer as part of the consumer's current interaction with the business under this title. (2) A service provider to the business. (3) A contractor."

Read the two together and the structure is plain. There is no fourth category and no default other than third party. A recipient is a service provider or a contractor because a written contract carrying specific prohibitions says so, and if that contract is missing or incomplete the recipient falls into paragraph (ai) by elimination. The label is an output of the paperwork, not a description of the relationship.

One consequence is worth stating directly: renaming a vendor agreement a "Data Processing Addendum" changes nothing. Subparagraphs (A) to (D) either appear in it or they do not.

The current version of these definitions

Section 1798.140 has been amended since the CCPA's original text, and cached copies circulate widely. The version currently printed by California Legislative Information carries the line "Amended by Stats. 2025, Ch. 67, Sec. 27. (AB 1170) Effective January 1, 2026", and in that text the cross-reference inside both the service provider and contractor definitions runs to "paragraph (9) of subdivision (a) of Section 1798.185". Older copies point at paragraph (10). If your contract template quotes the statute, check which version it was drafted against.

Compliance checklist

  • List every outside company that receives California consumers' personal information, including analytics, support, hosting, and advertising vendors.
  • For each one, decide whether it is a service provider, a contractor under Section 1798.140(j)(1), or a third party, based on what the signed contract actually says.
  • Put the four prohibitions in Section 1798.140(ag)(1)(A) to (D) into every service provider contract: no selling or sharing, no use outside the specified business purposes, no use outside the direct business relationship, and no combining with other sources.
  • Include the five terms Section 1798.100(d) requires in every agreement with a third party, service provider, or contractor, including the duty to notify you when it can no longer meet its obligations.
  • Treat any recipient that will not sign those terms as a third party, and disclose and handle the transfer as a sale or share.

Sources

Last verified: 2026-09-18

Informational, not legal advice.