CCPA Regulations: Use and Retention of Personal Information by a Service Provider

CCPA Regulations: Use and Retention of Personal Information by a Service Provider

Under the CCPA, a service provider or contractor may only retain, use, or disclose personal information they receive from a business within strict limits. Their use of personal information must be reasonably necessary and proportionate to specific, permitted purposes. They cannot use the data for their own benefit or for any purpose unrelated to the business relationship.

The regulations allow five categories of permitted use:

1️ Use for the Contracted Business Purpose

A service provider or contractor may use personal information only for the business purposes explicitly identified in the written contract required by the CCPA.
This is the core limitation: the vendor must act strictly within the scope of the business’s instructions.

2️ Use to Hire Subcontractors

A service provider may disclose personal information to another service provider or contractor only if:

  • The subcontractor qualifies as a service provider/contractor under the CCPA, and
  • The subcontractor is bound by the same contractual restrictions.

This ensures the entire processing chain remains compliant.

3️ Internal Use to Improve Their Own Services

A service provider may internally use personal information to build or improve the quality of the services they provide to the business—even if this purpose is not listed in the contract—as long as:

  • The improvement relates to the service provided to the business, and
  • The service provider does not use the information to perform services for any other customer or for its own commercial benefit.

This is a narrow exception that allows product improvement but prohibits cross‑customer profiling or reuse.

4️ Use for Security and Fraud‑Prevention Purposes

A service provider may use personal information to:

  • Prevent, detect, or investigate security incidents
  • Protect against malicious, deceptive, fraudulent, or illegal activity

This is permitted even if not specified in the contract.
It aligns with the CCPA’s broader public‑interest and safety exceptions.

5️ Use for Statutory Exceptions in Civil Code § 1798.145(a)(1)

A service provider may use or disclose personal information when necessary to comply with legal obligations or public‑interest exceptions, including:

  • Complying with laws, court orders, or subpoenas
  • Responding to law enforcement or regulatory inquiries
  • Cooperating with government agencies investigating violations of law
  • Providing emergency access when a person faces risk of death or serious physical injury
  • Exercising or defending legal claims
  • Using deidentified or aggregated information
  • Conducting activities that occur wholly outside California

These exceptions ensure that legal compliance and public safety obligations override contractual limitations.

🧠 In Summary

A service provider’s use of personal information is tightly constrained. They may only use or retain the data:

  • For the contracted business purpose
  • For compliant subcontracting
  • For internal service improvement
  • For security and fraud‑prevention
  • For specific statutory exceptions

Any use outside these categories risks converting the service provider into a third party, triggering “sale/sharing” implications and potential noncompliance.

 

 

 

 

 

 

Here are the regulations on Use and Retention of Personal Information by a Service Provider

 

A service provider or contractor shall not retain, use, or disclose personal

information collected pursuant to its written contract with the business

except: for the following purposes, provided that the retention, use, or

disclosure is reasonably necessary and proportionate for those purposes.

 

(1) For the specific business purpose(s) set forth in the written contract

between the business and the service provider or contractor that is

required by the CCPA and these regulations.

 

(2) To retain and employ another service provider or contractor as a

subcontractor, where the subcontractor meets the requirements for a

service provider or contractor under the CCPA and these regulations.

 

(3) For internal use by the service provider or contractor to build or improve

the quality of the services it is providing to the business, even if this

business purpose is not specified in the written contract required by the

CCPA and these regulations, provided that the service provider or

contractor does not use the personal information to perform services on

behalf of another person.

 

(4) To prevent, detect, or investigate data security incidents or protect

against malicious, deceptive, fraudulent or illegal activity, even if this

business purpose is not specified in the written contract required by the

CCPA and these regulations.

 

(5) For the purposes enumerated in Civil Code section 1798.145, subdivisions

(a)(1) [which include (my summary from Civil Code section 1798.145] ):

 

  • comply with laws, court order or subpoena
  • comply with local authorities and law enforcement agencies inquiries and investigations
  • cooperate with law enforcement concerning violations of law
  • cooperate with government requests for emergency access if a natural person is at risk of death or serious physical injury, provided the process established is followed.
  • exercise of defend legal claims
  • deidentified or aggregate information
  • commercial conduct takes place wholly outside of California

[

 

 

What counts as “personal information” under the CCPA?

Under the CCPA, “personal information” means:

Information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.

This is intentionally broad. It covers any data that can be tied to a person or household — even indirectly, even probabilistically.

📘 1. Categories of Personal Information (Statutory List)

The statute provides a non‑exhaustive set of categories. These are the ones you see in privacy notices and DPAs:

  1. Identifiers
  • Real name, alias
  • Postal address
  • Unique personal identifier
  • Online identifier
  • IP address
  • Email address
  • Account name
  • Social Security number
  • Driver’s license number
  • Passport number
  1. Customer Records Information
  • Contact information
  • Financial information
  • Medical information
  • Insurance information
  1. Protected Classification Characteristics
  • Race, ethnicity
  • Gender, gender identity
  • Age
  • Disability
  • Citizenship
  • Veteran status
  1. Commercial Information
  • Purchase history
  • Product or service usage
  • Consumer profiles
  1. Internet or Network Activity
  • Browsing history
  • Search history
  • Interaction with websites, apps, or ads
  1. Geolocation Data
  • Precise or approximate location
  1. Sensory Data
  • Audio, electronic, visual, thermal, olfactory, or similar information
  1. Professional or Employment Information
  2. Education Information
  3. Inferences
  • Profiles about preferences, behavior, intelligence, abilities, or predispositions
  1. Sensitive Personal Information (CPRA expansion)
  • Government IDs
  • Financial account credentials
  • Precise geolocation
  • Racial or ethnic origin
  • Religious or philosophical beliefs
  • Union membership
  • Genetic data
  • Biometric information
  • Health data
  • Sexual orientation or sex life information

📘 2. What Is Not Personal Information?

  1. Publicly Available Information

But only if:

  • It is lawfully made available from government records, and
  • It is used for a purpose consistent with why it is publicly available.
  1. Deidentified Information

Must meet strict CPRA standards:

  • Cannot reasonably be used to infer identity
  • Must be subject to technical and organizational controls
  • Must include public commitments not to reidentify
  1. Aggregated Information

Data relating to a group or category of consumers where individual identities cannot reasonably be inferred.

📘 3. Household Information Counts Too

The CCPA is unusual in that it covers household‑level data, such as:

  • Shared IP addresses
  • Smart home device data
  • Utility usage data
  • Household purchase patterns

This is broader than GDPR’s “personal data” concept.

📘 4. “Reasonably Capable of Being Associated” Is the Key Standard

This is where most vendors underestimate their exposure.

Data counts as PI if:

  • It can be linked to a person with reasonable effort
  • It can be linked using other data the business holds
  • It can be linked using third‑party data that is commonly available
  • It is used to target or profile a person or household

This includes:

  • Cookie IDs
  • Mobile advertising IDs
  • Device IDs
  • Session IDs
  • Probabilistic identifiers

If it can be used to recognize or follow a person or household across contexts, it’s PI.

📘 5. Examples That Often Surprise Vendors

These are all PI under the CCPA:

  • IP addresses, even dynamic ones
  • Hashed email addresses
  • Cookie IDs
  • Clickstream data
  • Inferences (e.g., “likely parent,” “interested in SUVs”)
  • Metadata about user interactions
  • User IDs that are “pseudonymous” but linkable
  • Smart device telemetry
  • Chat logs
  • Customer support transcripts

If it can be tied to a person or household, it’s PI.

 

 

Does a service provider need to collect opt outs under the CCPA?

No. A service provider does not collect or honor consumer opt‑outs of sale or sharing.
Those obligations apply only to businesses, not to service providers.

But — and this is the part that matters operationally — a service provider must ensure that nothing it does would require an opt‑out in the first place.

Let’s unpack that.

📘 1. Service Providers Do Not Need to Collect Opt‑Outs

Under the CCPA/CPRA:

  • The business must provide “Do Not Sell or Share” links
  • The business must honor opt‑out preference signals (GPC)
  • The business must stop selling/sharing when a consumer opts out

A service provider has none of these obligations.

A service provider never:

  • Displays a “Do Not Sell or Share” link
  • Collects opt‑out requests
  • Honors GPC signals
  • Manages opt‑out preference cookies
  • Responds directly to opt‑out requests

These are business‑only duties.

📘 2. Why Service Providers Don’t Collect Opt‑Outs

Because a service provider is prohibited from:

  • Selling personal information
  • Sharing personal information
  • Using personal information for cross‑context behavioral advertising
  • Using personal information for its own purposes

If a service provider is operating correctly, there is nothing to opt out of.

Opt‑outs are only required when a company is engaging in sale or sharing — activities a service provider is legally barred from doing.

📘 3. What a Service Provider Must Do Instead

Even though service providers don’t collect opt‑outs, they must:

✔️ Honor instructions from the business

If the business tells the service provider to stop using certain data for a certain purpose (e.g., targeted advertising), the service provider must comply.

✔️ Ensure its processing does not constitute a sale/share

This is the real compliance burden.
A service provider must avoid:

  • Using data for its own benefit
  • Combining data across customers
  • Using data for advertising or profiling
  • Disclosing data to subprocessors without proper flow‑downs

If it violates these rules, it becomes a third party, and the transfer becomes a sale/share — which would require opt‑outs.

✔️ Support the business’s opt‑out obligations

This includes:

  • Notifying subprocessors when the business instructs it to stop certain uses
  • Ensuring data used for advertising is deleted or restricted
  • Ensuring no cross‑context behavioral advertising occurs

📘 4. When a Service Provider Might Need to Implement Opt‑Out Logic

There is one narrow scenario:

✔️ If the business instructs the service provider to implement opt‑out logic on the business’s behalf

For example:

  • A SaaS platform that hosts the business’s website
  • A marketing automation tool that sends emails for the business
  • A consent‑management platform integrated into the business’s app

In these cases, the service provider is acting as the business’s agent, not collecting opt‑outs for itself.

The service provider is simply executing the business’s opt‑out instructions.

🎯 Bottom Line

A service provider does not collect or honor consumer opt‑outs under the CCPA/CPRA.

But it must:

  • Avoid any processing that would require opt‑outs
  • Follow the business’s instructions regarding opt‑outs
  • Ensure subprocessors do the same
  • Support the business’s compliance operationally

If a service provider ever finds itself needing to collect opt‑outs for its own processing, it has already lost its service‑provider status.

 

 

 

 

 

CCPA: Business Compliance Assistance by Service Providers (Non–Data Subject Requests)

Under the CCPA regulations, service providers and contractors are required to support the business’s broader compliance obligations—not just consumer rights requests. When a service provider processes personal information on behalf of a business under a written contract, it must actively cooperate with the business in completing key regulatory duties, including cybersecurity audits, risk assessments, and access requests related to automated decision‑making technology (ADMT).

These obligations ensure that businesses can meet their statutory responsibilities even when critical processing activities occur within a vendor’s systems.

🔍 1. Cooperation with Cybersecurity Audits (Article 9)

A service provider or contractor must assist the business in completing its required cybersecurity audit. This includes:

  • Providing the auditor with all relevant information in the service provider’s possession, custody, or control
  • Ensuring that information is accurate and not misrepresented
  • Making available any materials the auditor deems necessary to evaluate the business’s cybersecurity posture

This requirement recognizes that a business cannot complete a meaningful cybersecurity audit without visibility into the systems and practices of its vendors.

🔍 2. Cooperation with Risk Assessments (Article 10)

Service providers must also support the business’s risk assessment obligations by:

  • Making available all facts necessary for the business to conduct its risk assessment
  • Ensuring that no relevant information is misrepresented or withheld

Because risk assessments often involve evaluating high‑risk processing activities—many of which may be performed by vendors—the service provider’s cooperation is essential for compliance.

🔍 3. Assistance with Access Requests for Automated Decision‑Making Technology (ADMT)

When a consumer submits a verifiable request to access information about automated decision‑making technology, the business may need information held by its service providers. In these cases, the service provider must:

  • Provide the business with all personal information in its possession that was collected under the contract or
  • Enable the business to access that information directly

This ensures that businesses can meet their transparency obligations regarding ADMT, even when the underlying processing occurs within a vendor’s systems.

🧠 Summary

Beyond supporting consumer data‑subject rights, service providers and contractors have affirmative duties to help businesses meet their broader compliance obligations under the CCPA. These duties include:

  • Supporting cybersecurity audits by providing accurate, relevant information
  • Supporting risk assessments by supplying all necessary facts
  • Supporting ADMT access requests by providing or enabling access to relevant personal information

These requirements reflect the CCPA’s shift toward a more GDPR‑like model in which vendors play an active, accountable role in the business’s overall compliance framework.

 

 

Business Compliance Assistance  by Service Providers under CCPA Regulations (other than data subject requests)

 

(h) A service provider or contractor shall, with respect to personal information

that they collected pursuant to their written contract with the business,

cooperate with the business:

(1) In the business’s completion of its cybersecurity audit pursuant to Article

9, including making available to the business’s auditor all relevant

information that the auditor requests to complete the business’s

cybersecurity audit and that is in the service provider’s or contractor’s

possession, custody, or control, and not misrepresenting any fact that the

auditor deems relevant to the business’s cybersecurity audit; and

(2) In conducting the business’s risk assessment pursuant to Article 10,

including making available to the business all facts necessary to conduct

the risk assessment that are in the service provider’s or contractor’s

possession, custody, or control, and not misrepresenting any fact

necessary to conduct the risk assessment

 

 

 A service provider or contractor must provide assistance to the business in

responding to a verifiable consumer request to access ADMT, including by

providing the business with the consumer’s personal information it has in its

possession that it collected pursuant to their written contract with the

business, or by enabling the business to access that personal information.

 

 

What are the expectations from a service provider for cybersecurity audits and risk assessments under the CCPA?

A service provider must:

  1. Cooperate fully with the business’s cybersecurity audits and risk assessments.
  2. Provide all relevant information in its possession, custody, or control.
  3. Not misrepresent any facts relevant to the audit or assessment.
  4. Allow audits, scans, testing, and assessments as required by the regulations.
  5. Flow down these obligations to its own subprocessors.

These are mandatory operational obligations, not optional contract terms.

🔍 1. What the CCPA Requires for Cybersecurity Audits (Article 9)

Under the CPRA regulations, a service provider must:

✔️ Make available all relevant information

✔️ Permit reasonable audit activities

✔️ Not misrepresent any fact

✔️ Provide access to personnel

✔️ Support remediation

🔍 2. What the CCPA Requires for Risk Assessments (Article 10)

Risk assessments are broader than audits.
A service provider must:

✔️ Provide all facts necessary for the business to complete its risk assessment

This includes:

  • Categories of personal information processed
  • Processing purposes
  • Sensitive personal information handling
  • Data flows and transfers
  • Retention periods
  • Security controls
  • Use of automated decision‑making technology (ADMT)
  • Subprocessor involvement
  • Locations of data storage and access

✔️ Disclose any high‑risk processing

Examples:

  • Profiling
  • Behavioral advertising
  • Sensitive PI processing
  • Large‑scale monitoring
  • AI/ML models trained on customer data

✔️ Provide documentation

The service provider must supply:

  • DPIA‑like assessments (if they exist)
  • Internal risk assessments
  • Threat modeling outputs
  • Security certifications
  • Privacy impact assessments

✔️ Not misrepresent any fact necessary to conduct the risk assessment

🔍 3. Required Operational Capabilities for Service Providers

To meet these obligations, a service provider must have:

✔️ Documented security program

Policies, procedures, and controls must be written and maintained.

✔️ Evidence repositories

Audit logs, access logs, vulnerability scans, and change‑management records.

✔️ Data mapping

The service provider must know:

  • What PI it holds
  • Where it is stored
  • How it flows
  • Who has access
  • How long it is retained

✔️ Subprocessor oversight

The service provider must:

  • Flow down audit and risk‑assessment obligations
  • Ensure subprocessors provide required information
  • Maintain visibility into subprocessor controls

✔️ Designated personnel

Security, privacy, and engineering staff must be available to support audits.

🔍 4. What the CCPA Does Not Require

A service provider does not need to:

  • Conduct its own CCPA‑specific cybersecurity audit
  • Conduct its own CCPA‑specific risk assessment
  • Submit audits to the CPPA
  • Certify compliance annually

Those obligations apply to businesses, not service providers.

But service providers must support the business’s obligations.

🎯 Bottom Line

Under the CCPA/CPRA, a service provider must:

  • Cooperate fully with cybersecurity audits
  • Provide all relevant information
  • Support risk assessments
  • Allow testing, scanning, and review
  • Avoid misrepresentation
  • Flow down these obligations to subprocessors