Regulated Customer Contract Checker
Regimes · CCPA

The CCPA as amended by the CPRA, with its regulations

Reaches every agreement with a business customer in California (US-CA) whose row names personal information: the written contract of 1798.100(d) (specified purposes, no selling or sharing, no combining, the same level of protection, audit and inspection, notice when the recipient can no longer meet its duties), the service provider duties of CCR 7050, and the private right of action of 1798.150 that is why a California customer asks for a breach clock.

On the register, tick "CCPA/CPRA" (every regime is ticked by default) and these rows attach where the customer's sector and country reach it. Source framework: CCPA/CPRA and its regulations.

What it expects, term by term

processor terms§1798.100(d) · CCR §7050Where the row names personal data the supplier handles
audit right§1798.100(d)On an ICT service arrangement, or where processor terms are expected
breach clock§1798.150Where the row names personal information

The clauses, quoted

3

Clause text from The Art of Service standards library at compliance.theartofservice.com, read against the held text of each standard and cited to its clause: our close statement of each clause, not the instrument verbatim. Where the UK text is held only as a summary, the EU GDPR article of the same number is quoted and the page says so.

CCPA CCR §7050 Service Provider and Contractor Obligations

A service provider or contractor shall only process PI on behalf of a business for a business purpose specified in the written contract. It shall not retain, use, or disclose PI for any purpose other than the business purpose, sell or share PI, or combine PI received from one business with PI received from another business or from its own interactions with consumers (with limited exceptions). Service providers must assist the business in responding to consumer requests.

Evidence an auditor accepts: Service provider acknowledgement of restrictions in contract; Subcontractor flowdown agreements; Consumer request assistance procedure (forwarding requests, providing data extracts)
Where it usually falls short: Service provider commingles client data
CCPA/CPRA and its regulations in The Art of Service standards library
CCPA §1798.100(d) Contractual Requirements for Third Parties, Service Providers, and Contractors

A business that collects PI and sells/shares it with a third party or discloses it to a service provider or contractor must enter into a written contract that specifies purposes, prohibits selling/sharing/retaining/using/disclosing PI for any purpose other than those specified, prohibits combining with PI from other sources except as permitted, requires same level of protection, grants the business audit/inspection rights, and requires notification if recipient can no longer meet obligations.

Evidence an auditor accepts: Service provider/contractor agreements containing all required CCPA clauses; Third party data sharing agreements; Vendor inventory classifying each recipient (service provider, contractor, third party)
Where it usually falls short: Legacy vendor contracts missing CPRA-required clauses
CCPA/CPRA and its regulations in The Art of Service standards library
CCPA §1798.150 Private Right of Action for Data Breaches

A consumer whose nonencrypted and nonredacted PI (or email address with password/security question allowing account access) is subject to unauthorized access and exfiltration, theft, or disclosure as a result of the business's violation of duty to implement and maintain reasonable security may bring a civil action for statutory damages of USD 100 to 750 per consumer per incident, or actual damages (whichever is greater), injunctive or declaratory relief, and any other relief the court deems proper. A 30-day notice and cure opportunity is required before action for statutory damages.

Evidence an auditor accepts: Reasonable security program documentation (encryption, access control, monitoring); Incident response plan including 30-day cure handling; Breach notification procedure
Where it usually falls short: Encryption not applied to sensitive elements
CCPA/CPRA and its regulations in The Art of Service standards library

See what it expects of your list

Paste the list of customer agreements and every row this regime reaches carries these terms, ticked or open. Eight agreements free, no account.

Check my contract list