Regulated Customer Contract Checker
Standards · CCPA

CCPA/CPRA and its regulations

Rendered when "CCPA/CPRA" is ticked and the customer reaches it. The register cites 3 of its 30 clauses, behind 2 findings: personal data with no dpa shown, audit rights granted, and on the rows it reaches.

Clause text from The Art of Service standards library at compliance.theartofservice.com, read against the held text of each standard and cited to its clause: our close statement of each clause, not the instrument verbatim. Where the UK text is held only as a summary, the EU GDPR article of the same number is quoted and the page says so. Source framework: CCPA/CPRA and its regulations. What it expects of an agreement: the CCPA regime page.

Clauses cited

3 of 30
CCPA CCR §7050 Service Provider and Contractor Obligations

A service provider or contractor shall only process PI on behalf of a business for a business purpose specified in the written contract. It shall not retain, use, or disclose PI for any purpose other than the business purpose, sell or share PI, or combine PI received from one business with PI received from another business or from its own interactions with consumers (with limited exceptions). Service providers must assist the business in responding to consumer requests.

Evidence an auditor accepts: Service provider acknowledgement of restrictions in contract; Subcontractor flowdown agreements; Consumer request assistance procedure (forwarding requests, providing data extracts)
Where it usually falls short: Service provider commingles client data
CCPA/CPRA and its regulations in The Art of Service standards library
CCPA §1798.100(d) Contractual Requirements for Third Parties, Service Providers, and Contractors

A business that collects PI and sells/shares it with a third party or discloses it to a service provider or contractor must enter into a written contract that specifies purposes, prohibits selling/sharing/retaining/using/disclosing PI for any purpose other than those specified, prohibits combining with PI from other sources except as permitted, requires same level of protection, grants the business audit/inspection rights, and requires notification if recipient can no longer meet obligations.

Evidence an auditor accepts: Service provider/contractor agreements containing all required CCPA clauses; Third party data sharing agreements; Vendor inventory classifying each recipient (service provider, contractor, third party)
Where it usually falls short: Legacy vendor contracts missing CPRA-required clauses
CCPA/CPRA and its regulations in The Art of Service standards library
CCPA §1798.150 Private Right of Action for Data Breaches

A consumer whose nonencrypted and nonredacted PI (or email address with password/security question allowing account access) is subject to unauthorized access and exfiltration, theft, or disclosure as a result of the business's violation of duty to implement and maintain reasonable security may bring a civil action for statutory damages of USD 100 to 750 per consumer per incident, or actual damages (whichever is greater), injunctive or declaratory relief, and any other relief the court deems proper. A 30-day notice and cure opportunity is required before action for statutory damages.

Evidence an auditor accepts: Reasonable security program documentation (encryption, access control, monitoring); Incident response plan including 30-day cure handling; Breach notification procedure
Where it usually falls short: Encryption not applied to sensitive elements
CCPA/CPRA and its regulations in The Art of Service standards library

See which clauses your list engages

Paste the list of customer agreements and every row names the clauses behind it. Eight agreements free, no account.

Check my contract list