CCPA/CPRA and its regulations
Rendered when "CCPA/CPRA" is ticked and the customer reaches it. The register cites 3 of its 30 clauses, behind 2 findings: personal data with no dpa shown, audit rights granted, and on the rows it reaches.
Clause text from The Art of Service standards library at compliance.theartofservice.com, read against the held text of each standard and cited to its clause: our close statement of each clause, not the instrument verbatim. Where the UK text is held only as a summary, the EU GDPR article of the same number is quoted and the page says so. Source framework: CCPA/CPRA and its regulations. What it expects of an agreement: the CCPA regime page.
Clauses cited
3 of 30CCPA CCR §7050 Service Provider and Contractor ObligationsA service provider or contractor shall only process PI on behalf of a business for a business purpose specified in the written contract. It shall not retain, use, or disclose PI for any purpose other than the business purpose, sell or share PI, or combine PI received from one business with PI received from another business or from its own interactions with consumers (with limited exceptions). Service providers must assist the business in responding to consumer requests.
Where it usually falls short: Service provider commingles client data
CCPA/CPRA and its regulations in The Art of Service standards library
CCPA §1798.100(d) Contractual Requirements for Third Parties, Service Providers, and ContractorsA business that collects PI and sells/shares it with a third party or discloses it to a service provider or contractor must enter into a written contract that specifies purposes, prohibits selling/sharing/retaining/using/disclosing PI for any purpose other than those specified, prohibits combining with PI from other sources except as permitted, requires same level of protection, grants the business audit/inspection rights, and requires notification if recipient can no longer meet obligations.
Where it usually falls short: Legacy vendor contracts missing CPRA-required clauses
CCPA/CPRA and its regulations in The Art of Service standards library
CCPA §1798.150 Private Right of Action for Data BreachesA consumer whose nonencrypted and nonredacted PI (or email address with password/security question allowing account access) is subject to unauthorized access and exfiltration, theft, or disclosure as a result of the business's violation of duty to implement and maintain reasonable security may bring a civil action for statutory damages of USD 100 to 750 per consumer per incident, or actual damages (whichever is greater), injunctive or declaratory relief, and any other relief the court deems proper. A 30-day notice and cure opportunity is required before action for statutory damages.
Where it usually falls short: Encryption not applied to sensitive elements
CCPA/CPRA and its regulations in The Art of Service standards library
See which clauses your list engages
Paste the list of customer agreements and every row names the clauses behind it. Eight agreements free, no account.
Check my contract list