Resource Center / Tools and Trackers / Summary of CPRA Contractual Obligations

 

Summary of CPRA Contractual Obligations

This chart provides a summary of the CPRA's contractual requirements.


Published: February 2021


Contributor:


The California Privacy Rights Act aims to provide a continuing level of protection for personal information as it flows from covered businesses to third parties, service providers, contractors, and even their sub-processors.

  • Outlining new contractual requirements to govern the sale, sharing, disclosure and receipt of personal information.
  • Placing direct enforceable obligations on service providers and contractors.
  • Mandating due diligence of processing operations.

This resource provides a summary of the CPRA's contractual requirements.

Summary of CPRA Contractual Requirements

Section 1798.100(d)(1-5)

  • expand_more

  • expand_more

  • expand_more

CPRA Sections 1798.140(ag) (“Service provider”) and 1798.140(j) (“Contractor”)

  • expand_more

  • expand_more

*These provisions are associated with a “person” under CCPA’s definition of third parties, which is subject to contractual restrictions and characterized as something other than a third party without any explanation as to how that “person” relates or doesn’t to a “service provider.” It appears that “person” became a “contractor” under CPRA.