The California Consumer Privacy Act (CCPA) doesn't care whether your developers sit in Kathmandu or Kansas City. It cares what your contract says.
A vendor handling Californians' personal information for you is a service provider only under a written contract with nine specific terms. Without them, the vendor is legally a third party, and giving it data can count as selling or sharing it.
Personal information is anything that identifies, or could reasonably be linked to, a California consumer or household (Cal. Civ. Code § 1798.140(v)). Names, email addresses, IP addresses and order histories all count. This guide covers the nine terms, the January 2026 changes, and the one federal rule that does care where developers live.
CCPA service provider contract requirements
The CCPA service provider contract requirements come down to one document. It's a written contract containing the nine terms in Cal. Code Regs., tit. 11, § 7051(a), signed before any personal information reaches the vendor. The statute sets the core rules in Cal. Civ. Code § 1798.140(ag). The CCPA Regulations, as amended effective January 1, 2026, give the full list.
Skipping the contract changes the vendor's legal status. Under § 7050(e), a person without a compliant contract "is not a service provider or a contractor under the CCPA." Your disclosure to it "may be considered a sale or sharing," which brings opt-out rights with it.
Both words have legal meanings. Under the CCPA, selling means disclosing personal information to a third party for money or other value (§ 1798.140(ad)). Sharing means disclosing it for ads targeted on a person's activity across other sites and apps (§ 1798.140(ah)). Consumers can tell you to stop both, and that's what opt-out rights mean.
Regulators check. In March 2025 the California Privacy Protection Agency (now CalPrivacy) fined Honda $632,500. One reason: Honda "could not produce contracts" with the ad tech firms receiving its customers' data (CalPrivacy, Honda order, 2025). Tractor Supply's $1,350,000 fine also covered disclosures "without entering into contracts that contain privacy protections" (CalPrivacy, 2025).
Takeaway: ask for the vendor's CCPA addendum before the first access request, not after.
Does CCPA apply to businesses outside California?
Yes, if the business does business in California and meets one test in § 1798.140(d)(1). The first is gross revenue above $26,625,000 last year, the current inflation-adjusted figure (CalPrivacy, 2025). The second is buying, selling or sharing the personal information of 100,000+ consumers or households a year. The third is earning at least half its revenue from selling or sharing it.
Note that the second test says buys, sells or shares. Holding 100,000 customer records for your own service doesn't meet it alone.
What is a service provider under CCPA?
A service provider processes personal information on your behalf, for a business purpose, under a written contract barring any other use (§ 1798.140(ag)(1)). It works for you. It doesn't decide what happens to the data.
Three of the statute's business purposes fit development work (§ 1798.140(e)). They are "Debugging to identify and repair errors," "Performing services on behalf of the business," and maintaining or improving a service you control. Since 2026, every use by the vendor must also be "reasonably necessary and proportionate" (§ 7050(a)).
Here's how it plays out. Say your offshore team fixes a checkout bug by reading production order records. That's processing personal information, so the vendor needs service provider terms. A team building a settings page on made-up test data receives no personal information at all. That follows from the definitions; no regulator has ruled on it.
CCPA contractor vs service provider
A contractor is someone you make personal information available to, under a written contract (§ 1798.140(j)). A service provider processes it on your behalf. The line is thin, and the paperwork barely differs.
A contractor's contract adds one piece: its certification that it understands the restrictions and will comply (§ 1798.140(j)(1)(B)). The statute also makes your monitoring right mandatory for contractors, and term 6 below gives you the same right over service providers. Anyone who is neither is a third party (§ 1798.140(ai)), and disclosures to third parties follow sale and share rules.
| Role | How it gets the data | Contract it needs | Typical example |
|---|---|---|---|
| Service provider | Processes it on your behalf | The nine § 7051(a) terms | A vendor team maintaining your app |
| Contractor | You make it available | Nine terms, plus its certification | Often an individual developer given database access |
| Third party | Neither of the above | § 7053 terms; sale and share rules apply | An ad network receiving customer data |
Takeaway: write one addendum that meets both the service provider and contractor terms, so the label can't trip you up.
The nine required CCPA contract terms
Section 7051(a), as amended from January 1, 2026, lists nine terms every service provider and contractor contract must contain (CCPA Regulations, 2026). Here's what each means for an offshore development team.
| # | Required term | Citation | What it means for a development team |
|---|---|---|---|
| 1 | No selling or sharing the data | (a)(1) | The vendor can't sell your users' data or share it for ad targeting. |
| 2 | Specific business purposes, and data disclosed only for them | (a)(2) | Name the apps and the tasks. "All services under the MSA" fails. |
| 3 | No retaining, using or disclosing it for other purposes | (a)(3) | No reuse for other clients, demos or sample datasets. |
| 4 | No use outside your direct relationship, including combining it with other data | (a)(4) | No merging your customer list with the vendor's own data. |
| 5 | Comply with the CCPA and give the same level of protection | (a)(5) | Reasonable security, plus help with consumer requests, audits and risk assessments. |
| 6 | Your right to check compliance | (a)(6) | Reviews, scans, assessments or audits, at least once every 12 months. |
| 7 | Notice if the vendor can no longer comply | (a)(7) | A new subcontractor it can't bind, or a hosting change it can't secure. |
| 8 | Your right to stop and fix unauthorized use | (a)(8) | Cut access, and get documented proof that deleted users' data is gone. |
| 9 | Help with consumer requests | (a)(9) | Deletion and access requests reach the vendor's copies. |
When you update an older template, keep its "commercial purpose" ban. The 2026 amendment dropped it from the regulation, but the statute still has it (§ 1798.140(ag)(1)(B)).
Writing a specific business purpose
Term 2 is the easiest one to get wrong. Purposes "shall not be described in generic terms, such as referencing the entire contract generally" (§ 7051(a)(2)). Compare two versions (illustrations, not legal drafting):
- Too generic: "Vendor may process Personal Information to provide the Services under the Master Services Agreement."
- Specific: "Vendor may process Personal Information only to fix production defects in the Acme web and iOS apps, run approved database migrations, and handle second-line support tickets."
The audit right in term 6 protects you only if you use it. Under § 1798.145(i)(1), you aren't liable for a service provider's violation unless you knew, or had reason to believe, it would happen. A business that "never enforces the terms of the contract nor exercises its rights to audit" may lose that defense (§ 7051(c)).
Takeaway: put the 12-month review in the calendar the day you sign.
Subcontractor flow-down for offshore teams
If your vendor brings in anyone else to process your data, it must tell you and bind them in writing to the same restrictions (§ 1798.140(ag)(2); § 7051(b)). The rule repeats at every level of the chain.
Offshore delivery often involves more hands than the proposal shows: freelancers for a busy month, a sister company for testing, an agency specialist. Each person with access needs the same terms. Deletion follows the same path, since the vendor must pass deletion requests to its own subcontractors (§ 1798.105(c)(3)).
Takeaway: ask for a named list of who has access, from which country, under which contract. Add it to your vetting checklist for an offshore development partner.
CCPA cross-border data transfer rules
The CCPA has no cross-border transfer rule. There's no approved-country list, no transfer assessment and no requirement to keep data in the US. A vendor in Kathmandu faces the same contract test as one in Kansas City.
Distance still matters in practice. Your contract is the main tool for holding a foreign vendor to its promises, and time zones stretch breach timelines. Customers abroad bring other laws that do restrict transfers, such as the EU's GDPR outsourcing requirements and the PDPA overseas transfer rule under Singapore's Personal Data Protection Act.
One US rule does care where your developers live. It isn't the CCPA.
DOJ bulk data rule for offshore teams
The Justice Department's Data Security Program restricts access to bulk US sensitive personal data by certain countries and people. Outsourced software development is one of its own examples. The rule, 28 CFR Part 202, took effect on April 8, 2025 (Federal Register, 2025).
It names six countries of concern: China (including Hong Kong and Macau), Cuba, Iran, North Korea, Russia and Venezuela (§§ 202.208, 202.601). Covered persons include companies at least 50% owned from those countries or based there, their staff and contractors, and foreigners "primarily resident" there (§ 202.211).
For most data types, a vendor or employment agreement giving a covered person access to bulk data is a restricted transaction. It needs security requirements set by the Cybersecurity and Infrastructure Security Agency (CISA), 10-year records, and, since October 6, 2025, due diligence and audits. The rule's Example 4 is a US company contracting "part of the software development" to a covered person: restricted (§ 202.258).
| Data type (§ 202.205) | "Bulk" means more than |
|---|---|
| Human genomic data (DNA) | 100 US persons |
| Other human 'omic data (such as proteomic or epigenomic) | 1,000 US persons |
| Biometric identifiers | 1,000 US persons |
| Precise geolocation data | 1,000 US devices |
| Personal health data | 10,000 US persons |
| Personal financial data | 10,000 US persons |
| Covered personal identifiers, such as names linked to account numbers | 100,000 US persons |
Human 'omic data (genomic and similar biological data) is stricter. A vendor or employment agreement giving a covered person access to it in bulk is prohibited outright, CISA controls or not (§§ 202.303, 202.401(b)). Government-related data, meaning location data for listed federal sites and data marketed as linked to US government personnel, counts at any volume (§ 202.222).
Here's an illustration. Say your fintech app has 120,000 US users, each record pairing a name with a bank account and payment history. That's financial data on 12 times the 10,000-person threshold. If your vendor's developers lived in a country of concern, they'd need the CISA controls before any access. The same team in Kathmandu, Pune or Ho Chi Minh City isn't covered by residence, though ownership still matters.
A hire you didn't know about or direct, at a vendor that isn't itself covered, doesn't become your restricted transaction (Example 3, § 202.401(c)). But "knowingly" includes what you reasonably should have known (§ 202.230), so ask. Civil penalties reach the greater of $368,136 (the January 2025 figure, adjusted yearly for inflation) or twice the transaction's value (§ 202.1301).
Takeaway: add two questions to vendor diligence. Who owns you? Where does everyone with access live?
2026 CCPA regulation changes for vendors
Regulations in force since January 1, 2026 narrowed what vendors may do and added duties to help you (CalPrivacy, 2025). Every retention, use or disclosure must be "reasonably necessary and proportionate" (§ 7050(a)). Vendors must give your auditor and your risk assessment the facts they hold, without misrepresenting anything (§ 7050(h)).
The new cybersecurity audit rules read like a security spec for an offshore engagement. Where applicable, the audit must assess (§ 7123(c)):
- phishing-resistant multi-factor authentication (such as hardware security keys or passkeys) for service providers and contractors;
- vendor access limited to what the contract's purposes need;
- "Secure development and coding best practices, including code-reviews and testing";
- oversight of service providers' compliance with § 7051.
Audits apply to businesses that cross the revenue threshold and process data on 250,000+ consumers, or sensitive data on 50,000+ (§ 7120(b)). Businesses earning at least half their revenue from selling or sharing data are covered too. First reports are due between April 1, 2028 and April 1, 2030, depending on revenue (§ 7121(a)).
One more change is coming. SB 923, signed on September 27, 2026, extends the right to delete to data a business got from third parties, from January 1, 2027 (CalPrivacy, 2026). Check that your vendor's deletion reaches staging copies and logs. Backups can wait until they're restored or next used (§ 7022(d)).
Takeaway: if your addendum predates 2026, add the audit and risk-assessment cooperation clause.
Keep personal information out of development
The cheapest CCPA contract is one that rarely has to work. Design the engagement so developers don't need personal information, and the contract covers only a few controlled exceptions.
- Build and test on synthetic data (realistic records that belong to no one) or properly deidentified data.
- Keep production access off by default. Grant it per ticket, logged and expiring.
- Mask personal fields in logs, error reports and analytics exports.
- Never copy production databases into staging or onto laptops.
Deidentified data has its own paperwork. The business must publicly commit not to reidentify it and contractually bind every recipient to the same rules (§ 1798.140(m)). So the vendor contract needs a no-reidentification clause for deidentified copies of real data. Purely synthetic records need none.
Picture a 10-person offshore team building on synthetic data, with two named on-call engineers holding time-limited production access. Eight people never touch personal information. Your access reviews shrink to two accounts.
If you'd like help drawing that line, a free 30-minute scoping call can map which parts of your roadmap an offshore team can build without personal information.
Vendor breach notice and damages
A vendor holding your data must report a breach "immediately following discovery" (Cal. Civ. Code § 1798.82(b)). Since January 1, 2026, you then have 30 calendar days to notify affected Californians (§ 1798.82(a)(2)(A), amended by SB 446). Above 500 residents, a sample notice goes to the Attorney General within 15 days of notifying them.
"Immediately" is vague across a nearly 14-hour gap, so put hours in the contract. Here's an illustration. Your vendor in Kathmandu finds an exposed staging database at 10:00 am on Tuesday, November 10, 2026. In San Francisco it's 8:15 pm on Monday, November 9 (Nepal is UTC+5:45; Pacific Standard Time is UTC-8). See how Kathmandu and US working hours line up.
With a 24-hour clause, you hear by 8:15 pm Tuesday, Pacific time. Notified on November 10, you owe consumer notices by Thursday, December 10. Send them that day, and the Attorney General's sample is due by Friday, December 25. The statute allows delay for law enforcement or to determine scope.

Consumers can also sue. If a breach of certain data results from a failure to keep reasonable security, each Californian can claim $107 to $799 per incident (Cal. Civ. Code § 1798.150; CalPrivacy, 2025). Actual damages apply if higher. The covered data is narrow. It's a name combined with an ID number, an account number plus its access code, or medical or biometric data. An email with its password also counts (§ 1798.81.5(d)(1)).
The arithmetic gets large fast. Say a staging copy at your vendor holds 40,000 California customers' names and driver's license numbers, unencrypted, and it's stolen. The range is 40,000 × $107 = $4,280,000 to 40,000 × $799 = $31,960,000. At 100,000 customers, it's $10,700,000 to $79,900,000. That's the range a court works within, not a forecast.

The claim runs against the business whose security duty failed. The cautious reading is that your data in a vendor's environment is still your exposure. CalPrivacy took the same line on vendor tools in a different context. It fined Todd Snyder $345,178 over a misconfigured privacy portal and said "the buck stops with the businesses that use them" (CalPrivacy, 2025).
Takeaway: write "within 24 hours of discovery" and named contacts on both sides into the addendum.
Does CCPA require a data processing agreement?
Not by that name. The CCPA requires a written contract with the § 7051 terms. The usual home is a CCPA addendum, or a US data processing addendum (DPA), attached to the master services agreement.
On its own, a DPA written for the EU's General Data Protection Regulation (GDPR) usually falls short. Article 28 of the GDPR asks for the processing's purpose, but not the CCPA's sale and share ban, its specific-purpose test, or its combining ban. Nor does it require the CCPA's contractor certification. Add a California section, and keep it in the same contract set as your IP assignment clause.
When offshore development is the wrong choice
Offshore development isn't right for every product holding personal information. Four situations argue against the usual setup:
- The work can't be separated from sensitive data. If developers query health or financial records daily, the controls can cost more than the rates save.
- The chain touches a country of concern. Ownership or staff there, plus data over a DOJ threshold, means a separate compliance program.
- Nobody can supervise. If no one will run the 12-month review, a vendor with production access is a risk you can't manage.
- You're early and small. Below the CCPA thresholds, a heavy program may be premature. The contract terms are still cheap insurance.
CCPA service provider contract checklist
Use this before any offshore developer gets access to systems holding California residents' data.
Before access
- To do: Check the CCPA thresholds, and whether enterprise customers require the terms anyway
- To do: Sign a CCPA addendum with all nine § 7051(a) terms, plus the statute's "commercial purpose" ban
- To do: Describe the business purposes specifically: apps, tasks, environments
- To do: Add the contractor certification for individuals given access
- To do: Get a named list of people and subcontractors with access, and their countries
- To do: Ask who owns the vendor (the DOJ rule)
Access design
- To do: Build and test on synthetic or deidentified data, with a no-reidentification clause
- To do: Keep production access off by default: per ticket, logged, expiring
- To do: Require phishing-resistant multi-factor authentication for vendor accounts
Running and ending the engagement
- To do: Book the 12-month compliance review, and keep the evidence
- To do: Route deletion and access requests to the vendor and its subcontractors
- To do: Set breach notice in hours, with named contacts on both sides
- To do: Require deletion of all data at exit, with written confirmation
This is general information, not legal advice.
