CCPA Outsourcing
Definition
CCPA Outsourcing
CCPA outsourcing is the practice of placing California consumers’ personal information with a provider under the state’s privacy law. The service provider designation is the pivot, because it determines whether passing data to your provider counts as a sale.
That word carries more weight in California than anywhere else.
A sale triggers consumer opt-out rights and disclosure duties. Handing records to a vendor looks nothing like selling them — and without the right contractual terms the law may treat it as exactly that.
Get the designation right and the transfer is ordinary processing — get it wrong and you have created opt-out obligations you never intended.
Key takeaways
- The California Consumer Privacy Act of 2018 applies to for-profit businesses meeting set thresholds.
- Proposition 24 created the CPRA, whose additional protections began on 1 January 2023.
- A properly designated service provider relationship keeps a transfer outside the definition of a sale.
- The business, not the service provider, answers consumer requests.
How it works
The law applies by threshold rather than to everyone. California’s Attorney General states it covers for-profit businesses with a gross annual revenue of over $25 million, or that buy, sell or share the personal information of 100,000 or more California residents.
A third trigger catches data brokers: deriving 50% or more of annual revenue from selling California residents’ personal information. Meeting any one threshold brings you inside.
The framework was amended rather than replaced. The Attorney General records that in November 2020 voters approved Proposition 24, the CPRA, which amended the CCPA and added new additional privacy protections that began on January 1, 2023.
Those additions include a right to correct inaccurate information and a right to limit the use of sensitive personal information — both of which your provider has to be able to action operationally.
The outsourcing mechanism is the service provider relationship. The Attorney General notes that the business, not the service provider, is responsible for responding to consumer requests, which places the operational burden squarely on the buyer.
| Consumer right | What your provider must be able to do |
|---|---|
| Right to know | Retrieve and report what it holds |
| Right to delete | Delete on instruction, including backups |
| Right to opt out of sale or sharing | Stop the relevant processing |
| Right to correct | Amend records accurately |
| Right to limit sensitive data use | Restrict processing to permitted purposes |
Every row is a capability, not a clause. A contract promising deletion means nothing if the provider cannot locate records across its systems inside the statutory window.
European law approaches the same problem differently, requiring a processor contract to specify the subject-matter and duration of the processing and related particulars. California regulates the label; Europe regulates the contract.
Examples
California’s framework produces surprises for buyers who assume it mirrors European law, and outsourced arrangements are where the divergence bites. What follows happened to organisations that assumed the certificate answered the question.
A retailer shares customer records with an analytics vendor without service provider terms. The transfer may constitute a sale, which creates opt-out rights nobody planned for.
A company receives a deletion request and forwards it to its offshore provider. The business remains answerable for the response, whatever its compliance outsourcing arrangements say.
A firm subject to both regimes writes one contract for California and another for Europe. The two do different jobs, and merging them tends to satisfy neither.
A business below every threshold discovers a client requires CCPA terms anyway. Contractual reach extends past statutory reach, which is common in regulated outsourcing.
Related terms
Privacy regimes across different jurisdictions use overlapping vocabulary for genuinely different legal structures. The terms below are defined once and walled off from their closest neighbours.
- GDPR (General Data Protection Regulation): the European regime, which regulates the contract rather than the designation.
- TCPA compliance: the US telephone consumer protection rules, a separate regime affecting contact centres.
- Compliance outsourcing: buying regulatory capability, which does not move the duty to respond.
- Data Privacy Act Philippines: the national law where much of this processing physically occurs.
- Vendor management outsourcing: running supplier assurance, including verifying deletion capability.
- Cybersecurity outsourcing: buying security operations, adjacent to but distinct from privacy duties.
- Regulated outsourcing: outsourcing under sector rules that sit above general privacy law.
FAQ
What thresholds bring a business inside the CCPA?
Over $25 million gross annual revenue, handling personal information of 100,000 or more California residents or households, or deriving 50% or more of revenue from selling it.
Is sharing data with a vendor a sale?
Not if the vendor is properly designated a service provider with the required contractual terms. Without them, the transfer can fall inside the definition.
What is the CPRA?
Proposition 24, approved by voters in November 2020. It amended the CCPA and its additional protections began on 1 January 2023.
Who answers a consumer request?
The business. Service providers assist operationally, but responsibility for responding does not transfer with the data.
How does it differ from the GDPR?
California turns on whether a transfer is a sale and how the recipient is designated. Europe prescribes the contents of the processor contract.
Does it apply to offshore providers?
Yes, through the contract. The law reaches the business, which must impose the corresponding obligations on providers wherever they operate.
Compare verified partners in the Outsource Accelerator directory and decide whether your provider is a service provider in law.







Independent




