Skip to main content
14 speakers. 7 enterprise risk teams. One day in Charlotte, Oct. 22.Save My Seat
BlackKite: Home
Menu
Back to Glossary

CCPA (California Consumer Privacy Act)

The California Consumer Privacy Act is a U.S. state privacy law granting California residents rights over the collection and use of their personal data. Organizations that share consumer data with third-party vendors must ensure those vendors handle data in compliance with CCPA requirements. It is one of the growing body of U.S. state-level privacy regulations that drive third-party risk management obligations.

Which Vendor Categories Does CCPA Hold Businesses Accountable For?

CCPA sorts a business's outside relationships into three categories, and the label determines both the contract terms required and the liability if something goes wrong. Under the law, an outside company that touches a California resident's personal information falls into one of these groups:

  • Service providers: process data under a written contract restricted to the business's stated purpose, and can't sell the data, use it for their own purposes, or combine it with data from other sources.
  • Contractors: a category the CPRA added, facing similar restrictions but typically entering the relationship without collecting data directly from consumers.
  • Third parties: the default category. Without a compliant contract, any vendor relationship is treated as a third party, which triggers the same opt-out and disclosure duties as if the business had sold the data outright.

Section 7051 of the CCPA regulations lists the specific terms every service provider or contractor contract needs. Miss one, and the relationship can default into the stricter third-party category without anyone intending it to.

Who CCPA Covers and How CPRA Expanded It

The California Privacy Rights Act (CPRA) expanded CCPA's vendor duties in 2023. The law covers any for-profit business that collects California residents' personal information and meets revenue or data-volume thresholds, and its reach extends to every vendor, processor, and subcontractor that business shares data with.

Enforcement Has Moved From Warnings to Real Penalties

The California Privacy Protection Agency (CPPA) enforces the law and has moved from warnings to real penalties. In September 2025, the CPPA fined Tractor Supply $1.35 million, its largest penalty to date, citing in part vendor contracts that lacked terms the CCPA requires. For a company managing hundreds of vendor relationships, CCPA turns contract housekeeping into an enforcement risk.

What Happens When a Vendor Contract Falls Short of CCPA?

A California business remains liable for a vendor's noncompliance unless it can show the contract met CCPA's specific requirements and that it didn't know the vendor intended to violate them. In September 2025, the CPPA fined Tractor Supply $1.35 million, one of the largest CCPA penalties issued to date. Regulators cited several failures, including a job applicant privacy notice that lacked required disclosures and contracts with advertising technology vendors that were missing mandatory CCPA terms.

The CPPA made the same point in its May 2025 action against Todd Snyder, faulting the retailer for deferring to a vendor's privacy tool without validating that it worked. Deferring to a vendor's own privacy practices, without verifying them, leaves the hiring business exposed regardless of what was promised. A signed contract establishes what the vendor promised. It says nothing about whether the vendor is actually keeping that promise six months later.

How Is CCPA Different From GDPR for Vendor Oversight?

CCPA and GDPR both regulate how vendors handle personal data, but they start from different premises and bind different companies. GDPR applies to any organization processing EU residents' data, uses an opt-in consent model in most cases, and caps fines at €20 million or 4% of global annual turnover, whichever is higher. CCPA applies to for-profit businesses that meet California-specific revenue or data-volume thresholds, leans on an opt-out and disclosure model, and is enforced by both the CPPA and the California Attorney General.

A vendor operating in both markets typically needs separate contract language for each, since a GDPR-compliant data processing agreement doesn't automatically satisfy Section 7051's mandatory contract terms. Teams building a broader regulatory risk program, the kind that feeds a wider TPRM program for cyber risk, need to track both as genuinely distinct obligations, each with its own compliance checklist.

What Does a CCPA-Compliant Contract Fail to Catch?

A compliant vendor contract proves what a vendor promised. What a vendor is actually doing is a separate question, and that gap is where most third-party privacy incidents originate. California law requires businesses to notify residents when their data has been compromised, but a business can only report what it discovers. Black Kite's Third-Party Breach Report 2026 estimates roughly 26,000 additional Shadow Victims, companies affected by a vendor breach but never publicly named, often because the vendor disclosed aggregate customer impact without identifying which customers were affected.

That's the practical limit of contract-based oversight. Nine mandatory terms in a due diligence file don't tell a business whether a vendor's credentials are already circulating on the dark web or whether its systems carry an unpatched, exploited vulnerability. A data breach at a service provider can sit undisclosed for months while the paperwork stays perfectly in order.

How Does Black Kite Support CCPA Vendor Oversight?

Black Kite doesn't replace CCPA's contract requirements, but it closes the gap between what a vendor signed and what continuous monitoring shows it's actually doing today. Vendor risk monitoring tracks a vendor's external security posture continuously, so a business gets more than the vendor's own word between audit cycles. Vendor compliance management centralizes vendor compliance documentation and assessment history, producing audit-ready reports a business can provide quickly if the CPPA comes asking.

Neither capability negotiates a vendor's contract terms, and neither replaces the compliance management work of tracking which frameworks apply to which vendor. Both make it harder for a vendor's actual practices to drift silently away from what that contract promised.

See also: A CCPA Perspective Into Third-Party Risk Management