Contract-first privacy governance for California operators

Data Processing & Security Addenda (DPAs)

Vendor onboarding should not create accidental “sale” or “sharing” outcomes under the California Consumer Privacy Act (CCPA). The operational failure is usually definitional, a recipient is treated as a service provider or contractor in procurement, but behaves like a third party in marketing, analytics, or adtech. “Sale” can include non-monetary valuable consideration under Cal. Civ. Code § 1798.140(ad). Law Laguna drafts and negotiates Data Processing and Security Addenda (DPAs) that lock the intended data-flow classification into enforceable restrictions, cooperation duties, and security boundaries.

Prevent vendor misclassification from becoming sale or sharing

California Consumer Privacy Act (CCPA) compliance turns on how personal information flows are classified and documented, not only on whether a vendor is “trusted.” The statute and regulations distinguish a “sale,” “sharing” for cross-context behavioral advertising, and disclosures for a “business purpose,” each with different notice and opt-out mechanics. The definition of “sharing” targets cross-context behavioral advertising under Cal. Civ. Code § 1798.140(ah), which frequently intersects with cookies, software development kits, and identity signals. If a contract does not impose the service provider or contractor restrictions that match the intended purpose limitation, the recipient can be treated as a third party. Law Laguna builds DPAs that are implementation-aware, so procurement, security, and privacy notices align with actual vendor behavior.

We map each vendor use case to the correct CCPA category, then draft clauses that operational teams can enforce. We align the DPA with your Notice at Collection and privacy policy disclosures to avoid mismatch escalations. We set clear cooperation and security obligations that support consumer access, deletion, and correction workflows.

  • Classify data transfers to preserve a business purpose disclosure, and avoid accidental sale or sharing outcomes tied to cross-context behavioral advertising.
  • Enforce opt-out preference signal logic by contract, so vendors honor “Do Not Sell or Share My Personal Information” constraints in practice.
  • Limit Sensitive Personal Information (SPI) processing to Permitted SPI Purposes, and support the “Limit the Use of My Sensitive Personal Information” pathway when needed.

A DPA is only effective when it matches real data flows, vendor features, and your public-facing notices. We draft for definitional accuracy and operational follow-through.

Counsel for Compliance-Minded Operators

Based in Laguna Beach and serving Southern California teams that need contract-ready privacy governance. We also support California clients statewide through remote-first vendor contracting workflows.

General Counsel (or Fractional GC)

You need DPAs that preserve your intended classification, service provider or contractor versus third party, across marketing, analytics, and customer support tools. The hidden issues show up when a cookie or software development kit enables cross-context behavioral advertising, creating “sharing” and opt-out link obligations you did not plan for.

  • Negotiate a DPA to keep analytics vendors from acting as third parties.
  • Align a vendor’s security exhibit with your incident escalation path and consumer request timelines.
  • Redline a platform’s addendum that expands secondary use beyond your Notice at Collection.

Head of Procurement / Vendor Management

You are moving fast on onboarding and renewals, but vendor templates often bury broad use rights that conflict with “service provider” restrictions. The hidden risk is a mismatch between “Do Not Sell or Share My Personal Information” commitments and what the vendor’s product actually does, which forces mid-cycle renegotiation and delayed implementations.

  • Standardize procurement playbooks for service provider and contractor DPAs.
  • Resolve a renewal where a vendor refuses purpose limitation and subprocessor controls.
  • Handle an adtech addendum that implies cross-context behavioral advertising services.

Director of Information Security / Security & Compliance

You need contract language that translates security expectations into measurable obligations, including incident notice paths, access controls, and cooperation. The hidden risk is unclear boundaries on retention, portable copy production, and consumer request support, which creates internal escalations when access, deletion, or correction requests arrive.

  • Add breach cooperation language that supports security containment and consumer-right response workflows.
  • Require retention criteria that matches Notice at Collection statements and operational deletion capability.
  • Set audit and assurance terms that match the vendor’s role and risk profile.

General Counsel (or Fractional GC)

You need DPAs that preserve your intended classification, service provider or contractor versus third party, across marketing, analytics, and customer support tools. The hidden issues show up when a cookie or software development kit enables cross-context behavioral advertising, creating “sharing” and opt-out link obligations you did not plan for.

  • Negotiate a DPA to keep analytics vendors from acting as third parties.
  • Align a vendor’s security exhibit with your incident escalation path and consumer request timelines.
  • Redline a platform’s addendum that expands secondary use beyond your Notice at Collection.

Head of Procurement / Vendor Management

You are moving fast on onboarding and renewals, but vendor templates often bury broad use rights that conflict with “service provider” restrictions. The hidden risk is a mismatch between “Do Not Sell or Share My Personal Information” commitments and what the vendor’s product actually does, which forces mid-cycle renegotiation and delayed implementations.

  • Standardize procurement playbooks for service provider and contractor DPAs.
  • Resolve a renewal where a vendor refuses purpose limitation and subprocessor controls.
  • Handle an adtech addendum that implies cross-context behavioral advertising services.

Director of Information Security / Security & Compliance

You need contract language that translates security expectations into measurable obligations, including incident notice paths, access controls, and cooperation. The hidden risk is unclear boundaries on retention, portable copy production, and consumer request support, which creates internal escalations when access, deletion, or correction requests arrive.

  • Add breach cooperation language that supports security containment and consumer-right response workflows.
  • Require retention criteria that matches Notice at Collection statements and operational deletion capability.
  • Set audit and assurance terms that match the vendor’s role and risk profile.

DPA Drafting, Retrofit, and Data-Flow Classification

Law Laguna supports teams that need vendor paperwork to reflect the correct CCPA and California Privacy Rights Act (CPRA) posture. Our work product is designed to be adopted by legal, procurement, privacy, and security stakeholders without rewriting your entire commercial agreement stack.

DPA Drafting and Negotiation

  • DPA drafting for CCPA/CPRA vendor engagements (service provider / contractor alignment and restrictions). We draft DPAs that designate the correct role, constrain processing to business purposes, and define “not a third party” treatment where the statute and regulations permit. We also add implementation-ready cooperation and security provisions that operational teams can enforce.
  • Consumer rights operational support clauses. We add contract terms that require vendor assistance for access, delete, and correct requests, including portable copy production and verification cooperation. The clauses are written to reduce friction in internal escalations and preserve response timelines.
  • Strategic Assessment: Website Terms, Policies & Consumer-Facing Agreements (Strategic Assessment). We review how your DPAs interact with public-facing notices and online workflows, including opt-out and limitation links. The goal is traceability between what you state and what vendors actually do.
  • Notice-to-contract alignment package. We map DPA restrictions to your Notice at Collection and privacy policy, covering categories, purposes, retention framing, and link posture. This reduces the risk of collecting undisclosed categories or using data for incompatible purposes without a new notice.

Retrofit and Gap Review for Existing Vendors

  • Vendor contract retrofit project (gap review + redlines). We review existing master service agreements and addenda for service provider or contractor requirements, purpose limitation, and prohibitions that support business purpose disclosures rather than sale or sharing, where appropriate. We deliver redlines and a negotiation plan that fits procurement cadence.
  • Data transfer classification memo: sale vs. sharing vs. business-purpose disclosure analysis tied to each vendor use case. We analyze each data flow, including cookies and identifiers, against the statutory definitions of sale and sharing. The memo is written for auditability so stakeholders can document why a vendor is treated as a service provider, contractor, or third party.
  • DPA drafting for CCPA/CPRA vendor engagements (service provider / contractor alignment and restrictions). For high-volume vendor portfolios, we create standard DPA templates and fallback positions that fit your procurement playbook. This reduces renegotiation time while keeping definitional accuracy intact.
  • Consumer rights operational support clauses. For customer support and CRM tooling, we add cooperation duties that align with your intake and fulfillment process. This includes provisions for retrieving data across systems and producing a portable copy when required.

Data Use Boundaries and Sensitive Personal Information Controls

  • Sensitive Personal Information (SPI) permitted-purpose limitations. We restrict SPI use and disclosure to Permitted SPI Purposes, and align contract language to limitation mechanics when SPI is used beyond those purposes. This supports proportionality expectations and reduces downstream feature creep.
  • Data minimization + purpose limitation. We require processing that is reasonably necessary and proportionate to the stated purposes, then tie those purposes to the vendor’s documented services. The clauses help avoid secondary uses that conflict with your notices and consumer expectations.
  • Consent/notice gating for new or incompatible purposes. We include clear triggers for when a new notice or consent is required before expanding processing. This supports change management when product teams enable new vendor features.
  • Retention period / retention criteria alignment. We set retention periods or criteria that track your Notice at Collection statements and your operational deletion capability. This reduces disputes when data needs to be deleted due to a consumer request or vendor offboarding.

Notice and Workflow Alignment

  • Notice-to-contract alignment package. We link your disclosures about categories, purposes, sale or sharing posture, and retention to DPA restrictions that vendors must follow. This mitigates misalignment between public documents and actual processing.
  • Data transfer classification memo: sale vs. sharing vs. business-purpose disclosure analysis tied to each vendor use case. We create a practical record of how each vendor is classified and why. This supports internal governance and reduces inconsistent answers across legal, marketing, and information security.
  • Vendor contract retrofit project (gap review + redlines). We prioritize quick wins for high-impact vendors such as analytics, advertising, and customer engagement platforms. The project focuses on the specific clauses that drive classification and notice obligations.
  • Strategic Assessment: Website Terms, Policies & Consumer-Facing Agreements (Strategic Assessment). We check that “Do Not Sell or Share My Personal Information” and “Limit the Use of My Sensitive Personal Information” implementations match your vendor posture. This closes the loop between contracts and consumer-facing workflows.

Sale, sharing, and business purpose, draft to the correct category

Under the California Consumer Privacy Act (CCPA), a “sale” can occur even without money changing hands if personal information is transferred for valuable consideration under Cal. Civ. Code § 1798.140(ad). “Sharing” is separately defined for cross-context behavioral advertising under Cal. Civ. Code § 1798.140(ah). A disclosure for a “business purpose” is treated differently under Cal. Civ. Code § 1798.140(e) and is commonly the intended posture for operational vendors. The risk is that vendor features, especially cookie-based tracking, can push a relationship into third-party behavior if the contract and implementation do not match.

California regulations treat certain cross-context behavioral advertising arrangements as third-party processing even when a vendor is otherwise positioned as a service provider, which changes notice and opt-out mechanics. Notice at collection rules also apply regardless of how personal information is collected, including passive collection, under Cal. Civ. Code § 1798.175. For many businesses, workforce and business-to-business contact data flows make DPAs relevant across human resources systems, procurement tooling, and customer operations.

  • Identify each personal information transfer, including unique identifiers and cookie-level signals, then classify it as sale, sharing, or business purpose disclosure.
  • Designate the vendor role as service provider or contractor only when the contract imposes purpose limitation and other required restrictions.
  • Prohibit cross-context behavioral advertising services when you intend service provider or contractor treatment, and confirm product settings support that position.
  • Limit Sensitive Personal Information (SPI) to permitted purposes, and document whether limitation notices and links are required for the use case.
  • Align retention periods or retention criteria with your Notice at Collection, and confirm the vendor can execute deletion at end of term and upon request.
  • Require cooperation with access, deletion, and correction requests, including secure retrieval and portable copy production when applicable.

We draft DPAs to support accurate classification, consistent notices, and executable privacy operations under California law.

officebgposter-1.jpg

California Regulatory Compliance

DPAs matter under the California Consumer Privacy Act (CCPA) because vendor contracts often determine whether a recipient is treated as a service provider, contractor, or third party, which directly affects whether a transfer is a “sale” under Cal. Civ. Code § 1798.140(ad) or “sharing” for cross-context behavioral advertising under Cal. Civ. Code § 1798.140(ah). If selling or sharing occurs, the opt-out right and link obligations in Cal. Civ. Code §§ 1798.120(b) and 1798.135 apply, with presentation requirements in Cal. Code Regs. Title 11, § 7013 and alternative “Your Privacy Choices” options under Cal. Code Regs. Title 11, § 7015.

DPAs also need to track notice obligations and purpose limitation rules. Notice at collection must cover categories, purposes, whether information is sold or shared, and retention period or criteria under Cal. Civ. Code § 1798.100(a) and Cal. Code Regs. Title 11, § 7012. California also prohibits collecting undisclosed categories and using information for incompatible purposes without a new notice under Cal. Code Regs. Title 11, §§ 7002(f) and 7012(d). Where Sensitive Personal Information (SPI) is involved, limitation mechanics and permitted-purpose constraints arise under Cal. Civ. Code § 1798.121(a) and Cal. Code Regs. Title 11, § 7027(m).

Flexible Legal Counsel

DPA Drafting and Redlines

  • Review your vendor template, map the data flow classification, and deliver redlines that implement service provider or contractor restrictions where appropriate.
  • Negotiate priority clauses, including purpose limitation, cross-context behavioral advertising prohibitions, retention, and consumer request cooperation.
  • Finalize execution-ready addenda that align with your procurement process and the master service agreement.

Vendor Portfolio Retrofit

  • Inventory key vendors, then triage by data type, identifiers, Sensitive Personal Information (SPI), and cookie-based tracking exposure.
  • Standardize fallback language, then run a repeatable gap review and redline cycle across renewals and new onboarding.
  • Deliver a classification memo and contracting matrix that procurement and security teams can apply consistently.

Privacy Operations Alignment

  • Map DPA terms to Notice at Collection and privacy policy disclosures, including categories, purposes, retention framing, and link posture.
  • Add implementation clauses for access, deletion, and correction requests, plus escalation and cooperation mechanics with vendors.
  • Coordinate with security requirements and incident response procedures so contract duties match operational reality.

Engagements are structured to fit procurement cadence and internal approval paths. We keep drafting grounded in the California Consumer Privacy Act (CCPA) definitions and the way your vendors actually process data.

California Privacy and Contracts Network

Build a contract-to-notice system that holds up in practice

Data Processing & Security Addenda (DPAs) FAQs

What contract terms are required to treat a vendor as a service provider or contractor under the California Consumer Privacy Act (CCPA)?

It depends, the contract must control personal information assets such as identifiers, online activity, customer records, and in some cases Sensitive Personal Information (SPI). The scope is role definition plus enforceable restrictions, including processing limited to specified business purposes, limits on retention, and cooperation duties for access, deletion, and correction requests. The hidden risk is calling a vendor a “service provider” in a template while leaving broad reuse rights that make the recipient function as a third party. Law Laguna drafts and redlines DPAs to match Cal. Civ. Code §§ 1798.100 to 1798.199.100 and Cal. Code Regs. Title 11, §§ 7000 to 7304 expectations for classification, notices, and operational workflows.

Does sharing data with a vendor count as a “sale” under the California Consumer Privacy Act (CCPA)?

It depends, sharing personal information assets such as cookie identifiers, device identifiers, household-level identifiers, and online activity data can be a “sale” even without money. The scope turns on whether the transfer is for “valuable consideration” and whether an exception applies, versus a disclosure for a defined business purpose. The hidden risk is assuming no payment means no “sale,” even though Cal. Civ. Code § 1798.140(ad) covers non-monetary consideration and common adtech benefits. Law Laguna prepares a data transfer classification memo, then drafts the DPA and notice alignment needed to support the intended posture under Cal. Civ. Code § 1798.140(ad), § 1798.140(ah), and § 1798.140(e).

When do we need a “Do Not Sell or Share My Personal Information” link for vendor-related tracking?

You need the link when your data flows involve personal information assets such as online identifiers, cookie IDs, and browsing activity that are sold or shared. The scope is consumer-facing implementation plus vendor controls, meaning the opt-out must be honored across the relevant tools and recipients and reflected in your opt-out notice. The hidden risk is treating a cross-context behavioral advertising vendor as a service provider when Cal. Code Regs. Title 11, § 7050(b) can treat that function as third-party behavior, triggering opt-out requirements. Law Laguna aligns your DPA restrictions and technical settings with Cal. Civ. Code §§ 1798.120(b) and 1798.135 and Cal. Code Regs. Title 11, § 7013 so your link obligations match actual processing.

What must our Notice at Collection say about retention periods and categories if vendors receive the data?

Notice at Collection must address personal information assets such as categories collected, purposes, whether sold or shared, and retention period or retention criteria, including when vendors receive or process the data. The scope is traceability, your notice statements must match the DPA’s purpose limitation, retention, and deletion mechanics so the vendor can comply throughout the lifecycle. The hidden risk is collecting new categories through a vendor feature without updating the notice, which conflicts with Cal. Code Regs. Title 11, §§ 7002(f) and 7012(d) restrictions on undisclosed categories and incompatible purposes. Law Laguna maps vendor data elements to Cal. Civ. Code § 1798.100(a) and Cal. Code Regs. Title 11, § 7012, then drafts retention and deletion terms that operations can execute.

How should a DPA handle Sensitive Personal Information (SPI) and “Permitted SPI Purposes”?

Sensitive Personal Information (SPI) assets can include precise geolocation, government identifiers, and other statutorily defined SPI categories. The scope is to restrict use and disclosure to Permitted SPI Purposes, document reasonable necessity and proportionality, and set limitations that integrate with your consumer-facing limitation notices and internal workflows. The hidden risk is allowing a vendor to use SPI for secondary analytics or profiling outside permitted purposes, which can trigger limitation obligations and create notice-to-contract mismatches. Law Laguna drafts SPI clauses tied to Cal. Civ. Code § 1798.121(a) and Cal. Code Regs. Title 11, § 7027(m), with operational controls that support limitation requests and change management.

If a vendor provides cross-context behavioral advertising, can we still treat them as a service provider or contractor?

No, providing cross-context behavioral advertising services with personal information assets like cookie identifiers, device identifiers, and online activity typically pushes the relationship into third-party treatment for that function. The scope is to decide whether to classify the flow as “sharing,” implement opt-out mechanisms, and adjust contract and product settings accordingly rather than relying on labels. The hidden risk is keeping a “service provider” addendum in place while the vendor runs cross-context behavioral advertising, which can undermine your classification and notice posture. Law Laguna applies Cal. Civ. Code § 1798.140(ah) and the restrictions referenced in Cal. Civ. Code § 1798.140(e)(6), (j)(1)(A)(ii), (ag)(1)(B), and Cal. Code Regs. Title 11, § 7050(b) to draft defensible terms.

Do employees and job applicants count as “consumers” for purposes of DPAs with human resources vendors in California?

Yes, employees, applicants, and contractors can fall within consumer scope, and DPAs may cover personal information assets such as payroll identifiers, benefits data, recruiting profiles, and device identifiers used for workforce tools. The scope is to ensure human resources vendors follow purpose limitation, retention boundaries, and cooperation duties for access, deletion, and correction workflows that your organization must manage. The hidden risk is treating human resources data as outside the California Consumer Privacy Act (CCPA) program, which can lead to missing notices, unclear retention criteria, and vendor reuse beyond business purposes. Law Laguna aligns human resources DPAs with Cal. Civ. Code § 1798.140(i), Cal. Code Regs. Title 18, § 17014, and the notice-at-collection structure in Cal. Civ. Code § 1798.100(a) and Cal. Code Regs. Title 11, § 7012.

lagunabgposter-1.jpg

Stop accidental sale or sharing outcomes in vendor contracts

Misclassification and loose DPA language often surface later, during cookie audits, renewal negotiations, or consumer request escalations. When notices, links, and vendor behavior do not match, teams lose time reconciling public disclosures with actual processing. The fix is contract-first classification, then enforceable restrictions and cooperation duties that operations can execute.

We start with a focused intake on your vendor use case, data elements, and intended posture, service provider, contractor, or third party. Then we deliver redlines, a classification memo if needed, and an alignment checklist for notices and workflows.