Skip to content
← Back to blog
Security·October 8, 2026·8 min read

Does your agency's subcontractor need its own CCPA contract? What section 7051(b) says

If your agency touches a California client's customer data, the CCPA says the contract has to reach every subcontractor you bring in. Here is the text.

If your agency touches a California client's customer data and you hand part of the work to a subcontractor, the CCPA regulations say you need a written contract with that subcontractor, and they say what it has to contain. Most agency subcontracts are a rate, an NDA and an IP clause. The privacy terms usually aren't there.

You won't feel the gap while the project is going well. You'll feel it when the client's privacy counsel sends a vendor questionnaire with a line that reads "list every subprocessor and attach the flow-down terms."

This is a builder's read, not legal advice. Your counsel decides what applies to you. This is what the regulation says, so you know what to ask them.

Does the CCPA apply to my agency at all?

Only if you handle personal information for a client. The statute defines a "service provider" as a person that processes personal information on behalf of a business and receives it from or on behalf of that business for a business purpose, under a written contract. That wording is in Civil Code section 1798.140(ag)(1), as published by the California Privacy Protection Agency (CPPA) in its CCPA statute PDF, posted in January 2025.

An agency lands in that definition more easily than most owners expect. Production database access counts. So does a customer-support inbox you triage, a CRM migration, an analytics export you build a report from, or a test run against a copy of live data. If the work never touches a real person's record, none of this applies, and I'll come back to that.

What does the law say about subcontractors?

Two sources say it, and they agree. The statute, in section 1798.140(ag)(2), says that if a service provider "engages any other person to assist it in processing personal information for a business purpose on behalf of the business," it "shall notify the business of that engagement." The engagement must also be "pursuant to a written contract binding the other person to observe all the requirements" that apply to the service provider. The same paragraph reaches one level further down: if that other person engages someone, the same notice and contract rules apply again.

The CPPA's regulations, in section 7051(b) of Title 11 as effective 1 January 2026, say it from the contract side: a service provider "that subcontracts with another person in providing services to the business... shall have a contract with the subcontractor that complies with the CCPA and these regulations, including subsection (a)."

So there are two duties, and agencies tend to remember only one. You need the contract, and you need to tell the client the subcontractor exists. The statute doesn't say when the notice has to happen, so the safe habit is to put the subcontractor's name in your client agreement before they get access, not after.

What does the subcontract have to say?

Subsection (a) of section 7051 lists nine things the service-provider contract must do. Subsection (b) pulls all of them down to your subcontractor. Here they are in the order the CPPA's regulation text (effective 1 January 2026) gives them, with what each means in a subcontract.

Section 7051(a) itemWhat it means in your subcontract
(1) No selling or sharingThe subcontractor may not sell or share the personal information
(2) Specific business purposeName the task, like "build the loyalty-points export," not "the services under the agreement"
(3) No other useNo keeping, using or disclosing it for any other purpose
(4) Stay inside the relationshipNo combining it with data from another client or source
(5) Same privacy protectionComply with the CCPA, cooperate on consumer requests, and help with the client's cybersecurity audit, risk assessment and ADMT requirements
(6) Right to checkYour client, and so you, can review, scan and test at least once every 12 months
(7) Duty to warnTell you when they can no longer meet their obligations
(8) Right to stop and fixYou can require them to stop unauthorized use and prove deletion
(9) Consumer requestsThey must help you act on a request, or you must tell them what to do

Item (2) is the one with a trap in it. The regulation says the purpose "shall not be described in generic terms, such as referencing the entire contract generally." A subcontract that says "for the purposes of the Statement of Work" doesn't meet it.

A worked example: the loyalty-portal export

Picture a 14-person agency rebuilding the loyalty-program portal for a California retailer. The agency subcontracts two engineers to build the data export and import feature, and to do it they need a recent copy of the customer table: names, emails, purchase history.

The agency's contract with the retailer has the privacy terms. The agency's contract with the two engineers is a day rate, an NDA and an assignment clause (the kind covered in who owns code a subcontractor writes). Check it against the table and three things fail.

There's no specific purpose, so item (2) fails. There's no right for anyone to audit the engineers' laptops or cloud accounts, so item (6) fails, and the agency can't give the retailer an audit right it doesn't hold downstream. And when a customer sends a deletion request, nothing obliges the engineers to find and delete the export file sitting on a drive, so item (9) fails.

My view is that the audit right and the deletion path are the two that bite. The purpose language is easy to fix with an afternoon of drafting. Deleting data you can't locate isn't.

How do you keep this small, and what will clients ask?

Don't hand over the data

A flow-down contract is the minimum for a subcontractor who has to see real records. For most subcontracted work they don't. The export feature above can be built against masked or synthetic data, with the real records staying in the client's environment under access the agency controls and can revoke.

I'd defend this on a sales call: an agency that gives subcontractors production personal information by default has chosen the most expensive way to run the project. You still need the contract for the incidental cases, such as a bug that only reproduces on real data. But a subcontractor who never holds the data can't leave a copy of it behind.

Why clients will ask for your terms

Section 7051(c) is aimed at your client, not at you, but it explains the questionnaires. It says that whether a business does due diligence on its service providers "factors into whether the business has reason to believe" they're misusing data. Its example is a business that "never enforces the terms of the contract nor exercises its rights to audit or test" which "might not be able to rely on the defense that it did not have reason to believe" a vendor would misuse the data.

Read that from the client's side. They need evidence they checked. Your signed flow-down terms, a current list of subcontractors, and a record of the last 12-month review are that evidence. An agency that has it ready answers the questionnaire in an hour. One that doesn't spends a week assembling it, with a client waiting on the answer.

When none of this is the answer

Three cases. If the engagement never touches personal information, a privacy flow-down is paperwork you can skip, and a clean NDA is enough. If your client isn't a business covered by the CCPA, the regulation's obligations don't come to you through them. And a table of nine items isn't a contract: have a lawyer draft the clauses, because the wording matters and an engineering partner isn't the person to write it.

Where an engineering partner does help is in the practical half: who gets access to what, masked staging data, the deletion path, the 12-month review. If you're a US agency that wants overflow capacity from a team that can show you that process before it sees a row of client data, the partner program describes how we work with agencies. How to vet a development partner with a global team lists the questions to ask any bench, ours included. For the client-side view of the same rules, what California's privacy rules require in your AI vendor's contract is the other half. And if you'd like to talk through a specific engagement, get in touch with the scope and we'll tell you honestly whether it fits.

Sources

Frequently asked questions.

If the subcontractor helps process personal information on behalf of your California client, yes. Section 7051(b) of the California Privacy Protection Agency regulations (effective 1 January 2026) says a service provider that subcontracts must have a contract with the subcontractor that complies with the CCPA, including the terms in subsection (a). Civil Code section 1798.140(ag)(2) adds that the engagement must be under a written contract and that the client must be notified of it.

Where the subcontractor helps process the client's personal information, yes. Civil Code section 1798.140(ag)(2), in the statute text the CPPA posted in January 2025, says the service provider "shall notify the business of that engagement." The statute does not set a timing rule, so naming the subcontractor in the client agreement before they get access is the safest way to meet it.

Section 7051(a) of the CPPA regulations (effective 1 January 2026) lists nine terms. They include a ban on selling or sharing the data, a specific (not generic) business purpose, a ban on other uses, and the same privacy protection the CCPA requires of businesses. They also include the right to review and test at least once every 12 months, a duty to warn of non-compliance, a right to stop and fix unauthorized use, and help with consumer requests.

The CCPA contract requirements attach to processing personal information, so work done only on masked or synthetic data that identifies no real person generally falls outside them. That is a reading of the definition of service provider in Civil Code section 1798.140(ag)(1), not a CPPA ruling on test data. Have counsel confirm it for your engagement, and keep a contract in place for any case where real records are needed.

Section 7051(c) of the CPPA regulations (effective 1 January 2026) says a business that never enforces its vendor contracts or exercises its audit rights might not be able to claim it had no reason to believe a vendor would misuse data. Clients therefore collect evidence of oversight, and a signed flow-down contract with each subcontractor is part of it.