If your agency touches a California client's customer data and you hand part of the work to a subcontractor, the CCPA regulations say you need a written contract with that subcontractor, and they say what it has to contain. Most agency subcontracts are a rate, an NDA and an IP clause. The privacy terms usually aren't there.
You won't feel the gap while the project is going well. You'll feel it when the client's privacy counsel sends a vendor questionnaire with a line that reads "list every subprocessor and attach the flow-down terms."
This is a builder's read, not legal advice. Your counsel decides what applies to you. This is what the regulation says, so you know what to ask them.
Does the CCPA apply to my agency at all?
Only if you handle personal information for a client. The statute defines a "service provider" as a person that processes personal information on behalf of a business and receives it from or on behalf of that business for a business purpose, under a written contract. That wording is in Civil Code section 1798.140(ag)(1), as published by the California Privacy Protection Agency (CPPA) in its CCPA statute PDF, posted in January 2025.
An agency lands in that definition more easily than most owners expect. Production database access counts. So does a customer-support inbox you triage, a CRM migration, an analytics export you build a report from, or a test run against a copy of live data. If the work never touches a real person's record, none of this applies, and I'll come back to that.
What does the law say about subcontractors?
Two sources say it, and they agree. The statute, in section 1798.140(ag)(2), says that if a service provider "engages any other person to assist it in processing personal information for a business purpose on behalf of the business," it "shall notify the business of that engagement." The engagement must also be "pursuant to a written contract binding the other person to observe all the requirements" that apply to the service provider. The same paragraph reaches one level further down: if that other person engages someone, the same notice and contract rules apply again.
The CPPA's regulations, in section 7051(b) of Title 11 as effective 1 January 2026, say it from the contract side: a service provider "that subcontracts with another person in providing services to the business... shall have a contract with the subcontractor that complies with the CCPA and these regulations, including subsection (a)."
So there are two duties, and agencies tend to remember only one. You need the contract, and you need to tell the client the subcontractor exists. The statute doesn't say when the notice has to happen, so the safe habit is to put the subcontractor's name in your client agreement before they get access, not after.
What does the subcontract have to say?
Subsection (a) of section 7051 lists nine things the service-provider contract must do. Subsection (b) pulls all of them down to your subcontractor. Here they are in the order the CPPA's regulation text (effective 1 January 2026) gives them, with what each means in a subcontract.
| Section 7051(a) item | What it means in your subcontract |
|---|---|
| (1) No selling or sharing | The subcontractor may not sell or share the personal information |
| (2) Specific business purpose | Name the task, like "build the loyalty-points export," not "the services under the agreement" |
| (3) No other use | No keeping, using or disclosing it for any other purpose |
| (4) Stay inside the relationship | No combining it with data from another client or source |
| (5) Same privacy protection | Comply with the CCPA, cooperate on consumer requests, and help with the client's cybersecurity audit, risk assessment and ADMT requirements |
| (6) Right to check | Your client, and so you, can review, scan and test at least once every 12 months |
| (7) Duty to warn | Tell you when they can no longer meet their obligations |
| (8) Right to stop and fix | You can require them to stop unauthorized use and prove deletion |
| (9) Consumer requests | They must help you act on a request, or you must tell them what to do |
Item (2) is the one with a trap in it. The regulation says the purpose "shall not be described in generic terms, such as referencing the entire contract generally." A subcontract that says "for the purposes of the Statement of Work" doesn't meet it.
A worked example: the loyalty-portal export
Picture a 14-person agency rebuilding the loyalty-program portal for a California retailer. The agency subcontracts two engineers to build the data export and import feature, and to do it they need a recent copy of the customer table: names, emails, purchase history.
The agency's contract with the retailer has the privacy terms. The agency's contract with the two engineers is a day rate, an NDA and an assignment clause (the kind covered in who owns code a subcontractor writes). Check it against the table and three things fail.
There's no specific purpose, so item (2) fails. There's no right for anyone to audit the engineers' laptops or cloud accounts, so item (6) fails, and the agency can't give the retailer an audit right it doesn't hold downstream. And when a customer sends a deletion request, nothing obliges the engineers to find and delete the export file sitting on a drive, so item (9) fails.
My view is that the audit right and the deletion path are the two that bite. The purpose language is easy to fix with an afternoon of drafting. Deleting data you can't locate isn't.
How do you keep this small, and what will clients ask?
Don't hand over the data
A flow-down contract is the minimum for a subcontractor who has to see real records. For most subcontracted work they don't. The export feature above can be built against masked or synthetic data, with the real records staying in the client's environment under access the agency controls and can revoke.
I'd defend this on a sales call: an agency that gives subcontractors production personal information by default has chosen the most expensive way to run the project. You still need the contract for the incidental cases, such as a bug that only reproduces on real data. But a subcontractor who never holds the data can't leave a copy of it behind.
Why clients will ask for your terms
Section 7051(c) is aimed at your client, not at you, but it explains the questionnaires. It says that whether a business does due diligence on its service providers "factors into whether the business has reason to believe" they're misusing data. Its example is a business that "never enforces the terms of the contract nor exercises its rights to audit or test" which "might not be able to rely on the defense that it did not have reason to believe" a vendor would misuse the data.
Read that from the client's side. They need evidence they checked. Your signed flow-down terms, a current list of subcontractors, and a record of the last 12-month review are that evidence. An agency that has it ready answers the questionnaire in an hour. One that doesn't spends a week assembling it, with a client waiting on the answer.
When none of this is the answer
Three cases. If the engagement never touches personal information, a privacy flow-down is paperwork you can skip, and a clean NDA is enough. If your client isn't a business covered by the CCPA, the regulation's obligations don't come to you through them. And a table of nine items isn't a contract: have a lawyer draft the clauses, because the wording matters and an engineering partner isn't the person to write it.
Where an engineering partner does help is in the practical half: who gets access to what, masked staging data, the deletion path, the 12-month review. If you're a US agency that wants overflow capacity from a team that can show you that process before it sees a row of client data, the partner program describes how we work with agencies. How to vet a development partner with a global team lists the questions to ask any bench, ours included. For the client-side view of the same rules, what California's privacy rules require in your AI vendor's contract is the other half. And if you'd like to talk through a specific engagement, get in touch with the scope and we'll tell you honestly whether it fits.
Sources
- California Privacy Protection Agency: CCPA regulations, Title 11, Division 6, Chapter 1 (effective 1 January 2026), sections 7051(a), (b) and (c), checked 5 October 2026
- California Privacy Protection Agency: California Consumer Privacy Act of 2018, statute text (updated for SB 1223, AB 1008 and AB 1824, posted January 2025), Civil Code section 1798.140(ag)(1) and (ag)(2), checked 5 October 2026