Data Privacy

CCPA to CPRA: What In-House Counsel Still Get Wrong

Sensitive personal information, contractor obligations and the difference between a service provider and a third party.

California privacy law is now several years past the CPRA amendments, and the same handful of misunderstandings continue to surface in reviews.

1. Service provider is a status, not a label

Calling a vendor a service provider in the agreement does not make it one. The status depends on the contractual restrictions actually imposed — prohibitions on retaining, using or disclosing personal information outside the business purpose, on combining it with other data, and on selling it. Where those restrictions are absent, the transfer may be a sale or a share regardless of what the heading says, with opt-out consequences attached.

2. Sharing is not the same as selling

The CPRA added “sharing” for cross-context behavioural advertising, which does not require money to change hands. Most organisations that concluded they do not sell personal information nevertheless share it, because that is what standard advertising pixels do. The opt-out obligations follow.

3. Sensitive personal information has its own regime

A defined category — including precise geolocation, racial or ethnic origin, contents of communications, biometric data used for identification, and health and sexual orientation data — carrying a right to limit use and disclosure to specified purposes. It is not simply higher-risk personal information; it triggers a distinct notice and a distinct control.

4. Employee and B2B data is fully in scope

The exemptions expired. Job applicants, employees, contractors and business contacts have the full set of rights, which means notices at collection for staff, a rights process that handles HR data, and retention disclosures for personnel records. This remains the most common gap we find.

5. Retention disclosure is mandatory

Notices must state the retention period for each category, or the criteria used to determine it. “As long as necessary” is not criteria. This is a small drafting task that requires a real answer from the business, which is why it is so often postponed.

6. Contractor obligations flow down

Required contractual terms apply to service providers, contractors and third parties, and must be flowed down to sub-processors. A vendor programme that stops at the first tier does not meet the requirement.

A necessary note

This article is general information about legal technology and practice, not legal advice, and it does not create a lawyer–client relationship. JuriPro is a technology company, not a law firm. Take advice from a qualified lawyer admitted in the relevant jurisdiction before acting on anything here.

Elena Vasquez

Head of Compliance, JuriPro

Privacy and regulatory lead; previously data protection officer at a multinational financial services group.

Keep reading

Related articles

Data Privacy

GDPR and Generative AI: Choosing a Lawful Basis

Legitimate interest, consent or contract? A structured way to reason about lawful basis for training, fine-tuning and inference, with the balancing test written out.

All JuriPro Insights

See what JuriPro finds in your contracts

Start a 14-day trial, or book a 30-minute walkthrough with someone who has practised.