CCPA and CPRA for Indian service providers work through the client’s written contract, not through the statute’s size thresholds. The revenue and consumer-count tests that most firms check first define a “business” under Civil Code section 1798.140(d) of the California Consumer Privacy Act, and a firm in India processing a US client’s data on that client’s instructions is not a business. It is a service provider, and the duties attaching to it sit in the contract the client is legally required to put in place, currently ten mandatory terms under California’s privacy regulations. A two-person bookkeeping practice and a 2,000-seat delivery centre are held to the same ten.
This is not an edge case affecting a handful of firms. India’s software services exports reached 221.4 billion dollars in 2025-26, the United States accounted for 54.1 per cent of that, and 91.7 per cent of the total was delivered off-site rather than from the client’s premises, according to the Reserve Bank of India’s 2025-26 software exports survey. Remote delivery on a foreign client’s data is the ordinary shape of the industry. It is also the exact fact pattern California’s service-provider rules were written to govern.
Two things changed on 1 January 2026, and both cut against the vendor. A new regulation makes the Indian firm answerable to the client’s cybersecurity auditor directly rather than only to the client. And the contract regulation grew from nine required terms to ten, which is easy to miss (the page ranking first for this subject in most searches still serves the March 2023 text), so a data processing addendum drafted against the older list is already one clause short.
Contract terms under CCPA and CPRA for Indian service providers
Contract terms under CCPA and CPRA for Indian service providers are set by section 7051 of title 11 of the California Code of Regulations, which now lists ten of them. The list is only useful once the classification is right, because the same data flow can put an Indian firm in one of three positions.
A service provider receives personal information and processes it on behalf of the business, under Civil Code section 1798.140(ag). A contractor has personal information made available to it, and its contract must additionally carry a certification that the contractor understands the restrictions and will comply with them, under section 1798.140(j)(1)(B). That certification is the only substantive difference between the two (the regulations otherwise treat them as a single class, which is why most guidance addresses them together). A third party is the residual category: anyone who is neither of the first two, under section 1798.140(ai).
Here is where the classification stops being terminology and starts costing money. Regulation 7050(e) says a person without a contract complying with 7051(a) is not a service provider or a contractor at all, and the client’s disclosure to that person may be treated as a sale or sharing of personal information. Status does not follow from what the recitals call the parties. It follows from whether the paper is right.
On the client’s side this sits with the third-party risk management function, whose job is to produce evidence that every contract clears the list. An Indian vendor that can hand that evidence over in days rather than weeks is answering a deadline the client already has.
The ten terms the contract must carry
The ten terms fall into four prohibitions and six affirmative duties. The contract must bar the vendor from selling or sharing the personal information; from retaining, using or disclosing it for any purpose other than the business purposes the contract specifies; from doing so for any other commercial purpose; and from retaining, using or disclosing it outside the direct business relationship, which the regulation illustrates with combining or updating that data with information from another source. That fourth prohibition is the paragraph inserted in the 2026 text (the restriction itself already sat in the statutory definition at section 1798.140(ag)(1), but it now has to appear in the contract as a term).
The second affirmative duty is the one most contracts fail. Regulation 7051(a)(2) requires the contract to identify the specific business purposes, and it says in terms that they “shall not be described in generic terms, such as referencing the entire contract generally”. A clause saying the vendor may process personal information “for the purposes of providing the Services” does not satisfy this. Here is what a compliant one looks like: Service Provider shall process the Personal Information solely to perform accounts payable invoice capture, three-way matching and vendor master maintenance for Client’s United States entities, and for no other purpose. Named processes, named scope, nothing else permitted by implication.
The remaining five affirmative duties run as follows. The contract must require compliance with the CCPA and provision of the same level of privacy protection as the law requires of businesses. It must grant the client verification rights, including assessments, audits or technical and operational testing at least once every twelve months.
It must also require the vendor to notify the client once the vendor determines it can no longer meet its obligations (no deadline is set for that notice, which is a drafting gap worth closing in the contract itself). It must grant the client the right, on notice, to stop and remediate unauthorised use, including by requiring documentation that deleted data is no longer retained. And it must require the vendor to enable the client to comply with consumer requests.
Subsection (b) is the one that reshapes how a BPO or KPO operates. A vendor that subcontracts must have a contract with the subcontractor complying with the CCPA and the regulations, including the whole of subsection (a). Not a cut-down version, not a confidentiality annexure. The same ten terms have to reach the Tier-2 firm handling overflow volumes and the individual freelancer brought in for a three-week surge, and the statute at section 1798.140(ag)(2) separately requires the vendor to notify the client of that engagement, reaching sub-subcontractors as well.
Subsection (c) works in the vendor’s favour, oddly enough. Whether the client conducts due diligence bears on whether it “has reason to believe” the vendor is misusing data, which means a client that never exercises its audit rights weakens its own defence. The practical reading is that audit clauses get exercised more often now, not less, because the client needs the record.
Permitted uses of the client’s data
Regulation 7050(a) sets out what a service provider may actually do with the data, and everything in it is governed by a single qualifier: the retention, use or disclosure must be reasonably necessary and proportionate to the purpose. Five purposes qualify.
They are the specific business purposes named in the contract, engaging a subcontractor that meets the CCPA’s requirements, internal use to build or improve the quality of the services the vendor provides to that business, security work (preventing, detecting or investigating incidents, and protecting against malicious, deceptive, fraudulent or illegal activity), and the purposes enumerated at Civil Code section 1798.145(a)(1) to (a)(7). Everything outside that list is a breach of the contract the client was obliged to impose.
The third one is where the argument usually happens, and the regulation is unusually concrete about it. An email marketing provider may analyse how a client’s customers interacted with marketing emails to improve its own service, and may then offer that improvement to every customer it has. What it may not do is use the original email list to send marketing on behalf of another business.
The shipping example runs the same way. A provider may use delivery experience to identify faulty addresses, but it may not compile addresses from one client to advertise for another, or sell them to data brokers.
So where does that leave a vendor building internal tooling on live client data? Inside the line, provided the output improves the service delivered to that client and the data itself never crosses into work for anyone else. The moment a model trained on one client’s records starts serving another client’s account, the permitted purpose has been left behind.
Regulation 7050(b) adds a separate bar that catches people who have satisfied themselves on everything above. A service provider must not combine the personal information of consumers who have opted out of sale or sharing with personal information it receives from another person, or collects from its own interaction with consumers. Contextual advertising and work on aggregated or demographic information stay available.
Consumer requests and the deadlines behind them
The consumer-request deadlines belong to the client, not the vendor, and that is precisely why they turn into contractual obligations on the vendor. A business has ten business days to confirm receipt of a request to delete, correct or know, under regulation 7021(a). It has forty-five calendar days for the substantive response, regardless of how long verification takes, extendable once by up to forty-five more for a ninety-day ceiling, under 7021(b). On an opt-out of sale or sharing it must stop within fifteen business days, under 7026(f)(1), and the same fifteen-day window applies to a request limiting the use of sensitive personal information under 7027(g)(1).
Deletion has its own mechanics. Under 7022(b)(2) the client notifies its service providers of the need to delete, and under 7022(c) the vendor must then cooperate by permanently and completely erasing, deidentifying or aggregating that personal information. The verb matters. Erasing, deidentifying or aggregating are three different operations with three different evidence trails, and the contract typically picks one.
In practice, though, the gap between the rule and the delivery floor is where offshore vendors get caught. A deletion instruction has to reach the production database, and then it has to reach the ticketing system where an agent pasted a customer’s address into a comment, the quality-assurance call recordings, the shared drive holding a reconciliation extract, and the local copies on agent desktops (backups are their own argument, and the contract should say which of the three verbs applies to them). Forty-five days sounds generous until a vendor has to prove all five. But the mistake that recurs most often is not missing the date, it is treating deletion as a database operation when the contract treats it as an evidence obligation.
One provision cuts the other way and is worth raising with a nervous client. Regulation 7026(f)(1) states that a service provider collecting personal information under a compliant contract does not itself constitute a sale or sharing. The compliant contract is not just the vendor’s burden: it is what keeps the client’s ordinary outsourcing off the sale register.
Security and the 2026 audit cooperation duty
Security enters through Civil Code section 1798.81.5, which requires reasonable security procedures and practices appropriate to the nature of the information, and requires a discloser to impose the same by contract on a nonaffiliated recipient. Regulation 7051(a)(6) then names implementing those practices as an example of the same level of privacy protection the vendor owes. Most Indian firms already hold evidence that answers it, and mapping an existing SOC 2 report or ISO 27001 certificate onto a client questionnaire is faster than building a separate control narrative.
The change that took effect on 1 January 2026 goes further, and most guidance still describes it from the buyer’s side only. Regulation 7050(h) imposes a duty that does not depend on the contract at all. A service provider must cooperate with the client’s cybersecurity audit by making available to the client’s auditor all relevant information the auditor requests that sits in the vendor’s possession, custody or control, and must not misrepresent any fact the auditor deems relevant. The same duty runs to the client’s risk assessment.
That is a direct line from a California regulation to an Indian delivery centre’s records, and it changes what the twelve-month testing right in 7051(a)(7) actually costs to service. An audit clause used to mean answering a questionnaire once a year. Read together with 7050(h), it means holding evidence in a state where someone else’s auditor can be shown it, on their schedule, with a regulatory penalty attached to getting an answer wrong.
Worth flagging alongside it: the notification duty at 7051(a)(8), which requires the vendor to tell the client once it determines it can no longer meet its obligations, has no stated deadline and no stated format. That makes it an internal trigger rather than an external one, and the incident response plan is where it needs to live, because nothing else in the vendor’s process will fire it.
Penalties and liability for the vendor itself
The vendor is directly liable, not merely contractually exposed, and this is where the Indian firm’s own balance sheet enters the picture. Civil Code section 1798.155(a) makes “any business, service provider, contractor, or other person” liable for an administrative fine. The statute prints 2,500 and 7,500 dollars, but the operative figures are 2,663 dollars per violation and 7,988 dollars for an intentional violation or one involving the personal information of a consumer the violator knows to be under sixteen, as inflation-adjusted by the California Privacy Protection Agency from 1 January 2025.
Those figures hold through 2026, because the adjustment runs in odd-numbered years only (the next one falls due on 1 January 2027). And the Attorney General holds a parallel civil-penalty power at the same amounts under section 1798.199.90, so there are two authorities rather than one.
The thirty-day cure period that shaped early CCPA advice is gone for regulator enforcement. It was repealed by the CPRA and expired on 1 January 2023, a point the Attorney General’s own 2022 cosmetics-retailer settlement states explicitly. Cure is now discretionary under section 1798.199.45, with no period specified.
The private right of action is narrower than its reputation. Section 1798.150 covers only breaches of nonencrypted, nonredacted personal information caused by a failure to maintain reasonable security, at 107 to 799 dollars per consumer per incident as adjusted. Its thirty-day cure survives, but fixing security after a breach expressly does not cure that breach.
In three separate California actions the failure was the contract rather than the data handling. An August 2022 Attorney General settlement of 1,200,000 dollars with a cosmetics retailer required it to conform its service provider agreements to the CCPA’s requirements. A March 2025 order against an automobile manufacturer, at 632,500 dollars, found it had shared personal information with ad-tech companies without producing contracts containing the necessary terms. And a September 2025 order against a rural lifestyle retailer, at 1,350,000 dollars and the largest CPPA fine to date, turned on disclosing personal information without contracts containing privacy protections.
Here is the mechanism that actually reaches an Indian vendor, and it is not a California regulator knocking on the door. The September 2025 stipulated final order did not stop at the fine. It required the company to modify its contract management process so that all required terms are in place with every external recipient of personal information, to confirm that in writing to the Enforcement Division by 31 March 2026, and to keep four years of audit records showing each contract meets the regulations.
The July 2025 matter went the same way. That 1,550,000 dollar settlement with a health content publisher (which had assumed rather than verified that third parties agreed to the contractual framework) requires annual contract audits reported to the Attorney General for three years. So the vendor’s experience of California enforcement is rarely California at all. It is a dated re-papering demand from a client working to its own regulatory deadline.
CCPA and CPRA for Indian service providers alongside DPDP and GDPR
CCPA and CPRA for Indian service providers impose no cross-border transfer restrictions at all, and this is the misconception that sends most readers hunting for machinery that does not exist. The statute and the approved 2026 regulations contain no adequacy mechanism, no standard contractual clauses, no transfer impact assessment and no localisation duty. Nothing corresponds to Chapter V of the General Data Protection Regulation. Moving a Californian’s personal information to Pune is a contract question rather than a transfer question, and a client asking for standard contractual clauses anyway is making a commercial or GDPR-driven request, not a CCPA one.
The GDPR divergence that does bite sits at the sub-processor stage. Article 28(2) of the GDPR requires the controller’s prior specific or general written authorisation before a processor engages another processor, with a right to object. California requires notification of the engagement and full flow-down, but not prior authorisation. A data processing agreement drafted for the GDPR therefore does not convert into a compliant 7051 contract, because it was built against a different list, and the DPDP and GDPR comparison that most Indian compliance teams start from does not carry the California terms either.
Then there is the finding that reverses the usual framing, and it sits in Indian law rather than Californian. Section 17(1)(d) of the Digital Personal Data Protection Act 2023 disapplies Chapter II (other than sections 8(1) and 8(5)), Chapter III and section 16 where personal data of people outside India is processed under a contract with a person outside India by a person based in India. On a California engagement the Indian firm therefore sits largely outside the DPDP Act’s substantive obligations, and its compliance load comes from the client’s contract rather than from Indian law.
But the corollary matters just as much, and it is the part that catches firms running mixed books. The moment the same firm handles the data of users in India, the carve-out stops applying and the DPDP obligations return in full.
The structural difference behind all of this is worth stating plainly. DPDP section 8(2) requires a data fiduciary to engage a processor “only under a valid contract” and prescribes no mandatory terms. Regulation 7051(a) prescribes ten, and California regulators have now fined buyers three times for omitting them. But that is a difference of specification rather than severity, and it is why a firm comfortable with the Indian regime arrives under-prepared for California.
FAQs
Can an independent contractor or freelancer in India be a CCPA service provider?
Section 1798.140(ag) defines a service provider as a “person” that processes personal information on behalf of a business, with no qualifier for size, entity type or headcount. A sole proprietor doing data entry for a California client under a written contract occupies the same legal position as a listed IT services group, and is liable for administrative fines on the same terms under section 1798.155(a).
Can client data be used to train a model or publish benchmarks if it is aggregated first?
Regulation 7050(a)(3) permits internal use to build or improve the quality of the services the vendor provides to that particular business, which covers a model that makes that client’s work better. Using the same data to perform services for another person falls outside the permitted purposes, and aggregating it first does not fix that, because the restriction attaches to the service being performed rather than to the format of the data.
Does a confidentiality clause in the master services agreement satisfy the CCPA?
Regulation 7051(a)(2) requires the contract to identify the specific business purposes and states that they must not be described in generic terms such as referencing the entire contract generally, which a confidentiality clause never does. Without the ten terms, regulation 7050(e) treats the recipient as something other than a service provider, and the client’s disclosure may count as a sale or sharing.
Who answers a consumer who sends a deletion request straight to the Indian vendor?
Regulation 7050(c) gives the vendor two options: act on the business’s instructions, or inform the consumer that the request cannot be acted upon because it was sent to a service provider. Answering the request independently is not one of them. The routing question belongs in the contract, because the client’s ten-business-day acknowledgement clock is already running.
References
- California Privacy Protection Agency, California Consumer Privacy Act of 2018, official statute compilation. https://cppa.ca.gov/regulations/pdf/ccpa_statute.pdf
- California Legislative Information, Civil Code section 1798.140 (definitions). https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1798.140
- California Legislative Information, Civil Code section 1798.150 (private right of action). https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1798.150
- California Legislative Information, Civil Code section 1798.155 (administrative fines). https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1798.155
- California Legislative Information, Civil Code section 1798.81.5 (reasonable security procedures and practices). https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1798.81.5
- California Privacy Protection Agency, Text of Regulations (CCPA Updates, Cybersecurity Audits, Risk Assessments, ADMT and Insurance), approved text effective 1 January 2026. https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf
- California Privacy Protection Agency, Updated monetary thresholds in the CCPA, effective 1 January 2025. https://cppa.ca.gov/regulations/cpi_adjustment.html
- Ministry of Electronics and Information Technology, Government of India, Digital Personal Data Protection Act, 2023. https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
-
EUR-Lex, Regulation (EU) 2016/679, General Data Protection Regulation. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679
-
California Privacy Protection Agency, enforcement action against a rural lifestyle retailer, 30 September 2025. https://cppa.ca.gov/announcements/2025/20250930.html
- California Privacy Protection Agency, Board Decision and Stipulated Final Order in the same matter, 30 September 2025. https://cppa.ca.gov/pdf/20250930_tractor_supply_bd_sfo.pdf
- California Department of Justice, settlement with a health content publisher, 1 July 2025. https://oag.ca.gov/news/press-releases/attorney-general-bonta-announces-largest-ccpa-settlement-date-secures-155
- California Privacy Protection Agency, enforcement action against an automobile manufacturer, 12 March 2025. https://cppa.ca.gov/announcements/2025/20250312.html
-
California Department of Justice, settlement with a cosmetics retailer, 24 August 2022. https://oag.ca.gov/news/press-releases/attorney-general-bonta-announces-settlement-sephora-part-ongoing-enforcement
-
Reserve Bank of India, Survey on Computer Software and Information Technology Enabled Services Exports, 2025-26, 18 September 2026. https://www.rbi.org.in/Scripts/BS_PressReleaseDisplay.aspx?prid=63625
This article is for informational and educational purposes only and does not constitute legal, compliance or professional advice. Readers should consult a qualified professional before acting on any contractual or regulatory matter described here.


Allow notifications