Appearance
Service providers, third parties, and ADMT suppliers
The ADMT duties sit on the CCPA's Article 4 rules for service providers, contractors, and third parties (§§ 7050–7053) and on one ADMT-specific provision for suppliers (§ 7153). MFF-29 carries them as MRF-496, which is tagged with all four CCPA Role values and scores each limb the organization occupies; the organization framework's ORF-491 carries the notice, purpose-compatibility, and contract program behind them. The roles are non-exclusive: one organization can be the business for its own ADMT, a service provider for a customer's, and a supplier of a trained ADMT to a third business.
Timing
The Article 4 rules, and the service provider's and contractor's duty to assist with requests to access ADMT (§ 7222(i)), have applied with the regulations since January 1, 2026, with no delayed compliance date. The § 7221(n)(2) flow-down belongs to the business's Article 11 compliance on the § 7200(b) branches. The § 7153 facts are needed whenever the recipient-business must assess: before initiating (§ 7155(a)(1)), or by December 31, 2027 for processing initiated before January 1, 2026 that continues (§ 7155(b)).
As the business — contracts and the opt-out flow-down
The service-provider or contractor contract (§ 7051(a); Civ. Code § 1798.100(d)) must: prohibit selling or sharing the personal information collected under it ((1)); identify the specific business purposes for the processing and specify that the business discloses the information only for those limited and specified purposes, described specifically and not in generic terms ((2)); prohibit retaining, using, or disclosing it for any purpose other than the business purposes specified in the contract or as otherwise permitted by the CCPA and the regulations ((3)); prohibit retaining, using, or disclosing it outside the direct business relationship between the service provider or contractor and the business, unless expressly permitted by the CCPA or the regulations ((4)); and, verbatim ((5)):
Require the service provider or contractor to comply with all applicable sections of the CCPA and these regulations, including—with respect to the personal information that it collected pursuant to the written contract with the business—providing the same level of privacy protection as required of businesses by the CCPA and these regulations.
The regulation's illustration of how that protection may be secured is that the contract may require cooperation in responding to and complying with consumers' CCPA requests, assistance with the business's Article 9 cybersecurity audit, Article 10 risk assessment, and Article 11 ADMT requirements, and implementation of reasonable security procedures and practices appropriate to the nature of the personal information to protect it from unauthorized or illegal access, destruction, use, modification, or disclosure in accordance with Civ. Code § 1798.81.5. The same-protection term is mandatory; the cooperation list is the Agency's illustration. A contract securing the outcome otherwise still satisfies (a)(5); one naming the cooperation but omitting the same-protection term does not. The contract must also grant the business the right to take reasonable and appropriate steps to ensure consistent use ((6)); require notice once the service provider or contractor determines it can no longer meet its obligations ((7)); grant the business the right, upon notice, to take reasonable and appropriate steps to stop and remediate unauthorized use of the personal information ((8)); and either require it to enable the business to comply with consumer requests made under the CCPA, or require the business to inform it of any such request that it must comply with and to provide the information necessary for it to comply ((9)), two permitted architectures.
The third-party agreement (§ 7053(a)) is required where the business sells or shares personal information with a third party. It must identify the limited and specified purposes for which the information is made available, described specifically ((1)); specify that the business makes the information available only for those purposes and require the third party to use it only for them ((2)); require the third party to comply with all applicable sections of the CCPA and the regulations, including the same level of privacy protection for the information made available ((3)); grant the business the right to take reasonable and appropriate steps to ensure the third party uses it consistently with the business's obligations ((4)); grant the business the right, upon notice, to take reasonable and appropriate steps to stop and remediate unauthorized use ((5)); and require the third party to notify the business after it makes a determination that it can no longer meet its obligations ((6)).
The opt-out flow-down (§ 7221(m)–(n)) has two branches. A request submitted before the business initiates the processing bars the business from initiating it; no downstream step is triggered. Where the consumer did not opt out in response to the Pre-use Notice and submits the request after the processing began, the business must cease processing that consumer's personal information using that ADMT as soon as feasibly possible and no later than 15 business days from receipt, and must notify all its service providers, contractors, or other persons to whom it has disclosed or made personal information available to process that consumer's personal information using that ADMT, instructing them to comply within the same time frame ((n)(2)). The recipients named are the service providers, contractors, or other persons to whom the business disclosed or made available that consumer's personal information to process it using that ADMT, including one that has not yet begun; not every service provider or contractor the business uses. The command runs to the business; what recipients then owe rests on their contract.
Due diligence is a liability-protection factor, not a duty (§ 7051(c), § 7053(b)). Whether a business conducts due diligence of its service providers, contractors, or third parties factors into whether it has reason to believe that they are using personal information in violation of the CCPA and the regulations; the regulation's example is that a business that never enforces the contract or exercises its audit and testing rights might not be able to rely on the defense that it did not have reason to believe, at the time of disclosure, that the recipient intended such a violation. Under Civ. Code § 1798.145(i), a business that disclosed personal information to a service provider or contractor in compliance with the CCPA is not liable where the recipient uses it in violation of the CCPA's restrictions, provided that, at the time of disclosure, the business had neither actual knowledge nor reason to believe the recipient intended to commit such a violation; for a third party the protection also requires a written contract requiring the same level of protection of the consumer's rights as the business provides, and it does not reach the personal information of consumers who have exercised their right to opt out of the sale or sharing of their personal information, consumers who have limited the use or disclosure of their sensitive personal information, or minor consumers who have not opted in to the collection or sale of their personal information. A service provider or contractor is likewise not liable for the business's obligations but remains liable for its own violations.
As a service provider or contractor
| Duty | Content | Anchor |
|---|---|---|
| Use limits | Personal information collected under the written contract may be retained, used, or disclosed only for the § 7050(a) purposes, and only where that retention, use, or disclosure is reasonably necessary and proportionate for them | § 7050(a) |
| Direct consumer requests | A CCPA request received directly from a consumer is either acted on per the business's instructions or answered by telling the consumer it cannot be acted upon because it was sent to a service provider or contractor | § 7050(c) |
| Contract compliance | The service provider or contractor must comply with the terms of the contract the CCPA and the regulations require | § 7050(f) |
| Subcontracting | Engaging any other person to assist in processing personal information for a business purpose on the business's behalf, or a further engagement by a person already so engaged for that business purpose, requires notifying the business of the engagement, and the engagement must be under a written contract binding the other person to observe all the same requirements; a service provider or contractor that subcontracts with another person in providing services to the business must have a contract with the subcontractor that complies with the CCPA and the regulations, including § 7051(a) | Civ. Code § 1798.140(j)(2), (ag)(2); § 7051(b) |
| Risk-assessment cooperation | With respect to personal information collected under its written contract, cooperation in the business's risk assessment, making available all facts necessary to conduct it that are in its possession, custody, or control, and not misrepresenting any such fact | § 7050(h)(2) |
| Access-to-ADMT assistance | Quoted below | § 7222(i) |
The assistance duty, verbatim (§ 7222(i)):
A service provider or contractor must provide assistance to the business in responding to a verifiable consumer request to access ADMT, including by providing the business with the consumer’s personal information it has in its possession that it collected pursuant to their written contract with the business, or by enabling the business to access that personal information.
No § 7051(a)-compliant contract, no service provider or contractor status, and the business's disclosure to that person may be a sale or sharing with its own opt-out (§ 7050(e)). A service provider or contractor that is itself a business complies in its own right for information handled outside that role (§ 7050(d)), including for ADMT it uses for its own significant decisions.
As a third party
The bar binds the third party directly, verbatim (§ 7052(a)):
A third party that does not have a contract that complies with section 7053, subsection (a), shall not collect, use, process, retain, sell, or share the personal information that the business made available to it.
With such a contract, the third party must comply with its terms, which include treating the information made available to it consistently with the business's obligations under the CCPA and the regulations (§ 7052(b)). A third party that independently meets the business definition carries the business duties for its own uses.
As an ADMT supplier
The duty, verbatim (§ 7153(a)):
A business that makes ADMT available to another business (“recipient-business”) to make a significant decision as set forth in section 7150, subsection (b)(3), must provide to the recipient-business all facts available to the business that are necessary for the recipient-business to conduct its own risk assessment.
Three points bound it:
- It applies only to ADMT trained using personal information (§ 7153(b)).
- The trigger is making the ADMT available to another business for a significant decision; no transfer of personal information to that business is required.
- It runs one way. It binds the business making the ADMT available; the recipient-business has no § 7153 duty to obtain the facts, and gathering them is practice under its own § 7152 duty.
The facts the recipient-business needs are those its own § 7152 assessment must contain, including, for a use, the logic of the ADMT with its assumptions and limitations and the output and how it will be used (§ 7152(a)(3)(G)); see Risk assessments and Agency submissions. An ADMT supplier is also a business using ADMT wherever it uses the technology for its own significant decisions.
How this maps in Modulos — MRF-496 and ORF-491
MRF-496 (Service providers, third parties and ADMT suppliers) scores, by role, the limbs the organization occupies for this ADMT: as the business, the § 7051(a)(5)–(9) and § 7053(a) contract terms and the § 7221(n)(2) notify-and-instruct step; as a service provider or contractor, the § 7050 limits, contract compliance, direct-request handling, noticed and bound subcontracts, and the risk-assessment and access-to-ADMT assistance; as a third party, § 7052; as a supplier, the § 7153 facts. It is carried by the new Control MCF-702 (Service-provider, third-party and supplier duties for the ADMT). The contract terms, the notify-and-instruct step, the service-provider and contractor rules, the third-party bar, and the § 7153 facts are duties; contract inventories, fact packs, supplier-fact intake, and contract enforcement are practice. A limb the organization does not hold is marked not applicable; an organization that only uses an ADMT it built itself, with no service provider, contractor, third party, or recipient-business, marks the whole Requirement not applicable.
ORF-491 (Notice, purpose-compatibility and contract program) carries the CCPA-wide capabilities the ADMT duties build on. Owed independently of Article 11: disclosure quality under § 7003, with the Article 2 additions of a readable format (including on smaller screens, if applicable), the languages in which the business ordinarily provides contracts, disclaimers, sale announcements, and other information to consumers in California, and reasonable accessibility to consumers with disabilities (online by following generally recognized industry standards such as WCAG 2.1, and in other contexts by information on how a consumer with a disability may access the policy in an alternative format); the privacy policy (§ 7010(a)); the Notice at Collection, owed by a business that controls the collection of a consumer's personal information from the consumer, with its § 7012(e)(1)–(6) content (§ 7010(b)); processing that is reasonably necessary and proportionate to the purpose for which the information was collected or processed (where consistent with consumers' reasonable expectations) or to another disclosed purpose compatible with the context of collection, with § 7004 consent required where neither holds and proportionality applying to the consented purpose as well, established before already-collected personal information reaches an ADMT (§ 7002); and the § 7051 and § 7053 contract estate carrying the same-protection term. Attaching only with Article 11, on the § 7200(b) branches: the Pre-use Notice (§ 7010(c)) and, except as set forth in § 7221(b), the opt-out link inside it (§ 7010(d)). It is carried by the new Control OCF-388. Notice templates, a notice inventory, the written compatibility and proportionality analysis, contract playbooks, and contract enforcement are practice; the regulation sets substantive limits and factor-based tests, not a freestanding assessment-report or record-keeping duty for § 7002.
Where to go next
- Coverage and roles — the four CCPA roles and their definitions.
- Pre-use Notice, opt-out, and access — the opt-out that triggers the flow-down and the access request the service provider assists with.
- Operationalizing the CCPA ADMT Regulations in Modulos — the full
MFF-29/OFF-29rollout.
Disclaimer
This page is for general informational purposes and does not constitute legal advice. Always verify against the current published text and consult qualified advisers.