CCPA service provider vs contractor vs third party in data licensing
In a data licensing project, a de-identification vendor acting on the company's instructions is the clearest service provider or contractor, while the buyer using the data for its own purposes is a third party. Roles follow the contract and actual data use, so company counsel must confirm each party's terms.
Verdict: which CCPA role does each party in a licensing project play?
The role follows the contract and the actual data flow, not the label a party uses for itself. In a typical licensing project, a vendor that de-identifies the company's records on its instructions is the clearest candidate for service provider or contractor status. A buyer that receives the data for its own purposes is the clearest candidate for a third party. A transaction platform may fall in either place depending on what it does with the data.
This matters only if the records contain California personal information and the company is a covered business. The CCPA applicability thresholds come first. Everything below is a framework for the company's counsel, who decides the real roles.
Side-by-side: service provider, contractor and third party
| Question | Service provider | Contractor | Third party |
|---|---|---|---|
| Typical example in a licensing project | Vendor that de-identifies or hosts records on the company's instructions | Vendor given access to personal information for a business purpose, under contract | Buyer that licenses the dataset for its own use |
| Who decides the purpose | The company | The company | The recipient |
| Written agreement required | Yes, limiting use to specified purposes | Yes, with similar limits | Yes, if the company sells or shares personal information |
| Can it use data for its own ends | Not beyond what the contract and law allow | Not beyond what the contract and law allow | Yes, within the license terms |
| Is disclosure a sale or share | Normally not, if the contract terms are met | Normally not, if the terms are met | Possibly, depending on the definitions |
| Key risk | Contract lacks required terms | Contract lacks required terms | Dataset still contains personal information |
| Main fix | Add the required clauses and check how the vendor really works | Same | De-identify first, or license only non-personal records |
The statute behind the table is the California Consumer Privacy Act, Civil Code section 1798.100 and following. Section 1798.100 requires that a business that sells or shares personal information, or discloses it to a service provider or contractor, have a written agreement limiting use to specified purposes. Section 1798.140 holds the definitions, including "sell" and "share". The California Privacy Protection Agency regulations page lists the regulations that add detail on contract content.
This is general information, not legal, tax or financial advice. Confirm with your own counsel, tax adviser or professional body before acting.
When does the service provider role fit a de-identification vendor?
A de-identification vendor looks like a service provider when four things hold.
- It processes records only on the company's documented instructions.
- It has no right to keep, combine or reuse the data for its own products.
- Its contract states the permitted purposes and prohibits other use.
- The company can audit or verify what it does, and gets the data back or deleted at the end.
If the vendor also wants to retain derivatives, train its own models on the raw text, or sell insights, the role starts to look like a third party, and the company should hear that before signing.
When is the transaction platform a service provider and when is it not?
A platform that only arranges the sale, prepares an inventory and delivers data on the company's instructions is closer to a service provider. A platform that takes its own rights in the personal information, for example to enrich it or resell it elsewhere, is closer to a third party. The honest answer for any specific arrangement is to read the agreement. Companies should ask for a clear statement of what the platform does with records it touches, and whether it ever sees personal information before de-identification.
SourceX manages the licensing process between companies and AI data buyers, and de-identification and redaction requirements are agreed with the company before any work begins. Data is delivered only after an executed agreement and the company's authorization.
Contract checklist for company counsel
- Each party's role is written down, and matches what it actually does.
- Service provider and contractor agreements limit use to specified business purposes.
- The vendor cannot sell or share the personal information it receives.
- The agreement lets the company stop or remediate unauthorized use.
- Flow-down terms apply to any sub-processor.
- The licensee's agreement covers de-identification commitments and a ban on re-identification, see the CCPA deidentified data page.
- Records of EU personal data are handled separately, for example under the CCPA versus GDPR employee data comparison.
Common mistakes
| Mistake | Why it hurts | Fix |
|---|---|---|
| Calling every vendor a service provider | The label does not decide the role | Match the contract terms to real data use |
| Skipping the written agreement | The statute expects one for these disclosures | Put it in place before access |
| Treating the buyer as a service provider | A buyer using data for its own purpose is a third party | Plan for de-identified or non-personal data |
| Forgetting sub-processors | The vendor's vendors see the data too | Require flow-down terms |
| Assuming de-identified means out of scope | The definition has conditions | Check the commitments the company must make |
What does this mean for a referral partner?
You do not decide roles or draft contracts. You can tell an owner that the roles of each party are mapped at the contract stage, with the company's counsel, and that a buyer expecting de-identified data is a different relationship from a vendor working on the company's instructions. Buyers also care about legal exposure from how data was obtained, which is the theme of the FTC algorithmic disgorgement guide, and the first-party data explainer shows why records a company created itself are easier to clear.
The partner earns 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, up to $100,000 per referred company, paid only after the buyer pays and SourceX receives its fee.
Next step
Use the company fit checker for a preliminary screen, read how it works, and register as a partner to introduce a US company with 50+ full-time employees at peak (contractors excluded).
Common questions
Is the buyer of a licensed dataset a third party under the CCPA?
Usually yes, because it uses the data for its own purposes rather than on the company's instructions. That is why companies normally license de-identified or non-personal records, and why the license adds de-identification commitments and a ban on re-identification.
What is the difference between a service provider and a contractor?
Both receive personal information under a contract that limits use to specified business purposes. The statutory definitions differ in details such as certification and how the relationship is structured, so counsel should read the current definitions in section 1798.140 and the regulations.
Does the company need a written contract with a de-identification vendor?
The statute calls for a written agreement limiting use to specified purposes when personal information is disclosed to a service provider or contractor. Companies also ask for audit rights, deletion at the end and flow-down terms for sub-processors.
Can a transaction platform be a third party?
It can, if it takes its own rights in the personal information, such as reusing or reselling it. If it only arranges the sale and delivers on the company's instructions it looks more like a service provider. The agreement and real practice decide, not the platform's label.
Does this apply if the company is not covered by the CCPA?
If the company is outside the CCPA's thresholds, these labels may not bind it, but other state laws, contracts and buyer requirements can impose similar terms. Companies often adopt the same contract discipline anyway because buyers expect it.
Related pages
- Does the CCPA apply to my business? Thresholds explained
- CCPA deidentified data: the three commitments a company must make
- CCPA vs GDPR for employee data: a side-by-side for US companies
- FTC algorithmic disgorgement and why AI buyers want licensed, documented data
- What is first-party data in AI licensing?
- Check Company Fit for Data Licensing
Free resources
- Operational data inventory builder — List systems, record types, years held and owners.
- AI readiness assessment — Ten questions, five dimensions, a score out of 100.
- EBITDA calculator — Reported and adjusted EBITDA from net income.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment