US State Privacy Laws and Service Provider Agreements: How They Compare to a GDPR DPA
CCPA/CPRA and other US state privacy laws require their own vendor contract terms, similar in spirit to a GDPR DPA but not identical. Here's what's different and where one contract can cover both.
If your business has both EU/UK and US exposure, you’re likely dealing with two related but distinct sets of vendor contract requirements: GDPR’s Article 28 DPA, and CCPA/CPRA’s “service provider” or “contractor” contract terms. They solve a similar problem, but aren’t automatically interchangeable.
What CCPA/CPRA requires
Under CCPA/CPRA, a vendor qualifies as a “service provider” (processing data on your behalf, similar in concept to a GDPR processor) only if your contract with them includes specific required terms:
- Data may only be processed for the specific business purpose(s) stated in the contract.
- The service provider is prohibited from selling or sharing the personal information.
- The service provider is prohibited from retaining, using, or disclosing the data outside the direct business relationship, or combining it with data from other sources, with narrow exceptions.
- The service provider must comply with applicable CCPA/CPRA obligations and provide the same level of privacy protection required of the business itself.
- The business retains the right to take reasonable steps to verify the service provider is using the data in a manner consistent with its obligations.
Without these specific contractual terms in place, a vendor legally can’t be treated as a service provider under CCPA/CPRA, which matters because sharing data with a non-qualifying vendor can be treated as a “sale” of personal information, triggering additional obligations (like honoring opt-out-of-sale requests) you may not have accounted for.
Where it overlaps with a GDPR DPA, and where it doesn’t
A well-drafted GDPR DPA already covers a lot of the same ground: purpose limitation, restrictions on independent use of the data, audit rights. But CCPA/CPRA’s language is specific enough (the prohibition on “selling,” the “same level of privacy protection” standard) that a generic DPA written purely for GDPR compliance may not technically satisfy it without CCPA-specific provisions added.
Most vendors serving both EU and US customers now build a single combined DPA that includes both GDPR Article 28 language and CCPA/CPRA service-provider terms as separate sections or an attached addendum, worth checking for specifically rather than assuming one automatically covers the other.
CookieYes
If you have both EU and California traffic, check that your consent platform's DPA addresses both frameworks rather than just GDPR. CookieYes's data processing terms are built to cover GDPR, CCPA/CPRA, and other regional frameworks in one document.
Other US states
Colorado, Connecticut, Virginia, and other states with comprehensive privacy laws have broadly similar processor/vendor contract requirements to CCPA/CPRA, generally modeled closely enough on each other that a contract meeting CCPA/CPRA’s bar will substantially cover the others, though it’s worth a specific check if a given state’s law has a notably different requirement.
The bottom line
A GDPR-only DPA and a CCPA/CPRA-compliant service provider agreement aren’t automatically the same document, even though they’re solving a similar problem. If your business has meaningful exposure under both frameworks, confirm your vendor contracts explicitly address both rather than assuming GDPR coverage extends automatically to US state law requirements.
This guide is educational and not legal advice. For your specific vendor contracts and regulatory exposure, consult a privacy attorney.