# What US state privacy laws require in a processor contract

_Published 2026-10-05 · Updated 2026-10-05_

**The short answer**

- California, Colorado and Virginia all require a written contract between the business that controls the data and the vendor that processes it for them.
- Colorado and Virginia list nearly the same terms: instructions, nature and purpose, type of data and duration, confidentiality, deletion or return, compliance information, audits or assessments, and subcontractor flow-down.
- California's regulations set their own, more prescriptive list (Cal. Code Regs. tit. 11, § 7051), and without a compliant contract the vendor isn't a service provider at all.
- A single standard DPA can be written to carry the shared core. Whether yours fits your engagements is a question for your counsel.

Most guides to state privacy contract requirements are written by law firms for the company *buying* services. They help in-house counsel update the vendor contracts it sends out. This one is for the other side: the media agency, analytics shop or CRM implementer whose brand client has just sent "our DPA" before a campaign can start.

It maps what three statutes require the contract to contain, so you can tell what the law asks for and what is one client's preference. If you're in paid media, analytics or marketing services, [Pacts for media and marketing services](/for/media-services) covers how this plays out across a client book.

## Who's who: service provider, contractor, processor

Each law uses its own terms for the company handling data on someone else's behalf. The labels differ, but the role is the same: you process the client's data for the client, under the client's instructions.

**Service provider (California):** A person that processes personal information on behalf of a business and receives it for a business purpose "pursuant to a written contract" that prohibits the uses the statute lists, such as selling or sharing it (Cal. Civ. Code § 1798.140(ag)(1)).

**Contractor (California):** A person to whom the business makes personal information available for a business purpose under a written contract with the same prohibitions, plus a certification that the contractor understands and will comply with them (Cal. Civ. Code § 1798.140(j)(1)).

**Processor (Colorado and Virginia):** A person that processes personal data on behalf of a controller (C.R.S. § 6-1-1303(19); Va. Code § 59.1-575). The controller is whoever determines the purposes and means of the processing.

## What does each law require in the contract?

The table below lists each term against the three laws, with the subsection that requires it. Colorado and Virginia are close to identical. California overlaps on the core but adds terms the other two don't have, and doesn't list some of theirs. "Not a listed term" means the contract section doesn't require it; the law may still impose the duty some other way.

For the same terms across 15 states, each row checked against its statute, see the [state-by-state table of processor contract requirements](/guides/state-privacy-law-contract-requirements-by-state).

**Contract terms required for service providers and processors, by state**

| | California (CCPA + § 7051) | Colorado (§ 6-1-1305) | Virginia (§ 59.1-579) |
| --- | --- | --- | --- |
| Written, binding contract | Yes (Yes, § 1798.140(ag)(1)) | Yes (Yes, § 6-1-1305(5)) | Yes (Yes, § 59.1-579(B)) |
| Processing instructions, nature and purpose | Yes (Specific business purpose(s), not generic, § 7051(a)(2)) | Yes (Yes, (5)(a)) | Yes (Yes, (B)) |
| Type of data and duration of processing | No (Not a listed term) | Yes (Yes, (5)(b)) | Yes (Yes, (B)) |
| No selling or sharing; no use beyond the purpose | Yes (Yes, § 7051(a)(1), (3), (4)) | Limited (Processor must follow the controller's instructions, (2)) | Limited (Processor must follow the controller's instructions, (A)) |
| Confidentiality duty on each person processing | No (Not a listed term) | Yes (Yes, (3)(a) via (5)(c)) | Yes (Yes, (B)(1)) |
| Delete or return data at the end of services | No (Not a listed term) | Yes (Yes, at the controller's choice, (5)(d)(I)) | Yes (Yes, at the controller's direction, (B)(2)) |
| Information to demonstrate compliance | Limited (Covered by the business's right to take reasonable steps, § 7051(a)(6)) | Yes (Yes, (5)(d)(II)(A)) | Yes (Yes, on reasonable request, (B)(3)) |
| Audits or assessments | Yes (Right to take reasonable steps, which may include assessments or audits at least every 12 months, § 7051(a)(6)) | Yes (Audits, or an independent auditor at least annually with consent, (5)(d)(II)(B)) | Yes (Assessments, or an independent assessor, (B)(4)) |
| Notify the client if you can no longer comply | Yes (Yes, § 7051(a)(7)) | No (Not a listed term) | No (Not a listed term) |
| Client's right to stop and remediate unauthorized use | Yes (Yes, § 7051(a)(8)) | No (Not a listed term) | No (Not a listed term) |
| Help with consumer requests | Yes (Yes, § 7051(a)(9)) | Limited (A statutory duty, (2)(a); not a listed contract term) | Limited (A statutory duty, (A)(1); not a listed contract term) |
| Subcontractor flow-down | Yes (Yes, plus notice to the business, § 1798.140(ag)(2); § 7051(b)) | Yes (Yes, after an opportunity to object, (3)(b)) | Yes (Yes, (B)(5)) |

_As of 2026-10-04._

Sources: [Cal. Civ. Code § 1798.140(ag), (j) (service provider and contractor)](https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=1798.140); [Cal. Code Regs. tit. 11, §§ 7050–7051 (CCPA regulations, effective Jan. 1, 2026)](https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf); [Colo. Rev. Stat. §§ 6-1-1303, 6-1-1305 (Colorado Privacy Act), C.R.S. 2024](https://leg.colorado.gov/sites/default/files/images/olls/crs2024-title-06.pdf); [Va. Code § 59.1-579 (processor duties and contract)](https://law.lis.virginia.gov/vacode/title59.1/chapter53/section59.1-579/); [Va. Code § 59.1-575 (definitions)](https://law.lis.virginia.gov/vacode/title59.1/chapter53/section59.1-575/)

> **What we checked** Every row comes from the statute or regulation text, read on 2026-10-04: California's regulations as effective January 1, 2026, Colorado's statute as published in C.R.S. 2024 (we found no later amendment to § 6-1-1305), and Virginia's current code. Other states have their own processor sections, and they aren't in this table.

## Why California is different

California's statute sets the basic prohibitions, and its regulations add a longer, more prescriptive list. Section 7051(a) says the contract "shall" contain nine terms, from a ban on selling or sharing to a specific, non-generic statement of the business purpose. We cover each one in [the CCPA service-provider contract terms](/when/ccpa-service-provider).

The stakes are also different. Under the regulations, "a person who does not have a contract that complies with section 7051, subsection (a), is not a service provider or a contractor under the CCPA," and the business's disclosure to that person "may be considered a sale or sharing of personal information" (Cal. Code Regs. tit. 11, § 7050(e)). That's why a California client's legal team checks the paper so closely.

One more difference, noted by Seyfarth Shaw's Danny Riley in a May 2026 survey of these laws: the CCPA "uniquely reaches employee personal information unlike the other state laws." For a vendor handling a client's HR or recruiting data, that can change which contract terms apply.

## What about subcontractors?

All three laws require a written contract that passes your obligations on to any subcontractor. California also requires you to notify the business, and Colorado requires an opportunity to object before the subcontractor is engaged. The details, and how to run a notice across your client list, are in [sub-processor change notices under US privacy laws](/blog/subprocessor-change-notice-us-privacy-laws).

## Their DPA or yours?

A 25-person performance agency with 50 brand clients can end up on 50 different DPAs, each with its own audit clause, deletion timeline and sub-processor process. Every vendor change then means checking 50 different promises.

The alternative is to send your own standard DPA to every client. The laws above share most of their contract terms. In Riley's words, "a well-drafted DPA template can generally cover the controller-processor laws with jurisdiction-specific riders." Whether a particular text does that for your business is a question for your counsel; this page doesn't draft it for you. What a standard text gives you is one document, one version history, and one place to update when it changes. Some clients' procurement teams will still insist on their own paper, and for those the usual negotiation applies.

If you're starting from nothing, there are openly licensed texts. Pacts hosts Common Paper's [Data Processing Agreement, Version 1.1](https://commonpaper.com/standards/data-processing-agreement/1.1/), published under CC BY 4.0, with its publisher, version, license and source link shown. Before a workspace adopts a library text, it confirms once that the text isn't legal advice and will be reviewed with its own counsel. Pacts doesn't host a California § 7051 addendum; it links to the regulation instead. When a client accepts a text adopted from the library, the certificate shows whether it was the published standard unchanged. [Your first DPA](/when/first-dpa) walks through getting one out the door.

Once the text is settled, the remaining work is getting every client to accept it and re-accept when it changes. If you're comparing ways to do that, see [clickwrap vs e-signature](/vs/clickwrap-vs-e-signature).

### Do US state privacy laws require a DPA?

California, Colorado and Virginia each require a written contract between the business or controller and the vendor processing data for it, and each lists terms it must contain. Whether it is called a DPA doesn't matter; what it contains does.

### What terms do Colorado and Virginia have in common?

Both require processing instructions, the nature and purpose of processing, the type of data and duration, confidentiality, deletion or return at the end, compliance information on request, audits or assessments, and a written flow-down contract with subcontractors (C.R.S. § 6-1-1305(5); Va. Code § 59.1-579(B)).

### What happens in California without a compliant contract?

Under Cal. Code Regs. tit. 11, § 7050(e), a person without a contract that complies with § 7051(a) is not a service provider or contractor, and the business's disclosure to that person may be considered a sale or sharing of personal information.

### Can one DPA cover California, Colorado and Virginia?

The laws share most of their terms, and practitioners have written that a well-drafted template can generally cover them with jurisdiction-specific riders. Whether your DPA does is a question for your counsel.

### Do I have to sign my client's DPA?

The statutes require a compliant contract, not a particular party's form. Who drafts it is a commercial question between you and your client.

**Sources**

- [Cal. Civ. Code § 1798.140(ag), (j) (service provider and contractor)](https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=1798.140)
- [Cal. Code Regs. tit. 11, §§ 7050–7051 (CCPA regulations, effective Jan. 1, 2026)](https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf)
- [Colo. Rev. Stat. §§ 6-1-1303, 6-1-1305 (Colorado Privacy Act), C.R.S. 2024](https://leg.colorado.gov/sites/default/files/images/olls/crs2024-title-06.pdf)
- [Va. Code § 59.1-579 (processor duties and contract)](https://law.lis.virginia.gov/vacode/title59.1/chapter53/section59.1-579/)
- [Va. Code § 59.1-575 (definitions)](https://law.lis.virginia.gov/vacode/title59.1/chapter53/section59.1-575/)
- [Danny Riley, Seyfarth Shaw, "The Paper Trail: State Privacy Law Contracting Requirements", Global Privacy Watch, May 6, 2026](https://www.globalprivacywatch.com/2026/05/the-paper-trail-state-privacy-law-contracting-requirements/)
- [Common Paper, Data Processing Agreement, Version 1.1 (CC BY 4.0)](https://commonpaper.com/standards/data-processing-agreement/1.1/)

_Pacts is not a law firm and this page is not legal advice. Speak to a licensed attorney about your situation._

Source: https://pacts.io/blog/state-privacy-law-processor-contract-requirements
