Without a compliant service-provider contract, the data your client shares may count as a sale.
Every client that sends you personal information now needs the same nine terms in writing — and so does every subcontractor of yours.
Where this goes.
Your first client under the CCPA — or one of the 2026 state privacy laws — asks for service-provider terms before the data flows.
§7051 lists nine terms the contract must carry: the specific business purpose, no selling or sharing, no use beyond that purpose or outside the relationship, no combining, the same level of protection, the client’s right to check and to stop and remediate, notice when you can no longer comply — and the same terms in your contracts with subcontractors (Cal. Code Regs. tit. 11 §7051).
Without a compliant contract you are not a service provider, and the disclosure ‘may be considered a sale or sharing’ — for the client, and downstream for you.
A client’s privacy counsel asks which contract makes you a service provider — and the answer is an email thread.
The quiet version: a DPA written for GDPR, signed once, and nobody checks whether it carries the nine terms.
“Accept terms” is not “Sign.”
Same terms, a different reflex. A request to sign enters legal routing and invites redlines; a page your client accepts says “standard”, and the business owner who said yes stays the owner.
Your clients already do this every day — Meta, Google and TikTok Ads terms are accepted by click. See the same DPA sent both ways →
Three things to do before the next client.
Write one service-provider addendum with the nine §7051 terms — the text you would send any client.
Send it as a link with the proposal; the business contact accepts the same day, and the record is written before data flows.
Flow it down: send the same terms to every subcontractor from the same board, and re-ask everyone when the text changes.
Put one standard agreement on Pacts today. Free for 3 standard terms and 5 clients — no card, no time limit.