Rights and contracts
Is an AI data buyer a service provider or a third party under CCPA?
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
An AI developer that licenses records to train its own models is usually a third party under the CCPA, not a service provider, because it uses the data for its own purposes. If the records still contain personal information and the developer pays, the transfer can be a sale, so suppliers usually remove personal information before delivery.
Key takeaways
- A service provider processes personal information on your behalf and for your purposes; an AI developer training its own models usually does neither.
- Licensing personal information to a third party for money or other value can be a sale under the CCPA, with notice and opt-out duties.
- A vendor that builds a model only for your company may fit the service provider role if the written contract restricts its use.
- Delivering properly deidentified records usually takes the transfer out of the sale analysis, but the CCPA standard also needs a public commitment and contract terms, not just technical removal.
- Employee records and business contact details are generally in scope, so B2B archives still need the analysis.
What do the CCPA roles mean for a data license?#
The CCPA roles decide what a company owes consumers when personal information leaves its systems. The law separates a business, which decides why and how personal information is processed, from a service provider or contractor that processes it for the business under a restrictive written contract, and from a third party, which is essentially everyone else.
For a company licensing support tickets, job records or CRM histories, the recipient's role changes both the paperwork and the consumer-facing obligations. A service provider relationship needs specific contract terms. A third-party relationship can make the transfer a sale, which brings notice and opt-out duties and contract terms of its own. The CCPA's separate concept of sharing covers cross-context behavioral advertising, which a training license usually is not, so the sale question is normally the one that matters.
Other state privacy laws use similar ideas under different names, usually controller, processor and third party. The California analysis is a useful starting point, but each state law that may apply is assessed on its own terms, deal by deal, with counsel.
Why is an AI developer usually treated as a third party?#
An AI developer that licenses records to train or evaluate its own models is usually treated as a third party because it uses the data for its own business purposes, not to perform a service for the supplier. The model it trains serves the developer's customers, and the supplier does not direct that processing.
The service provider role rests on processing on behalf of the business. Service provider contracts generally bar the recipient from retaining, using or disclosing personal information outside the direct relationship, which is the opposite of what a training license grants. Calling a training license a service agreement does not change what the recipient actually does with the data, and regulators look at conduct as well as labels.
Payment is what moves a third-party transfer toward being a sale. The CCPA defines sale broadly, covering disclosures for money or other valuable consideration, such as credits, services or rights in return, so a license fee for records that still contain personal information deserves the analysis even when the contract never uses the word sale.
Service provider, contractor and third party compared#
Service providers and contractors differ from third parties mainly in whose purposes the processing serves, and that difference decides whether a transfer can be a sale. The comparison below shows how the roles usually differ when records are licensed for AI; definitions and regulations change, so treat it as a map of questions for counsel rather than an answer for any one deal.
Where a transfer to a third party is a sale, the CCPA also expects a written agreement with that third party. The items below summarize what that agreement generally needs to cover; counsel checks the current statute and regulations for the exact wording.
- The limited and specified purposes for which the personal information is made available.
- A commitment by the recipient to comply with the CCPA and give the same level of privacy protection the law requires of the business.
- The business's right to take reasonable steps to make sure the recipient uses the information consistently with those obligations.
- A duty on the recipient to notify the business if it can no longer meet its obligations.
- The business's right to stop and remediate unauthorized use.
| Question | Service provider or contractor | Third party |
|---|---|---|
| Whose purposes does the processing serve? | The supplier's, for a specified business purpose | The recipient's own, such as training models it offers to others |
| Can the transfer be a sale? | Generally not, if the contract and conduct fit the role | Yes, if personal information is made available for money or other valuable consideration |
| What contract is needed? | Written terms limiting use to the specified business purpose | Terms on specified purposes, compliance, oversight and stopping unauthorized use |
| What consumer notice applies? | Disclosure in the privacy policy of categories disclosed for a business purpose | Sale disclosures, a Do Not Sell or Share link and opt-out handling, unless the delivered data is no longer personal information |
| Typical AI example | A vendor tuning a support assistant used only by your company | A model developer licensing archives to train general models |
When can an AI vendor be a service provider?#
An AI vendor can be a service provider when it processes personal information to build or run something for the supplier alone, under a contract that bars other uses. A company that hires a vendor to tune a dispatch assistant on its own job records, with no right for the vendor to reuse those records elsewhere, sits closer to this pattern.
The line blurs when the vendor's terms allow it to reuse customer records to improve its general products or foundation models. California's regulations give service providers limited room to use personal information to build or improve their own services, but not to perform services for other businesses, so where general model training falls is a judgment for counsel based on the actual contract and settings, not the label. The same vendor can be a service provider under one contract and a third party under another. Signs that a vendor is acting more like a third party include the following.
- The vendor may keep records after the engagement ends for its own use.
- The contract lets the vendor combine your records with other customers' data to improve its general models.
- The price is lower because the vendor gains training rights in return.
- The vendor may sublicense or disclose the records to affiliates or partners.
What changes when personal information is removed first?#
Removing personal information before release is the main way a supplier can keep a training license outside the sale analysis. If the delivered dataset meets the CCPA's definition of deidentified information, it is generally not personal information, and the recipient's role matters far less.
The CCPA's deidentification standard is more than a technical step. In general terms it requires reasonable measures so the data cannot be associated with a consumer, a public commitment to keep the data in deidentified form and not attempt to re-identify it, and contract terms requiring recipients to do the same. Check the current definition with counsel before relying on it. Pseudonymized data, where a retained key could restore identities, usually remains personal information.
Free-text fields are where removal fails. Technician notes, chat messages and email bodies carry names, street addresses, phone numbers and account details in places a column-level rule never reaches, so review samples by hand after automated scanning.
Illustrative: a California plumbing and HVAC company#
Illustrative: a fictional plumbing and HVAC contractor serving California homeowners runs dispatch, estimates and invoices in ServiceTitan, with years of technician notes, equipment photos and callback records. A model developer asks to license the job history to train a field service assistant it will sell to other contractors.
Counsel classifies the developer as a third party, because the assistant serves the developer's customers. The raw records include homeowner names, addresses and phone numbers, so licensing them as stored would raise the sale question and the opt-out duties that follow.
The company licenses only prepared records: customer identifiers removed, addresses generalized to the service region, photos screened for faces, house numbers and paperwork, and technician names replaced with role labels. The contract bars re-identification and resale, the company adds the public no-re-identification commitment that the deidentification standard calls for, and it refreshes its privacy policy wording so its notices describe the program plainly.
Questions to settle before signing#
The questions to settle before signing cover coverage, identifiability, the recipient's purpose, notices, contract terms and sensitive data. Sensitive personal information deserves its own pass: precise location from routing records, government identifiers in onboarding files and log-in details pasted into support tickets raise additional limits, so the cautious approach is to exclude them outright rather than rely on preparation alone.
- Is the company a business covered by the CCPA, and which other state laws may apply?
- Which delivered fields could still identify a consumer, an employee or a business contact?
- Does the recipient use the data for its own purposes, and could the license fee make the transfer a sale?
- Do the privacy policy and notices describe the disclosure, and is an opt-out route needed?
- Does the contract contain the terms required for the recipient's actual role?
- Are sensitive categories, such as precise location or account credentials, excluded?
How SourceX handles the role question#
SourceX settles the recipient's role during the Rights step of the SourceX five-step transaction, before any records are prepared. The buyer's intended use is written down, the supplier's counsel completes the role analysis, and personal and confidential details are then removed in the Preparation step, to the standard both sides agreed.
The outcome is recorded in the SourceX Evidence Packet: the permitted use, the privacy record of what was removed and how, and the release authorization signed by the supplier. The initial fit check collects metadata only, so no records move while the role question is open.
Frequently asked questions
Does the CCPA apply to B2B companies?
It can. The CCPA applies to for-profit businesses that meet its thresholds, whether their customers are consumers or companies. Employee records and business contact details in CRM histories are generally personal information under current law, so a B2B archive is not automatically outside the analysis. Confirm coverage with counsel.
Is a license the same as a sale under the CCPA?
Not in name, but possibly in effect. The CCPA looks at whether personal information is made available to a third party for money or other valuable consideration, not at what the contract calls the deal. A license fee for records containing personal information can meet that test, which is why prepared, deidentified records are usually the safer delivery.
What if our privacy policy says we do not sell personal information?
Treat that statement as a constraint. California's regulations generally do not let a business sell personal information it collected while telling consumers it does not sell, unless those consumers consent. Changing the policy usually works only for information collected afterwards, which is one more reason suppliers deliver deidentified records. Confirm the current rule with counsel.
What is the difference between a service provider and a contractor?
Both process personal information for a business purpose under a written contract with use restrictions, and the CCPA treats them as separate roles with similar limits. Counsel decides which label fits a given vendor. In practice, both roles describe vendors working for you, not developers training models they offer to others.
Do other states use the same roles?
Most comprehensive state privacy laws use controller and processor rather than business and service provider, and many define sale in their own way. A transfer that is not a sale in one state may be treated differently in another, so suppliers with customers in several states have counsel review each law that may apply.
Does a promise not to re-identify data make the buyer a service provider?
No. A promise not to re-identify is a contract protection, not a change of role. The developer still uses the data for its own purposes, so it remains a third party. The promise matters for another reason: commitments like it are typically part of what keeps prepared data outside the definition of personal information.
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.