Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Who is accountable for CPPA compliance when personal…
Governance, Ownership & Risk

Who is accountable for CPPA compliance when personal data is shared with service providers?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 25, 2026 Domain: Governance, Ownership & Risk

Accountability remains with the organisation that collected the personal data, even when processing is shared with service providers. The service provider must provide substantially the same protection through contract or comparable controls, but the collecting organisation still needs oversight, contract terms, and evidence that privacy and security obligations are being met across the relationship.

How accountability works when a controller uses service providers

Under CPPA, shared processing does not shift the core accountability burden away from the organisation that collected the personal data. The collecting organisation remains responsible for choosing the relationship carefully, defining the processing boundaries, and making sure the service provider’s handling stays within the legal and contractual terms that support the original purpose.

That means accountability is not just a privacy label. It is an operational obligation to know what data is shared, why it is shared, who can access it, and whether the service provider’s controls are strong enough to preserve the same protection level expected from the collecting organisation itself.

What service-provider protection has to cover

The service provider is not acting as a free-standing counterpart to the collecting organisation’s duties. The protection has to extend to the real processing environment, including access control, security safeguards, retention limits, and onward use restrictions. In practice, that usually requires contract terms, documented instructions, and evidence that the provider can actually meet the required standard.

This is where many implementations fail: organisations rely on paper terms but do not validate the provider’s control environment. A contract can define obligations, but it cannot by itself prove that personal data is handled securely, that staff access is limited, or that the provider will delete or return data when the relationship ends.

What accountability means in day-to-day governance

For practitioners, the important point is that accountability survives delegation. The collecting organisation still needs oversight, periodic review, and a clear escalation path when the provider changes subprocessors, expands processing scope, or weakens security. It also needs evidence that privacy commitments are being maintained over time, not just at onboarding.

In other words, the organisation must be able to demonstrate control, not merely intent. That usually means maintaining the processing inventory, reviewing vendor terms, validating security attestations or control evidence, and confirming that the provider’s access, retention, and incident handling practices remain aligned with the shared processing arrangement.

Risk and Threat Considerations

Shared processing increases exposure because personal data may move into a control environment the collecting organisation does not directly operate. The main risk is that responsibility remains centralised while operational control becomes distributed, which can create blind spots in access, retention, subcontracting, and breach response.

Failure mechanism: Weak oversight, vague contract terms, or incomplete vendor evidence can leave the collecting organisation unable to verify that the provider is applying equivalent protection, especially where data is reused, retained too long, or accessed by too many parties.

Impact: The result can be compliance failure, privacy leakage, delayed incident detection, and difficulty proving that the organisation met its accountability obligations if regulators, clients, or affected individuals challenge the relationship.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CSA Cloud Controls Matrix set the technical controls, while GDPR, ISO/IEC 27001:2022 and SOC 2 (AICPA) define the regulatory obligations.

FrameworkControl / ReferenceRelevance
GDPRA.5.15 — Data sharing with service providersShared processing requires contractual and operational accountability over service providers.
Recommendation — Document processor obligations and verify equivalent protection through contract and oversight.
ISO/IEC 27001:2022A.5.19 — Information security in supplier relationshipsThe question turns on supplier oversight and security expectations across shared processing.
A.5.20 — Addressing information security within supplier agreementsAccountability depends on contract terms that bind the service provider to required protection.
Recommendation — Define supplier security requirements and review evidence that controls are being met. Embed processing limits, security duties, and incident obligations in supplier agreements.
NIST SP 800-53 Rev 5SA-9 — External System ServicesService-provider use requires defined, monitored security obligations for external services.
AC-20 — Use of External Information SystemsShared processing introduces risks when data is handled outside the collecting organisation.
Recommendation — Specify and monitor provider controls before allowing external system services. Restrict and govern external system use for data processing and access.
CSA Cloud Controls MatrixGRC — Governance, Risk & ComplianceVendor accountability and evidence are core governance requirements in shared processing.
Recommendation — Maintain vendor governance records and review compliance evidence on an ongoing basis.
SOC 2 (AICPA)CC9.2 — Vendor and Third-Party Risk ManagementThird-party processing hinges on supplier due diligence and continuous oversight.
Recommendation — Assess third-party risk and retain evidence of monitoring and contractual controls.

Practitioner Guidance

What to verify: Confirm that the service agreement, privacy terms, and security addendum all describe the same processing scope, retention rules, access model, and breach notification expectations. If any of those three documents diverge, treat the relationship as unresolved until corrected.

Decision rule: If the provider can process the data only through opaque subcontracting chains or cannot show current control evidence, do not treat the arrangement as low risk just because the provider is reputable. Escalate for stronger contractual safeguards or a different provider design.

Practitioner takeaway: CPPA accountability stays with the organisation that collected the data, so the real test is whether it can prove ongoing control over the vendor relationship, not whether the vendor promised to comply.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 25, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org