DPA — Multi-State US (CCPA, VCDPA, CPA, CTDPA, UCPA, TDPSA, OCPA, DPDPA) review
Multi-state DPA covering CCPA + VCDPA + CPA + CTDPA + UCPA + TDPSA + OCPA + DPDPA.
Review your document — free → See a sample report- 25 document-specific checks
- + 115 general checks
- Nothing uploaded
- Free forever (MIT)
What it checks
CCPA: purpose-limitation clause
CCPA service-provider contract must prohibit use of personal information outside the specific business purpose.
Critical · USDPA-001
CCPA: no-sale prohibition
CCPA service-provider contract must prohibit selling personal information.
Critical · USDPA-002
CCPA: no-cross-context-advertising prohibition
CCPA service-provider contract must prohibit cross-context behavioral advertising.
Critical · USDPA-003
CCPA: no-combining-with-other-data restriction
CCPA service-provider contract must prohibit combining personal information with data from other sources.
Warning · USDPA-004
CCPA: same-level-of-privacy-protection
CCPA contract must require the service provider to comply with applicable CCPA obligations and provide the same level of privacy protection.
Critical · USDPA-005
CCPA: contractor certification of understanding
A CCPA contractor's contract must include the contractor's certification that it understands and will comply with the contract's restrictions.
Warning · USDPA-006
CCPA: monitoring / oversight right
CCPA contract must grant the business the right to take reasonable steps to ensure consistent use.
Critical · USDPA-007
CCPA: assistance with consumer requests
CCPA service-provider contract must require assistance with consumer rights requests.
Critical · USDPA-008
CCPA: notification of inability to comply
CCPA service-provider must notify business if it can no longer meet its obligations under CCPA.
Critical · USDPA-009
CCPA: subcontractor flow-down
CCPA service-provider must require subcontractors to meet the same CCPA obligations.
Critical · USDPA-010
Multi-state: processing instructions clear
Processor contract must set out the processing instructions binding on the processor.
Critical · USDPA-011
Multi-state: nature and purpose of processing
Processor contract must specify the nature and purpose of the processing.
Critical · USDPA-012
Multi-state: type of personal data identified
Processor contract must identify the type of personal data processed.
Critical · USDPA-013
Multi-state: duration of processing
Processor contract must specify the duration of processing.
Critical · USDPA-014
Multi-state: deletion or return
Processor must delete or return personal data at end of services at controller's direction.
Critical · USDPA-015
Multi-state: confidentiality duty
Processor must ensure persons processing personal data are subject to a duty of confidentiality.
Critical · USDPA-016
Multi-state: audit cooperation
Processor must cooperate with reasonable assessments / audits by the controller.
Critical · USDPA-017
Multi-state: subcontractor written contract
Processor must engage subcontractors only pursuant to a written contract.
Critical · USDPA-018
Multi-state: information for compliance demonstration
Processor must make information available to demonstrate compliance.
Critical · USDPA-019
Service Provider status claimed but not earned
Flags a document that claims CCPA 'Service Provider' status but does not contain the § 7051(a) required elements.
Critical · USDPA-020
Multi-state contract does not meet strictest applicable requirement
Flags multi-jurisdiction DPAs that explicitly contemplate multiple states but use weaker (e.g., Utah-style) language.
Note · USDPA-021
Sensitive personal information separately addressed
DPAs should specifically address sensitive personal information (SPI) handling.
Warning · USDPA-022
Consumer rights process documented
DPA should document the process for handling consumer rights requests.
Warning · USDPA-023
Data minimization principle referenced
DPA should reference the data-minimization principle.
Warning · USDPA-024
Personal information / data referenced
Document should reference 'personal information' or 'personal data'; absence likely means the wrong template.
Critical · USDPA-025
Every run also applies 115 general checks that belong to any agreement: structure, parties and signatures, defined terms, cross-references, dates, amounts, and one-sided terms.
Sources
Often reviewed with
How it works
- Open vaulytica.com — no account, nothing to install.
- Drop your PDF or DOCX. The document type is detected and only the checks that belong to it run, inside your browser tab.
- Get a Word report in which every finding quotes the clause and cites the rule and source behind it — one of 1,825 checks across 268 document types.
More privacy & data protection documents
- Biometric Data Consent (BIPA-style)
- Children's Privacy Notice (COPPA)
- Cookie / Tracking Notice
- Data Sharing Agreement (Research / Inter-Agency)
- DPA — CCPA Service Provider (CPRA-aligned)
- DPA — Controller to Processor (EU/UK)
- DPA — Processor to Sub-Processor (EU/UK GDPR)
- Data Protection Impact Assessment (GDPR Art. 35)
- Data-Incident Notification Template
- Privacy Notice (GDPR)
- Privacy Notice (US / CCPA)
- Privacy Policy Linter
- Records of Processing Activities (GDPR Art. 30)
- EU Standard Contractual Clauses — Module 2 (Controller to Processor)
- EU Standard Contractual Clauses — Module 3 (Processor to Processor)
- SMS / Telemarketing Consent Disclosure
- UK International Data Transfer Addendum / IDTA
- Vendor Security Addendum
- Vendor Security Questionnaire (SIG / CAIQ)