4.2 Data-Flow Mapping, Sharing, and Transfers
Key Takeaways
- A data-flow map follows personal information from collection through use, storage, sharing, and deletion, and it distinguishes internal flows from external ones.
- GDPR controller/processor language does not copy into U.S. law; the CCPA roles are business, service provider, contractor, and third party under Cal. Civ. Code § 1798.140.
- A CCPA "sale" is a disclosure to a third party for monetary or other valuable consideration; a CCPA "share" is a disclosure to a third party for cross-context behavioral advertising, whether or not money is paid.
- Cross-context behavioral advertising means targeting based on PI from the consumer's activity across distinctly branded businesses, sites, apps, or services other than the one the consumer intentionally interacts with.
- Domestic sharing can still be a sale or share; cross-border transfers add a second layer of tools (SCCs, the EU-U.S. Data Privacy Framework) taught in the next I.C chapter.
4.2 Data-Flow Mapping, Sharing, and Transfers
BoK 2.6.1 I.C PI1 does not stop at a static list of fields. You must also know data-flow mapping and data sharing and transfers. Inventory answers "what do we have." The map answers "how does it move." CIPP/US questions are almost always movement questions in disguise: a pixel, a nightly extract, an employee laptop, a cloud region, or an advertising partner. If you cannot draw the path, you will mis-label the role and then mis-label the legal consequence.
Map collection → use → storage → sharing → deletion
A complete map traces each processing activity through five stages:
- Collection. Cal. Civ. Code § 1798.140(f) defines collect broadly: buying, renting, gathering, obtaining, receiving, or accessing PI by any means, including observing the consumer. A web form, a store camera, a software-development kit, a data-broker file, and a badge swipe are all collection.
- Use. Every purpose after collection — fulfillment, analytics, product improvement, advertising, model training, fraud, HR. The map should flag secondary uses that were not disclosed at collection.
- Storage. Primary systems, data lakes, backups, logs, email archives, vendor tenants, and paper. Storage location is a transfer fact as well as a security fact.
- Sharing. Internal hand-offs and external disclosures. This is where CCPA sale, share, service-provider, contractor, and third-party analysis happens.
- Deletion / disposal. End-of-retention destruction, consumer-requested deletion, and the harder problem of backups, subprocessors, and derived models.
If any stage is missing, the map is not exam-ready. A diagram that shows only "app → cloud" hides the advertising pixel, the customer-support export, and the backup replica in a second region.
Internal versus external flows
Internal flows stay inside the same legal entity, or sometimes inside a controlled affiliate group that still has to honor employee-access, minimization, and purpose rules. Moving a customer file from sales to billing is internal. Moving it from the U.S. HQ to the company's own Irish support desk is still an internal organizational flow, but it may also be a cross-border transfer for GDPR or Swiss Federal Act on Data Protection (FADP) purposes. Internal is not the same as unregulated.
External flows leave the company: vendors, ad platforms, analytics companies, payment processors, data brokers, researchers, affiliates that are separate businesses, and government requesters. Every external flow needs a role label and a contract or legal process. The inventory's "sharing / recipients" column and the flow map should reconcile. If the map shows a pixel and the inventory does not, the inventory is stale.
Worked internal/external split. A bank's fraud team queries the deposit system — internal. The bank sends the same identifiers to a consortium fraud-scoring vendor under a use-limited contract — external, likely a service provider if the contract holds. The bank later sells a marketing segment to a retailer — external, a sale. The bank's Irish branch pulls a U.S. customer's file to answer a card-dispute call — internal to the corporate family, but a cross-border transfer that the international-transfers chapter will pick up.
Controller/processor versus CCPA roles
European vocabulary is useful and dangerous. A controller determines purposes and means. A processor processes on the controller's documented instructions. The CCPA does not use those words as its primary roles. Cal. Civ. Code § 1798.140 instead defines:
| Role | Statutory hook | Closest EU analog | Exam distinction |
|---|---|---|---|
| Business | § 1798.140(d): determines purposes and means, does business in California, and meets a threshold ($25 million inflation-adjusted revenue; buys/sells/shares PI of 100,000+ consumers or households; or derives 50%+ of revenue from selling or sharing) | Controller | The business owes consumer rights and notices |
| Service provider | § 1798.140(ag): processes on behalf of a business and receives PI from or on behalf of the business under a written contract that prohibits sale/share, secondary use, use outside the direct relationship, and most combining | Processor | Status is contractual and factual, not a brand name |
| Contractor | § 1798.140(j): the business makes PI available for a business purpose under a written contract with the same use limits, plus a certification of understanding and a right for the business to monitor at least once every 12 months | Processor-like | Often used when the recipient collects from the consumer or sits in the business's environment |
| Third party | § 1798.140(ai): anyone who is not the business the consumer intentionally interacts with, a service provider, or a contractor | Independent controller / other recipient | Sale and share are defined as disclosures to a third party |
A payment processor that only authorizes charges under a locked-down contract is typically a service provider. A freelance photographer who is given gallery access to customer wedding photos and certifies the statutory restrictions is typically a contractor. An advertising exchange that uses the identifiers for its own cross-site targeting is a third party. Calling all three "processors" loses the sale/share analysis.
Service-provider and contractor contracts must also flow down to subprocessors / downstream persons, with notice to the business. If the recipient keeps the right to train its own models, build its own marketing graph, or sell the file, the contract does not create service-provider or contractor status no matter what the cover page says.
Cross-border versus domestic sharing
Domestic sharing is still sharing. Sending California PI from an Ohio data center to a Texas analytics company is a U.S.-to-U.S. external flow. It can be a service-provider disclosure, a sale, or a share. It is not "safe" merely because no packet left the United States.
Cross-border transfers add a second legal layer. For EU or Swiss personal data entering or leaving the United States, the company may need Standard Contractual Clauses (SCCs), the EU-U.S. Data Privacy Framework (DPF) (adequacy decision 10 July 2023, still available as of August 2026), the UK Extension, or the Swiss-U.S. DPF. Those tools are I.C PI6–PI7 and belong in the international-transfers chapter. On this chapter's questions, flag the border, do not pretend a DPF certification erases CCPA role analysis, and do not pretend a CCPA service-provider clause is an SCC.
When a "share" is a California sale — and when it is the other statutory share
Everyday English collapses. The CCPA splits the words.
Sale (§ 1798.140(ad)) is communicating a consumer's PI to a third party for monetary or other valuable consideration. Cash is enough. So is a barter — access to a dataset in exchange for ad inventory, enrichment, or a discounted tool — if the consideration is valuable.
Share (§ 1798.140(ah)) is communicating a consumer's PI to a third party for cross-context behavioral advertising (CCBA), whether or not money or other valuable consideration is paid. The statute expressly includes CCBA transactions in which no money is exchanged.
CCBA (§ 1798.140(k)) is targeting advertising to a consumer based on PI obtained from the consumer's activity across businesses, distinctly branded websites, applications, or services, other than the business, site, app, or service with which the consumer intentionally interacts. On-site, current-interaction advertising that is not built from cross-context tracking is a different concept (nonpersonalized or first-party contextual advertising). Hovering, muting, or closing content is not an intentional interaction.
A disclosure to a qualifying service provider or contractor for a business purpose is generally not a sale or a share, because those recipients are defined out of "third party" — if the contract actually imposes the statutory prohibitions. A cloud host or tag-management vendor that uses the same identifiers to retarget the consumer on other brands is not saved by the word "processor" in the order form.
Exceptions exist: the consumer directs the disclosure; the business passes an opt-out signal so others will honor it; or the PI moves as an asset in a merger or similar transaction and continues to be used consistently with the title. Those exceptions are narrow. They do not convert an ad-exchange feed into a service-provider relationship.
Worked scenario. A shoe retailer drops a third-party pixel. The pixel sends a hashed email and a product-view event to an advertising platform. The platform uses that event, plus the same email seen on other retailers' sites, to show the consumer sneaker ads on a news site. The retailer pays nothing; it receives cheaper, better-targeted impressions. Under § 1798.140(ah) this is sharing for CCBA even with no cash. If the retailer also paid a CPM to buy the audience, it is likely both a share and a sale. The consumer is entitled to a Do Not Sell or Share My Personal Information path. Relabeling the pixel a "service provider analytics tag" without the statutory contract terms fails the role test and the transfer test.
A retailer sends hashed emails and browsing segments to an advertising platform so the platform can target those consumers on other sites. No cash changes hands; the retailer receives better-targeted ad inventory. How does the CCPA as amended treat this disclosure?
Which mapping of GDPR-style roles onto CCPA roles is accurate for a CIPP/US information-management question?
What must a complete personal-information data-flow map show?