Overview
This check reconciles your live Tag Inventory against your documented Vendor Register, confirming that every recipient of personal information observed on the wire has a corresponding entry classifying it as a Service Provider, Contractor, or Third Party (the three CCPA-defined recipient categories, each carrying a different contractual requirement).
Note: This guide is provided for informational purposes only and does not constitute legal advice. Consult qualified legal counsel regarding your organization's specific CCPA/CPRA compliance obligations.
Why it is important
You cannot prove appropriate contractual coverage for a data recipient you haven't classified in the first place. Any tag observed sending data to a party absent from your vendor register is, by definition, a recipient you can't demonstrate you've contracted with appropriately, regardless of whether a contract actually happens to exist somewhere in your organization.
Implementation
Run a full Tag Inventory audit, prioritizing tags already labeled "CCPA Sale/Share" first, then mark each known-good vendor's tags as "Approved" in ObservePoint's own Tag Compliance settings as you complete the vendor-register reconciliation below.
Check the pre-built ObservePoint report for Tag Inventory to get the full baseline of every tag account and vendor observed on the property, then check the pre-built ObservePoint report for Pages with Unapproved Tags to see what ObservePoint's own compliance-status setting has already flagged.
Join the Tag Inventory report's TAG_ACCOUNT/TAG_VENDOR columns against your Vendor Register. Any tag account with no matching register entry, or a vendor listed but missing a CCPA contract-type classification (Service Provider / Contractor / Third Party), is a finding, whether or not it also shows up in the Unapproved Tags report (that report only reflects what someone has already marked unapproved inside ObservePoint, not what's missing from the register).
Remediation
For remediation, follow the next steps:
For any tag with no matching vendor register entry, determine the receiving party and work with procurement/legal to establish the appropriate classification and contract type before continuing to allow the tag to fire. In the interim, consider temporarily disabling a newly discovered, unclassified high-risk tag rather than allowing an unclassified data flow to continue indefinitely.
For tags whose actual data use doesn't match their documented classification (for example, a vendor contracted as a Service Provider that is actually using the data for its own independent purposes), escalate to legal/privacy counsel, since this is a substantive compliance question rather than a technical fix.
Update the Vendor Register and re-run the reconciliation after each classification is finalized.
Conclusion
This reconciliation check is what turns your Vendor Register from a static document into a living control. Pairing it with the quarterly full-site Tag Inventory cadence keeps new vendor relationships from accumulating undetected.
