Skip to content

CCPA ADMT Regulations

CCPA ADMT Regulations illustration

The CCPA ADMT Regulations are the California Privacy Protection Agency's (CalPrivacy) regulations on automated decisionmaking technology (ADMT) under the California Consumer Privacy Act (Civ. Code § 1798.100 et seq.), codified in Cal. Code Regs. tit. 11. They implement the CCPA; they are not a new statute. The Agency adopted them on July 24, 2025, the Office of Administrative Law approved them on September 22, 2025, and they took effect on January 1, 2026. A business that uses ADMT to make a significant decision concerning a consumer owes a Pre-use Notice, the ability to opt out of ADMT (except on the conditions of three exceptions), responses to requests to access ADMT, and a risk assessment before it initiates the processing (by December 31, 2027 for processing that began before January 1, 2026 and continues); a business that processes consumers' personal information it intends to use to train such ADMT owes the risk assessment too. Consumers include California-resident employees, job applicants, independent contractors, and students.

Modulos models the regulations as two paired templates with the Regulation label: MFF-29 for one ADMT and OFF-29 for the organization's repeatable capabilities. This page orients you on what the regulations require, who they reach, the clocks, and where to go next.

Read this first: the regulations' own vocabulary governs

Several regimes use similar words for different things. Under the CCPA regulations, ADMT is defined by a three-part human-involvement test (§ 7001(e)(1)), reaches rules-based technology as well as AI, and a significant decision is a closed list of five categories (§ 7001(ddd)) with no general "legal or similarly significant effects" test. Colorado SB 26-189 uses "ADMT" for a differently defined technology, with "consequential decisions", "adverse outcomes", "developers" and "deployers"; the GDPR speaks of controllers, processors, data subjects and "solely automated" decisions; the California bills AB 1018 and SB 947 (pending as of August 2026, neither law) use "automated decision system". None of that vocabulary applies here. These pages use the regulations' terms only.

Quick decision — is this framework for you?

  • You are a CCPA business, and a technology that processes personal information and uses computation produces an output that, without a human who meets all three parts of the § 7001(e)(1) test, results in the provision or denial of financial or lending services, housing, education enrollment or opportunities, employment or independent contracting opportunities or compensation, or healthcare services for a California resident (a customer, employee, applicant, contractor, or student), each category on its § 7001(ddd) subdefinition → Article 11 applies on the § 7200(b) branches: no later than January 1, 2027 for a use begun before that date, and whenever you use the ADMT on or after it. Run the conjunctive test in Coverage and roles and record the determination.
  • You are a CCPA business and process consumers' personal information you intend to use to train such an ADMT → the Article 10 risk assessment is due before you initiate the processing, whether or not the ADMT is ever used (§§ 7150(a), (b)(6), 7155(a)(1)); processing that began before January 1, 2026 and continues must be assessed by December 31, 2027. See Risk assessments and Agency submissions.
  • You are a CCPA business that makes ADMT trained using personal information available to another business for its significant decisions, or you are a service provider or contractor processing personal information for a business, or a third party to whom a business made personal information available → role duties attach under §§ 7050–7053 and § 7153. See Service providers and ADMT suppliers.
  • You already run the GDPR, Colorado SB 26-189, or NYC Local Law 144 in Modulos → no Control is shared: all 13 mapped Controls are new, because the regulations' specific notices, request mechanics, exceptions, and assessment content do not align with existing Controls. See Operationalizing the CCPA ADMT Regulations in Modulos.

TL;DR

  • The instrument: Cal. Code Regs. tit. 11, the CCPA regulations, as amended by the Agency's 2025 rulemaking that added the ADMT provisions (Article 11, §§ 7200–7222), the risk-assessment article (Article 10, §§ 7150–7157), and the supporting definitions. Adopted July 24, 2025; approved by the Office of Administrative Law September 22, 2025; effective January 1, 2026.
  • ADMT = any technology that processes personal information and uses computation to replace or substantially replace human decisionmaking; human involvement requires a reviewer who knows how to interpret and use the output to make the decision, reviews and analyzes the output and any other relevant information, and has the authority to make or change the decision based on that analysis; all three parts must hold (§ 7001(e)(1)).
  • Significant decision = a closed list: financial or lending services, housing, education enrollment or opportunities, employment or independent contracting opportunities or compensation, healthcare services (§ 7001(ddd)).
  • Article 11 duties: the Pre-use Notice (§ 7220); the ability to opt out of ADMT, with three exceptions on their conditions (§ 7221); responses to requests to access ADMT (§ 7222).
  • Article 10 duties: a risk assessment before initiating the use, and before processing personal information intended to train such ADMT (§§ 7150–7156); information about the assessments filed with the Agency (§ 7157).
  • Clocks: Article 11 compliance no later than January 1, 2027 for a use begun earlier, and at all times for a use on or after that date; risk assessments before initiation, and by December 31, 2027 for processing begun before 2026 that continues; the first filing of the § 7157(b) information by April 1, 2028 (for 2026 and 2027 assessments; § 7157(a)(1)), then April 1 after any year with assessments.
  • Modulos: MFF-29 (AI application, 8 Requirements, MRF-489MRF-496) + OFF-29 (organization, 5 Requirements, ORF-488ORF-492), templates 1.0.32, mapped to 13 new Controls (none shared). A CCPA Role tag (Business using ADMT; Service provider or contractor; Third party; ADMT supplier) marks the role branches; the roles are not exclusive.

Primary source

California Consumer Privacy Act regulations, Cal. Code Regs. tit. 11, §§ 7000 et seq., as adopted by the California Privacy Protection Agency on July 24, 2025 and approved by the Office of Administrative Law on September 22, 2025: regulations on cppa.ca.gov. The Agency's Final Statement of Reasons explains the narrowed ADMT and significant-decision definitions; it is a rationale document, not a source of duties. Always verify claims against the current published text.

Key facts
Regulator
California Privacy Protection Agency (CalPrivacy)
Instrument
Cal. Code Regs. tit. 11, implementing the CCPA (Civ. Code § 1798.100 et seq.); ADMT provisions in §§ 7001, 7150–7157, 7200–7222 (Regulation label in Modulos)
Adopted / approved / effective
July 24, 2025 / September 22, 2025 (Office of Administrative Law) / January 1, 2026
Article 11 compliance
No later than January 1, 2027 for a business that used ADMT for a significant decision before that date; any time a business is using ADMT for a significant decision on or after it (§ 7200(b))
Covers
CCPA businesses using ADMT for a significant decision concerning a consumer, or processing personal information they intend to use to train such ADMT; consumers include California-resident employees, applicants, contractors, and students. Direct duties also bind service providers, contractors, third parties, and businesses that make PI-trained ADMT available to another business for a significant decision
Modulos templates
MFF-29 (application) + OFF-29 (organization): 13 Requirements, 13 Controls

Which instrument is which

The regulations sit inside a stack, and adjacent regimes share words with them. Knowing which instrument a source describes is the first scoping task.

InstrumentWhat it isStatus for this framework
California Consumer Privacy Act, Civ. Code § 1798.100 et seq.The statute: the definitions of business, consumer, personal information, service provider, contractor and third party; the consumer rights; non-retaliation (§ 1798.125); the exemptions (§§ 1798.145, 1798.146); the request-response mechanics (§ 1798.145(h)); enforcement by the Agency and the Attorney GeneralThe source the regulations implement; coverage turns on its definitions
CCPA regulations, Cal. Code Regs. tit. 11, §§ 7000 et seq.The Agency's implementing regulations: disclosures and notices, request methods and timelines, service-provider and third-party contracts, verification, non-discrimination, training and recordsThe host text; the ADMT duties cross-reference these articles throughout
The 2025 ADMT rulemaking (adopted July 24, 2025; approved September 22, 2025; effective January 1, 2026)Added the ADMT and significant-decision definitions (§ 7001(e), (ddd)), Article 11 on ADMT (§§ 7200–7222), and the Article 10 risk-assessment regime (§§ 7150–7157), among other changesThis framework
Civil Rights Council regulations on automated-decision systems in employmentA separate California regime under the Fair Employment and Housing Act, with its own vocabularyNot covered by this framework
Colorado SB 26-189; AB 1018 and SB 947 (California, pending as of August 2026)A different state's ADMT statute; two California bills that, as of August 2026, are not lawColorado has its own framework; the bills are watch items only (ORF-492; the September 2026 backstop is under Pending developments)

What the regulations require

Provision (Cal. Code Regs. tit. 11)What it holds
§ 7001 — DefinitionsADMT and the three-part human-involvement test, profiling, and the utility exclusion ((e)); significant decision as a closed list with subdefinitions and the advertising carve-out ((ddd)); performance at work and in an educational program ((cc), (dd)); request to appeal ADMT ((kk)); risk assessment report ((zz)); train ((fff)); authorized agent ((d)).
§ 7002 — Restrictions on collection and usePurpose compatibility with the context of collection, the reasonably-necessary-and-proportionate standard, consent under § 7004 where a purpose fails, and a new Notice at Collection for additional categories or incompatible purposes.
§§ 7003, 7010–7012 — Disclosures and noticesDisclosure quality (plain language; a readable format, including on smaller screens if applicable; the business's ordinary languages; accessibility for consumers with disabilities); the notice set, including the Pre-use Notice and, except as set forth in § 7221(b), the opt-out link inside it; the privacy policy's ADMT-rights content; the Notice at Collection.
§ 7004 — Request methods and consentEasy to understand, symmetrical, free of confusing language and choice architecture that impairs choice, easy to execute, and tested; dark patterns.
§§ 7020–7028 — Request handlingThe methods for submitting requests and the § 7021 timelines: confirmation within 10 business days, response within 45 calendar days, one extension of up to 45 further days where necessary, never beyond 90.
§§ 7050–7053 — Service providers, contractors, and third partiesWhat a service provider or contractor may do with contracted personal information; the mandatory contract terms (§ 7051); the bar on third parties without a compliant contract (§ 7052); third-party agreements (§ 7053).
§§ 7060–7063 — Verification and authorized agentsReasonable verification methods; never required for a request to opt out of ADMT; the certainty tier for requests to access ADMT from non-accountholders; authorized agents.
§ 7080 — Non-discriminationA denial of a request to delete, correct, know, access ADMT, opt out of sale/sharing, or opt out of ADMT for reasons the CCPA or the regulations permit is not discriminatory; financial incentives and price or service differences.
§§ 7100–7102 — Training, records, metricsInformed request handlers; 24-month request records; the training policy and annual metrics for businesses meeting the 10,000,000-consumer predicates.
§§ 7150–7157 — Risk assessmentsThe triggers, including using ADMT for a significant decision and processing personal information intended to train such ADMT; content; stakeholders; the weighing goal; timing, review, update and retention; reuse; the Agency submissions and production on request.
§ 7200 — ApplicabilityArticle 11 applies to a business that uses ADMT to make a significant decision concerning a consumer, on the two § 7200(b) timing branches.
§ 7220 — Pre-use NoticeTiming, placement, channel, content (specific purpose, rights, non-retaliation, how the ADMT works and how the decision would be made for a consumer who opts out), the narrow carve-outs, and consolidated notices.
§ 7221 — Opt-out of ADMTThe ability to opt out; the three exceptions and their conditions; methods, burden, fraud, confirmation, agents, the 12-month waiting period, non-retaliation, pre-initiation requests, and, on a post-initiation request from a consumer who did not opt out at the Pre-use Notice, cessation as soon as feasibly possible and no later than 15 business days with recipient instruction.
§ 7222 — Access to ADMTThe four plain-language explanations; the carve-outs on the logic and outcome elements; methods, verification, delivery, the aggregate option, and non-retaliation; the service provider's and contractor's duty to assist.

Who is covered

Article 11 applies to a business that uses ADMT to make a significant decision concerning a consumer (§ 7200(a)). The test is conjunctive:

  • the organization is a business within Civ. Code § 1798.140(d): a sole proprietorship, partnership, limited liability company, corporation, association, or other legal entity organized or operated for the profit or financial benefit of its shareholders or other owners, that collects consumers' personal information or on whose behalf it is collected, that alone or jointly with others determines the purposes and means of processing, that does business in California, and satisfying one or more of the statutory thresholds (as of January 1 of the calendar year, annual gross revenues in the preceding calendar year above the adjusted figure of $26,625,000 since January 1, 2025; alone or in combination, annually buying, selling, or sharing the personal information of 100,000 or more consumers or households; or deriving 50 percent or more of annual revenues from selling or sharing it), or reaching business status as an entity that controls or is controlled by such a business, shares common branding with it, and with whom it shares consumers' personal information; as a joint venture or partnership of businesses each holding at least a 40 percent interest; or as a person doing business in California, not covered by the other routes, that voluntarily certifies to the Agency that it complies with and is bound by the CCPA (§ 1798.140(d)(2)–(4));
  • the affected people are consumers, meaning California residents, which includes employees, job applicants, independent contractors, and students;
  • the information is personal information in scope after the CCPA's exclusions and conditional exemptions (medical information governed by the Confidentiality of Medical Information Act and protected health information collected by a HIPAA covered entity or business associate; providers of health care, covered entities, and business associates to the stated extent; research information; consumer-report activity under the Fair Credit Reporting Act; Gramm-Leach-Bliley Act information; and others, each on its conditions);
  • the technology is ADMT: it processes personal information and uses computation to replace or substantially replace human decisionmaking, and no human meeting all three parts of the § 7001(e)(1) test sits in the original decision flow;
  • the decision is a significant decision on the closed § 7001(ddd) list.

Separately, a business that processes consumers' personal information it intends to use to train an ADMT for a significant decision owes the Article 10 risk assessment for that processing, whether or not the ADMT is ever used (§ 7150(b)(6)).

The CCPA roles are not exclusive: the same organization can be a business for one technology and a service provider, contractor, third party, or ADMT supplier for another, and a service provider, contractor, or third party that independently meets the business definition carries the business duties for ADMT it uses for its own significant decisions.

→ Full treatment, including the exemption conditions, the human-involvement test, the subdefinitions of each significant-decision category, and the four roles: Coverage and roles.

How Modulos models it

TemplateProject typeHoldsRequirements
MFF-29 — CCPA ADMT RegulationsAI applicationFor one ADMT: the coverage determination; the Pre-use Notice; the opt-out of ADMT; the human-appeal route; the hiring and work-allocation exceptions; access to ADMT; the risk assessment for the ADMT; the service-provider, third-party and ADMT-supplier duties8 (MRF-489MRF-496)
OFF-29 — CCPA ADMT RegulationsOrganizationThe repeatable capabilities: the ADMT request-handling infrastructure; the human-involvement and human-appeal capability; the risk-assessment program and Agency submissions; the notice, purpose-compatibility and contract program; the California ADMT regulatory watch5 (ORF-488ORF-492)

One MFF-29 project assesses one ADMT. Every Requirement carries a CCPA Role tag; all 13 carry Business using ADMT, MRF-495 and MRF-496 also carry ADMT supplier, and MRF-496 carries Service provider or contractor and Third party as well. The roles are deliberately non-exclusive. There is no scoping questionnaire: MRF-489 records the coverage determination inside the project, and the conditional Requirements (MRF-490MRF-494) apply only where the ADMT is used for a significant decision.

The 13 Requirements group into four coverage areas, each with its own topic page.

1. Coverage and roles

The conjunctive test (business, consumer, personal information, ADMT, significant decision), the three-part human-involvement test, the exemptions with their conditions, the training trigger, the § 7200(b) timing branches, and purpose compatibility for repurposed information (MRF-489), with the four CCPA roles defined as context for the role duties in MRF-496.

→ Deep dive: Coverage and roles.

2. Pre-use Notice, opt-out, and access

The Pre-use Notice with its timing, content, and substitutions (MRF-490); the ability to opt out of ADMT with its methods, no-verification rule, and cessation clock (MRF-491); the human-appeal route and its reviewer conditions (MRF-492); the admission, acceptance, or hiring and the work-allocation exceptions on their conditions (MRF-493); the response to a request to access ADMT (MRF-494); and, organization-side, the request-handling infrastructure (ORF-488) and the human-involvement and human-appeal capability (ORF-489).

→ Deep dive: Pre-use Notice, opt-out, and access.

3. Risk assessments and Agency submissions

The Article 10 risk assessment for the ADMT, with the § 7152 content and, for a use of ADMT for a significant decision, the logic-and-output element, the weighing, the approver, and the review, update, and retention cycle (MRF-495); and, organization-side, the program and the § 7157 submissions (ORF-490).

→ Deep dive: Risk assessments and Agency submissions.

4. Service providers, third parties, and ADMT suppliers

The duties by role: the business's contract terms and the opt-out flow-down; the service provider's and contractor's limits and assistance duties; the third-party bar; the ADMT supplier's duty, for ADMT trained using personal information, to provide all facts available to it that a recipient-business's own risk assessment needs (MRF-496); and, organization-side, the notice, purpose-compatibility and contract program (ORF-491).

→ Deep dive: Service providers and ADMT suppliers.

What the regulations do not do

The regulations do not create a new statute or a new enforcement body; the duties are CCPA duties, enforced under the CCPA. They do not limit ADMT to artificial intelligence: rules-based technology that substantially replaces human decisionmaking qualifies on the same terms. They do not contain a general test for decisions with "legal or similarly significant effects"; the significant-decision list is closed, advertising is carved out, and insurance is not on it. They do not remove a technology from the ADMT definition because an appeal is available after the decision: human involvement is tested in the original decision flow, and the human-appeal route is an exception to the opt-out, not a scoping argument. They do not state the three § 7221(b) opt-out exceptions as flat carve-outs: each applies only where its conditions are true and stay true, and an exception relied on for one use does not excuse the opt-out for another use of the same ADMT. And they do not prescribe a bias audit, a test method, or a documentation format for the condition that an ADMT "works for the business's purpose and does not unlawfully discriminate based upon protected characteristics"; the regulations set the condition and leave the showing to the business.

Clocks

DutyClockAnchor
Article 11 (Pre-use Notice, opt-out, access) for ADMT used for a significant decision before January 1, 2027In compliance no later than January 1, 2027§ 7200(b)
Article 11 for ADMT used for a significant decision on or after January 1, 2027In compliance any time the business is using ADMT for a significant decision§ 7200(b)
Risk assessment for newly covered processingBefore initiating the processing§ 7155(a)(1)
Risk assessment for processing begun before January 1, 2026 that continuesNo later than December 31, 2027§ 7155(b)
Review and update of risk assessmentsReviewed, and updated as necessary, at least once every three years; a material change updated as soon as feasibly possible and no later than 45 calendar days after the change§ 7155(a)(2)–(3)
Retention of risk assessmentsWhile the processing continues or five years after the assessment is completed, whichever is later§ 7155(c)
First § 7157(b) information filing with the Agency (for assessments conducted in 2026 and 2027)No later than April 1, 2028§ 7157(a)(1)
Later filingsApril 1 following any year during which the business conducted risk assessments§ 7157(a)(2)
Risk assessment reports on request of the Agency or the Attorney GeneralWithin 30 calendar days of the request§ 7157(e)

The information § 7157(b) requires in the filings is information about the risk assessments (counts, categories, a point of contact, an executive attestation), not the assessments or the reports themselves; the reports are required on request of the Agency or the Attorney General under § 7157(e).

Pending developments

No provision of the regulations requires a watch, and nothing pending changes the clocks above. Four developments can change what the framework asks. In its Final Statement of Reasons the Agency said it may revisit the ADMT definition (§ 7001(e)), the significant-decision definition (§ 7001(ddd)), and the Article 11 applicability provision (§ 7200) in future rulemaking. AB 1018 and SB 947 are California bills on automated decision systems with their own vocabulary; as amended on August 21, 2026, AB 1018 was on second reading in the Senate and SB 947 had been ordered to third reading in the Assembly, and as of August 2026 neither is law. This passage has a known expiry: each house must pass bills by August 31, 2026, and a bill passed before September 1, 2026 and in the Governor's possession on or after that date becomes a statute if it is not returned on or before September 30, 2026 (Cal. Const. art. IV, § 10(b)(2)), so the Governor may sign either bill, veto it, or let it become law without signature. This framework does not implement them. The CCPA's monetary thresholds are adjusted in odd-numbered years for any increase in the Consumer Price Index, next effective January 1, 2027, the same day the Article 11 transitional deadline falls, so a business near the revenue threshold may cross it on that date. And federal preemption proposals would displace California privacy law if enacted; none has been.

The organization framework's ORF-492 carries the watch as a readiness practice under five markers. Modulos will update the framework and these pages if the Agency revisits the ADMT provisions or a bill becomes law; framework versioning notifies affected projects.

Enforcement

The regulations are enforced as part of the CCPA, by the Agency administratively and by the Attorney General civilly. The per-violation ceilings effective January 1, 2025 are $2,663, rising to $7,988 on two distinct triggers that are not the same test: administratively, for each intentional violation and for violations involving the personal information of consumers the business, service provider, contractor, or other person has actual knowledge are under 16 years of age (Civ. Code § 1798.155(a)); civilly, for each intentional violation and each violation involving the personal information of minor consumers, with no stated knowledge condition (Civ. Code § 1798.199.90(a)). The figures move with the odd-year adjustment. A business also must not retaliate against a consumer, including an employee, applicant, or independent contractor, for exercising a CCPA right (Civ. Code § 1798.125; § 7080), and a denial of a request to delete, correct, know, access ADMT, opt out of sale/sharing, or opt out of ADMT for reasons permitted by the CCPA or the regulations is not discriminatory (§ 7080(c)).

How Modulos operationalizes the CCPA ADMT Regulations

Each Requirement is evidenced through its linked Control; the Requirement Owner reviews the completed Control and marks the Requirement as Fulfilled. The California-specific tests, clocks, and content elements live in the Requirement text, which quotes the operative regulatory text verbatim, and in the 13 new Controls.

  • 8 new application Controls: MCF-695 (CCPA ADMT coverage determination), MCF-696 (Pre-use Notice), MCF-697 (ADMT opt-out mechanics), MCF-698 (Human-appeal route), MCF-699 (Hiring and work-allocation exception evidence), MCF-700 (Access-to-ADMT response), MCF-701 (CCPA risk assessment for the ADMT), MCF-702 (Service-provider, third-party and supplier duties for the ADMT).
  • 5 new organization Controls: OCF-385 (ADMT request-handling infrastructure), OCF-386 (Human involvement and human-appeal capability), OCF-387 (Risk-assessment program and Agency submissions), OCF-388 (Notice, purpose-compatibility and contract program), OCF-389 (California ADMT regulatory watch).
  • No shared Controls. Every mapped Control is new, and none is mapped by another template.

The reuse story is empty by design. The regulations' duties are specific in content, trigger, and clock: a Pre-use Notice with two timing branches and two substitutions, an opt-out that may not be verified, that bars initiation when requested beforehand, and that, on a request after initiation from a consumer who did not opt out at the Pre-use Notice, must stop processing as soon as feasibly possible and no later than 15 business days, an appeal route with five reviewer conditions, two exceptions that hold only while a purpose limitation and an outcome condition stay true, an access response with four mandatory explanations (subject to the § 7222(c) carve-outs on the logic and outcome elements and the § 7222(f) denial route) and, where the business used the ADMT with respect to that consumer more than four times in a 12-month period, an aggregate option for the logic information only, a risk assessment with a prescribed logic-and-output element for uses of ADMT for a significant decision and an executive-attested filing. Existing Controls did not align closely enough to carry any of them.

→ Full rollout: Operationalizing the CCPA ADMT Regulations in Modulos: project structure, the Requirement mapping tables, the 13 new Controls, the CCPA Role tag, the rollout sequence, and the watch.

Where to go next

Frequently asked questions about the CCPA ADMT Regulations

What are the CCPA ADMT Regulations?

The CCPA ADMT Regulations are the California Privacy Protection Agency's (CalPrivacy) regulations on automated decisionmaking technology (ADMT) under the California Consumer Privacy Act, Civ. Code § 1798.100 et seq., codified in Cal. Code Regs. tit. 11. They implement the CCPA and are not a new statute. The Agency adopted them on July 24, 2025, the Office of Administrative Law approved them on September 22, 2025, and they took effect on January 1, 2026. A business that uses ADMT to make a significant decision concerning a consumer must give a Pre-use Notice, provide the ability to opt out of ADMT except where one of three conditional exceptions applies, respond to requests to access ADMT, and conduct a risk assessment before initiating the processing (processing that began before January 1, 2026 and continues must be assessed by December 31, 2027); a business that processes consumers' personal information it intends to use to train such ADMT must also conduct a risk assessment. Article 11 compliance is due no later than January 1, 2027 for a business that used ADMT for a significant decision before that date, and at any time a business uses ADMT for a significant decision on or after it.

What is automated decisionmaking technology (ADMT) under the CCPA regulations?

Under § 7001(e), ADMT means any technology that processes personal information and uses computation to replace human decisionmaking or substantially replace human decisionmaking. A business substantially replaces human decisionmaking when it uses the technology's output to make a decision without human involvement, and human involvement requires the human reviewer to know how to interpret and use the technology's output to make the decision, to review and analyze that output and any other information relevant to make or change the decision, and to have the authority to make or change the decision based on that analysis. All three parts must hold, in the original decision flow; a post-decision appeal does not take a technology outside the definition. ADMT includes profiling that replaces or substantially replaces human decisionmaking, rules-based technology qualifies on the same terms, and the definition does not turn on whether a technology is called AI. The listed utility technologies (web hosting, domain registration, networking, caching, website-loading, data storage, firewalls, anti-virus, anti-malware, spam- and robocall-filtering, spellchecking, calculators, databases, and spreadsheets) are excluded only provided that they do not replace human decisionmaking; an unlisted technology is tested against the definition. Coverage and roles walks through the test.

What is a significant decision under the CCPA ADMT Regulations?

Under § 7001(ddd), a significant decision is a decision that results in the provision or denial of financial or lending services, housing, education enrollment or opportunities, employment or independent contracting opportunities or compensation, or healthcare services. The list is closed, and each item has its own subdefinition: financial or lending services cover extending credit or a loan, transmitting or exchanging funds, deposit or checking accounts, check cashing, and installment payment plans; housing covers any building, structure, or portion of one that is used or occupied as, or designed, arranged, or intended to be used or occupied as, a home, residence, or sleeping place by one or more consumers, permanent or temporary, but an ADMT that provides or denies housing based solely on its availability or vacancy or on the successful receipt of payment for housing from the consumer is not making a significant decision; education enrollment or opportunities cover admission or acceptance into academic or vocational programs, educational credentials, suspension, and expulsion; employment or independent contracting opportunities or compensation cover hiring; allocation or assignment of work for employees, or salary, hourly or per-assignment compensation, incentive compensation such as a bonus, or another benefit; promotion; and demotion, suspension, and termination; healthcare services cover services related to the diagnosis, prevention, or treatment of human disease or impairment, or the assessment or care of an individual's health. Advertising to a consumer is carved out, and insurance is not on the list. The regulations contain no general test for decisions with legal or similarly significant effects.

Who must comply with the CCPA ADMT Regulations, and by when?

A business within the meaning of Civ. Code § 1798.140(d) that uses ADMT to make a significant decision concerning a consumer, or that processes consumers' personal information it intends to use to train ADMT for a significant decision. Consumers are California residents, including employees, job applicants, independent contractors, and students, so workforce and education uses are covered alongside customer-facing ones. Service providers and contractors are bound directly to the limits on contracted personal information and to assist with the business's risk assessment and with requests to access ADMT (§§ 7050, 7222(i)); a third party without a compliant contract must not process the personal information a business made available to it (§ 7052); and a business that makes ADMT trained using personal information available to another business for a significant decision must provide the facts available to it that the recipient-business's risk assessment needs (§ 7153). § 7200(b) sets two Article 11 timing branches: a business that uses ADMT for a significant decision before January 1, 2027 must be in compliance no later than January 1, 2027, and a business that uses ADMT on or after January 1, 2027 must be in compliance any time it is using ADMT for a significant decision. The Article 10 risk-assessment duties have applied since January 1, 2026: a risk assessment is conducted before the business initiates the processing, processing that began before January 1, 2026 and continues must be assessed by December 31, 2027, and information about assessments conducted in 2026 and 2027 is submitted to the Agency by April 1, 2028, with later filings due by April 1 following any year in which assessments were conducted.

What must a business do when it uses ADMT for a significant decision?

Provide a Pre-use Notice prominently and conspicuously, at or before the point when it collects the personal information it plans to process using the ADMT (or, for information already collected for a different purpose, before that processing), stating the specific purpose; the right to opt out of ADMT and how to submit the request (or, where the business relies on the human-appeal exception, the ability to appeal with instructions, or, where it relies on another section 7221(b) exception, the specific exception relied upon); the right to access ADMT and how to submit the request; non-retaliation; and how the ADMT works and how the significant decision would be made for a consumer who opts out, including the alternative process unless a section 7221(b) exception applies. Provide the ability to opt out of the ADMT's use for the significant decision through two or more designated methods, without verification, unless it relies on one of the three § 7221(b) exceptions on their conditions: a human-appeal route to a reviewer with the authority to overturn the decision; the admission, acceptance, or hiring exception; or the allocation or assignment of work and compensation exception. Respond to verified requests to access ADMT with plain-language explanations of the specific purpose, the logic of the ADMT, and the outcome for the consumer including how the output was used (and, where the business plans an additional significant decision from that output, how it will be used), plus the non-retaliation statement with instructions for exercising the consumer's other CCPA rights, including links to any online request form or portal the business offers, within the § 7021 timelines; the logic and outcome explanations need not include trade secrets or information whose disclosure would compromise the specified security, anti-fraud, or physical-safety functions, and a verified request may be denied in whole or in part for a conflict with federal or state law or a CCPA exception, with the basis explained unless the law prohibits the business from doing so and, on a partial denial, the other information sought disclosed. Conduct a risk assessment with the § 7152 content before initiating the use, or by December 31, 2027 for a use that began before January 1, 2026 and continues (§ 7155), reviewed and approved by an individual with authority to participate in the initiation decision. Not retaliate against consumers for exercising their rights. Pre-use Notice, opt-out, and access has the detail.

What are the risk-assessment and Agency submission duties?

Under Article 10, a business must conduct and document a risk assessment before initiating processing that presents significant risk to consumers' privacy, which includes using ADMT for a significant decision concerning a consumer (§ 7150(b)(3)) and processing consumers' personal information the business intends to use to train such ADMT (§ 7150(b)(6)). The assessment identifies the specific purpose, the personal information involved, the operational elements, and, for the use of ADMT for a significant decision (not a standalone training assessment), the logic of the ADMT with its assumptions and limitations and the output and how it will be used; weighs negative privacy impacts against benefits; records the safeguards and whether the business will initiate the processing; and is reviewed and approved by an individual with authority to participate in the initiation decision. Employees whose job duties include participating in the processing must be included in the assessment process, and external parties may be. The assessment is reviewed, and updated as necessary, at least every three years, updated as soon as feasibly possible and no later than 45 calendar days after a material change, and retained while the processing continues or for five years after the completion of the assessment, whichever is later. Processing that began before January 1, 2026 and continues must be assessed by December 31, 2027. The business's § 7157 filings carry information about its risk assessments, not the assessments or reports themselves: by April 1, 2028 for assessments conducted in 2026 and 2027, then by April 1 following any year in which it conducted assessments. The Agency or the Attorney General may require the reports themselves at any time, due within 30 calendar days of the request. Risk assessments and Agency submissions has the detail.

How does Modulos model the CCPA ADMT Regulations?

As two paired templates carrying the Regulation label (templates 1.0.32). MFF-29 assesses one ADMT across 8 Requirements (MRF-489 through MRF-496): the coverage determination, the Pre-use Notice, the opt-out of ADMT, the human-appeal route, the hiring and work-allocation exceptions, access to ADMT, the risk assessment for the ADMT, and the service-provider, third-party and ADMT-supplier duties. OFF-29 covers the organization across 5 Requirements (ORF-488 through ORF-492): the ADMT request-handling infrastructure, the human-involvement and human-appeal capability, the risk-assessment program and Agency submissions, the notice, purpose-compatibility and contract program, and the California ADMT regulatory watch. The 13 Requirements map to 13 new Controls (MCF-695 through MCF-702 and OCF-385 through OCF-389), one per Requirement; no Control is shared with another framework. A CCPA Role tag with four deliberately non-exclusive values (Business using ADMT; Service provider or contractor; Third party; ADMT supplier) marks which duties attach in which role. Each Requirement states its own clock, and the framework will be updated if the Agency revisits the ADMT provisions.

Source attribution

This page summarizes the California Consumer Privacy Act regulations, Cal. Code Regs. tit. 11, §§ 7000 et seq., as adopted by the California Privacy Protection Agency on July 24, 2025 and approved by the Office of Administrative Law on September 22, 2025, and the California Consumer Privacy Act, Civ. Code § 1798.100 et seq. Quoted passages are verbatim from the regulations. The Agency's Final Statement of Reasons is paraphrased where cited. Requirement and Control codes (MFF-29, OFF-29, MRF-, ORF-, MCF-, OCF-) are Modulos template identifiers, not references used by the regulations.

Disclaimer

This page is for general informational purposes and does not constitute legal advice. The regulations took effect January 1, 2026; the Article 11 duties run on the § 7200(b) timing branches, and the Agency has said it may revisit the ADMT provisions in future rulemaking. AB 1018 and SB 947 were pending bills, not law, as of August 2026; the September 2026 backstop is noted under Pending developments. Always verify against the current published text and consult qualified advisers.