Appearance
Operationalizing the CCPA ADMT Regulations in Modulos
Modulos ships the CCPA ADMT Regulations as a paired framework (templates 1.0.32): MFF-29 produces the per-technology evidence for one ADMT, and OFF-29 establishes the organization's repeatable capabilities once. Both carry the Regulation label and the california-admt.svg icon. Requirements quote the regulation's operative text verbatim, so teams can audit against the source.
Project structure
| Template | Project type | Scope | Requirements | Distinct Controls |
|---|---|---|---|---|
MFF-29 — CCPA ADMT Regulations | AI application | One ADMT, in whichever CCPA roles the organization holds for it | 8 (MRF-489–MRF-496) | 8 (all new) |
OFF-29 — CCPA ADMT Regulations | Organization | The organization's request-handling, reviewer, risk-assessment, notice-and-contract, and watch capabilities | 5 (ORF-488–ORF-492) | 5 (all new) |
One MFF-29 project per ADMT. The coverage determination, the Pre-use Notice, the opt-out and any exception relied on, the access responses, the risk assessment, and the role duties are all technology-specific. The two templates' Control sets do not overlap, so together the 13 Requirements map to 13 distinct Controls, all new. There is no scoping questionnaire; MRF-489 records the coverage determination inside the project, and a conclusion that the regulations do not apply is what makes the conditional Requirements not applicable.
The CCPA Role tag
Template version 1.0.32 adds one tag category, CCPA Role, with four values attached directly to the Requirements:
- Business using ADMT — a business within Civ. Code § 1798.140(d) that uses ADMT to make a significant decision about a consumer (the Article 11 duties), or that processes personal information it intends to use to train ADMT for significant decisions (the Article 10 trigger).
- Service provider or contractor — a service provider within § 1798.140(ag) (a person that processes personal information on behalf of a business and receives it from or on behalf of the business for a business purpose under a written contract with the prescribed terms) or a contractor within § 1798.140(j) (a person to whom the business makes personal information available for a business purpose under such a contract), including for personal information processed with the ADMT or intended to train it.
- Third party — a third party within § 1798.140(ai), receiving personal information that the business made available for processing with the ADMT.
- ADMT supplier — a business that makes ADMT trained using personal information available to another business, the recipient-business, to make a significant decision, and must therefore provide to the recipient-business all facts available to it that are necessary for the recipient-business's own risk assessment (§ 7153).
The roles are deliberately non-exclusive: the same organization can be a business for one technology and a service provider, contractor, third party, or supplier for another, and a service provider, contractor, or third party that independently meets the business definition carries the business duties for ADMT it uses for its own significant decisions. All 13 Requirements carry Business using ADMT; MRF-495 and MRF-496 also carry ADMT supplier; MRF-496 carries all four. Filter a project by role to see the branch that applies.
The application framework — MFF-29
| Requirement | Legal anchor (Cal. Code Regs. tit. 11 unless noted) | CCPA Role | Conditional on | Mapped Control |
|---|---|---|---|---|
MRF-489 — Coverage determination | §§ 7001(e), (ddd), 7002, 7150(b), 7155, 7200, 7271(a); Civ. Code §§ 1798.140(d), (i), (v), 1798.145, 1798.146 | Business using ADMT | Always applicable | MCF-695 |
MRF-490 — Pre-use Notice | §§ 7003, 7010, 7011, 7012, 7200, 7220 | Business using ADMT | Use for a significant decision | MCF-696 |
MRF-491 — Opt-out of ADMT | §§ 7001, 7004, 7060, 7063, 7080, 7200, 7221; Civ. Code § 1798.125 | Business using ADMT | Use for a significant decision, no § 7221(b) exception relied on | MCF-697 |
MRF-492 — Human-appeal route | §§ 7001, 7003, 7004, 7021, 7060, 7080, 7200, 7220, 7221; Civ. Code §§ 1798.140(ak), 1798.145(h) | Business using ADMT | Reliance on § 7221(b)(1) in place of the opt-out | MCF-698 |
MRF-493 — Hiring and work-allocation exceptions | §§ 7001, 7152, 7220, 7221 | Business using ADMT | Reliance on § 7221(b)(2) or (b)(3) | MCF-699 |
MRF-494 — Access to ADMT | §§ 7021, 7060–7062, 7080, 7222; Civ. Code §§ 1798.140(ak), 1798.145(h) | Business using ADMT | Use for a significant decision, whether or not an exception is relied on | MCF-700 |
MRF-495 — Risk assessment for the ADMT | §§ 7001, 7150–7156 | Business using ADMT; ADMT supplier | Use for a significant decision, or processing personal information intended to train such ADMT | MCF-701 |
MRF-496 — Service providers, third parties and ADMT suppliers | §§ 7050–7053, 7153, 7221, 7222; Civ. Code §§ 1798.100(d), 1798.140(j)(2), (ag)(2), 1798.145(i) | All four | Each limb the organization occupies | MCF-702 |
Each Requirement's detail content carries the source list with the adoption, approval, and effective dates, the application and transition clocks, the obligations addressed with the operative regulatory text quoted verbatim, the key concepts, and a modeling note separating duty from practice and stating the not-applicable rule. Reliance on an opt-out exception is per use: an exception relied on for one significant decision does not excuse the opt-out for another use of the same ADMT, and every other use is resolved on its own terms.
The organization framework — OFF-29
| Requirement | Legal anchor (Cal. Code Regs. tit. 11 unless noted) | Conditional on | Mapped Control |
|---|---|---|---|
ORF-488 — ADMT request-handling infrastructure | §§ 7004, 7011, 7020–7021, 7060–7063, 7080, 7100–7102, 7221–7222; Civ. Code §§ 1798.140(ak), 1798.145(h) | Using or planning to use ADMT for a significant decision; the opt-out limb falls away where an exception is relied on for every use, the access limb never does | OCF-385 |
ORF-489 — Human involvement and human-appeal capability | §§ 7001(e)(1), 7021, 7221(b)(1); Civ. Code § 1798.145(h) | Reliance on human involvement to keep a technology outside ADMT, or on the human-appeal exception; an organization relying on neither route may mark it not applicable | OCF-386 |
ORF-490 — Risk-assessment program and Agency submissions | §§ 7150–7157 | Conducting any § 7150(b) activity; the § 7157 filing remains due for non-ADMT activities even where the ADMT content scoring falls away | OCF-387 |
ORF-491 — Notice, purpose-compatibility and contract program | §§ 7002, 7003, 7010, 7012, 7050, 7051, 7053, 7220(e) | Any organization in scope; the Pre-use Notice wiring attaches with Article 11, § 7053 where personal information is sold or shared | OCF-388 |
ORF-492 — California ADMT regulatory watch | No binding provision; the Agency's Final Statement of Reasons; Civ. Code § 1798.199.95(d) | Readiness practice; may be marked not applicable without legal consequence | OCF-389 |
All five carry CCPA Role: Business using ADMT. ORF-492 is framed in its own text as a supporting readiness practice, not a statutory duty: its anchors bind the Agency and the Legislature, not the organization.
The 13 new Controls
All thirteen carry the tag Framework: Specific; the application Controls are Scope: Project with AI System Lifecycle tags, the organization Controls Scope: Organization. Each has a guidance component (what the law requires, key considerations, what would fail the Control, relationships to other Controls, and the evidence an auditor expects), an evidence upload, and a report template.
| Control | Carries |
|---|---|
MCF-695 — CCPA ADMT coverage determination | A current, dated determination of whether the regulations reach this technology: business and consumer status (workers and students included), personal information in scope after exclusions and conditional exemptions, the ADMT test with the three-part human-involvement test in the decision flow, the significant-decision category, purpose compatibility for repurposed information, the training trigger, and the § 7200(b) timing branch; recorded as practice, not as a document Article 11 requires |
MCF-696 — Pre-use Notice | The notice presented prominently and conspicuously at or before collection (or before processing of repurposed information), in the primary interaction channel, with the specific purpose, the opt-out and access rights with how to submit each request (or, replacing the opt-out, the appeal route with instructions or the specific exception named), non-retaliation, and how the ADMT works with the alternative process absent an exception |
MCF-697 — ADMT opt-out mechanics | Two or more § 7004-compliant methods, one in the primary interaction manner and online a form via the notice link naming the opted-out use; no verification, account, or burdensome ask; fraud denial only on a documented, reasonable good-faith belief; confirmation; any granular choice alongside one option covering all significant-decision uses; a pre-initiation request barring processing; on a request after initiation from a consumer who did not opt out at the Pre-use Notice, cessation as soon as feasibly possible and no later than 15 business days from receipt, and instruction to the persons given that consumer's personal information for that ADMT to comply within the same time frame |
MCF-698 — Human-appeal route | Where § 7221(b)(1) replaces the opt-out: a designated reviewer who reviews the output and other relevant information, considers what the consumer submits, knows how to interpret and use the output, and can change the decision, reached through a clearly described, easy, minimal-step, § 7004-compliant method, with § 7003(a)–(b) communications, the § 7021 clocks, and Article 5 verification |
MCF-699 — Hiring and work-allocation exception evidence | Where § 7221(b)(2) or (b)(3) is relied on: the ADMT used solely for the permitted purpose, the business's evidence that it works for its purpose and does not unlawfully discriminate based upon protected characteristics, and the Pre-use Notice naming the exception |
MCF-700 — Access-to-ADMT response | Verified requests answered with the specific purpose, the logic, the outcome and how the output was used, and planned future use where it applies, plus non-retaliation and rights instructions; withholding from the logic and outcome elements limited to the § 7222(c) grounds; denials for a conflict with federal or state law or a CCPA exception explained under § 7222(f), and manifestly unfounded or excessive requests handled under Civ. Code § 1798.145(h)(3); Article 5 verification, secure delivery, and the § 7021 clocks |
MCF-701 — CCPA risk assessment for the ADMT | Before initiating the use (and, for pre-2026 continuing processing, by December 31, 2027), and likewise for personal information processed with intent to train such an ADMT: a § 7152 assessment with the logic-and-output element for a use, reviewed and approved by someone with authority to participate in the initiation decision; reviewed, and updated as necessary, at least every three years; updated as soon as feasibly possible and no later than 45 calendar days after a material change; retained while the processing continues or for five years after the completion of the assessment, whichever is later |
MCF-702 — Service-provider, third-party and supplier duties for the ADMT | By role: the business's § 7051(a)(5)–(9) and § 7053(a) contract terms and the § 7221(n)(2) notify-and-instruct step; the service provider's or contractor's § 7050 limits, contract compliance, direct-request handling, noticed subcontracts, and risk-assessment and access-ADMT assistance; the third-party bar under § 7052; the supplier's § 7153 facts |
OCF-385 — ADMT request-handling infrastructure | One intake, verification, clock, records, and reporting capability for opt-out, access, and appeal requests: tested § 7004 methods; the 10-business-day and 45/90-calendar-day limits with the Civ. Code § 1798.145(h) mechanics; Article 5 verification, never for an opt-out; agents and other submitters; handler training; the 10,000,000-consumer predicates for the training policy and the July 1 metrics; 24-month records; the § 7011(e) privacy-policy content |
OCF-386 — Human involvement and human-appeal capability | Conditional on the route the organization states: reviewers in the original decision flow who meet all three parts of § 7001(e)(1), or designated appeal reviewers who meet § 7221(b)(1)(A) with a channel for the consumer's information and answers on the § 7021 clocks; not applicable where neither route is relied on |
OCF-387 — Risk-assessment program and Agency submissions | § 7152 assessments before initiation, the three-year review, the material-change update as soon as feasibly possible and within 45 calendar days, the December 31, 2027 legacy deadline, retention, the § 7157(b) information for every § 7150(b) activity from a qualifying executive by April 1, 2028 and April 1 after any later assessment year, and reports on request within 30 calendar days |
OCF-388 — Notice, purpose-compatibility and contract program | § 7003 disclosure quality with the Article 2 additions (readable format, the business's ordinary languages, accessibility for consumers with disabilities online by standards such as WCAG 2.1 and offline by alternative-format information); the Notice at Collection and privacy-policy wiring for the Pre-use Notice; § 7002's original-purpose, compatible-purpose, and consent routes with proportionality for repurposed information; the § 7051 and § 7053 contracts carrying the same-level-of-protection term |
OCF-389 — California ADMT regulatory watch | An owned watch on the five tracks below, each development routed into the affected notices, procedures, and determinations; may be marked not applicable |
Control reuse — none
No Control in either template is shared with another framework, and none of the 13 is mapped by any other template. The regulations' duties are specific in content, trigger, and clock: a Pre-use Notice with two timing branches and two substitutions, an opt-out that may not be verified, that bars initiation when requested beforehand, and that, on a request after initiation from a consumer who did not opt out at the Pre-use Notice, must stop processing as soon as feasibly possible and no later than 15 business days with recipient instruction, an appeal route with five reviewer conditions, two exceptions that hold only while a purpose limitation and an outcome condition stay true, an access response with four mandatory explanations and a narrow aggregate option, and a risk assessment with a prescribed logic-and-output element for uses of ADMT for a significant decision, an approver with authority to participate in the initiation decision, and an executive-attested filing. Existing Controls did not align closely enough to carry any of them, and the coverage determination is a conjunctive legal conclusion rather than risk tiering, so the shared risk-tiering Control was not reused either. Nothing was edited in other frameworks.
An AI-application project that already carries another framework and adds MFF-29 therefore gains 8 new Controls with no overlap; Evidence attached to Controls of the other framework does not serve these. Separate per-technology projects keep separate Control instances and Evidence libraries.
The watch — five tracks
ORF-492 / OCF-389 own five greppable watch markers, each naming what it feeds:
| Marker | What it watches | Feeds |
|---|---|---|
CA-WATCH-AGENCY-RULES | Future Agency rulemaking or guidance on ADMT; in its Final Statement of Reasons the Agency said it may revisit the ADMT definition (§ 7001(e)), the significant-decision definition (§ 7001(ddd)), and the Article 11 applicability provision (§ 7200) | MRF-489 and every Article 11 Requirement |
CA-WATCH-AB1018 | AB 1018, a California bill that would add a separate regime with its own defined terms (an automated decision system, a covered ADS, a consequential decision, a developer and a deployer); its duty set has shifted with each amendment, the August 21, 2026 floor amendment removed its assessment regime, it was on second reading in the Senate as of that date, and as of August 2026 it is not law | Whether a second California regime arrives |
CA-WATCH-SB947 | SB 947, a California bill that would place Labor Code limits on employers' use of an automated decision system in disciplinary and termination decisions; as amended August 21, 2026 it had been ordered to third reading in the Assembly, and as of August 2026 it is not law | Workforce uses |
CA-WATCH-THRESHOLDS | The odd-year adjustment of the CCPA monetary thresholds for any increase in the Consumer Price Index (Civ. Code § 1798.199.95(d)), next effective January 1, 2027, the same day the Article 11 transitional deadline falls | MRF-489 business status |
CA-WATCH-FEDERAL-PREEMPTION | Proposals that would displace California privacy law; CalPrivacy opposed the federal SECURE Data Act in April and June 2026; no enacted federal law changes the duties | Every Requirement |
Modulos updates the framework content if the Agency revisits the ADMT provisions or a bill becomes law; framework versioning notifies affected projects. The two bills are watch items only: as of August 2026 neither is law, this framework does not implement them, and their vocabulary is theirs, not the regulation's. The watch has a known expiry: each house must pass bills by August 31, 2026, and a bill passed before September 1, 2026 and in the Governor's possession on or after that date becomes a statute if it is not returned on or before September 30, 2026 (Cal. Const. art. IV, § 10(b)(2)); both items resolve within weeks of that date.
Rollout sequence
- Determine coverage for each technology (
MRF-489): run the conjunctive test, apply the exemptions on their conditions, test human involvement in the original decision flow, place the decision on the closed significant-decision list, determine the training limb, and record which § 7200(b) branch the use is on. - Assess before you initiate (
MRF-495,ORF-490): a newly covered use or training activity needs its § 7152 assessment, reviewed and approved by someone with authority to participate in the initiation decision, before it starts; continuing pre-2026 processing needs it by December 31, 2027. Name the executive who will file under § 7157(c) and build the register behind the per-activity counts for the April 1, 2028 filing. - Stand up the organization capabilities (
ORF-488,ORF-491): the request intake with tested § 7004 methods, the § 7021 clocks, Article 5 verification for access and appeals, 24-month records, and the privacy-policy content; the notice templates meeting § 7003, the Notice at Collection wiring, the purpose-compatibility analysis for repurposed information, and the contract estate with the same-protection term. - Decide the opt-out posture per use (
MRF-491,MRF-492,MRF-493,ORF-489): offer the opt-out, or rely on an exception on its conditions. A human-appeal route needs designated reviewers meeting all five conditions and a channel for the consumer's information; the hiring and work-allocation exceptions need the "solely" purpose limitation kept true and the outcome evidence in hand. Where human involvement is claimed to keep a technology outside ADMT, the reviewers in the decision flow must meet all three parts of § 7001(e)(1). - Publish the Pre-use Notice and wire the access response (
MRF-490,MRF-494): the notice at or before collection, in the primary channel, with the right opt-out paragraph or substitution and the how-it-works layer; the four-explanation access response on the § 7021 clocks with the verification tier by account status. A use begun before January 1, 2027 has until that date; a use begun on or after it has no grace period. - Settle the role duties (
MRF-496): confirm the contract terms; on a post-initiation opt-out from a consumer who did not opt out at the Pre-use Notice, cease as soon as feasibly possible and no later than 15 business days and instruct the persons given that consumer's personal information for that ADMT to comply within the same time frame; and, as a supplier of ADMT trained using personal information, give each recipient-business all facts available to you that its own assessment needs. - Own the watch (
ORF-492): assign the five tracks; as each development lands, reconcile the notices, the privacy policy, the request procedures, the assessment templates, and the contract terms against the new text, and re-run the coverage determination where the ADMT definition, the significant-decision definition, or the applicability threshold moved.
Each Requirement is evidenced through its linked Control; the Requirement Owner reviews the completed Control and marks the Requirement as Fulfilled.
What the framework deliberately does not include
- Vocabulary from other regimes. No controller, processor, data subject, or "solely automated" decision from the GDPR; no consequential decision, adverse outcome, developer, or deployer from Colorado SB 26-189 or AB 1018. The regulations' terms are the only ones the Requirements use.
- AB 1018 and SB 947 as duties. Both were pending bills as of August 2026, tracked under the watch with its September 2026 backstop; neither is implemented.
- The Civil Rights Council's employment regulations on automated-decision systems, a separate California regime under a different statute.
- The other § 7150(b) activities' assessment content. The framework scores the ADMT use and training limbs; the counts for the other activities belong in the § 7157 filing, their content does not belong here.
- A prescribed test for the exceptions' outcome condition. The regulations set the condition that an ADMT "works for the business's purpose and does not unlawfully discriminate based upon protected characteristics" and leave the showing to the business; the framework records the evidence relied on and claims nothing beyond that.
Where to go next
CCPA ADMT Regulations overview
What the regulations require, who is covered, the clocks, enforcement, and the pending developments
Coverage and roles
The conjunctive test, the human-involvement test, the closed list, exemptions, the training trigger — MRF-489; the four roles defined
Pre-use Notice, opt-out, and access
The Article 11 duties and the request machinery — MRF-490–494, ORF-488, ORF-489
Risk assessments and Agency submissions
Article 10 for ADMT and the April 1 filings — MRF-495, ORF-490
Service providers and ADMT suppliers
Contracts, the opt-out flow-down, and the supplier's fact duty — MRF-496, ORF-491
Disclaimer
This page is for general informational purposes and does not constitute legal advice. The Agency has said it may revisit the ADMT provisions in future rulemaking, and AB 1018 and SB 947 were pending bills, not law, as of August 2026 (see the watch above for the September 2026 backstop). Always verify against the current published text and consult qualified advisers.