Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Automated decision-making technology under the CCPA

Automated Decision-Making Technology: A Clear 2027 Guide

Automated decision-making technology is the CCPA’s newest obligation and the one most programmes are scoping too narrowly. From 1 January 2027 businesses using ADMT to make significant decisions about Californians owe a pre-use notice, an opt-out and an access right — and “Californians” here includes employees, contractors and job applicants.

This guide covers what counts as ADMT, which decisions are caught, the three consumer rights, and how to scope the exercise before the deadline.

Automated decision-making technology under the CCPA: scope, rights and deadline
Two tests decide whether you are in scope — and both are broader than people assume.

What counts as automated decision-making technology

The California Privacy Protection Agency’s regulations, approved in late 2025, cover technology that processes personal information to replace or substantially replace human decision-making. Two points do most of the work.

First, it does not have to be artificial intelligence. A scoring rule, a filter, a threshold in a workflow — anything that produces the decision without a human meaningfully making it — can be automated decision-making technology. Second, human involvement has to be real. A person who rubber-stamps an output, without the authority, information and competence to overturn it, does not take the process out of scope.

Which decisions are “significant”

The obligations attach where ADMT is used for a significant decision about a consumer — decisions affecting things like financial or lending services, housing, education enrolment or opportunity, employment or independent contracting opportunities and compensation, and healthcare services.

The employment limb is the one that surprises people. California treats employees, applicants and contractors as consumers under the CCPA, so recruitment screening, performance scoring and compensation tooling sit squarely inside this regime — and those systems usually live outside the privacy function’s usual inventory.

Automated decision-making technology: the 3 rights

Right What it requires Where the work lands
Pre-use notice Tell people before the ADMT is used, in plain terms, including the purpose Product, HR and the systems that present the journey
Opt-out Offer a way to decline the automated route, subject to exceptions Operations — you need a human path that actually works
Access Explain the logic and how the output was used in the decision Data science and vendor management

Of the three automated decision-making technology rights, the opt-out is the expensive one. It means designing and staffing an alternative process, not adding a checkbox — and if the automated route exists because the manual one could not cope with the volume, that tension has to be resolved before the deadline rather than at it.

The access right is the one vendors complicate. Explaining the logic of a model you licensed requires contractual rights to the information, and those clauses are absent from most existing agreements. Our guide to the service provider and contractor classification covers the contracting side.

The timeline, and what sits alongside

The regulations took effect on 1 January 2026 with a compliance deadline for ADMT of 1 January 2027, and further requirements phased through the end of the decade. Two neighbouring obligations arrived in the same package and share the same evidence: risk assessments for higher-risk processing, and cybersecurity audits on a phased schedule. Treat them as one programme — the risk assessment for an ADMT use case is most of the documentation the other two need. Our guide to every CCPA deadline sets out the full ladder.

Scoping it without missing half the systems

  1. Inventory decisions, not tools. Start from the significant-decision categories and ask which decisions the business makes in each. Then find what makes them.
  2. Include HR systems from the start. Applicant screening, scheduling, monitoring and performance tooling are where most in-scope ADMT actually sits.
  3. Test the human in the loop honestly. Does the reviewer have the authority, the information and the time to disagree? Ask them, not the system owner.
  4. Map vendor dependencies. For each in-scope system, what you would need from the vendor to answer an access request, and whether the contract gives it to you.
  5. Write the risk assessment as you go. It is required for this processing anyway, and it is the artifact that makes the rest defensible.

Where programmes will get caught

Assuming ADMT means AI. Deterministic rules engines that decide outcomes are in scope. Scoping by technology rather than by effect misses them.

Treating the notice as a privacy policy update. It is a pre-use notice, delivered before the decision, not a paragraph added to a document nobody reads.

An opt-out with no alternative behind it. Offering the right without staffing the manual route produces a queue and a complaint.

California-only thinking about automated decision-making technology. The EU AI Act, Colorado’s AI law and existing anti-discrimination rules land on the same systems from different directions. Build one control set. See our guide to the EU AI Act risk categories.

Frequently asked questions

What is automated decision-making technology under the CCPA?
Technology that processes personal information and replaces or substantially replaces human decision-making. It is defined by effect rather than by whether the system uses machine learning.

When is the compliance deadline?
1 January 2027 for the ADMT requirements. The regulations themselves took effect on 1 January 2026, with related obligations phased through 2030.

Does it apply to employees?
Yes. Employees, applicants and independent contractors are consumers under the CCPA, and employment decisions are within the significant-decision categories.

Can we refuse an opt-out?
There are defined exceptions, and they are narrower than most businesses would like. Do not build a programme on the assumption that yours qualifies without checking the regulation text.

What has to go in the access response?
Information about the business’s use of the ADMT, including the logic involved and how the output was used in the decision about that person — which is why vendor cooperation has to be contractual.

Where this leaves you

Scope automated decision-making technology by decision rather than by tool, and start with HR, because that is where the systems nobody inventoried are. Test whether your human reviewers can genuinely overrule the output, build a manual path before you publish an opt-out, and get the contractual right to explain vendor logic now rather than when the first access request lands. Then write the risk assessments as you go — they are required anyway, and they are what makes the whole programme defensible when enforcement starts in 2027.

References

More on US privacy compliance

Notices, opt-out procedures and risk assessment templates are in the CCPA-CPRA Compliance Toolkit, or start with the free ISO templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.