How to comply with the CCPA automated decision-making rules
California CCPA automated decision-making (ADMT) regulations
- Status
- Phasing in
- Binding
- Yes
- Object analysed
- Automated decision
- Requirements
- 4
- Next milestone
- Jan 1, 2027
In short
CPPA rules: pre-use notice, opt-out and access rights for automated significant decisions, risk assessments, cybersecurity audits.
Steps to compliance
- Qualify each AI systemAxes to decide: ADMT for a significant decision.
- Determine your roleDuties vary by role: Business.
- Apply the 4 requirementsThey focus on: Explanation & redress, Transparency & notice, Human oversight and Impact assessments.
- Prove it with checks4 checks to document, 4 of which also serve PL 2338, RGPD and AI Act.
- Track the deadlinesNext milestone: Jan 1, 2027, ADMT compliance required (set in the text).
Scope and penalties
- Kind
- Implementing rules
- Scope
- CCPA-covered businesses using ADMT for significant decisions.
- Territorial reach
- California resident consumers.
- Penalties
- $2,663 to $7,988 per violation (indexed amounts).
- Jurisdiction
- California
Timeline
Qualifying a system
Classification axes and possible verdicts
ADMT for a significant decision
Requirements
4 requirements
| Code | Article | Requirement | Applies to | Checks |
|---|---|---|---|---|
| ADMT-01 | §7220 | Pre-use notice for ADMT | ||
| ADMT-02 | §7221 | Right to opt out or human appeal | ||
| ADMT-03 | §7222 | Right to access logic and outcome | ||
| ADMT-04 | §7150-7157 | Risk assessment before processing |
Checks to document
Evidence collected for a check counts for every regulation that uses it.
| Code | Check | Scope | Themes | Also used by |
|---|---|---|---|---|
| VER-029-D-01 | Affected persons informed of the use of the AI system | System | ||
| CHK-BR-CONTEST | Procedure to contest a decision and obtain human review published | Organisation | ||
| VER-033-D-03 | Explanations provided on request within a reasonable timeframe | System | ||
| VER-019-D-02 | DPIA carried out in accordance with GDPR Art. 35 | System |
Themes covered
Frequently asked questions
Who is in scope of CCPA ADMT?
CCPA-covered businesses using ADMT for significant decisions. California resident consumers.
What penalties does CCPA ADMT carry?
$2,663 to $7,988 per violation (indexed amounts).
When do the CCPA ADMT obligations apply?
Sep 23, 2025: Approved by OAL; Jan 1, 2026: Effective date; Jan 1, 2027: ADMT compliance required; Apr 1, 2028: First risk-assessment attestations.
Is CCPA ADMT binding?
Yes. Kind: implementing rules. Status: phasing in.
How does CCPA ADMT relate to other regulations?
The same checks serve several texts. Shared checks: PL 2338 (4), RGPD (4) and AI Act (2).
Related regulations
Official sources
Data checked on Sep 25, 2026. General information, not legal advice. Check the official texts and get advice for your situation.
Run these requirements across all your AI systems
TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.