CACaliforniaPhasing inCCPA ADMT

How to comply with the CCPA automated decision-making rules

California CCPA automated decision-making (ADMT) regulations

Status
Phasing in
Binding
Yes
Object analysed
Automated decision
Requirements
4
Next milestone
Jan 1, 2027

In short

CPPA rules: pre-use notice, opt-out and access rights for automated significant decisions, risk assessments, cybersecurity audits.

Steps to compliance

  1. Qualify each AI systemAxes to decide: ADMT for a significant decision.
  2. Determine your roleDuties vary by role: Business.
  3. Apply the 4 requirementsThey focus on: Explanation & redress, Transparency & notice, Human oversight and Impact assessments.
  4. Prove it with checks4 checks to document, 4 of which also serve PL 2338, RGPD and AI Act.
  5. Track the deadlinesNext milestone: Jan 1, 2027, ADMT compliance required (set in the text).

Scope and penalties

Kind
Implementing rules
Scope
CCPA-covered businesses using ADMT for significant decisions.
Territorial reach
California resident consumers.
Penalties
$2,663 to $7,988 per violation (indexed amounts).
Jurisdiction
California

Timeline

Sep 23, 2025Approved by OAL
Jan 1, 2026Effective date
Release
Jan 1, 2027ADMT compliance requiredSet in the text
Apr 1, 2028First risk-assessment attestationsSet in the text
PastSet in the textPotentialTo verify

Qualifying a system

Classification axes and possible verdicts

ADMT for a significant decision

Automated significant decisionOut of scope

Requirements

4 requirements

CodeArticleRequirementApplies toChecks
ADMT-01§7220Pre-use notice for ADMT
BusinessADMT for a significant decision
ADMT-02§7221Right to opt out or human appeal
BusinessADMT for a significant decision
ADMT-03§7222Right to access logic and outcome
BusinessADMT for a significant decision
ADMT-04§7150-7157Risk assessment before processing
BusinessADMT for a significant decision

Checks to document

Evidence collected for a check counts for every regulation that uses it.

CodeCheckScopeThemesAlso used by
VER-029-D-01Affected persons informed of the use of the AI systemSystem
CHK-BR-CONTESTProcedure to contest a decision and obtain human review publishedOrganisation
VER-033-D-03Explanations provided on request within a reasonable timeframeSystem
VER-019-D-02DPIA carried out in accordance with GDPR Art. 35System

Themes covered

Frequently asked questions

Who is in scope of CCPA ADMT?

CCPA-covered businesses using ADMT for significant decisions. California resident consumers.

What penalties does CCPA ADMT carry?

$2,663 to $7,988 per violation (indexed amounts).

When do the CCPA ADMT obligations apply?

Sep 23, 2025: Approved by OAL; Jan 1, 2026: Effective date; Jan 1, 2027: ADMT compliance required; Apr 1, 2028: First risk-assessment attestations.

Is CCPA ADMT binding?

Yes. Kind: implementing rules. Status: phasing in.

How does CCPA ADMT relate to other regulations?

The same checks serve several texts. Shared checks: PL 2338 (4), RGPD (4) and AI Act (2).

Related regulations

Official sources

Data checked on Sep 25, 2026. General information, not legal advice. Check the official texts and get advice for your situation.

Run these requirements across all your AI systems

TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.

Request a demo