Artifact GuideUSADMT

US CPRA ADMT

California's ADMT rules apply when a covered business uses technology to replace or substantially replace human decisionmaking for a significant decision concerning a consumer.

Apply the cited California statute and regulations to the actual entity, data flow, system, and recipient role; escalate unresolved legal interpretation.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
6

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

This page explains which automated decisions fall under California's rules, the January 1, 2027 compliance date, the required and consumer rights, and the records product, privacy, legal, and engineering teams should keep.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

How should teams inventory and govern ADMT under the US CPRA?

Apply four gates to each use. First, confirm that the entity is a covered CCPA business. Second, identify whether the technology processes personal information and uses computation. Third, decide whether its output replaces or substantially replaces a person's decision; requires a reviewer who understands the output, considers other relevant information, and can change the result. Routine storage, firewall, calculator, database, and spreadsheet functions remain outside the definition when they do not replace human decisionmaking.

Fourth, connect the output to a about the consumer. Article 11 covers decisions that provide or deny financial or lending services, housing, education enrollment or opportunities, employment or independent-contracting opportunities or compensation, or healthcare services. Advertising is excluded. A prediction, score, ranking, or recommendation can still be covered when the business uses it to make a listed decision without qualifying human review.

Representative covered examples include software that screens resumes to decide whom to hire, evaluates productivity to allocate work or compensation, screens student work to decide suspension, or scores an exam to decide whether to grant a diploma. These examples depend on how the business uses the output. The same software used only to organize records or assist a reviewer who retains real decision authority may fall outside the definition.

The regulations became effective January 1, 2026, but Article 11 has a separate compliance date. A business using covered before January 1, 2027 must comply by January 1, 2027; a use beginning on or after that date must comply whenever it is used. Before processing, provide a that states the specific purpose, data categories affecting the output, output type, role of the output and any human reviewer, access right, opt-out or appeal path, and alternative decision process. The same use may also require a risk assessment before it begins or materially changes.

Consumers generally receive access and opt-out rights. An opt-out exception applies only if its conditions are met. One exception replaces opt-out with an appeal to a human reviewer who understands the output, considers the consumer's information, and can overturn the decision. Separate exceptions for specified admission, hiring, work-allocation, and compensation uses require the to work for the stated purpose and not unlawfully discriminate; document the exact exception rather than treating these fields as categorically exempt.

  • Record the decision domain, the 's input and output, and whether a human reviewer has authority to change the outcome.
  • Map the , access response, opt-out path, exception, and any required appeal to the exact use case.
  • Complete the related risk-assessment analysis before starting or materially changing covered processing.
  • Reassess when the purpose, decision domain, personal-information inputs, model or rules, output, human-review authority, vendor, or consumer path changes.
Citations
Question 2

What evidence should teams keep for ADMT under the US CPRA?

Keep the inventory, significant-decision analysis, purpose, data categories, logic and output documentation, , access and opt-out tests, exception and appeal analysis, human-review authority, vendor terms, related risk assessment, approval, and January 1, 2027 readiness evidence. Record material changes because they can require the analysis, risk assessment, and notice to be updated.

For each consumer request, retain the receipt date, verification record where required, response or appeal due date, information supplied, outcome, and downstream action. Keep test evidence showing that opt-out routes do not require an account or unnecessary data and that the non- alternative or human appeal works in the live decision process.

  • Source URL and quote used for the decision.
  • Scope notes, screenshots, data-flow or system references, decision owner, vendor, and role mapping.
  • Implementation ticket, approval record, exception conditions, appeal test, access-response sample, and review date.
Citations
California CCPA ADMT regulations

Sections 7021 and 7200-7222 support the ADMT inventory, notice, access, opt-out, exception, appeal, timing, and request evidence described in this section.

Question 3

Which mistakes create risk when handling ADMT under the US CPRA?

Common failures include classifying a nominal human check as meaningful review when the reviewer cannot change the decision, treating every automated tool as covered, overlooking employment or independent-contractor decisions, using a generic privacy notice instead of a , or claiming an opt-out exception without implementing the required appeal path.

  • Calling review meaningful when the reviewer lacks authority, competence, or enough information to change the decision.
  • Reusing one exception across different significant decisions without checking its conditions and appeal requirement.
  • Describing the model generally while omitting how its output affects the consumer's decision.
Citations
Primary sources

References and citations

cppa.ca.gov
Referenced sections
  • Sections 7021 and 7200-7222 support the ADMT inventory, notice, access, opt-out, exception, appeal, timing, and request evidence described in this section.
leginfo.legislature.ca.gov
Referenced sections
  • Statutory CPRA source authorizing regulations for access and opt-out rights tied to automated decisionmaking technology.
"access and opt-out rights with respect to a business’ use of automated decisionmaking technology"
cppa.ca.gov
Referenced sections
  • Current consolidated regulation text for ADMT notices, access, opt-out, exceptions, appeals, and request handling.
"A business that uses ADMT to make a significant decision must provide a consumer with information about this use when responding to a consumer’s request to access ADMT."
cppa.ca.gov
Referenced sections
  • CPPA FAQ confirms that the CPRA amended the CCPA and added consumer privacy rights and business obligations.
"additional consumer privacy rights and obligations for businesses"
Related guides

Explore more topics

California CCPA and CPRA Applicability Test
Decide whether the CCPA as amended by the CPRA applies, using California nexus, current business thresholds, related-entity rules, and data-specific exemptions.
California CCPA and CPRA Compliance Checklist
A California CCPA/CPRA implementation checklist covering scope, notices, rights, opt-outs, vendor contracts, retention, security, and 2026 regulations.
California CCPA/CPRA Deadlines and Compliance Calendar
Track California CCPA and CPRA request clocks, phased 2026 regulation deadlines, recurring metrics, and separate Delete Act dates.
California CCPA/CPRA Penalties, Fines, and Private Damages
Understand current California CCPA and CPRA fine caps, who enforces them, the limited private action for security breaches, and the evidence to preserve.
California CPRA FAQ
Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
California CPRA Requirements Guide
California CCPA/CPRA requirements for covered businesses: notices, rights, opt-outs, data-use limits, contracts, security, and phased 2026 rules.
California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide
Apply the separate California trigger tests, duties, phase-in dates, evidence, and consumer rights for risk assessments, cybersecurity audits, and ADMT.
California Data Broker Deletion Workflow Guide
California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
California Data Broker Registry and DROP Guide
California Delete Act guide to data-broker scope, annual registration, DROP processing from August 1, 2026, deletion, opt-out fallback, metrics, and audits.
California Delete Act data broker registry and DROP guide
California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
CCPA vs CPRA: What Changed in California Privacy Law
Compare the original CCPA with the CPRA amendments, including scope thresholds, new rights, contracts, retention, enforcement, and implementation steps.
CPPA Regulations Tracker | CCPA and CPRA
Track the in-force 2023 and 2026 CCPA regulations, their legal status, affected processing, and phased risk, audit, and ADMT deadlines.
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ
US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
CPRA vs Colorado Privacy Act: Practical Comparison
Compare California and Colorado privacy law on scope, consumer rights, opt-outs, sensitive data, contracts, assessments, and enforcement.
CPRA vs Virginia VCDPA: Practical Comparison
Compare California and Virginia privacy law on scope, rights, sale, advertising, sensitive data, contracts, assessments, and enforcement.
US CPRA Compliance Guide
Build a CCPA/CPRA compliance program for scope, notices, consumer rights, opt-outs, vendor contracts, retention, security, and phased 2026 duties.
US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
US CPRA Contract Terms Guide
Required CCPA/CPRA contract terms for service providers, contractors, and third parties, with role tests, clause checks, and evidence.
US CPRA Contracts Contractors and Service Providers Guide
Classify CCPA recipients as service providers, contractors, or third parties and apply the correct purpose limits, contracts, and consumer instructions.
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
US CPRA Cyber Audit Readiness Workflow Guide
US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
US CPRA Risk Assessment Intake Workflow Guide
Screen the six CPPA risk-assessment triggers, record exceptions and evidence, hold covered launches for approval, and track review and submission dates.
US CPRA Risk Assessment Template Guide
US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
US CPRA Risk Assessments and Cybersecurity Audits Guide
Apply the separate CPPA trigger tests for processing-level risk assessments and entity-level annual cybersecurity audits, with phase-in dates and evidence.
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.
What counts as sharing under the California CPRA?
How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.
What should teams do about Contract Terms under the US CPRA?
Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.
What should teams do about Correction Rights under the US CPRA?
Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.
What should teams do about Cybersecurity Audits under the US CPRA?
US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about retention under the California CPRA?
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
What should teams do about Sensitive Personal Information Limits under the US CPRA?
US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
When is a CPRA risk assessment required?
When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.