AI Policy Wiki
Dashboard

California CCPA/CPRA Regulations — Automated Decision-Making Technology (ADMT)

medium confidence · updated 2026-07-23

California's implementing regulations for the CCPA/CPRA, including ADMT provisions that regulate AI through the lens of privacy and consumer data protection.

The California Consumer Privacy Act Regulations (Title 11, Division 6, California Code of Regulations) are the implementing regulations for the CCPA, promulgated by the California Privacy Protection Agency (CPPA). They regulate AI through privacy and consumer-data-protection law rather than as a distinct technology category (like SB 53) or through anti-discrimination law (like the Colorado AI Act). The regulations' automated decision-making technology (ADMT) provisions create obligations that reach many AI systems by virtue of how those systems process personal information.

Full title: California Consumer Privacy Act Regulations (Title 11, Division 6, California Code of Regulations) Promulgated by: California Privacy Protection Agency (CPPA) Statutory basis: California Consumer Privacy Act (CCPA, Civil Code §1798.100 et seq.), as amended by the California Privacy Rights Act (CPRA, 2020) Key AI sections: §§ 7150–7155 (Risk Assessments), ADMT provisions throughout Scope: 127 pages of implementing regulations; applies to businesses meeting CCPA thresholds that process California residents' personal information

Scope and definitions

The regulations apply to any business meeting CCPA thresholds — more than $25M in annual revenue, the data of more than 100,000 consumers, or more than 50% of revenue from data sales — that processes California residents' personal information. The framework regulates deployers based on how they use personal data rather than developers based on the technology they build, distinguishing it from a developer-focused, safety-first statute such as SB 53.

The definition of "Train" (§ 7001(fff)) explicitly encompasses AI: "the process through which a technology discovers underlying patterns, learns a series of actions, or is taught to generate a desired output. Examples of training include adjusting the parameters of an algorithm used for ADMT." The definition of ADMT is broad enough to encompass many AI-powered decision systems, including uses that the businesses may not categorize as "AI."

Key provisions

Mandatory risk assessments (§ 7150)

Businesses must conduct a risk assessment before any processing that presents "significant risk to consumers' privacy," including:

  1. Using ADMT for a significant decision concerning a consumer (§ 7150(b)(3)).
  2. Automated profiling of employees, students, or job applicants — inferring intelligence, ability, aptitude, work performance, economic situation, health (including mental health), preferences, reliability, predispositions, behavior, location, or movements based on systematic observation (§ 7150(b)(4)).
  3. Sensitive-location-based profiling — the same inferences based on presence in a sensitive location, such as healthcare facilities, domestic violence shelters, or houses of worship (§ 7150(b)(5)).
  4. AI training data collection — processing personal information intended to train an ADMT for significant decisions, or to train facial-recognition, emotion-recognition, or other biometric identification technology (§ 7150(b)(6)).

Risk assessment requirements (§§ 7151–7155)

  • Stakeholder involvement (§ 7151): employees whose duties include processing personal information subject to a risk assessment must participate in the assessment process.
  • Documentation (§ 7152): detailed risk assessment reports are required.
  • Goal (§ 7154): "Restricting or prohibiting the processing of personal information if the risks to privacy of the consumer outweigh the benefits resulting from processing to the consumer, the business, other stakeholders, and the public."
  • Timing (§ 7155): assessments must be conducted before initiating processing and updated when processing changes materially.

Consumer rights relevant to AI

  • Right to opt out of the sale or sharing of personal information, including when used for AI training.
  • Right to limit the use of sensitive personal information.
  • Right to know what personal information is collected and how it is used.
  • Right to delete personal information.
  • Data minimization: collection limited to what is "reasonably necessary and proportionate" to the disclosed purpose.

Enforcement

Enforcement is carried out by the CPPA, alongside a private right of action available for data breaches. The framework's central obligation is the pre-processing risk assessment, paired with consumer opt-out rights. It is a state-level (California) framework.

On July 21, 2026, the CPPA launched its first sectoral compliance audit, targeting gig-economy platforms over the geolocation, biometric, and performance data feeding algorithmic dispatch, ratings, and pay decisions, and testing whether workers' access requests are fulfilled within the 45-day statutory window (Source: privacy.ca.gov; hunton.com).

Position in the US AI regulatory landscape

The CCPA regulations represent a privacy and consumer-data-protection approach to AI governance, distinct from the other approaches in US Regulatory Approaches Compared. The trigger is processing personal information via ADMT for significant decisions.

DimensionCCPA/CPRA Approach
Regulatory lensPrivacy and consumer data protection
Who's regulatedAny business meeting CCPA thresholds (>$25M revenue, >100K consumers' data, or >50% revenue from data sales)
TriggerProcessing personal information via ADMT for significant decisions
EnforcementCPPA enforcement + private right of action for data breaches
Key obligationPre-processing risk assessment; consumer opt-out rights
LevelState (California)

The approach differs from several other US frameworks. Unlike SB 53, which is safety-first and targets developers, the CCPA targets deployers based on how they use personal data. Unlike the Colorado AI Act, which is anti-discrimination law, the CCPA focuses on privacy and data minimization rather than equitable outcomes. Unlike the AI LEAD Act, which imposes post-harm liability, the CCPA requires a pre-processing risk assessment. Unlike EO 14365, which seeks federal preemption, the CCPA creates new state-level obligations that the federal government has not preempted.

Comparison with the EU AI Act

The CCPA's ADMT provisions share structural similarities with the EU AI Act:

FeatureCCPA/CPRAEU AI Act
Risk assessmentRequired for ADMT used in significant decisionsRequired for high-risk AI systems (Art. 9)
TransparencyRight to know about automated processingTransparency obligations for deployers (Art. 13)
Human oversightConsumer right to opt outHuman oversight requirements (Art. 14)
Training dataRisk assessment required for AI training on personal dataData governance requirements (Art. 10)
Regulatory mechanismPrivacy law (horizontal)AI-specific regulation (horizontal)
Prohibited usesNone (risk-based, not ban-based)8 prohibited practices (Art. 5)

The principal difference is that the CCPA regulates AI through privacy law, while the EU AI Act regulates AI as AI. The CCPA approach captures only AI systems that process personal information; the EU approach captures all AI systems regardless of data type.