TwinEthosRequest access

Law

CCPA ADMT Regulations

California Privacy Protection Agency · California (US-CA) · 3 provisions encoded · verified against the official source as of 2026-09-06.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Official text: cppa.ca.gov.

Binding law — not yet in force or stayed

Consumers requesting access to ADMT must receive a plain-language explanation

11 CCR 7200(a)-(b) · official text · Enacted, not yet applying: applies from 1 Jan 2027 · California (US-CA)

A California business using automated decisionmaking technology (ADMT) for a significant decision must provide a requesting consumer information about that use. The response must explain the specific purpose, the relevant logic, the outcome and use of the output, and the consumer's other CCPA rights in plain language. Detect an ADMT significant-decision path with no consumer access request mechanism or explanation artifact.

Who it applies to

  • Duty falls on: controller
  • Systems covered: automated decision, consequential decision
  • CCPA-covered businesses using ADMT for significant decisions about California consumers. The ADMT requirements apply from 2027-01-01.
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Store each ADMT decision's purpose, logic, output, and use at decision time, and return them in plain language from a consumer access-request path.

At decision time, write a decision-log row with the purpose, the key factors or reason codes, the model output, how the output was used, the human's role, and the model version. Provide an access-request path (privacy portal endpoint or DSAR export job) that verifies the requester and assembles a plain-language response from those rows using a template that explains the purpose, the logic, the outcome, and the person's other rights. Without decision-time records the access response cannot be reconstructed later, so the logging belongs in the decision service, not in the privacy team's tooling.

Where it goes: 2 data models, 9 AI output handling, 14 user-facing text.

What this provision adds:

  • The access response explains in plain language the specific purpose, the relevant logic, the outcome and how the output was used, and the consumer's other CCPA rights.

Example (Python + scikit-learn), before:

score = model.predict_proba([features])[0][1]
applications.update(app_id, status='approved' if score >= 0.6 else 'denied')

After:

score = model.predict_proba([features])[0][1]
status = 'approved' if score >= 0.6 else 'denied'
decision_log.insert({'consumer_id': cid, 'purpose': 'credit line eligibility',
                     'key_factors': reason_codes(features), 'model_output': score,
                     'how_used': 'scores of 0.6 or more approve; lower scores deny',
                     'human_role': 'underwriter reviews appeals', 'model_version': MODEL_VERSION})
applications.update(app_id, status=status)

Control: Significant-decision ADMT without consumer access explanation. The same guard addresses 1 item with binding law in 1 jurisdiction. Engineering guidance, not legal advice.

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

  • UnitedHealth nH Predict claim-denial litigation (2023-11; alleged (not proven)). A class action filed in November 2023 alleges that UnitedHealth's nH Predict model had a 90% error rate, measured by denials reversed on appeal, while only about 0.2% of members appealed. UnitedHealth disputes the allegations; the litigation is ongoing. Source: STAT News · evidence grade: primary · cited by Explain adverse AI-assisted decisions and offer a way to contest them — everywhere

Rule id ccpa-admt.access-explanation · review status: primary source derived

Binding law — not yet in force or stayed

Consumers must be able to opt out of automated decision technology

11 CCR 7010(c)-(d) · official text · Enacted, not yet applying: applies from 1 Jan 2027 · California (US-CA)

A business using automated decisionmaking technology (ADMT) to make a significant decision about a California consumer must provide an opt-out method. The opt-out requirement can be replaced only by a qualifying appeal to a human reviewer who can interpret the ADMT output and overturn the decision. Detect an ADMT significant-decision path with no opt-out mechanism and no qualifying human-appeal alternative.

Who it applies to

  • Duty falls on: controller
  • Systems covered: automated decision, consequential decision
  • CCPA-covered businesses using ADMT for significant decisions about California consumers. ADMT obligations effective 2027-01-01. 'Substantially replace human decisionmaking' = output used without qualifying human involvement.
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Offer an ADMT opt-out (or a qualifying human appeal), store the consumer's choice, and check it before the model runs on any significant-decision path.

Two pieces: an opt-out endpoint linked from the pre-use notice (e.g. POST /privacy/admt-opt-out) that stores a per-consumer admt_opt_out preference, and a check at the top of the server-side decision function that reads that preference and routes opted-out consumers to a human decision-maker without calling the model. Where the business instead relies on a human appeal, the decision response carries an appeal route (POST /decisions/{id}/appeal) to a reviewer who can interpret the model output and overturn the decision. A UI-only toggle that the decision service never reads does not count.

Where it goes: 1 application source code, 2 data models, 9 AI output handling, 14 user-facing text.

What this provision adds:

  • The opt-out may be replaced only by an appeal to a human reviewer who can interpret the ADMT output and overturn the decision.
  • Link the opt-out method from the Pre-use Notice.

Example (FastAPI + OpenAI SDK), before:

def decide_tenancy(applicant):
    resp = client.chat.completions.create(model=MODEL, messages=tenant_prompt(applicant))
    return approve_or_deny(resp.choices[0].message.content)

After:

def decide_tenancy(applicant):
    if prefs.get(applicant.consumer_id, 'admt_opt_out'):
        return route_to_human(applicant, reason='admt_opt_out')   # model never runs
    resp = client.chat.completions.create(model=MODEL, messages=tenant_prompt(applicant))
    return approve_or_deny(resp.choices[0].message.content)

@app.post('/privacy/admt-opt-out')
def admt_opt_out(user=Depends(current_user)):
    prefs.set(user.consumer_id, 'admt_opt_out', True)
    return {'opted_out': True}

Control: Automated decision tech without opt-out. The same guard addresses 1 item with binding law in 1 jurisdiction. Engineering guidance, not legal advice.

Rule id ccpa-admt.opt-out · review status: primary source derived

Binding law — not yet in force or stayed

Automated decision technology requires pre-use notice

11 CCR 7010(c)-(d) · official text · Enacted, not yet applying: applies from 1 Jan 2027 · California (US-CA)

A business using automated decisionmaking technology (ADMT) to make a significant decision about a California consumer must provide a prominent pre-use notice before processing. The notice must describe the ADMT use and the consumer's opt-out and access rights in the manner the business primarily interacts with the consumer. Detect an ADMT significant-decision path with no pre-use notice or no notice artifact covering the required rights.

Who it applies to

  • Duty falls on: controller
  • Systems covered: automated decision, consequential decision
  • CCPA-covered businesses using ADMT for significant decisions about California consumers. ADMT obligations effective 2027-01-01. 'Substantially replace human decisionmaking' = output used without qualifying human involvement.
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Send the person an AI-use notice on the decision path, before or when an AI system makes or substantially factors a consequential decision about them, and record its delivery.

A notice step in the decision workflow itself (application intake, underwriting, eligibility, applicant or employee scoring, diagnostic support) that runs before the model call, e.g. send_admt_notice(consumer) ahead of underwrite(), or a notice block rendered on the intake page the person submits from. The notice says that AI is used in the decision, for what, and how to get more information or ask for review, and its delivery is stored with the decision (notice id, channel, timestamp). The template lives in the repo so its content is reviewable; a privacy-policy paragraph alone is not on the decision path.

Where it goes: 1 application source code, 9 AI output handling, 14 user-facing text.

What this provision adds:

  • Give a prominent Pre-use Notice before processing that describes the ADMT use and the consumer's opt-out and access rights, delivered in the manner the business primarily interacts with the consumer.

Example (FastAPI + OpenAI SDK), before:

@app.post('/applications')
def apply(app_in: Application):
    resp = client.chat.completions.create(model=MODEL, messages=underwriting_prompt(app_in))
    return {'decision': underwrite(resp.choices[0].message.content)}

After:

@app.post('/applications')
def apply(app_in: Application):
    notice = send_admt_notice(app_in.applicant_id, template='ai_decision_notice_v2')
    resp = client.chat.completions.create(model=MODEL, messages=underwriting_prompt(app_in))
    decision = underwrite(resp.choices[0].message.content)
    db.decisions.insert(app_in.id, decision, notice_id=notice.id)
    return {'decision': decision, 'ai_notice': notice.text}

Control: Consequential AI decision without consumer notice. The same guard addresses 6 items with binding law in 5 jurisdictions. Engineering guidance, not legal advice.

Standards that recommend the same control

Rule id ccpa-admt.pre-use-notice · review status: primary source derived