{"$schema":"https://json-schema.org/draft/2020-12/schema","name":"California ADMT & CCPA compliance obligations","description":"Structured reference for California’s automated decisionmaking technology (ADMT) rules under the CCPA: coverage thresholds, significant-decision categories, the human-involvement test, the four consumer rights, and the compliance calendar.","url":"https://www.ivector.co/tools/admt-checker","license":"https://creativecommons.org/licenses/by/4.0/","attribution":"ivector (https://www.ivector.co)","disclaimer":"A builder’s read of the published regulation, not legal advice. Counsel decides coverage and which decisions count.","source":{"name":"CCPA regulations, Title 11 Division 6 Chapter 1","agency":"California Privacy Protection Agency","effective":"2026-01-01","url":"https://cppa.ca.gov/regulations/pdf/ccpa_statute_eff_20260101.pdf"},"coverageThresholds":[{"id":"revenue","label":"Gross annual revenue above $26,625,000","detail":"The inflation-adjusted version of the original $25 million, in force since January 2025 and revisited every two years against CPI. Generally read as total global gross revenue, not California revenue — so a company with modest California business can clear it on the strength of everywhere else."},{"id":"volume","label":"Buying, selling or sharing the personal information of 100,000 or more California consumers or households in a year","detail":"A company well under the revenue line can still be covered this way. Checking only the revenue figure and stopping is the common miss."},{"id":"data-revenue","label":"Deriving 50% or more of annual revenue from selling or sharing personal information","detail":"Independent of company size."}],"coverageLogic":"OR — any single threshold is sufficient to be a covered business.","significantDecisions":[{"id":"financial","label":"Financial or lending services","examples":["Loan or credit approval","Credit limit setting","Insurance underwriting or terms"]},{"id":"housing","label":"Housing","examples":["Tenant screening or scoring","Rental application approval"]},{"id":"education","label":"Education enrollment or opportunities","examples":["Admissions decisions","Programme or course placement"]},{"id":"employment","label":"Employment or independent contracting opportunities or compensation","examples":["Applicant ranking or screening","Allocation or assignment of work (e.g. which shifts someone gets)","Compensation, including incentive and bonus eligibility","Promotion, discipline or termination"]},{"id":"healthcare","label":"Healthcare services","examples":["Care authorisation or hours","Triage or acuity scoring","Coverage determinations"]}],"significantDecisionsNote":"Exhaustive list per section 7001(ddd). Recommendation engines, churn models, ad targeting and fraud scoring are not significant decisions under this definition.","humanInvolvementTest":[{"id":"interpret","requirement":"The reviewer knows how to interpret and use the output","failsWhen":"A reviewer who has never been told what the score means cannot interpret it."},{"id":"analyze","requirement":"The reviewer reviews the output AND any other information relevant to the decision","failsWhen":"A recruiter working down a ranked shortlist in order, without opening anything the ranking did not surface, is not reviewing other relevant information."},{"id":"authority","requirement":"The reviewer has the authority to make or change the decision","failsWhen":"A reviewer who can technically overturn an output but must escalate to a manager to do it does not plainly have that authority."}],"humanInvolvementLogic":"AND — all three parts must be satisfied per section 7001(e)(1).","conditionalExclusions":{"note":"Listed at 7001(e)(3), each qualified by \"provided that they do not replace human decisionmaking\". The exclusions are conditional, not categorical.","technologies":["Web hosting","Domain registration","Networking","Caching","Website-loading","Data storage","Firewalls","Anti-virus","Anti-malware","Spam and robocall filtering","Spellchecking","Calculators","Databases","Spreadsheets"]},"rights":[{"id":"pre-use-notice","right":"Pre-use notice","whatToBuild":"A notice that renders before the decision is made, describing how the technology works, what personal information it uses, what it outputs, and what happens on opt-out.","reference":"https://www.ivector.co/blog/building-a-pre-use-notice-and-opt-out"},{"id":"opt-out","right":"Opt out","whatToBuild":"A path for a person to refuse ADMT processing — or a documented exception plus a human-appeal route good enough to substitute for it.","reference":"https://www.ivector.co/blog/building-a-pre-use-notice-and-opt-out"},{"id":"access","right":"Access","whatToBuild":"A decision log detailed enough to answer \"why me?\" — inputs, output, logic and the reviewer's role, retained and retrievable per person.","reference":"https://www.ivector.co/blog/audit-trail-for-ai-decisions"},{"id":"appeal","right":"Appeal","whatToBuild":"A place for requests to land, and a path to reverse a decision that has already propagated downstream.","reference":"https://www.ivector.co/blog/audit-trail-for-ai-decisions"}],"timeline":[{"date":"2026-01-01","milestone":"CCPA regulations take effect","appliesTo":"All covered businesses","detail":"Adopted regulations effective, including the ADMT definitions at 7001(e) and 7001(ddd).","section":"7001"},{"date":"2027-01-01","milestone":"ADMT rights live: pre-use notice, opt-out, access, appeal","appliesTo":"All covered businesses using ADMT for a significant decision","detail":"Section 7200(b) requires a business already using ADMT for a significant decision to be in compliance by this date. This is the deadline the engineering work has to beat.","section":"7200(b)"},{"date":"2027-12-31","milestone":"Risk assessments documented","appliesTo":"Processing that began before 1 January 2026 and continues past it","detail":"Risk assessments for pre-existing processing must be documented no later than this date.","section":"7155"},{"date":"2028-04-01","milestone":"First risk-assessment filing to the CPPA","appliesTo":"Businesses with documented assessments covering 2026 and 2027","detail":"The required information must be submitted to the Agency no later than this date.","section":"7157"},{"date":"2028-04-01","milestone":"First cybersecurity audit due","appliesTo":"Businesses above $100M in 2026 gross revenue","detail":"Audit obligations cascade in later years for smaller revenue bands — this is the first cohort only.","section":"7123"}]}