From 1 January 2027, a Californian who is scored, ranked or screened by automated software can tell the business to stop, and the clock for stopping is 15 business days. That is shorter than the 45 calendar days most teams have in their heads from access requests, and it carries a second duty that is easy to miss: the business has to tell every vendor that touched the person's data to stop within the same window. Section 7221 of the California Privacy Protection Agency (CPPA) regulations spells both out, along with a list of things you may not ask the person to do first.
This piece is about the opt-out request handler: what the text of section 7221 requires it to do, which rules a ticket queue quietly breaks, and the one case where you do not need the handler at all. It assumes ADMT already covers you. If you are not sure, start with what counts as automated decisionmaking technology.
A definition first. A request to opt out of ADMT is a consumer request that a business not use automated decisionmaking technology (ADMT) with respect to that consumer, as defined in the CCPA regulations at section 7001(qq). It applies to ADMT used to make a significant decision: lending, housing, education, employment or healthcare.
When do you not need an opt-out at all?
Section 7221(b) of the CPPA regulations (effective 1 January 2026) says a business is not required to offer the opt-out in three situations. Know which one you are in before you build anything.
- 1.A human appeal route. You give the person a way to appeal to a human reviewer with authority to overturn the decision. Section 7221(b)(1) requires a designated reviewer who knows how to read the ADMT output, looks at the person's own submission, and can change the outcome.
- 2.Hiring and admission decisions, where you use the tool solely to assess ability to perform at work or in an educational program, and the tool works for your purpose without unlawful discrimination (section 7221(b)(2)).
- 3.Work allocation and compensation decisions, on the same two conditions (section 7221(b)(3)).
Notice what is not on the list. Lending, housing and healthcare decisions have no tool-quality exception. They get the opt-out or the human appeal, and nothing else. For the appeal route, we covered what that reviewer has to be able to do. If you pick the appeal, you can skip most of what follows.
What does the request intake have to look like?
Section 7221(c) through (f) is a list of constraints on the front door, and most of them are things a generic support form does by default.
- Two or more methods. At least one must match how you mainly deal with the person. An online business must offer an interactive form reachable from an opt-out link in the pre-use notice, and the link title must say what is being opted out of, such as "Opt-out of Automated Decisionmaking Technology." The other methods can be a toll-free number, an email address, an in-person form or mail.
- Not a cookie banner. Section 7221(c)(4) says a cookie banner or cookie controls are not by themselves an acceptable method, because cookies concern collection and not use.
- No account. Section 7221(e) bars requiring the person to create an account or hand over more than is needed to route the request.
- No identity verification. Section 7221(f) says you cannot require a verifiable consumer request, and section 7060(b) says verification cannot be required for an ADMT opt-out. You may ask for what you need to find the person's records, but the regulation's own example is that asking for a name is fine and asking for a photo of a driver's licence is not.
- Symmetry. Section 7221(d) points to section 7004, which says the path to the more privacy-protective choice cannot be longer than the path to the other one.
- A confirmation. Section 7221(h) requires a way for the person to confirm you processed the request.
The most common failure is the verification step. A team that routes opt-outs through the same flow as access and deletion requests, where identity checks are normal and expected, has built a handler that section 7060(b) forbids.
What happens in the 15 business days?
Section 7221(m) and (n) split the timing in two. If the person opts out before you have started processing them, you must not start. If they opt out afterward, you must stop using that ADMT on their personal information as soon as feasibly possible and no later than 15 business days from the date you receive the request.
The same subsection then adds the part that turns a form into an integration. Within the same timeframe you must notify every service provider, contractor and other person to whom you disclosed or made the person's personal information available for that ADMT, and instruct them to stop. Section 7221(n)(2) puts the notification on you and the clock on both of you.
Picture a 30-person tenant-screening SaaS company. Its scoring model runs on a managed inference API, and a sub-processor enriches applications with address history. A rental applicant in Fresno opts out on a Monday. The company has three jobs due by the 15th business day, not one: remove the applicant from the scoring queue, suppress the model's output for anything already pending, and send a stop instruction to the inference provider and the data enricher. Contracts that say a vendor will act on instructions "within a commercially reasonable period" are the first thing that breaks. Which of the two parties is the business and which is the service provider depends on the contracts, and counsel should settle that, but the engineering shape is the same either way: an opt-out flag per person, per tool, that every downstream system reads.
What does the handler have to remember?
Three records matter, and one limit.
- The request log. Section 7101 requires keeping consumer requests and your responses for at least 24 months, as a ticket or log with the request date, its nature, how it was made, your response date, your response, and the basis for any denial.
- The suppression state. Section 7221(k) says you must wait at least 12 months from receipt of an opt-out before asking the person to consent to that ADMT. Store the receipt date, not just a boolean, or the re-ask campaign will break the rule.
- The vendor notices. The only proof you met section 7221(n)(2) is the notice itself and the date it went out.
The limit is purpose. Section 7101(d) says records kept for this purpose may not be used for anything else except reviewing and improving your compliance, and may not be shared with third parties except to meet a legal obligation. Do not let the opt-out table become a marketing suppression list that feeds a sales dashboard.
The regulation also lets you offer a granular choice, such as allowing some uses of ADMT, but only if you also offer a single option that opts out of all of them (section 7221(i)). Build the single switch first.
What can you still refuse?
Section 7221(g) lets a business deny a request it has a good-faith, reasonable and documented belief is fraudulent. It must tell the requester it will not comply and explain why. This is narrow, and it needs documentation before the denial, not after. Section 7221(j) lets an authorised agent submit a request, but you may deny it if the agent does not provide the person's signed written permission. Neither is a licence to add friction for everyone.
The reporting side matters only for the largest businesses. Section 7102 requires a business handling the personal information of 10,000,000 or more consumers in a calendar year to compile the number of ADMT opt-out requests received, complied with in whole or in part, and denied. Everyone else can ignore it, but if you are close, count from day one.
Where this fails, and where we would not help
This handler fails in three places in practice: identity checks copied from the access flow, no machine-readable link to vendors, and a flag that lives in one system while the model runs in another. Each is an afternoon of design and weeks of plumbing.
We would not be the right call if your tool does not make or substantially replace a significant decision, or if you have chosen the human appeal and the hiring or work-allocation exception genuinely applies. In those cases a handler is overbuilt, and your effort belongs in the evaluation records and the reviewer's authority instead.
This is general information about the regulation's text, not legal advice, and counsel should decide questions about roles, denials and exceptions. If you are the engineering side of a business or vendor that has to ship this before 1 January 2027, check your scope with the ADMT checker, read how we approach the work on the ADMT compliance engineering page, or tell us what your decision tool does and where its data goes. To see how a decision log supports a response when the person asks why, read how to answer an ADMT access request.
Sources
- California Privacy Protection Agency: CCPA regulations, Title 11 Division 6 Chapter 1 (effective 1 January 2026), sections 7001(qq), 7004, 7060(b), 7101, 7102, 7200(b) and 7221.