CCPA Regulations: Automated Decision-Making Technologies (ADMT) Business Guide
Is your company ready to meet California’s new requirements for automated decision-making technologies?
New CCPA regulations finalized by the California Privacy Protection Agency (CalPrivacy) took effect on January 1, 2026, and include new obligations for businesses that use automated decision-making technologies (ADMT) for “significant decisions.” The rules also extend to profiling, where automated processing is used to evaluate, analyze, or predict things about an individual.
To help companies navigate these new requirements, we created the CCPA Regulations: Automated Decision-Making Technologies (ADMT) Business Guide. It covers when ADMT obligations apply, provides details on consumer notices and choice, highlights what privacy risk assessments must include, and more, giving companies a clear path toward compliance.
What’s Inside the CCPA Regulations: Automated Decision-Making Technologies (ADMT) Business Guide?
New ADMT rules introduce obligations that might touch multiple functions across your organization. The challenge is understanding when it crosses into regulated activity. Our guide cuts through the regulatory complexity and delivers a practical overview of what businesses need to know and do now.
Inside, you’ll find:
- Important definitions, including ADMT, significant decisions, profiling, and substantial replacement of human decision-making
- Examples of significant decisions that trigger compliance obligations
- A breakdown of pre-use notice requirements and what disclosures must be included
- Consumer privacy rights obligations covering opt-out and access rights
- What to include in a privacy risk assessment
- A phased compliance timeline by obligation
- Recommended compliance steps
- And more
Why Download the CCPA Regulations: Automated Decision-Making Technologies Business Guide?
Many companies are already using AI and automated tools without fully understanding how regulators define “significant decisions” or what triggers compliance obligations. This guide answers those questions directly. If your company is trying to figure out where to start or whether your current program holds up, this guide will help you get the answers.
Download the CCPA Regulations: Automated Decision-Making Technologies Business Guide
Most of the ADMT obligations become effective January 1, 2027; however, conducting privacy risk assessments is in effect now.
Businesses should be conducting privacy risk assessments on all high-risk processing activities and start preparing for future obligations today. Now is the perfect time to get your processes in place.
Join hundreds of privacy professionals who rely on Red Clover Advisors for actionable, up-to-date, expert guidance.
Download your complimentary copy today and take the first step toward meeting California’s new legal requirements.
Additional Resources
Explore more resources to help you manage CCPA privacy requirements with confidence and support your ongoing privacy and compliance goals.
Privacy Risk Assessments vs. Cybersecurity Audits Guide
Download our CCPA Regulations: Privacy Risk Assessments vs. Cybersecurity Audits Business Guide. It provides companies with the context and structure needed to assess the new obligations and build a plan that withstands regulatory scrutiny.
Privacy Risk Assessments: PIA/DPIA Business Guide
Get the Privacy Risk Assessments PIA/DPIA Business Guide and take the guesswork out of conducting privacy risk assessments with confidence and clarity.
