California’s privacy regulator has proposed new rules for businesses that use automated decisionmaking technology, or ADMT. If adopted, the framework would give state residents ways to learn how their personal information is used in automated systems and, in some cases, opt out.
The proposal is a draft, not a finalized regulation. Its details and scope may change during consultation, but its central idea is to connect notice and access rights with limits on how businesses can use personal data in automated decisions.
Notice and choice before automated decisions
The California Privacy Protection Agency (CPPA) proposes requiring businesses to provide a “pre-use notice” to consumers affected by ADMT. That notice would give people information before their data is used, helping them decide whether to opt out or ask for further details.
The draft would establish an opt-out right, with a limited set of possible exceptions. A business could rely on an exception when using ADMT is necessary for security, fraud prevention, safety, or providing a good or service the consumer requested.
The requested-service exception comes with additional conditions. The business would need to show it has no reasonable alternative method of processing and meet one of the draft’s specified tests, such as showing that an alternative would produce a result that is not as valid, reliable, and fair, or would impose extreme hardship.
That structure could make it harder for a business to argue that a product’s use of automation alone means consumers cannot opt out. The draft places importance on whether another way of providing the service is available and on the business’s ability to explain why it needs the processing.
What consumers could ask businesses to explain
The proposed access rights would let California residents request information about a business’s use of ADMT and the system’s output concerning them. They could also ask how a decision was made, including whether a person was involved and whether the system was evaluated for validity, reliability and fairness.
Other information covered by the draft includes the system’s logic and key parameters affecting its output, how those parameters applied to the individual, and the range of possible outputs. Businesses would also need to explain how consumers can exercise other rights under the California Consumer Privacy Act (CCPA) and submit a complaint about ADMT.
These details are intended to make access more meaningful. Knowing that a system was used may not explain how it shaped an outcome; information about its inputs, logic and human involvement could give consumers a clearer account of the process.
The draft proposes only three exceptions to these access rights: security, fraud prevention and safety. As with the opt-out provisions, the narrow list suggests an effort to limit the circumstances in which businesses can withhold information.
Profiling could widen the proposal’s impact
The CPPA defines ADMT broadly in the draft, covering systems and processes that use computation to make or carry out a decision, or to help a person make one. The proposal also says ADMT includes profiling: automated processing of personal information to assess or predict aspects of a person, such as their behavior, interests, health or location.
That definition could matter for companies that use personal data to build profiles. The Agency says its upcoming consultation will consider whether the rules should cover profiling for behavioral advertising, profiling consumers the business knows are under the age of 16, and processing personal information to train ADMT.
Those questions remain open. If behavioral advertising is covered, the draft says businesses would need to offer consumers a way to opt out of having their data processed for that purpose. It also proposes that behavioral advertising cannot use certain opt-out exceptions that might apply to other uses, such as security or fraud prevention.
The final scope will help determine how much the rules affect advertising and data-driven AI practices. The draft signals that these uses are being considered, but it does not settle whether each will fall under the final requirements.
A proposal still moving through rulemaking
The CPPA published the draft as the start of a rulemaking process. The Agency Board was expected to provide feedback at its December 8, 2023, meeting, and the Agency said it expected formal rulemaking to begin next year. A public consultation would give stakeholders an opportunity to weigh in before the text is finalized.
The proposal sits within California’s broader effort to strengthen privacy protections. The California Consumer Privacy Act (CCPA) came into effect in early 2020, and measures backed by state residents in fall 2020 reinforced and redefined parts of the privacy law. The draft ADMT rules are part of that continuing effort.
Any eventual requirements would focus on protecting California residents, and the CPPA’s reach and enforcement are tied to the state. Companies could choose to extend similar protections to people elsewhere in the United States, but the proposal does not require them to do so.
For now, the draft sets out a possible framework: tell people when their data is about to be used in automated decisionmaking, give them ways to opt out in covered situations, and provide useful information about how systems reach or support decisions. Consultation will determine which uses are covered and what the final obligations require.