Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Automated Decision Making topic

No spam. Unsubscribe anytime.

CPPA narrows draft ADMT rules, removes behavioral-advertising trigger and asks staff for targeted redrafts

2956992 · April 11, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

California Privacy Protection Agency board members spent the bulk of their April 4 meeting debating proposed regulations on automated decision‑making technology, risk assessments and cybersecurity audits and directed staff to narrow several definitions and remove a high‑profile behavioral‑advertising trigger from the draft.

California Privacy Protection Agency board members spent the bulk of their April 4 meeting debating proposed regulations on automated decision‑making technology, risk assessments and cybersecurity audits and directed staff to narrow several definitions and remove a high‑profile behavioral‑advertising trigger from the draft.

The board’s meeting followed a 45‑day public comment period. Philip Laird, the agency’s general counsel, told the board staff had identified six “high priority” issues and presented alternatives for each. "Staff are prepared to walk the Board and the public through six high priority issues," Laird said as the discussion opened. Board members then debated definitions, thresholds and enforcement mechanics for more than four hours.

The board’s direction and why it matters

Board members and staff agreed on several policy moves that narrow the draft regulations’ reach rather than expand it. Major board directions from the meeting, summarized by staff and confirmed by multiple board members, were: - Remove the draft’s profiling‑for‑behavioral‑advertising threshold from both the risk‑assessment and ADMT (pre‑use notice/opt‑out) sections. Staff said that deletion would leave the underlying sale/share opt‑out framework in statute but would remove a separate ADMT/assessment trigger for behavioral‑targeting profiling. Several industry commenters had argued the draft would otherwise limit first‑party advertising and small‑business marketing; consumer‑advocacy groups had urged keeping the threshold. The board chose removal as the near‑term course. - Narrow the ADMT definition toward a human‑involvement standard (staff’s “Alternative 2”) rather than the broader formulation that would capture systems that merely assist human decision‑making. Under the narrower approach, meaningful human involvement would take regulated systems out of the ADMT bucket; by contrast, systems that operate without such involvement would remain in scope. Board members said they prefer a narrower, APA‑clarified test drawn from concepts in GDPR and Colorado law but rewritten to meet California administrative‑rule clarity requirements. - Remove explicit references to “artificial intelligence” from the risk‑assessment thresholds and remove language that swept in systems merely “capable of” being used for certain outcomes. The board asked staff to replace the breadth of “capable of being used” with a more concrete knowledge/intent standard tied to use, plans to use, or permitting others to use the system for the covered purposes (for risk assessments and for ADMT‑notice/opt‑out triggers). - Revisit and tighten the “significant decision” definition. Staff will remove the phrase "access to" and consider deleting or narrowing certain enumerated items that had drawn widespread comment (insurance, some criminal‑justice references and the broad category “essential goods or services”), and will prepare examples and clarifications for financial, housing and health contexts so regulated parties know what is — and is not — in scope. - Return with clarified text and examples on worker/educational profiling and public profiling. Members asked staff to present use‑case guidance that distinguishes routine workplace monitoring (time cards, fleet tracking, attendance systems) from higher‑risk uses (surveillance that affects hiring, termination or other consequential outcomes) and to consider separate treatment for gig‑platform assignment rules versus permanent employment decisions. - Streamline the agency’s proposed annual risk‑assessment submission. Staff proposed a shorter annual filing with six summarized data points (business contact, covered period, number of assessments done, categories of personal information assessed, an attestation by a senior executive, and a certification). Full, unabridged risk assessments would remain producible to CPPA or the Attorney General upon request.

Board members framed the changes as both a response to the public record and a narrowing step designed to reduce litigation risk and regulatory burden. Board member Robert McTaggart argued privately and publicly that staff should analyze the legal challenges raised in comments and report back before the agency moves to further notice; several other members supported getting staff and the new executive director more time to assess litigation exposure and economic impact. McTaggart said, "In the interim, agency efforts to promulgate and enforce regulations around cybersecurity, risk assessment and ADMT should be paused," and asked staff to produce a report addressing potential constitutional and statutory‑authority challenges.

What staff will do next

Staff said they will prepare revised regulatory text reflecting the board directions and will also: - Provide a document that clarifies how the ADMT and significant‑decision definitions align or differ from GDPR and Colorado law and propose APA‑compliant language for California. - Supply use‑case examples and tighter definitions for housing, health‑care and financial contexts (including how existing federal carve‑outs such as FCRA/GLBA interact with the rules). - Rework the training threshold language to narrow the universe of covered activity (replacing "capable of" with standards tied to actual use, intent, plans to use or permission to use, and to account for developer/deployer relationships). - Produce a more concise annual submission template for risk assessments and explain how comparable assessments under other jurisdictions (e.g., Colorado or EU templates) might be accepted or cross‑walked. - Prepare an economic update and identify whether aligning with other jurisdictions or recognized standards (for example, NIST) would materially reduce compliance costs for California businesses. - Provide privileged legal analysis on litigation risk to the board (staff said they have previously provided confidential advice to the board and will update that analysis where needed). Several board members asked for legal advice on the six major legal challenges identified in the public comments; staff agreed to provide that advice in the appropriate format.

Public comment split: industry, consumer and labor voices

The meeting included extended public comment. Business groups emphasized cost and cross‑border regulatory harmonization; industry speakers urged removing or narrowing ADMT and behavioral‑advertising triggers and suggested the board align with Colorado or GDPR drafting where appropriate. Trade‑association speakers cited the agency’s economic assessment and urged the board to reduce regulatory burden for small businesses.

Consumer advocates and labor‑oriented commenters urged stronger notice and opt‑out protections for ADMT, broader coverage for profiling and clearer protections for workers affected by automated workplace systems. TechEquity and UC‑Berkeley‑labor‑center representatives urged the board to retain robust worker protections and to limit easy carve‑outs that would let systems evade meaningful human involvement tests.

Where the board stopped short of votes

No final, binding regulation was adopted at the April 4 meeting. Instead the board approved multiple directions to staff and asked for revised regulatory text and analyses to return at a future meeting. The board specifically approved removing the behavioral‑advertising profiling threshold from both the risk‑assessment and ADMT sections and signaled support for the narrower ADMT definition staff labeled as Alternative 2; staff will implement those directions and return with the revised package for further public comment before any final OAL submission.

Why this matters

The board’s narrowing of draft language is intended to reduce the number of systems and ordinary business uses swept into ADMT obligations (pre‑use notices, opt‑outs, access rights) while maintaining CPPA’s statutory mandate to provide consumer access and opt‑out rights where high‑risk, automated decision making materially affects consumers.

Next steps and schedule

Staff told the board they will aim to present revised text at the next board meeting and asked the board for flexibility on timing because of the scope of changes requested. The board discussed scheduling a mid‑July meeting window to continue the rulemaking work; staff committed to return with revised text, a clarified economic update, and legal analysis of the litigation risks described in public comments.

Ending

Board members and staff closed the agenda item by thanking public commenters and rulemaking participants for the extensive record. The agency will post revised regulatory text and supporting materials for additional public comment after the board reviews the staff redraft.