Automated Decision-Making Under Privacy Law: The Rules That Actually Bind
Key Takeaways
- California's ADMT regulations reach technology that replaces or substantially replaces human decisionmaking for a significant decision, defined as a closed list of six life domains, with compliance required by January 1, 2027
- The opt-out in the state comprehensive privacy statutes reaches profiling only where it furthers decisions producing legal or similarly significant effects, not automated processing generally
- New York City requires an annual bias audit of automated employment decision tools, calculating selection rates and impact ratios by race, ethnicity and sex
- Illinois amended its Human Rights Act to make discriminatory AI use in employment a civil rights violation, and separately to prohibit zip codes as a proxy for protected classes, effective January 1, 2026
- The FTC's Rite Aid order required deletion not only of collected images but of any data, models or algorithms derived from them — a remedy that reaches the trained model itself
Where Privacy Law Meets Automated Decisions
There is no general American statute governing algorithmic decision-making. What exists instead is a set of regimes that reach it obliquely, each from the direction of a law written for something else — consumer privacy, civil rights, unfair trade practices — and each defining its own trigger. The result is that a single hiring model can sit inside three regulatory perimeters at once, with different definitions, different obligations and different commencement dates.
The unifying feature across almost all of them is that they do not regulate automation as such. They regulate automation applied to particular decisions about particular people. What varies is how the consequential decision is defined, and that definition does most of the work of determining scope.
California: The ADMT Rules
The most detailed regime is California's. The approved text of the CCPA updates, cybersecurity audit, risk assessment, ADMT and insurance regulations adds a new article on automated decisionmaking technology to Title 11 of the California Code of Regulations.
The definition is narrower than the phrase suggests. Automated decisionmaking technology "means any technology that processes personal information and uses computation to replace human decisionmaking or substantially replace human decisionmaking." The regulation then defines the second limb rather than leaving it to argument: to substantially replace human decisionmaking "means a business uses the technology's output to make a decision without human involvement," and human involvement requires a reviewer who knows "how to interpret and use the technology's output to make the decision" and who reviews and analyses that output alongside other information.
That construction means a scoring tool feeding a reviewer who genuinely exercises judgement falls outside the article, while the same tool feeding a nominal reviewer who rubber-stamps its output does not. The distinction is about the quality of the human step, not its presence.
The second limiting element is the decision. Section 7200 provides that "[a] business that uses ADMT to make a significant decision concerning a consumer must comply with the requirements of this Article," and significant decision "means a decision that results in the provision or denial of financial or lending services, housing, education enrollment or opportunities, employment or independent contracting opportunities or compensation, or healthcare services." The list is closed. Advertising, pricing outside lending, content ranking and recommendation are not on it.
Timing is set within the article itself. A business using ADMT for a significant decision before January 1, 2027 must be in compliance no later than that date; one that begins on or after it must comply whenever it is using ADMT for such a decision.
Notice, Opt-Out and the Access Right
Three obligations follow. The first is a pre-use notice under section 7220, which must describe the specific purpose rather than state it "in generic terms, such as 'to make a significant decision' without further detail."
The second is an opt-out. Section 7221 provides that "[a] business must provide consumers with the ability to opt-out of the use of ADMT to make a significant decision concerning the consumer," subject to exceptions enumerated in the same section.
The third is the most novel, because it requires explanation rather than disclosure. Under section 7222, a business using ADMT for a significant decision "must provide a consumer with information about this use when responding to a consumer's request to access ADMT," and must give "plain language explanations" including the specific purpose for which it used the technology with respect to that consumer. This is an individualised account of a particular decision, not a general description of a system.
Risk Assessments as a Separate Track
Running alongside the ADMT article is a risk assessment obligation triggered by a list of processing activities, and its reach is wider than the ADMT rules themselves.
Using ADMT for a significant decision is one trigger. But the list also includes using automated processing to infer or extrapolate a consumer's "intelligence, ability, aptitude, performance at work, economic situation, health (including mental health), personal preferences, interests, reliability, predispositions, behavior, location, or movements" based on systematic observation of that person acting as an educational programme applicant, job applicant, student, employee or independent contractor.
That trigger does not require a significant decision at all. Inference about employees or students from systematic observation is enough, which captures workplace and educational monitoring that produces no decision in any of the six named domains.
Profiling Opt-Outs in the Comprehensive Statutes
Outside California, most state comprehensive privacy statutes reach automated decisions through a profiling opt-out that follows a common template. Colorado's is representative.
Under C.R.S. § 6-1-1306(1)(a)(I), a consumer has the right to opt out of processing for targeted advertising, the sale of personal data, or "[p]rofiling in furtherance of decisions that produce legal or similarly significant effects concerning a consumer." Profiling is defined broadly at § 6-1-1303(20) as "any form of automated processing of personal data to evaluate, analyze, or predict personal aspects concerning an identified or identifiable individual's economic situation, health, personal preferences, interests, reliability, behavior, location, or movements."
The breadth of the definition is not the operative limit; the qualifier is. Profiling is opt-outable only where it furthers decisions producing legal or similarly significant effects. Profiling that informs a recommendation, a segment or an advertisement is reached, if at all, by the separate targeted-advertising opt-out rather than by this one.
The same provision requires controllers to honour an opt-out signalled "through a technology indicating the consumer's intent to opt out such as a web link indicating a preference or browser setting, browser extension, or global device setting" — the universal opt-out mechanism, which applies to the profiling opt-out as much as to the others.
Employment: Audits and Notice
Employment is where the obligations become specific to the tool rather than to the data, and where two jurisdictions have gone furthest.
New York City reaches automated employment decision tools through a bias audit requirement. The Department of Consumer and Worker Protection's final rule implementing Local Law 144 conditions use of such a tool on its having "been subject to a bias audit within one year of the use of the tool," with the audit results published. The rules prescribe the arithmetic: an audit "must calculate the selection rate for each race/ethnicity and sex category" reported under the EEO Component 1 report and "compare the selection rates to the most selected category to determine an impact ratio," an approach the rules describe as consistent with section 1607.4 of the EEOC Uniform Guidelines.
Illinois took a different route, amending its civil rights statute rather than creating a disclosure regime. House Bill 3773 makes it a civil rights violation, with respect to recruitment, hiring, promotion, discharge, discipline, tenure and the terms of employment, "for an employer to use artificial intelligence that has the effect of subjecting employees to discrimination on the basis of protected classes under this Article or to use zip codes as a proxy for protected classes." A separate clause makes it a violation "[f]or an employer to fail to provide notice to an employee that the employer is using artificial intelligence for the purposes described." The Act takes effect January 1, 2026, and directs the Department of Human Rights to adopt rules on when and how notice must be given.
The zip-code clause is worth isolating. It names a specific proxy variable in statute rather than leaving proxy discrimination to be established case by case — a drafting choice no other state statute surveyed here makes.
Colorado's Algorithmic Discrimination Statute
Colorado enacted the broadest state framework in Senate Bill 24-205, which creates duties for developers and deployers of high-risk artificial intelligence systems. It defines algorithmic discrimination as "any condition in which the use of an artificial intelligence system results in an unlawful differential treatment or impact that disfavors an individual or group of individuals" on the basis of an enumerated list of protected characteristics, and defines a consequential decision as one with a material legal or similarly significant effect on the provision, denial, cost or terms of education, employment, financial or lending services, an essential government service, health care, housing, insurance or a legal service.
The Act imposes a reasonable care duty on developers to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination, with a rebuttable presumption of reasonable care where the statutory requirements are met, and requires impact assessments of high-risk systems.
Its commencement has moved. As enacted, the operative duties applied "on and after February 1, 2026." Senate Bill 25B-004, from the 2025 First Extraordinary Session, amends those provisions to strike each February 1, 2026 date and substitute June 30, 2026, under a title concerning "measures effective no later than June 30, 2026, to increase transparency for algorithmic systems." The version of that bill retrieved for this guide is the revised text including amendments adopted on second reading in the second house.
Model Deletion as a Remedy
The remedy that reaches furthest into a system is not statutory. It comes from FTC orders, and its significance is that it operates on the model rather than on the data.
In the modified decision and order in the Rite Aid matter, FTC Docket No. C-4308, the company was prohibited for five years from deploying or using any facial recognition or analysis system. The order then requires, within 45 days of its effective date, that Rite Aid "delete or destroy all photos and videos of consumers" used or collected in connection with such a system before the order, "and any data, models, or algorithms derived in whole or in part therefrom," with written confirmation.
The phrase "derived in whole or in part therefrom" is what distinguishes this from ordinary data deletion. A model trained on improperly collected images is not made lawful by deleting the images, because the training has already been absorbed into the weights. Reaching the derived model closes that gap, and the same construction has appeared in other Commission orders concerning algorithms built on data the Commission alleged was unlawfully obtained.
How the Perimeters Differ
Three definitional choices separate these regimes, and a system can sit inside one and outside another for reasons that have nothing to do with how it works.
The first is what counts as automated. California asks whether human involvement is real, defining it by the reviewer's capacity to interpret and analyse the output. The Colorado Privacy Act's profiling definition asks only whether processing is automated. Illinois asks whether artificial intelligence was used, without defining the degree of automation.
The second is which decisions count. California's list of six domains, Colorado's list of nine, and the "legal or similarly significant effects" formula in the comprehensive statutes are three different perimeters, and the employment statutes dispense with the question by regulating a sector directly.
The third is what the obligation is. California grants individual rights — notice, opt-out, explanation. New York City requires an audit and publication. Illinois creates a discrimination cause of action. Colorado imposes a care duty with assessments. Only the FTC's remedy reaches the model itself.
What This Guide Does Not Cover
The European regimes are omitted rather than summarised. Article 22 of the General Data Protection Regulation and Regulation (EU) 2024/1689, the AI Act, are the obvious comparators for everything above, and both are cited constantly in discussion of automated decision-making. Neither is described here, because EUR-Lex could not be retrieved from the environment in which this guide was researched: repeated requests for the consolidated GDPR text and the AI Act, in both HTML and PDF, returned an empty body, and the ELI permalink returned no article text. Under this site's sourcing rules a document that was not fetched and read cannot be cited, and characterising either instrument from memory or from secondary coverage would breach that rule. The comparison is deferred rather than attempted.
Training data provenance is also left out. The question of what lawful basis supports scraping or repurposing personal data for model training is live in litigation and in regulator guidance, but no decision or guidance document resolving it was fetched and read for this guide, so no position on it is stated here.
No enforcement history is charted for the California ADMT rules, because compliance is not required until January 1, 2027 and there is none to report.
Background
For the underlying law rather than this development: California privacy law, Colorado privacy law, Illinois privacy law, HR & Employment privacy law, Technology & SaaS privacy law.
Frequently Asked Questions
What counts as automated decisionmaking technology under the California rules?
Which decisions do the California ADMT rules reach?
When do the California ADMT obligations start?
Does a profiling opt-out cover all automated processing?
What does a New York City bias audit have to calculate?
Can a regulator require deletion of a trained model?
Sources
Everything above is reported from these documents. Follow them to verify.
- California Privacy Protection Agency — approved text of the CCPA updates, cybersecurity audit, risk assessment, ADMT and insurance regulations (September 22, 2025) regulation
- Colorado Revised Statutes title 6 — Colorado Privacy Act, including § 6-1-1303(20) profiling and § 6-1-1306(1)(a) opt-out rights (December 31, 2024) statute
- Colorado Senate Bill 24-205 — Consumer Protections for Artificial Intelligence, as signed (May 17, 2024) statute
- Colorado Senate Bill 25B-004 — revised text moving the SB 24-205 dates to June 30, 2026 (August 25, 2025) statute
- Illinois House Bill 3773 (103rd General Assembly), enrolled — Human Rights Act amendments on artificial intelligence in employment (August 9, 2024) statute
- NYC Department of Consumer and Worker Protection — final rule implementing Local Law 144 on automated employment decision tools (April 6, 2023) regulation
- FTC — Rite Aid Corporation, modified decision and order, Docket No. C-4308 (December 19, 2023) agency release
Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.