Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Data Privacy

California's ADMT Rules Are Live: What Banks and Fintechs Get Wrong About the GLBA Exemption

The CPPA finalized ADMT regulations effective January 1, 2026 — and California's GLBA exemption is narrower than you think. Here's what financial institutions and fintechs actually need to do about automated decision-making, opt-out rights, and risk assessments.

By Rebecca Leung · July 13, 2026 ·
Table of Contents

Most financial institutions looked at California’s GLBA exemption, concluded it covered their operations, and moved on. That analysis is incomplete — and the CPPA has been proving it wrong all year.

The California Privacy Protection Agency finalized its Automated Decisionmaking Technology regulations on July 24, 2025. The Office of Administrative Law approved them September 22-23, 2025. They took effect January 1, 2026. Six months in, here’s where financial institutions and fintechs are getting caught.

TL;DR

  • California’s ADMT regulations took effect January 1, 2026 — ADMT means any technology that uses computation to replace or substantially replace human decision-making
  • The GLBA exemption under CCPA §1798.145(e) is DATA-LEVEL, not entity-level: it covers information collected under GLBA, not everything a financial institution handles
  • Employee data, marketing behavioral data, and B2B contact data are outside the GLBA exemption and fully subject to CPRA and ADMT obligations
  • Consumer opt-out rights for significant decisions (including financial/lending) take effect January 1, 2027 — risk assessments for new ADMT activities are already required
  • The CPPA’s $12.75M GM/OnStar settlement (May 2026), the largest CCPA penalty ever, involved data sharing with insurance data aggregators — a pattern that looks familiar to many bank-fintech data arrangements

What the ADMT Regulations Actually Cover

The CPPA defines “Automated Decisionmaking Technology” as “any technology that processes personal information and uses computation to replace or substantially replace human decision-making.” That definition is deliberately broad and deliberately includes machine learning models, scoring algorithms, and rules-based decision engines — not just generative AI.

Covered “significant decisions” include:

  • Financial and lending services — approvals, denials, pricing, credit limit adjustments
  • Housing — rental applications, property access decisions
  • Employment — hiring, promotion, termination, scheduling
  • Education — admissions, financial aid, academic standing
  • Healthcare — treatment authorization, benefit coverage

If you’re a bank underwriting loans with a model, a fintech setting credit limits with an algorithm, or an insurance affiliate using scoring data — you’re using ADMT for significant decisions covered by the regulations.

The key dates:

RequirementEffective Date
Regulations effectiveJanuary 1, 2026
Risk assessments (new ADMT)January 1, 2026
Consumer opt-out for significant decisionsJanuary 1, 2027
Risk assessments (pre-existing ADMT)December 31, 2027
Risk assessments submitted to CPPAApril 1, 2028
Cybersecurity audits (>$100M revenue)April 1, 2028
Cybersecurity audits ($50-100M revenue)April 1, 2029
Cybersecurity audits (<$50M revenue)April 1, 2030

If you started a new ADMT deployment after January 1, 2026, the risk assessment obligation is already active. You are behind.


The GLBA Exemption Problem

Here’s where financial institutions and their counsel frequently get the analysis wrong.

The CCPA’s GLBA exemption — codified at Civil Code §1798.145(e) — covers personal information collected and used pursuant to the Gramm-Leach-Bliley Act and the California Financial Information Privacy Act. When that exemption applies, CCPA and its ADMT overlay don’t.

The mistake is treating this as an entity-level exemption. It isn’t.

Compare:

  • Virginia CDPA: Entity-level GLBA exemption — a financial institution subject to GLBA is exempt from the whole law
  • Texas TDPSA: Entity-level GLBA exemption — same effect
  • Connecticut CDPA: Entity-level GLBA exemption — same effect
  • California CCPA/CPRA: Data-level exemption — only the specific personal information collected under GLBA activities is exempt

The practical difference is enormous. A bank that collects personal information for:

  • Loan underwriting ✓ covered by GLBA exemption
  • Employee HR data ✗ not GLBA-covered (fully subject to CPRA since January 1, 2023)
  • Website behavioral analytics ✗ not GLBA-covered
  • Marketing campaign targeting ✗ not GLBA-covered
  • B2B contact data ✗ B2B exemption sunset December 31, 2022

A mid-sized bank almost certainly maintains CPRA obligations for significant portions of the personal information it processes. When those non-exempt data sets flow into ADMT systems — including ADMT used for purposes that also involve GLBA-covered data — the analysis gets complicated fast.

The GM/OnStar enforcement action illustrates the exposure clearly: the data at issue was driving behavior and location data that GM collected through its OnStar service. GM sold that data to LexisNexis and Verisk, which used it in insurance pricing models. The $12.75 million settlement announced May 8, 2026 — the largest CCPA penalty ever — involved data that arguably sat at the intersection of a connected vehicle service and the insurance products that subsequently priced risk based on it. “We’re a financial institution” wouldn’t have helped GM there, and it won’t help a fintech selling behavioral data to an insurance affiliate.


What the Regulations Require: Pre-Use Notices and Opt-Out Rights

For ADMT used to make significant decisions affecting California consumers, the regulations require:

Pre-Use Notices

Before using ADMT to make a significant decision, a business must provide the consumer a pre-use notice that includes:

  1. A description of what ADMT is being used
  2. The purpose of the decision being made
  3. A high-level explanation of how the system operates
  4. The consumer’s right to opt out of ADMT for that decision
  5. The consumer’s right to request an appeal or human review of the decision
  6. How to exercise each of those rights

The notice must be provided before the ADMT runs — not buried in a privacy policy the consumer may never read, not in a consent form that covers fifty other things. The “pre-use” framing means the consumer gets notice specific to the context where the ADMT is being applied.

For a lender using an AI credit model, this means the loan application workflow needs to surface that notice before the model runs on the applicant’s data. That’s a product design requirement, not just a legal footnote.

Opt-Out Rights (Effective January 1, 2027)

Starting January 1, 2027, California consumers have the right to opt out of ADMT used for significant decisions affecting them. When a consumer exercises that right:

  • The business must cease ADMT use for that consumer’s case within 15 business days
  • An exception applies if a human reviewer can meaningfully review and override the automated decision — in that case, the business may offer human review as an alternative to ceasing ADMT entirely
  • The opt-out right is specific to the consumer — it’s not a blanket product shutdown, but it does require the infrastructure to identify and route individual cases outside the ADMT pipeline

That 15-business-day requirement is operationally meaningful. If your credit model makes 10,000 decisions per day and 2% of California applicants exercise the opt-out right, you need a human review queue and workflow that can handle that volume without creating disparate turnaround times that become their own fair lending problem.


The Enforcement Picture

The CPPA’s enforcement trajectory matters as much as the regulatory text. The agency has been active, the settlements have been large, and the patterns in enforcement actions are instructive for financial institutions.

GM/OnStar — $12.75 million (May 8, 2026): Largest CCPA penalty in the agency’s history. GM collected location and driving behavior data through OnStar and sold it to LexisNexis and Verisk — insurance data aggregators that used it in insurance pricing models — without adequate notice or consumer consent. The CPPA’s theory: consumers agreed to OnStar’s service for vehicle safety and assistance purposes; they didn’t consent to their driving data becoming inputs to insurance pricing algorithms. The data-sharing-to-insurance-aggregator pattern is common in financial services data arrangements.

Disney/ABC — $2.75 million (February 11, 2026): Fragmented opt-out systems that didn’t propagate consumer choices across services and affiliated entities. Disney had opt-out mechanisms, but exercising one didn’t stop data processing by affiliated properties. For financial holding companies with multiple regulated and non-regulated subsidiaries sharing consumer data, this settlement is directly on point.

Tractor Supply — $1.35 million (September 30, 2025): First CPPA action specifically targeting job applicant data. HR data — including applicant data from employment screening — falls outside the GLBA exemption and is fully subject to CPRA. Any company using ADMT in hiring (resume screening, interview analysis, skills assessments) for California applicants faces the ADMT overlay on top of existing CPRA obligations for that data.

Honda — $632,000 (March 12, 2025): Asymmetric UI dark patterns. Accept/agree buttons prominently displayed; reject/opt-out buttons several clicks and scrolls away, in smaller text. The CPPA has been explicit: opt-out mechanisms must be equally prominent and equally accessible as opt-in mechanisms. Any company designing a pre-use notice and opt-out flow for ADMT purposes should treat the Honda settlement as the design specification floor.


Risk Assessment Requirements

The ADMT regulations require a risk assessment before deploying new ADMT for covered purposes, and for pre-existing ADMT by December 31, 2027. The risk assessment must address:

  • The purpose and context of the ADMT use
  • The categories of personal information processed
  • The significant decisions being made and their potential impact on consumers
  • Safeguards implemented to address risks
  • Whether the ADMT could result in disparate impact on protected classes
  • The benefits of the ADMT use weighed against the risks

The assessments aren’t required to be public, but they must be completed and retained — and submitted to the CPPA by April 1, 2028. The CPPA can request them at any time during an investigation.

For financial institutions already conducting model risk management under SR 11-7 or OCC 2026-13, there is meaningful overlap with what a CPPA risk assessment requires. Model validation reports, pre-deployment fairness analyses, and model governance documentation can feed CPPA risk assessments — but the CPPA template isn’t the same as a model risk management package, and the consumer impact framing requires specific documentation most model governance programs don’t produce by default.

For the state-by-state comparison: Colorado has its own ADMT requirements under SB 26-189, with different thresholds and different definitions. California and Colorado are the two states with the most developed ADMT-specific regulatory frameworks, and they don’t align. Multistate compliance programs need both.


The DROP Platform and Data Broker Dimension

Financial services companies that sell or share consumer data — to affiliates, analytics vendors, data aggregators, or marketing platforms — have a related obligation that took effect January 1, 2026.

The CPPA launched the DELETE Request Opt-out Platform (DROP) at the start of 2026. DROP allows California consumers to submit a single deletion request to all registered data brokers simultaneously. Data brokers must process those requests and cannot sell or share the data after receipt.

Two changes make this more significant than the prior data broker regime:

  1. Registration fees: California SB-361 (signed October 8, 2025) raised the data broker registration fee from $400 to $6,600 per year. That fee increase signals the CPPA’s intent to use registration as a meaningful compliance and accountability mechanism, not a nominal filing requirement.

  2. GPC signal compliance: As of January 1, 2026, businesses must honor Global Privacy Control signals as legally binding opt-out requests for sale and sharing. The GPC obligation must be confirmed back to the consumer. Any financial services company operating a website with advertising or analytics partnerships needs the technical infrastructure to detect and honor GPC signals.

For companies feeding consumer data into AI credit models, the intersection of ADMT obligations and data broker/sharing rules creates a compliance surface that extends beyond the credit decisioning itself. A consumer who sends a GPC signal may be triggering opt-out rights for both the sale/sharing of their data and — starting January 1, 2027 — the use of ADMT in significant decisions about them.


The Cybersecurity Audit Requirement

Separate from ADMT-specific risk assessments, the CPPA regulations introduced a cybersecurity audit requirement phased by revenue:

  • Annual revenue over $100 million: Cybersecurity audit due April 1, 2028
  • Annual revenue $50-100 million: Audit due April 1, 2029
  • Annual revenue under $50 million: Audit due April 1, 2030

The cybersecurity audit must cover the security of personal information processed by the business and must be conducted by a qualified third party or qualified internal team. The audit findings must be documented and retained, and the CPPA can request them.

For financial institutions already conducting audits under GLBA Safeguards Rule requirements, the CPPA cybersecurity audit is additive — the Safeguards Rule framework doesn’t map directly to the CPPA audit requirements, and the CPPA is specifically focused on the personal information of California consumers rather than the broader institution-level security posture.


So What? The Practical Remediation Sequence

For financial institutions and fintechs with California consumer exposure, the action sequence:

Immediate (already overdue for new deployments):

  1. Inventory your ADMT. Every model, algorithm, and rules engine that makes or substantially informs a significant decision for a California consumer is covered. Include credit models, fraud scoring, marketing propensity models, and any HR screening tools for California applicants.

  2. Map your data categories against the GLBA exemption. For each ADMT deployment, identify whether the personal information processed is GLBA-covered. If the data touches marketing, behavioral analytics, employee data, or B2B contacts, the GLBA exemption doesn’t apply to that data.

  3. Start risk assessments for new ADMT. If you deployed a new model or algorithm after January 1, 2026, the risk assessment obligation is already active. Document the purpose, the data categories, the decision impact, and the safeguards.

By January 1, 2027 (opt-out rights go live):

  1. Build pre-use notice infrastructure. Pre-use notices need to be delivered in context — in the loan application flow, in the account opening process, wherever the ADMT runs on consumer data for significant decisions. This is a product requirement that needs to be scoped and built now.

  2. Design the opt-out and human review workflow. The 15-business-day compliance clock starts when the opt-out request arrives. If you’re offering human review as the alternative, the human review workflow needs to be scalable, well-documented, and consistent enough not to create its own fair lending exposure.

  3. Audit your GPC signal handling. California consumers who send GPC signals are legally opting out of sale and sharing today. Verify the technical implementation is detecting and honoring those signals, and that the confirmation mechanism works.

By December 31, 2027:

  1. Complete risk assessments for pre-existing ADMT. Every ADMT system already in production when the regulations took effect needs a completed risk assessment before the end of 2027.

The privacy program infrastructure that supports CPPA ADMT compliance — data inventory, vendor agreements, consumer request workflows, risk assessment documentation — is exactly what a structured data privacy compliance kit needs to capture. The risk assessments, in particular, require a repeatable template that maps to the CPPA’s requirements while integrating with existing model risk governance documentation.


External Resources

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is California's ADMT regulation and when does it take effect?
The CPPA finalized Automated Decisionmaking Technology (ADMT) regulations on July 24, 2025. The OAL approved them September 22-23, 2025, making them effective January 1, 2026. 'ADMT' means any technology that processes personal information and uses computation to replace or substantially replace human decision-making. Covered significant decisions include financial and lending services, housing, employment, education, and healthcare. Consumer opt-out rights for significant decisions take effect January 1, 2027.
Does the GLBA exemption protect banks and fintechs from California's ADMT rules?
Only partially. California's GLBA exemption under CCPA §1798.145(e) is DATA-LEVEL, not entity-level — which makes it narrower than the exemptions in Virginia, Texas, and Connecticut. It covers personal information collected and used in connection with financial products or services under Gramm-Leach-Bliley. It does not cover employee data (subject to full CPRA since January 1, 2023), marketing or website behavioral data, or B2B contact data (whose exemption sunset December 31, 2022). A bank that collects personal information for both GLBA-covered functions and non-GLBA marketing faces CPRA/ADMT obligations for the non-covered data.
What are the pre-use notice requirements under California's ADMT rules?
Before using ADMT to make a significant decision, businesses must provide a pre-use notice to the consumer explaining: what ADMT is being used, the purpose of the decision, how the system operates at a high level, the consumer's right to opt out or request appeal of a significant decision, and how to exercise those rights. The notice must be provided before the ADMT is used, not buried in a privacy policy.
What are the consumer opt-out mechanics under the ADMT regulations?
Consumers have the right to opt out of ADMT used for significant decisions affecting them. Businesses must cease ADMT use within 15 business days of an opt-out request for that consumer's data. An exception applies if a human reviewer can meaningfully review and overturn the automated decision — in that case, the business may offer the human review as an alternative to ceasing ADMT use entirely. The opt-out right for significant decisions takes effect January 1, 2027, giving businesses a year after the regulation's effective date to build the infrastructure.
When do risk assessments and cybersecurity audits need to be completed?
Risk assessments are required for new ADMT activities beginning January 1, 2026 (already in effect). Pre-existing ADMT activities must complete risk assessments by December 31, 2027. Completed risk assessments must be submitted to the CPPA by April 1, 2028. Cybersecurity audits are phased by revenue: businesses with annual revenues over $100 million must audit by April 1, 2028; $50-100 million by April 1, 2029; under $50 million by April 1, 2030.
What enforcement actions has the CPPA brought that financial institutions should know about?
The CPPA's enforcement posture is active and escalating. GM/OnStar settled for $12.75 million on May 8, 2026 — the largest CCPA penalty to date — after selling location and driving behavior data to insurance data aggregators LexisNexis and Verisk without adequate notice or consent. Tractor Supply settled for $1.35 million in September 2025 after a first-of-its-kind action targeting job applicant data practices. Disney/ABC settled for $2.75 million in February 2026 for fragmented opt-out systems that didn't propagate consumer choices across services. Honda paid $632,000 in March 2025 for asymmetric UI dark patterns — making opt-out significantly harder than opt-in.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Data Privacy Compliance Kit

Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.