Feature Data Privacy
California's ADMT Rules Are Live: What Banks and Fintechs Get Wrong About the GLBA Exemption
The CPPA finalized ADMT regulations effective January 1, 2026 — and California's GLBA exemption is narrower than you think. Here's what financial institutions and fintechs actually need to do about automated decision-making, opt-out rights, and risk assessments.
Table of Contents
Most financial institutions looked at California’s GLBA exemption, concluded it covered their operations, and moved on. That analysis is incomplete — and the CPPA has been proving it wrong all year.
The California Privacy Protection Agency finalized its Automated Decisionmaking Technology regulations on July 24, 2025. The Office of Administrative Law approved them September 22-23, 2025. They took effect January 1, 2026. Six months in, here’s where financial institutions and fintechs are getting caught.
TL;DR
- California’s ADMT regulations took effect January 1, 2026 — ADMT means any technology that uses computation to replace or substantially replace human decision-making
- The GLBA exemption under CCPA §1798.145(e) is DATA-LEVEL, not entity-level: it covers information collected under GLBA, not everything a financial institution handles
- Employee data, marketing behavioral data, and B2B contact data are outside the GLBA exemption and fully subject to CPRA and ADMT obligations
- Consumer opt-out rights for significant decisions (including financial/lending) take effect January 1, 2027 — risk assessments for new ADMT activities are already required
- The CPPA’s $12.75M GM/OnStar settlement (May 2026), the largest CCPA penalty ever, involved data sharing with insurance data aggregators — a pattern that looks familiar to many bank-fintech data arrangements
What the ADMT Regulations Actually Cover
The CPPA defines “Automated Decisionmaking Technology” as “any technology that processes personal information and uses computation to replace or substantially replace human decision-making.” That definition is deliberately broad and deliberately includes machine learning models, scoring algorithms, and rules-based decision engines — not just generative AI.
Covered “significant decisions” include:
- Financial and lending services — approvals, denials, pricing, credit limit adjustments
- Housing — rental applications, property access decisions
- Employment — hiring, promotion, termination, scheduling
- Education — admissions, financial aid, academic standing
- Healthcare — treatment authorization, benefit coverage
If you’re a bank underwriting loans with a model, a fintech setting credit limits with an algorithm, or an insurance affiliate using scoring data — you’re using ADMT for significant decisions covered by the regulations.
The key dates:
| Requirement | Effective Date |
|---|---|
| Regulations effective | January 1, 2026 |
| Risk assessments (new ADMT) | January 1, 2026 |
| Consumer opt-out for significant decisions | January 1, 2027 |
| Risk assessments (pre-existing ADMT) | December 31, 2027 |
| Risk assessments submitted to CPPA | April 1, 2028 |
| Cybersecurity audits (>$100M revenue) | April 1, 2028 |
| Cybersecurity audits ($50-100M revenue) | April 1, 2029 |
| Cybersecurity audits (<$50M revenue) | April 1, 2030 |
If you started a new ADMT deployment after January 1, 2026, the risk assessment obligation is already active. You are behind.
The GLBA Exemption Problem
Here’s where financial institutions and their counsel frequently get the analysis wrong.
The CCPA’s GLBA exemption — codified at Civil Code §1798.145(e) — covers personal information collected and used pursuant to the Gramm-Leach-Bliley Act and the California Financial Information Privacy Act. When that exemption applies, CCPA and its ADMT overlay don’t.
The mistake is treating this as an entity-level exemption. It isn’t.
Compare:
- Virginia CDPA: Entity-level GLBA exemption — a financial institution subject to GLBA is exempt from the whole law
- Texas TDPSA: Entity-level GLBA exemption — same effect
- Connecticut CDPA: Entity-level GLBA exemption — same effect
- California CCPA/CPRA: Data-level exemption — only the specific personal information collected under GLBA activities is exempt
The practical difference is enormous. A bank that collects personal information for:
- Loan underwriting ✓ covered by GLBA exemption
- Employee HR data ✗ not GLBA-covered (fully subject to CPRA since January 1, 2023)
- Website behavioral analytics ✗ not GLBA-covered
- Marketing campaign targeting ✗ not GLBA-covered
- B2B contact data ✗ B2B exemption sunset December 31, 2022
A mid-sized bank almost certainly maintains CPRA obligations for significant portions of the personal information it processes. When those non-exempt data sets flow into ADMT systems — including ADMT used for purposes that also involve GLBA-covered data — the analysis gets complicated fast.
The GM/OnStar enforcement action illustrates the exposure clearly: the data at issue was driving behavior and location data that GM collected through its OnStar service. GM sold that data to LexisNexis and Verisk, which used it in insurance pricing models. The $12.75 million settlement announced May 8, 2026 — the largest CCPA penalty ever — involved data that arguably sat at the intersection of a connected vehicle service and the insurance products that subsequently priced risk based on it. “We’re a financial institution” wouldn’t have helped GM there, and it won’t help a fintech selling behavioral data to an insurance affiliate.
What the Regulations Require: Pre-Use Notices and Opt-Out Rights
For ADMT used to make significant decisions affecting California consumers, the regulations require:
Pre-Use Notices
Before using ADMT to make a significant decision, a business must provide the consumer a pre-use notice that includes:
- A description of what ADMT is being used
- The purpose of the decision being made
- A high-level explanation of how the system operates
- The consumer’s right to opt out of ADMT for that decision
- The consumer’s right to request an appeal or human review of the decision
- How to exercise each of those rights
The notice must be provided before the ADMT runs — not buried in a privacy policy the consumer may never read, not in a consent form that covers fifty other things. The “pre-use” framing means the consumer gets notice specific to the context where the ADMT is being applied.
For a lender using an AI credit model, this means the loan application workflow needs to surface that notice before the model runs on the applicant’s data. That’s a product design requirement, not just a legal footnote.
Opt-Out Rights (Effective January 1, 2027)
Starting January 1, 2027, California consumers have the right to opt out of ADMT used for significant decisions affecting them. When a consumer exercises that right:
- The business must cease ADMT use for that consumer’s case within 15 business days
- An exception applies if a human reviewer can meaningfully review and override the automated decision — in that case, the business may offer human review as an alternative to ceasing ADMT entirely
- The opt-out right is specific to the consumer — it’s not a blanket product shutdown, but it does require the infrastructure to identify and route individual cases outside the ADMT pipeline
That 15-business-day requirement is operationally meaningful. If your credit model makes 10,000 decisions per day and 2% of California applicants exercise the opt-out right, you need a human review queue and workflow that can handle that volume without creating disparate turnaround times that become their own fair lending problem.
The Enforcement Picture
The CPPA’s enforcement trajectory matters as much as the regulatory text. The agency has been active, the settlements have been large, and the patterns in enforcement actions are instructive for financial institutions.
GM/OnStar — $12.75 million (May 8, 2026): Largest CCPA penalty in the agency’s history. GM collected location and driving behavior data through OnStar and sold it to LexisNexis and Verisk — insurance data aggregators that used it in insurance pricing models — without adequate notice or consumer consent. The CPPA’s theory: consumers agreed to OnStar’s service for vehicle safety and assistance purposes; they didn’t consent to their driving data becoming inputs to insurance pricing algorithms. The data-sharing-to-insurance-aggregator pattern is common in financial services data arrangements.
Disney/ABC — $2.75 million (February 11, 2026): Fragmented opt-out systems that didn’t propagate consumer choices across services and affiliated entities. Disney had opt-out mechanisms, but exercising one didn’t stop data processing by affiliated properties. For financial holding companies with multiple regulated and non-regulated subsidiaries sharing consumer data, this settlement is directly on point.
Tractor Supply — $1.35 million (September 30, 2025): First CPPA action specifically targeting job applicant data. HR data — including applicant data from employment screening — falls outside the GLBA exemption and is fully subject to CPRA. Any company using ADMT in hiring (resume screening, interview analysis, skills assessments) for California applicants faces the ADMT overlay on top of existing CPRA obligations for that data.
Honda — $632,000 (March 12, 2025): Asymmetric UI dark patterns. Accept/agree buttons prominently displayed; reject/opt-out buttons several clicks and scrolls away, in smaller text. The CPPA has been explicit: opt-out mechanisms must be equally prominent and equally accessible as opt-in mechanisms. Any company designing a pre-use notice and opt-out flow for ADMT purposes should treat the Honda settlement as the design specification floor.
Risk Assessment Requirements
The ADMT regulations require a risk assessment before deploying new ADMT for covered purposes, and for pre-existing ADMT by December 31, 2027. The risk assessment must address:
- The purpose and context of the ADMT use
- The categories of personal information processed
- The significant decisions being made and their potential impact on consumers
- Safeguards implemented to address risks
- Whether the ADMT could result in disparate impact on protected classes
- The benefits of the ADMT use weighed against the risks
The assessments aren’t required to be public, but they must be completed and retained — and submitted to the CPPA by April 1, 2028. The CPPA can request them at any time during an investigation.
For financial institutions already conducting model risk management under SR 11-7 or OCC 2026-13, there is meaningful overlap with what a CPPA risk assessment requires. Model validation reports, pre-deployment fairness analyses, and model governance documentation can feed CPPA risk assessments — but the CPPA template isn’t the same as a model risk management package, and the consumer impact framing requires specific documentation most model governance programs don’t produce by default.
For the state-by-state comparison: Colorado has its own ADMT requirements under SB 26-189, with different thresholds and different definitions. California and Colorado are the two states with the most developed ADMT-specific regulatory frameworks, and they don’t align. Multistate compliance programs need both.
The DROP Platform and Data Broker Dimension
Financial services companies that sell or share consumer data — to affiliates, analytics vendors, data aggregators, or marketing platforms — have a related obligation that took effect January 1, 2026.
The CPPA launched the DELETE Request Opt-out Platform (DROP) at the start of 2026. DROP allows California consumers to submit a single deletion request to all registered data brokers simultaneously. Data brokers must process those requests and cannot sell or share the data after receipt.
Two changes make this more significant than the prior data broker regime:
-
Registration fees: California SB-361 (signed October 8, 2025) raised the data broker registration fee from $400 to $6,600 per year. That fee increase signals the CPPA’s intent to use registration as a meaningful compliance and accountability mechanism, not a nominal filing requirement.
-
GPC signal compliance: As of January 1, 2026, businesses must honor Global Privacy Control signals as legally binding opt-out requests for sale and sharing. The GPC obligation must be confirmed back to the consumer. Any financial services company operating a website with advertising or analytics partnerships needs the technical infrastructure to detect and honor GPC signals.
For companies feeding consumer data into AI credit models, the intersection of ADMT obligations and data broker/sharing rules creates a compliance surface that extends beyond the credit decisioning itself. A consumer who sends a GPC signal may be triggering opt-out rights for both the sale/sharing of their data and — starting January 1, 2027 — the use of ADMT in significant decisions about them.
The Cybersecurity Audit Requirement
Separate from ADMT-specific risk assessments, the CPPA regulations introduced a cybersecurity audit requirement phased by revenue:
- Annual revenue over $100 million: Cybersecurity audit due April 1, 2028
- Annual revenue $50-100 million: Audit due April 1, 2029
- Annual revenue under $50 million: Audit due April 1, 2030
The cybersecurity audit must cover the security of personal information processed by the business and must be conducted by a qualified third party or qualified internal team. The audit findings must be documented and retained, and the CPPA can request them.
For financial institutions already conducting audits under GLBA Safeguards Rule requirements, the CPPA cybersecurity audit is additive — the Safeguards Rule framework doesn’t map directly to the CPPA audit requirements, and the CPPA is specifically focused on the personal information of California consumers rather than the broader institution-level security posture.
So What? The Practical Remediation Sequence
For financial institutions and fintechs with California consumer exposure, the action sequence:
Immediate (already overdue for new deployments):
-
Inventory your ADMT. Every model, algorithm, and rules engine that makes or substantially informs a significant decision for a California consumer is covered. Include credit models, fraud scoring, marketing propensity models, and any HR screening tools for California applicants.
-
Map your data categories against the GLBA exemption. For each ADMT deployment, identify whether the personal information processed is GLBA-covered. If the data touches marketing, behavioral analytics, employee data, or B2B contacts, the GLBA exemption doesn’t apply to that data.
-
Start risk assessments for new ADMT. If you deployed a new model or algorithm after January 1, 2026, the risk assessment obligation is already active. Document the purpose, the data categories, the decision impact, and the safeguards.
By January 1, 2027 (opt-out rights go live):
-
Build pre-use notice infrastructure. Pre-use notices need to be delivered in context — in the loan application flow, in the account opening process, wherever the ADMT runs on consumer data for significant decisions. This is a product requirement that needs to be scoped and built now.
-
Design the opt-out and human review workflow. The 15-business-day compliance clock starts when the opt-out request arrives. If you’re offering human review as the alternative, the human review workflow needs to be scalable, well-documented, and consistent enough not to create its own fair lending exposure.
-
Audit your GPC signal handling. California consumers who send GPC signals are legally opting out of sale and sharing today. Verify the technical implementation is detecting and honoring those signals, and that the confirmation mechanism works.
By December 31, 2027:
- Complete risk assessments for pre-existing ADMT. Every ADMT system already in production when the regulations took effect needs a completed risk assessment before the end of 2027.
The privacy program infrastructure that supports CPPA ADMT compliance — data inventory, vendor agreements, consumer request workflows, risk assessment documentation — is exactly what a structured data privacy compliance kit needs to capture. The risk assessments, in particular, require a repeatable template that maps to the CPPA’s requirements while integrating with existing model risk governance documentation.
External Resources
- CPPA — ADMT and Risk Assessment Regulations (Final Text)
- Skadden — California Finalizes CPPA Regulations on ADMT, Risk Assessments, and Cybersecurity Audits
- White & Case — CPPA Finalizes Rules on ADMT, Risk Assessments and Cybersecurity Audit Requirements
- Capco — California’s New ADMT Rules: What Financial Institutions Need to Know
- Future of Privacy Forum — CCPA Regulations Issue Brief
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is California's ADMT regulation and when does it take effect?
Does the GLBA exemption protect banks and fintechs from California's ADMT rules?
What are the pre-use notice requirements under California's ADMT rules?
What are the consumer opt-out mechanics under the ADMT regulations?
When do risk assessments and cybersecurity audits need to be completed?
What enforcement actions has the CPPA brought that financial institutions should know about?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Keep reading
Related posts.
Data Privacy
Oregon's Privacy Law Has a Feature No Other State Has — and Financial Services Companies Are Probably in Scope
The Oregon Consumer Privacy Act's 30-day cure period ended January 1, 2026. The AG can now sue without notice. More importantly for financial services: the GLBA exemption is narrower than most assume, fintechs have significant exposure on non-NPI data, and Oregon requires something no other state does — a list of the specific named third parties that received consumer data.
Jul 17, 2026
Data Privacy
Connecticut's CTDPA Just Got a Lot Bigger — And Fintechs May Not Know They're Covered
Connecticut's CTDPA expanded on July 1, 2026 — lower thresholds, narrowed GLBA exemption, eliminated cure period, new profiling impact assessments. Here's what fintechs and nonbank lenders need to do now.
Jul 16, 2026
Data Privacy
NYDFS Part 500 in 2026: What 27 Consent Orders and $144M in Fines Tell You About Examiner Priorities
All Part 500 amended requirements are now in effect. NYDFS has 27 consent orders and $144M in fines under its belt. Here's what examiners are finding — and what to do before they show up at your door.
Jul 15, 2026