CCPA LLM Requirements: Current Duties and the 2027 ADMT Deadline
CCPA duties attach to LLM deployments through ordinary collection, purpose, retention, contracting, consumer-rights, sensitive-information, and security rules. The CPPA risk-assessment regulations add current pre-launch work for specified processing, while the narrower ADMT consumer-rights rules reach significant decisions by January 1, 2027. This guide separates those obligations and their deadlines.

A California customer's complaint enters an LLM as a prompt and returns as a summary. Three copies remain: one in the application log, one in the provider record, one in an evaluation store. The CCPA analysis follows each copy. The model label changes the architecture and leaves the underlying privacy duties intact.
I would make the deployment owner draw that one request before approving a vendor. A data map that ends at the application box is already stale.
TL;DR
- Current CCPA duties cover collection notice; disclosed purposes; data minimization and retention; contracts; consumer rights; sensitive personal information; reasonable security.
- CPPA risk assessments are required before specified new processing begins, including sensitive-data processing and ADMT used for significant decisions.
- ADMT means computation replacing or substantially replacing human decisionmaking. Article 11 applies when it makes a significant decision in listed sectors.
- Continuing ADMT significant-decision uses must meet Article 11 by January 1, 2027. First risk-assessment submission information is due April 1, 2028.
- A routed HTTP control can enforce data and destination policy. Notice, contracts, rights, retention, legal analysis all stay with the business.
Existing CCPA duties apply to prompts and outputs now
The current Civil Code section 1798.100 requires a business controlling collection to tell consumers the categories of personal information collected and the purposes for collection or use. It also restricts additional collection and incompatible purposes without notice. Collection and use must be reasonably necessary and proportionate. Security procedures and practices must be reasonable and appropriate to the information.
Apply those duties to the full LLM flow. Inventory every copy: direct prompts, retrieved context, system-added fields, outputs about identifiable people, provider records, evaluation data, feedback. Name the purpose and retention rule for each copy. Give each recipient its CCPA role: business, service provider, contractor, third party. Describing every recipient as a vendor hides the distinction.
A general privacy-policy sentence about using technology says little about an employee sending a health complaint to a specific model endpoint. The deployment record should connect four things: the disclosed purpose, the approved data categories, the recipient contract, the production route.
Provider contracts and actual use must agree
A model provider acting as a service provider or contractor needs the CCPA contractual restrictions appropriate to that role. The business should verify the provider's permitted purposes, retention, training use, deletion, subprocessors, security commitments, support access. Procurement paperwork describes the approved arrangement. Runtime routing shows the arrangement the application actually used.
Dynamic routing deserves particular attention. One stable application URL can send requests to different providers or regions behind the scenes. Record the selected model endpoint and provider on each request. Compare production routes against the approved vendor register.
The CCPA compliance checklist covers the wider program. For LLM traffic, the central control is a destination rule tied to content classification and identity. A provider commitment against training reduces downstream use risk and still leaves the original disclosure, purpose, and consumer-rights obligations in scope.
Consumer rights need a retrieval path across every retained copy
Consumer requests reach prompt logs, response stores, evaluation datasets, application records. Access, deletion, correction, opt-out all land in the same places. Build a stable consumer reference that survives across those systems without exposing extra personal information to the model. Document where each request and response is retained. Note who controls it and how a rights request reaches it.
Deletion needs a tested path. Seed a synthetic consumer into an approved workflow. Locate every retained copy, execute the deletion, record the result. Where an exception supports retention, record the legal basis and access restrictions. Correction deserves the same treatment when an output about a person enters a downstream record.
A model output may create new personal information about a consumer, including an opinion or inference. Track that output with its source and model version. The CCPA audit-evidence guide describes the records that make a consumer-specific response defensible.
Sensitive personal information changes route policy
CCPA sensitive personal information reaches several distinct categories. They include defined account credentials and precise geolocation, plus racial or ethnic origin and specified beliefs. Union membership and message contents in specified circumstances also qualify. Genetic, biometric, health, sex-life, sexual-orientation information rounds out the categories most likely to appear in model traffic. The statute and regulations provide a right to limit certain uses and disclosures, with exceptions tied to specified purposes.
Classify the context window before transmission. A healthcare complaint may contain a diagnosis and account identifier in one paragraph. A support agent can paste it into an approved internal route or an unapproved public model using the same browser. The policy decision needs both the content class and destination.
The control should permit, redact, or refuse according to the approved purpose and role. Keep the policy version and outcome. Classification performed days later on a sample supports monitoring; classification at the request boundary supports enforcement.
Risk assessments are a current pre-launch duty
The CPPA's approved regulations took effect January 1, 2026. Section 7150 requires a risk assessment before specified processing begins. Triggers include sale or sharing, sensitive personal information, ADMT for a significant decision, specified profiling, personal information used to train defined technologies.
The assessment documents purpose, minimum data, operational elements, benefits, negative privacy impacts, safeguards, the business's decision about proceeding. Continuing activities that predate the regulations receive a December 31, 2027 assessment deadline. Material changes require an update as soon as feasibly possible and within 45 calendar days. Reviews occur at least every three years.
Our CCPA AI risk-assessment guide owns that workflow. The important LLM point is timing: a new sensitive-data assistant launched in September 2026 needs the assessment before launch, even if it falls outside the narrower ADMT rules.
ADMT applies to a defined decision use
The regulations define ADMT as technology processing personal information and using computation to replace or substantially replace human decisionmaking. A human reviewer counts only when that person understands the output and reviews relevant information. The reviewer also needs authority to make or change the decision.
Article 11 applies when the business uses ADMT to make a significant decision. The defined areas are financial or lending services, housing, education enrollment or opportunities, employment or independent contracting opportunities or compensation, healthcare services.
A summarizer can sit outside Article 11 while remaining subject to ordinary CCPA duties and a sensitive-data risk assessment. A model scoring loan applications can fall squarely inside. Scope by the downstream decision and actual human authority, rather than by model family.
For covered ADMT uses, Article 11 requires a pre-use notice, an opt-out subject to stated exceptions, access information, and qualifying appeal handling where the business relies on the human-appeal exception.
The deadline sequence for LLM deployers
Article 11 says a business using covered ADMT before January 1, 2027 must comply by that date. Uses beginning on or after January 1, 2027 must comply whenever the business uses ADMT for a significant decision.
Risk-assessment timing follows a separate sequence. New covered processing requires an assessment before initiation. Continuing pre-2026 processing receives the December 31, 2027 deadline. Summary submission information for assessments conducted in 2026 and 2027 is due to the CPPA by April 1, 2028. The Agency or Attorney General can request the reports themselves under the regulation.
Put these dates beside the release calendar. The visible artifact should be a launch gate containing the scope memo, assessment, notice version, opt-out or appeal design, rights retrieval test, approved routes, evidence owner. A calendar reminder without a release control tends to fire after the architecture is fixed.
DeepInspect
DeepInspect can enforce request-level rules on deliberately routed HTTP traffic between authenticated users or agents and LLM endpoints. It evaluates application-supplied identity and role, then checks content classification, destination, and model authorization against organizational policy before forwarding a prompt or returning a response.
The per-decision record can show which route and policy allowed or blocked a request. Collection purpose, consumer notice, contracts, rights fulfillment, human review, output correction, retention, deletion, CPPA submissions remain organizational responsibilities. Local model calls, browser traffic outside the route, and provider-side processing after delivery sit outside the proxy boundary.
Book a technical deep dive at deepinspect.ai.
Frequently asked questions
- Is every enterprise LLM an ADMT under the CPPA rules?
ADMT requires computation that replaces or substantially replaces human decisionmaking. Article 11 then narrows its coverage to ADMT making a significant decision in the listed areas. A general drafting assistant may sit outside that definition. It can still process personal information and trigger ordinary CCPA duties, plus a risk assessment when another section 7150 activity applies.
- Do enterprise provider terms settle CCPA compliance?
Provider terms support the role, use, security, retention, deletion analysis. The business still owns its collection purpose, notice, proportionality, consumer-rights process, sensitive-information handling, route approval, reasonable security. Production evidence should also show that requests used the contracted provider and configuration.
- Which deadline should a 2026 deployment use?
Run the section 7150 trigger screen before launch. Complete a required risk assessment before starting the processing. If the use is ADMT for a significant decision, prepare Article 11 controls for compliance by January 1, 2027. Include the assessment in the prescribed April 1, 2028 submission cycle. Legal should verify any use-specific exception and effective-date issue against the current regulation.