FEHA ADS vs CCPA ADMT: what is the difference?

Both are California. Both cover automated decisions about people. They come from different agencies, they were written for different reasons, and they are not interchangeable. Treat them as one requirement and you will meet one duty and miss the other.

Two agencies, not one

California: jurisdiction and source status

Jurisdiction
California (statewide) — two separate regimes
FEHA automated-decision systems
California Civil Rights Department, Civil Rights Council. In force October 1, 2025. Applies to employers with five or more employees in California.
CCPA automated decisionmaking technology
California Privacy Protection Agency. Regulations effective January 1, 2026; pre-use notice compliance deadline January 1, 2027.
Relationship
Independent. Neither regime treats compliance with the other as satisfying it.
Last reviewed
August 26, 2026

No single agency owns California's position on AI in employment. The Civil Rights Department's Civil Rights Council writes the FEHA regulations. The California Privacy Protection Agency writes the CCPA regulations. They were finalized months apart, they use different words for overlapping technology, and each is enforced on its own terms.

That is why the acronyms differ. The Civil Rights Council says automated-decision system, ADS. The CPPA says automated decisionmaking technology, ADMT. The words are close enough that people assume they are the same defined term. They are not.

FEHA ADS and CCPA ADMT compared. Reviewed August 26, 2026.
FEHA ADSCCPA ADMT
Written byCivil Rights CouncilCalifornia Privacy Protection Agency
Rooted inAnti-discrimination lawPrivacy law
In forceOctober 1, 2025Regulations effective January 1, 2026
Deadline aheadNoneJanuary 1, 2027 for pre-use notice
Main obligationDo not discriminate through an ADS; retain ADS data for at least four yearsGive a pre-use notice; support access and opt-out rights
ThresholdEmployers with five or more employees in CaliforniaBusinesses using ADMT for a significant decision
SourceCalifornia Civil Rights Council rulemaking actionsCalifornia Privacy Protection Agency CCPA regulations page

What each one is actually for

The FEHA regulations are an anti-discrimination instrument. Their concern is outcome: whether an automated system produces a result that disadvantages people on a protected characteristic, directly or by disparate impact. The recordkeeping duty follows from that: the four-year retention of automated-decision data, including machine-learning data and selection criteria, exists so the outcome can be examined after the fact.

The CCPA ADMT regulations are a transparency and control instrument. Their concern is whether the person knew, and whether the person had a say. Hence a notice given before the technology is used, stating the specific purpose, and telling the individual how to exercise their rights, including access and opt-out.

One asks whether the decision was fair. The other asks whether the person was told and given a choice. You can satisfy either one and still be exposed on the other.

Where the dates diverge

The FEHA rules have been in force since October 1, 2025. There is no runway left on that one.

The CCPA regulations took effect January 1, 2026 after the Office of Administrative Law approved the package on September 22, 2025. For ADMT specifically, a business already using the technology for a significant decision before January 1, 2027 must be in compliance by that date, and anything deployed on or after it must comply before first use. That is a deadline and a rule about new deployments at the same time — the second half is the one that catches teams who plan only around the date.

What operations has to do differently

These two regimes land on different parts of a hiring workflow, which is why treating them as one requirement fails in practice.

  • The FEHA side is a retention problem. The records have to exist, stay attached to the candidate and the tool, and survive four years, which is longer than many ATS retention schedules and longer than most vendor relationships.
  • The CCPA ADMT side is a sequencing problem. The notice has to go out before the technology runs. A notice sent afterwards does not become a pre-use notice, however well it is written.

Better notice language fixes neither. Putting the notice step and the record step inside the workflow does, because then both happen whether or not anyone remembers.

Common questions

Is FEHA ADS the same thing as CCPA ADMT?

No. They are separate California regimes. FEHA automated-decision system rules come from the Civil Rights Council and took effect October 1, 2025; they are anti-discrimination and recordkeeping rules. CCPA ADMT rules come from the California Privacy Protection Agency and carry a January 1, 2027 pre-use notice compliance deadline; they are privacy and transparency rules.

If I comply with one, am I covered for the other?

No. Different agencies enforce them, the duties are different in kind, and neither regulation treats the other as satisfying it. Whether both reach a specific workflow is a question for your counsel.

Is California's law the same as NYC Local Law 144?

No. Local Law 144 is a New York City ordinance covering automated employment decision tools, requiring at least ten business days notice and a published independent bias audit summary. Neither California regime contains a published bias audit requirement of that kind.

Notice Tracking keeps approved templates, delivery events and exports connected to the candidate record.

See pricing Review Your Notice Workflow

This page is general information about published government requirements, last reviewed August 26, 2026. Requirements change; confirm the current text with the agency and your own counsel before relying on it.