RatedWithAI

RatedWithAI

Accessibility scanner

Privacy LawJuly 24, 2026

CCPA and AI Lending 2026: Compliance Guide for Fintech Underwriting

Most AI-lending compliance conversations jump straight to fair-lending law — ECOA, disparate impact, adverse-action letters. That's necessary but incomplete. California's CCPA layers a separate, data-rights-based obligation on top: pre-use notice, an opt-out right, and disclosure of exactly what personal and alternative data your model touches.

Significant Decision
AI lending qualifies for CCPA's ADMT opt-out rules
$7,500
Max CCPA fine per intentional violation
Open Banking
Alternative-data feeds expand disclosure scope

Lending Is a "Significant Decision" Under CCPA's ADMT Rules

California's automated decision-making technology regulations single out decisions with legal or similarly significant effects — access to credit is one of the named examples, alongside employment, housing, and healthcare. If a fintech uses AI to approve, decline, price, or set terms on a loan, credit line, or BNPL offer without meaningful human review, that decision falls inside the ADMT framework, not just general CCPA data-handling rules.

The practical effect: consumers must receive pre-use notice explaining that an automated system will be used, what it evaluates, and how to opt out or request human review — before the decision is made, not buried in a privacy policy after the fact.

What Lenders Must Provide Consumers

Pre-Use Notice Must Cover
  • That an automated system will evaluate the application
  • The logic categories the model relies on (income, alt-data, etc.)
  • How to opt out or request a human-reviewed alternative
  • How to access more information about the decision
Consumer Rights That Apply
  • Right to opt out of the automated decision path
  • Right to access categories of personal information used
  • Right to correct inaccurate financial data feeding the model
  • Right to request deletion (subject to legal retention rules)

Alternative Data Raises the Disclosure Bar

Traditional credit-bureau scoring pulls from a handful of well-understood data categories. AI underwriting built on alternative data — bank-transaction history via open banking, cash-flow patterns, gig-income streams, even device or behavioral signals — ingests far more granular personal information. CCPA requires businesses to identify categories of personal information collected and disclose them, which means lenders using alt-data models need a data map that's accurate down to each source their scoring pipeline touches.

This is also where sensitive personal information rules can attach — bank account and transaction data qualifies, and consumers have a right to limit its use for purposes beyond what's necessary to provide the credit product they requested.

The Human-Review Exception — and Its Limits

Businesses that provide a meaningful, timely human-review path for a significant decision can narrow the opt-out obligation, but the review has to be real: a human with authority to override the AI output, not a rubber stamp. Lenders that route "opted-out" applicants back through the same automated model under a different label are not meeting this bar, and regulators have signaled they'll scrutinize sham human-review processes closely.

Compliance Checklist

Data and Model Inventory

  • Map every data source feeding the underwriting model
  • Flag alternative-data feeds (open banking, cash flow, gig income)
  • Classify which fields qualify as sensitive personal information
  • Document the model's role in approve/decline/pricing decisions

Consumer-Facing Requirements

  • Publish pre-use notice before AI evaluates an application
  • Build a functional opt-out that routes to real human review
  • Enable access and correction requests for underwriting data
  • Train support staff to handle ADMT-related consumer requests

Frequently Asked Questions

We're already ECOA/Reg B compliant with adverse-action letters. Does that cover CCPA too?

No — they're separate obligations that happen to overlap on documentation. ECOA governs fair-lending and requires specific denial reasons; CCPA's ADMT rules require pre-use notice and an opt-out mechanism before the decision, plus broader data-category disclosure. You need both, though the underlying documentation (what the model evaluates, why) can largely be shared.

Does a B2B lending platform serving only businesses need to worry about CCPA?

CCPA protects natural persons' personal information. Pure business-entity lending is generally outside scope, but sole proprietors, personal guarantors, and any individual whose personal financial data feeds the decision bring you back into CCPA territory.

What counts as a 'meaningful' human review for the opt-out exception?

A reviewer with real authority to override the AI's recommendation, access to the same or better information than the model used, and a genuine decision-making role — not someone who simply confirms the AI's output. Documentation of actual overrides occurring is strong evidence the review is real.

Do we need to disclose our underwriting model's exact scoring formula?

No. CCPA requires disclosure of the categories of personal information and logic involved, not proprietary model weights or a full technical specification. The bar is meaningful transparency about what's evaluated, not a reverse-engineerable formula.

Privacy Compliance Doesn't Replace Fair-Lending Compliance

CCPA's ADMT rules and fair-lending law solve different problems — one is about consumer control over data and automated decisions, the other is about discriminatory outcomes. Fintechs need to run both compliance tracks in parallel, not treat one as a substitute for the other.

Start with a data map of your underwriting pipeline, then build the pre-use notice and a genuinely functional opt-out. That foundation makes every other AI-lending compliance requirement easier to layer on top.