California has enacted SB 947, the No Robo Bosses Act. It adds new Labor Code requirements for employers that use automated decision systems (ADS) to make disciplinary and termination decisions, and it takes effect July 1, 2027. Importantly, the No Robo Bosses Act makes clear that the California Consumer Privacy Act (CCPA) also must be taken into account when certain automated decisionmaking technologies are used.
So, when applying this new law, organizations should consider not only this new law and their use of employee monitoring, performance management platforms and technologies which have entered the market over the last several years, but also the application of other regulatory and contractual obligations they may have, in particular the CCPA and similar privacy and data security laws.
Are monitoring platforms “automated decision systems”?
SB 947 defines an ADS as any computational process derived from machine learning, statistical modeling, data analytics, or AI that produces a simplified output, such as a score, classification, or recommendation, which is used to assist or replace human decisionmaking and materially impacts natural persons. The law carves out spam filters, firewalls, antivirus software, calculators, and databases.
“assist or replace human discretionary decisionmaking”
Many monitoring platforms turn keystrokes, application use, idle time, and website activity into productivity scores, risk ratings, or “low performer” flags. Those outputs arguably fit the definition above. A supervisor who disciplines an employee because a dashboard rated the employee 42% productive, or flagged the employee as an insider risk, might be considered to be using an ADS under SB 947. And, it is not necessary that the ADS make, substantially make, or replace human discretionary decisionmaking. Assisting such decisionmaking is enough. One point of note: The carve-out for firewalls and antivirus software may not apply to the insider risk and data loss prevention modules many organizations have added in recent years. The latter tools may assign risk scores based on file downloads, USB activity, or after-hours access. If a security analyst sends a high-risk score to employment decision-makers and the employee is subsequently disciplined or terminated, that insider risk or DLP tool may qualify as an ADS, even though IT, not HR, purchased and configured it.
What the law requires
- No sole reliance. An employer may not rely solely on an ADS to make a disciplinary or termination decision.
- Human corroboration when reliance is primary. If an employer primarily relies on ADS output to make a disciplinary or termination decision, a human must review and corroborate the decision. The reviewer may use the data behind the output or other relevant information, such as manager evaluations, personnel records, work product, peer reviews, and witness interviews. If the output can’t be corroborated, or the reviewer finds it inaccurate, incomplete, or misleading, the employer may not use it.
- Post-use notice. When delivering a decision described in the bullet above, the employer must give the employee a separate, plain-language written notice. The notice must explain the employer’s reliance on the ADS, confirm human review, give a contact person, describe the employee’s data rights, and state that retaliation is prohibited.
- Prohibited uses. Employers may not use an ADS to infer an employee’s FEHA-protected status, or to predict and take adverse action against a worker for exercising legal rights.
For more information about the nuts and bolts of the law, check out our related post, here.
So, whether deploying a performance management platform, a dashcam, a surveillance technology, or some other technology constituting an ADS, organizations should assess the intended use cases along with the corresponding compliance obligations under applicable laws.
A fleet telematics system that scores drivers on hard braking and speeding, a video analytics tool that flags safety violations on a production floor, and a badge-data dashboard that ranks in-office attendance can each produce outputs that end up in a disciplinary file. The practical question for compliance teams is not just what a tool collects, but who sees its outputs, what decisions those outputs inform, and whether that use was disclosed when the decision was delivered.
The information request right and the CCPA
SB 947 gives employees the right to request, and requires employers to provide, “a meaningful, objective description of the employee’s own data used by the ADS” when the employer primarily used an ADS to discipline or terminate. To illustrate, if an employee was terminated after a platform ranked the employee in the bottom 5% of the team, a meaningful, objective description might identify the categories of data the tool used (for example, application activity, keystroke counts, and idle time), the period covered, and how those inputs contributed to the score.
It is likely such a request will rarely stand alone. As noted above, the No Robo Bosses Act provides:
An employer that is a business subject to the [CCPA] is subject to any privacy-related automated decisionmaking technology regulation duly adopted by the California Privacy Protection Agency.
Our earlier CCPA ADMT post covers the application of the CCPA and ADMT requirements. In short, the California Privacy Protection Agency’s ADMT regulations apply to “significant decisions,” including employment decisions. Businesses using ADMT for significant decisions must comply by January 1, 2027. They must give pre-use notices, offer opt-outs (subject to exceptions), and answer access requests with meaningful information about the logic and likely outcomes of the technology. Employees also retain their general CCPA right to know.
In practice, a disciplined or terminated employee, or the employee’s lawyer, potentially can pair an SB 947 request with a CCPA right to know request and an ADMT access request. Here is how this might play out: A sales representative is terminated after an engagement-scoring tool flags declining activity. The post-use notice states that a manager reviewed the decision and corroborated it with CRM records. Two weeks later, the employee’s attorney sends a letter requesting the SB 947 data description, the employee’s personal information under the CCPA, and information about the logic of the ADMT. If the CCPA response shows the platform had already purged the underlying activity logs, or the CRM records cited in the notice don’t reflect the decline, the employer’s own responses may undercut its stated reason for the termination.
Together, these access right requests could require the production of a significant amount of information concerning the use of the ADS and the employee’s associated activity. Accordingly, employers that are covered businesses under the CCPA should be considering their approach to these kinds of requests, bearing in mind that the CCPA bars retaliation against employees for exercising privacy rights.
Steps employers should take now
- Inventory the tools. Identify every monitoring or performance platform or other ADS technology that produces scores, flags, or recommendations, and map where those outputs feed into discipline or termination. Include tools owned by IT and security, such as insider risk and DLP platforms, not just HR systems.
- Configure for human judgment. Turn off automated discipline triggers, such as settings that auto-generate written warnings or performance improvement plans when a score falls below a threshold. Treat dashboard outputs as leads to investigate, not conclusions.
- Document corroboration. Build a review checklist that records the independent evidence supporting each decision and any reason an output was rejected. At a minimum, the checklist should capture who reviewed the output, what underlying data and other information they examined, whether the employee had a chance to explain, and the date of the review.
- Prepare notices and response workflows. Draft SB 947 post-use notices and data-description templates, and update CCPA notices at collection and ADMT pre-use notices.
- Coordinate the responses. Route SB 947, CCPA access, and ADMT access requests through a single team so the answers are timely, consistent and compliant.
- Review vendor contracts. Require vendors to explain how their scoring works, support data export, and help with access requests.
- Audit for protected-status and retaliation risk. Make sure no tool infers protected characteristics or flags protected activity. Test whether scores systematically decline for employees on leave, working with accommodations, or who recently raised complaints.
- Complete CCPA risk assessments for ADMT used in significant decisions.
- Train managers on the difference between “solely” and “primarily” relying on a tool, using realistic scenarios, such as what to do when a dashboard flags an employee who recently returned from medical leave.
Employers that build these processes before mid-2027 will be in a much stronger position to defend monitoring-driven decisions.

