On July 21, 2026, the California Privacy Protection Agency, now publicly branded CalPrivacy, announced that its Audits Division had opened its first formal sectoral audit under the CCPA. The target is gig economy platforms operating in California, meaning app-based transportation, delivery, and task services, and the review centers on one specific question: whether these platforms are actually honoring consumers' and workers' right to access their own personal information.
This is not an enforcement action and no fine has been announced. It is the first time CalPrivacy has used its audit authority to examine an entire sector at once, rather than responding to a single complaint or investigating a single company. The agency says it plans a series of these sectoral audits, with gig platforms simply first in line.

Source: California Privacy Protection Agency, Newsroom, captured August 4, 2026.
What the audit actually looks at
CalPrivacy's announcement is specific about scope. Gig platforms collect precise geolocation data, behavioral and performance metrics, biometric identification data, financial information, and communications records from both riders and the independent contractor workers who power the service. Algorithmic systems then use that data to make consequential decisions, including dispatch assignments, performance ratings, earnings calculations, and account suspension or deactivation.
The audit is examining whether platforms are processing access requests within the 45-day statutory window the CCPA requires, whether the responses they send back are actually complete, and whether the platforms have built systems that let a worker or consumer meaningfully exercise the right in the first place, not just technically accept a request. Sabrina Ross, CalPrivacy's Chief Privacy Auditor, put the stakes in plain terms in the announcement: "You cannot contest a decision made by an algorithm without the underlying data."
The Audits Division carries out this work under California Civil Code section 1798.199.40, which directs the agency to audit businesses for CCPA compliance. According to Executive Director Tom Kemp, this particular audit is a response to a pattern the agency was already seeing: "hundreds of consumer complaints" plus input gathered during public rulemaking, not a single triggering incident.
Why gig platforms specifically
California's privacy law does something most state privacy laws do not: it extends CCPA rights to employees, job applicants, and independent contractors, not just to consumers in the traditional retail sense. That is a meaningful distinction for gig platforms, where the bulk of the people whose data is collected are the drivers and couriers performing the work rather than the riders ordering it.
The Audits Division itself is new. CalPrivacy stood it up in February 2026, led by Ross, a former Meta director of public policy, and the state's June 2026 budget added $3.1 million in dedicated funding to support its work. Picking gig platforms as the first sector to audit is a deliberate signal about where the agency sees the sharpest gap between a legal right on paper and a right a person can actually use, since a worker whose account gets deactivated by an algorithm has little recourse without knowing what data drove that outcome.
Figure: The CCPA's initial 45-day statutory window to answer an access request, out of the 90-day maximum available if a business claims one extension. This is the exact clock CalPrivacy's audit is measuring gig platforms against.
Audit versus enforcement: what's different this time
| Complaint-driven enforcement | Sectoral audit | |
|---|---|---|
| Trigger | An individual complaint or referral | The agency's own initiative, informed by complaint patterns |
| Scope | One business at a time | An entire sector's practices at once |
| Immediate outcome | Investigation, possible fine or settlement | Findings, requested remediations, sector trend reporting |
| Publicity | Case-by-case, often after resolution | CalPrivacy has signaled it will publish sector-level findings |
| What it means for a business outside the sector | Little direct signal | A preview of what the agency will likely look for next in your sector |
The practical difference is that a sectoral audit is not really about punishing the specific platforms under review, at least not in this first phase. CalPrivacy has said audit findings can lead to enforcement referrals "in appropriate circumstances," but the stated purpose here is broader: identify where practices are weak across a whole category of business, agree on fixes with the companies involved, and publish trend reporting that puts every other business on notice about what "compliant" actually looks like in practice.
That last part is what should get the attention of any business outside the gig economy too. If access-request handling is where the agency chose to start, it is a reasonable bet that access rights are where CalPrivacy expects to keep looking, sector by sector, going forward.
What this means for your privacy policy
If your business handles access requests today, the practical question this audit raises is not whether your privacy policy says you'll honor the right of access. Nearly every policy does. It is whether your actual process can produce a complete, accurate response inside 45 days, and whether that process would hold up if a regulator asked to see it working, not just described on paper.
That means your privacy policy needs to say, specifically, what categories of personal information you collect, including anything used to make automated decisions about a person's account, standing, or eligibility, not a generic "we collect information you provide" line. It also means the request-handling process behind that policy has to actually exist: a way for someone to submit a request, a way to verify their identity, and a way to compile a complete answer within the statutory window, not just a promise.
Our Privacy Policy Generator builds California-specific access-right disclosures into your policy, so what you tell consumers and workers about their right to know matches what your business can actually deliver if that request comes in. Getting the wording right is the part fully within your control, regardless of which sector CalPrivacy decides to look at next.
The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.