CalPrivacy opens first CCPA sectoral audit of gig platforms
On July 21, 2026, the California Privacy Protection Agency (CalPrivacy) announced that its Audits Division has begun the agency’s first formal privacy audit. The first sectoral review targets gig economy platforms operating in California, including app-based transportation, delivery, and task services.
CalPrivacy framed the work as the first in a planned series of sectoral audits under its CCPA audit authority (California Civil Code section 1798.199.40).
What the audit looks at
The focus is practical compliance with the right to know / access, for both consumers and workers (employees, applicants, and independent contractors covered by the CCPA). CalPrivacy says it will examine whether platforms:
- Honor access requests within the 45-day statutory window
- Provide complete responses about what personal information was collected, why it is used, and with whom it is shared
- Maintain systems that let people exercise those rights in a meaningful way
The agency highlighted the volume and sensitivity of data these platforms hold, including precise geolocation, performance metrics, biometric data, financial information, and communications records, often feeding algorithmic decisions about assignments, ratings, earnings, and account status.
Audit findings may lead to remediation agreements and public sector trend reporting. They can also feed enforcement referrals when appropriate. Existing CCPA duties for other businesses are unchanged; this announcement is about how CalPrivacy will use its audit program, not a rewrite of the statute.
What to do now
- If you operate a California-facing consumer or worker data program, test your access-request intake end to end: identity verification, 45-day clock, completeness, and service-provider coordination.
- Treat employee and contractor request handling with the same rigor as consumer requests. Gig and workforce data is clearly in scope for this audit wave.
- Document how automated decisioning uses personal information, because access responses often fail when those uses are incomplete or vague.
- See the CCPA / CPRA page for how agency audits differ from the cybersecurity audits due from 2028, and follow CCPA on this site for later sectoral audits and any public findings report.