California Opens First Privacy Audit of Gig Platforms

Until now, California's privacy enforcement has worked one company at a time: a complaint comes in, the regulator investigates, a settlement lands. That changed on July 21, 2026. The California Privacy Protection Agency (CalPrivacy) opened its first sectoral audit, and instead of a single business it's looking at an entire industry at once. If your company handles consumer data, the shift matters more than the target does.

What Happened

CalPrivacy's Audits Division announced it is auditing gig economy platforms operating in California: the app-based transportation, delivery, and task services that route work through millions of independent contractors. The agency cites its authority under California Civil Code section 1798.199.40 to examine business practices directly, no complaint or settlement required.

The subject this time isn't opt-outs or the GPC signal, the ground most 2026 enforcement has covered. It's the right to access. Gig apps pull in an unusually rich stream of personal data from drivers and users alike: precise geolocation, behavioral and performance metrics, biometric identifiers, financial records, and communications logs. The audit asks a blunt question about all of it. When someone requests that data, do they actually get it, completely, and inside the 45-day window the law requires?

"Core to California's privacy rights is ensuring people have the power to access and understand the information that a company collects about them," said Chief Privacy Auditor Sabrina Ross. Executive Director Tom Kemp tied the choice of industry back to the public: the audit "is responsive to hundreds of consumer complaints and also comments received during public rulemaking." CalPrivacy says more sectoral audits will follow, and it plans to publish trend reporting on what it finds.

Why This Reaches Beyond Rideshare Apps

The right to know is the CCPA obligation businesses treat as an afterthought. Most compliance budgets go to the cookie banner and the "Do Not Sell" link, because those are what regulators fined companies over first. Access requests get a webform and a hope that few people use it.

A sector audit rewrites that math. CalPrivacy isn't waiting for your customers to complain; it can now pick a vertical and test every major player in it. Gig platforms are the opening move, not the whole game. Any business that collects a lot of personal data and processes access requests slowly, or returns partial results, sits in the same line of fire. The practical bar is specific: a complete response, covering every category of data you hold, delivered within 45 days. If your intake form works but the data assembled behind it skips your ad-tech vendors or your analytics warehouse, that's the gap this audit is built to find.

How Privisy Helps

An access-request backend is something Privisy can't reach from the outside; that part is on your data team. What Privisy does test is the front door regulators check first, and the disclosures that have to match reality behind it.

CalPrivacy has signaled the direction plainly: whole industries, audited proactively, with the results made public. See the CCPA enforcement actions tracker for the full record of California privacy actions to date.

Know What Your Site Actually Discloses

Before a regulator maps your data flows, map them yourself. Privisy scans your site for the tracker and disclosure gaps that make access requests impossible to answer completely.

Run a Free Scan