California’s main privacy watchdog recently announced its very first compliance audit, and while the sector-wide review will focus on gig economy platforms, the implications extend to all employers across the state and offer an early indication of the agency’s enforcement priorities. The California Privacy Protection Agency (CalPrivacy) audit, announced on July 21, will examine whether rideshare, delivery, and task-based platforms are complying with the California Consumer Privacy Act’s (CCPA) requirements governing the rights of California residents and workers to access and control their personal information. What do you need to know about this landmark audit, and what should your business do as a result?
What the Audit Will Examine
The audit will assess whether gig economy platforms have implemented effective processes to enable California consumers and workers to exercise their CCPA rights, including the ability to understand what personal information is collected, how it is used, and with whom it is shared.
In particular, the audit is expected to assess whether the targeted businesses have effective processes to receive, verify, and respond to access requests from their workforce within the CCPA’s 45-day statutory deadline. This includes the ability to provide complete and accurate disclosures of personal information collected, used, and shared. The audit will also assess whether platforms give workers meaningful transparency into the personal information used in algorithmic or automated decisions that affect them, including decisions related to dispatch assignments, performance ratings, earnings, suspension, or deactivation.
In its announcement, CalPrivacy emphasized that this is the first in a planned series of sectoral audits, signaling that similar reviews across additional industries are likely.
Why Employers Should Pay Attention
Although the audit targets gig economy platforms, the issues it raises are relevant to every employer subject to the CCPA. California remains the only state with a comprehensive privacy law that extends consumer style privacy rights to employees, job applicants, and independent contractors. As a result, employers should ensure their privacy compliance programs adequately address workforce data and procedures for responding to requests from employees, applicants, and independent contractors.
In particular, employers should evaluate whether their privacy governance and data management practices support timely and complete responses to workforce privacy requests. Workforce information is often maintained across multiple internal systems and third-party vendors, requiring coordination among legal, privacy, human resources, information technology, and other business functions to identify, collect, and produce responsive data.
As part of that review, employers should confirm that they:
- Include workforce systems and third-party vendors in data inventories. Do you know where all data about your workforce is collected and retained? Have you mapped out your data assets to be able to find all data you have about an individual, or will you have to build this workflow on the fly after receiving your first CCPA request?
- Maintain documented procedures for receiving, processing, and responding to access requests from employees, job applicants, and independent contractors within the CCPA’s 45-day response. Do you have a standard operating procedure or manual outlining your consumer request workflow? Have you tested your consumer request workstream to ensure that it works properly and nothing falls through the cracks? What is your process for verifying consumer requests that the law allows you to verify?
- Clearly assign responsibility for coordinating workforce privacy requests across legal, privacy, human resources, information technology, and other relevant business functions. Who owns the process? If an employee submits a CCPA request through your toll-free number or a form on your website, where does that request get routed and who keeps track of it?
- Provide CCPA-compliant privacy notices to employees, job applicants, and independent contractors, and keep them current as workforce data practices evolve. Have you updated your employee privacy policy and your separate job applicant privacy policy in the last 12 months? Do you even have a privacy policy for job applicants? Where and how do you present a CCPA notice at collection to job applicants and employees?
These are only some of the questions you should be able to answer to be audit ready. Each of the above topics will involve potentially dozens of questions. This is not an exercise you would want to be doing for the first time after receiving an audit letter from CalPrivacy.
Usama Kahf is an attorney with Fisher Phillips in Irvine, Calif. Stephanie Alvarez Salgado is an attorney with Fisher Phillips in Los Angeles. © 2026 Fisher Phillips. All rights reserved. Reposted with permission.
Was this resource helpful?