CalPrivacy Launches Its First Formal Privacy Audit Against Gig Economy Platforms

Table of Contents

We broke the news the other day about CalPrivacy ramping up audits for specific industries. The California Privacy Protection Agency has opened its first formal sector-wide privacy audit, placing gig economy platforms under examination for how they collect, use and disclose the personal information of workers and consumers.

The audit represents an important change in California privacy enforcement.

Rather than waiting for a public enforcement case after alleged violations have occurred, CalPrivacy’s newly formed Audits Division is proactively examining whether major transportation, delivery and task-based platforms can demonstrate that California Consumer Privacy Act rights actually work in practice.

The agency is focusing initially on the right of access: whether workers and consumers can obtain a complete and understandable account of the personal information collected about them, how that information is used and the parties with which it is shared.

For a gig worker, that information may determine much more than whether a company has an email address or telephone number on file.

It may reveal the data behind work assignments, performance ratings, earnings calculations, fraud flags, account suspensions and permanent deactivation decisions.

The Audit Targets Data That Can Affect a Worker’s Livelihood

Gig platforms can collect extensive information from both customers and the independent contractors who provide services through their applications.

CalPrivacy identified several categories that may be included within the audit:

  • Precise geolocation information
  • Behavioral and performance data
  • Biometric identification information
  • Financial and payment information
  • Communications records
  • Dispatch and assignment information
  • Ratings and account-status information

These categories may be collected from different systems and used for different purposes.

A platform may use location data to match a worker with a delivery, behavioral information to evaluate performance, identity information to prevent account sharing and financial information to calculate or distribute payments.

Algorithmic systems may then combine those data points to make decisions about which jobs a worker receives, how frequently work is offered, whether particular activity appears suspicious and whether an account should remain active.

That is why CalPrivacy is treating access as more than an administrative privacy right.

A worker who does not know what information was used to make a decision may have little ability to identify an error, dispute an allegation or challenge an automated conclusion.

The agency’s position is that meaningful access to the underlying information may be necessary before a worker can effectively exercise correction, deletion or other privacy rights.

Gig Workers Are Covered by California Privacy Rights

Some businesses continue to associate the CCPA primarily with customers, website visitors and online advertising.

That interpretation is outdated.

California’s temporary exemptions for employment-related and business-to-business personal information expired on Dec. 31, 2022. Since Jan. 1, 2023, covered businesses have generally been required to account for the CCPA rights of employees, job applicants and independent contractors.

That includes workers who use a platform to provide transportation, delivery or task-based services.

Covered businesses must therefore be prepared to identify and produce personal information maintained across both customer-facing and workforce systems.

A gig platform cannot necessarily satisfy a worker’s access request by providing only basic account information from a customer relationship management system.

The relevant information may also exist in:

  • Driver or contractor applications
  • Location and route records
  • Identity verification systems
  • Fraud prevention tools
  • Payment platforms
  • Customer complaint databases
  • Internal support tickets
  • Ratings systems
  • Algorithmic risk scores
  • Account suspension records
  • Third-party service providers

The operational challenge is finding, verifying and assembling that information into a legally sufficient response.

CalPrivacy Will Examine Whether Access Requests Work in Practice

The audit is expected to examine more than whether a platform has placed a privacy request form on its website.

CalPrivacy said it will evaluate whether requests are honored within the CCPA’s 45-day response period, whether the information provided is complete and whether the platform has implemented systems that allow workers to exercise their rights effectively.

That distinction matters.

A privacy request process may appear compliant from the outside while failing once a request enters the company’s internal systems.

Potential weaknesses include:

  • Request forms that are difficult for workers to locate
  • Systems designed only for customer data
  • Identity verification procedures that unnecessarily block legitimate requests
  • Incomplete searches across internal databases
  • Failure to retrieve information from service providers
  • Responses that omit inferences, scores or performance records
  • Inconsistent treatment of employees and independent contractors
  • Inability to explain the purposes for which information was used
  • Failure to identify categories of third parties receiving the information
  • Delayed responses without proper extension notices

A company may believe that it has completed a request because its privacy team exported information from one system. An auditor may reach a different conclusion after comparing that response with the company’s data map, vendor records and actual platform architecture.

The Audit Connects Privacy Rights to Algorithmic Accountability

CalPrivacy’s announcement does not frame the audit solely as a data inventory exercise.

It connects access rights to algorithmic decision-making.

Gig platforms commonly rely on automated systems to manage large workforces and high volumes of real-time transactions. Those systems can influence dispatch assignments, route selection, performance ratings, compensation, fraud detection and account status.

When those decisions are based on personal information, the quality and accessibility of the underlying data become material.

An inaccurate location record, mistaken identity flag, disputed customer complaint or incorrectly attributed cancellation could affect how a worker is evaluated.

Where the result is reduced assignments, withheld earnings or deactivation, the privacy request process may become one of the only mechanisms available to identify the source of the decision.

This creates an overlap between privacy compliance and AI governance.

Organizations using automated systems should be able to identify:

  • What personal information enters the system
  • Where the information originated
  • Whether the information is accurate
  • What inferences or scores are generated
  • How those outputs are used
  • Which decisions can affect a person
  • Whether a person can challenge an incorrect result
  • Who is responsible for reviewing disputed outcomes

A DSAR process that cannot reach the data used by an automated decision system may be inadequate even when the company responds on time.

This Is Different From California’s Mandatory Cybersecurity Audits

Businesses should not confuse this sectoral audit with California’s separate cybersecurity audit requirements.

California has adopted regulations requiring certain businesses whose processing presents significant cybersecurity risk to conduct recurring cybersecurity audits. Those requirements follow their own scope, thresholds, deadlines and reporting procedures.

The gig platform initiative is different.

This is an audit conducted by CalPrivacy under the agency’s statutory authority to examine business compliance with the CCPA.

Its initial emphasis is the practical operation of privacy rights, particularly access requests involving workers and consumers.

A company could therefore face several different forms of review:

  • An internal privacy compliance assessment
  • A mandatory cybersecurity audit under California regulations
  • A risk assessment covering qualifying processing activities
  • A sectoral audit initiated by CalPrivacy
  • An enforcement investigation arising from a complaint or suspected violation

These processes may overlap, but they are not interchangeable.

The Audit Does Not Yet Establish That Any Platform Violated the CCPA

CalPrivacy has not publicly named the platforms selected for examination.

The announcement also does not represent a finding that a particular company violated California law.

The agency described sectoral audits as a way to identify risks and vulnerabilities, recognize stronger practices, reach agreement on remediation and eventually publish broader findings about industry trends.

That makes the audit both supervisory and investigative.

Participating companies may have an opportunity to correct deficiencies before they become the subject of a public enforcement action. At the same time, an inability to produce records, explain data practices or demonstrate compliant request handling could create additional regulatory risk.

Businesses should not assume that an audit is informal merely because it begins as a proactive review.

California law gives the agency authority to examine compliance and obtain records relevant to its duties.

Hundreds of Complaints Helped Drive the Audit

CalPrivacy said the gig economy review responds to hundreds of consumer complaints as well as concerns raised during public rulemaking.

That disclosure provides useful insight into how the agency may select future industries for examination.

Patterns in consumer complaints can reveal recurring operational failures that may not be visible from a company’s published privacy policy.

Examples may include workers reporting that:

  • The platform failed to respond to an access request
  • The response contained only limited profile information
  • The company would not disclose performance or account records
  • The verification process was impossible to complete
  • The platform treated a contractor as ineligible for CCPA rights
  • The company could not explain a deactivation decision
  • The request was repeatedly redirected between departments

A high volume of similar complaints can turn an individual service issue into a sector-wide compliance concern.

Other industries should take notice. Gig platforms are the first sector selected, but the agency expressly described this as the beginning of a series of sectoral audits.

What Gig Platforms Should Review Immediately

Companies operating transportation, delivery, labor, freelance or task-based platforms should evaluate their privacy request programs before receiving an audit notice.

Confirm That Workers Are Included in the Privacy Program

The company’s policies, intake channels and internal procedures should expressly address employees, applicants and independent contractors where the CCPA applies.

A process designed only around customers may fail to locate workforce and platform-performance information.

Test Access Requests From Beginning to End

Companies should submit realistic test requests and follow them through every stage of the process.

The test should determine whether the company can identify the requester, search all relevant systems, obtain vendor-held information, apply appropriate exceptions and deliver a complete response within the statutory period.

Map Data Used in Worker Decisions

The organization should identify every system that contributes information to dispatch, scoring, payment, fraud, rating, suspension and deactivation decisions.

That map should include inputs, generated inferences, outputs, decision rules and downstream recipients.

Review Vendor Responsibilities

Location providers, identity verification services, payment processors, cloud platforms and fraud detection companies may maintain information required for a complete response.

Contracts and operational procedures should support timely retrieval and deletion where legally required.

Document Verification Standards

Companies must verify certain privacy requests, but verification should be proportionate to the sensitivity of the information and the risk of unauthorized disclosure.

Excessive verification can prevent legitimate workers from exercising their rights. Weak verification can expose sensitive employment and financial information to the wrong person.

Reconcile Privacy Responses With Actual Data Practices

The categories listed in the company’s response should match its data inventory, privacy notice, vendor relationships and technical environment.

An auditor may compare these sources to determine whether the company’s description is complete and accurate.

The First Audit Sends a Warning Beyond the Gig Economy

CalPrivacy’s first formal audit is significant because of the industry selected and the right being examined.

The agency did not begin with a narrow review of cookie banners or website privacy notices.

It selected an industry in which personal information can directly influence a person’s income and access to work.

It also selected the access right, which sits at the center of nearly every other privacy right. A person cannot effectively correct, delete or challenge information without first knowing that it exists.

The message to businesses is clear: California privacy compliance will be evaluated based on operational results, not merely written policies.

A company must be able to locate personal information, explain its use, retrieve it from connected systems and provide it to the correct person within the required period.

That obligation becomes especially important when automated systems use the information to make decisions about individuals.

Captain Compliance Helps Companies Prepare for Privacy Audits

Captain Compliance helps businesses operationalize CCPA rights through data mapping, privacy assessments, DSAR intake and fulfillment workflows, vendor coordination, request tracking and compliance documentation.

Organizations preparing for a CalPrivacy audit should be able to demonstrate how a request moves from intake through identity verification, system search, legal review, response delivery and final recordkeeping.

The existence of a privacy request form is not enough.

The company must be able to prove that the process reaches the data that matters.

Frequently Asked Questions

What is CalPrivacy auditing?

CalPrivacy is examining whether major gig economy platforms comply with the CCPA, with an initial focus on whether consumers and workers can meaningfully access and understand the personal information collected about them.

Which gig platforms are being audited?

The agency has not publicly identified the companies selected for the audit. It described the targets generally as major app-based transportation, delivery and task-service platforms operating in California.

Do independent contractors have CCPA rights?

California’s employment-related exemption expired at the end of 2022. Independent contractors who are California residents may therefore exercise applicable CCPA rights concerning personal information maintained about them by a covered business.

How long does a business have to respond to an access request?

A covered business generally must respond within 45 calendar days. The response period may be extended by an additional 45 days when permitted, but the requester must be notified of the extension.

What information might a gig worker receive?

Depending on the request and applicable exceptions, responsive information may include profile data, location records, performance information, payment records, communications, account activity and information used to make decisions about assignments or account status.

Is this an enforcement action?

The audit itself is not a public finding that a named platform violated the law. CalPrivacy described the process as a proactive compliance review that can identify deficiencies, support remediation and produce broader industry findings.

Is this the same as California’s cybersecurity audit requirement?

No. This is a regulatory audit initiated by CalPrivacy to examine CCPA compliance. California’s mandatory cybersecurity audits are separate requirements applying to qualifying businesses under their own regulations and implementation schedule.

Written by: 

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.