Sabrina Boyson Ross was appointed Chief Auditor in February 2026 and spent her first months assembling personnel, refining internal processes, and establishing the division’s foundational approach. By July the unit had launched its first formal sectoral audit, focused on gig-economy platforms. In an exclusive conversation with the IAPP six months into the role, Ross outlined how the division views its mandate, the practical steps of an audit, common misconceptions held by companies, and the longer-term trajectory that includes cybersecurity audits and deeper engagement with emerging technologies.
A Mandate Centered on Understanding Rather Than Immediate Punishment
CalPrivacy describes its audit authority as an opportunity to identify risks and vulnerabilities, agree on remediations, surface strong practices, and publish sector-level trend reporting that can inform the public, companies, and policymakers. Ross reinforced that characterization. While audit findings can ultimately feed into enforcement referrals when serious non-compliance is uncovered, the primary objectives are fact-finding and the development of a shared knowledge base about current privacy practices across industries.
“We can take a proactive approach to understanding the state of compliance,” Ross explained. The division is structured to conduct relatively broad reviews that reveal patterns rather than solely targeting isolated violations. She also highlighted a public-education dimension: sectoral reports are intended to give companies, legislators, and other stakeholders a clearer picture of both exemplary practices and recurring areas needing improvement.
This orientation distinguishes audits from the more reactive posture of traditional investigations. Companies that receive initial outreach frequently assume the interaction is a precursor to enforcement. Ross characterized the opening contact instead as an attempt to establish a constructive, fact-oriented dialogue. The goal is a shared understanding of how a business actually handles personal information, not an immediate adversarial posture.
Why a Particular Sector or Company Is Selected
The California Consumer Privacy Act sets out multiple factors that may lead the agency to open an audit. Ross distilled the practical prioritization to areas of potential harm. The choice of gig-economy platforms for the first sectoral exercise, for example, reflected the intersection of privacy rights with access to economic opportunity. Workers in that sector often face distinctive data-collection practices tied to ratings systems, location tracking, algorithmic task assignment, and account status decisions that can directly affect livelihood.
Because the division can now run multiple audits concurrently, selection will continue to balance potential impact, representativeness of a sector, and the agency’s capacity to generate useful public insights. Individual-company audits remain possible, yet the early emphasis on sectoral work suggests a preference for findings that travel beyond a single organization and can shape broader compliance expectations.
The Mechanics of an Audit Engagement
Once a decision to audit is made, the process follows a structured sequence. Initial outreach is followed by a formal introduction letter that sets out the scope and the types of information the division will seek. Typical early requests include document production, written interrogatories, and interviews with relevant personnel.
Ross stressed that the division prefers these exchanges to function as conversations rather than purely formal discovery. “We encourage inquiries to be a conversation with companies because we really are looking for the most efficient way to get to a shared understanding of the facts,” she said. Open dialogue often surfaces creative but reliable methods for clarifying how systems actually operate, something rigid document exchanges alone may miss.
After the initial collection of materials, the team conducts follow-up questions and, where appropriate, technical testing. A draft report containing findings and proposed remediations is then shared with the company. The organization has an opportunity to discuss areas of agreement and disagreement before the report is finalized. Individual company reports remain confidential. Sectoral reports, by contrast, will be published and will highlight both strong practices observed across the sector and common patterns of weakness or incomplete implementation.
Staffing Model and the Growing Role of Technical Expertise
The Audits Division currently organizes itself around two primary skill sets: auditors with deep process expertise and technologists capable of examining systems, data flows, and testing methodologies. Ross anticipates further diversification of subject-matter expertise as the division matures, particularly in anticipation of automated decision-making technology rules and the forthcoming cybersecurity audit regime.
Technical testing is among the most complex elements of any engagement. The team must evaluate available testing techniques and their respective strengths and limitations. Black-box testing—observing external behavior, outputs, and data flows without internal knowledge of code or architecture—offers one set of insights. Real-time testing with controlled accounts or instrumented environments offers another. Choosing the appropriate method, or combination of methods, depends on the systems under review and the specific compliance questions being examined. Ross described this area as both “deeply exciting and somewhat novel,” noting that substantial methodological ground remains to be developed.
Recurring Blind Spots: Employee Privacy as an Example
Drawing on more than fifteen years of experience that included senior privacy roles at Apple, Meta, Uber, and Nauto, as well as earlier work as outside counsel, Ross identified employee privacy as a topic that frequently receives less rigorous attention than consumer-facing programs. “Companies aren’t necessarily used to thinking about it quite as deeply,” she observed. Consumer privacy has been more extensively regulated for longer; employee data practices have historically operated under a lighter spotlight. That is changing, driven in part by the expansion of workplace AI tools, monitoring technologies, and people-analytics systems.
Audits are therefore likely to surface gaps in inventorying employee data, applying appropriate notices and access controls, governing secondary uses of workforce information, and ensuring that automated tools used in hiring, performance, or scheduling contexts receive adequate privacy scrutiny. Organizations that have concentrated compliance resources almost exclusively on consumer-facing flows may find employee-related findings among the more unexpected outcomes of an audit.
Current Priorities and the Path Toward Cybersecurity Audits
The gig-economy sectoral audit remains the division’s most visible near-term project, but it does not consume the entire workload. With full staffing now in place, the unit can conduct multiple audits in parallel. Ross planned to provide the CalPrivacy Board with a more detailed briefing on the first sectoral exercise, as well as broader reflections on hiring, infrastructure, prioritization theory, and the division’s public posture, at the Board’s 7 August 2026 meeting.
Looking further ahead, the division is already preparing for the three-tier cybersecurity audit framework whose first compliance wave begins 1 January 2027. Organizations with more than $100 million in annual gross revenue fall into the initial cohort; subsequent phases begin in January 2028 and January 2029. In the intervening months the Audits Division will build the submission portal and develop sample methodology materials that covered entities can use as reference points.
Ross noted that the volume of expected submissions—potentially many thousands—will require careful workflow design. Once the agency requests the underlying cybersecurity audit documentation from a company, the organization will generally have thirty days to respond. Assessing the resource intensity of reviewing those materials at scale is already a central planning exercise. Cybersecurity audits represent a different style of oversight from the process-oriented and technical privacy audits the division is currently refining, and capacity planning must reflect that difference.
Engaging the Research Community on Emerging Technologies
On 5 August 2026 the Audits Division issued a request for information focused on data inference and re-identification capabilities of emerging technologies. The RFI seeks technical input on inferences that may be probabilistic, latent, or emergent from model behavior rather than explicitly designed outputs, as well as information on new vectors for re-identification. Ross described the effort as a deliberate attempt to maintain high connectivity with the research community in rapidly evolving domains so that audit methodologies remain responsive to technological change.
She expressed hope that the RFI would be the first in a series. Future topics could include the ways artificial intelligence is altering the cybersecurity landscape—an area of direct relevance as the division prepares to receive and evaluate cybersecurity audit submissions. Building durable channels with independent researchers and technologists is viewed as essential to keeping the division’s tools current.
Practical Implications for Organizations
Companies that may fall within the scope of future audits—whether sectoral or individual—can take several preparatory steps. Maintaining accurate, up-to-date records of data processing activities, retention schedules, and third-party sharing arrangements reduces friction when document requests arrive. Ensuring that privacy program documentation reflects actual operational practice, rather than aspirational policy language, is equally important; auditors will look for evidence of implementation, not merely the existence of written procedures.
Organizations should also examine employee-data practices with the same rigor applied to consumer programs. Mapping workplace monitoring tools, people-analytics systems, and AI-assisted HR technologies, and confirming that appropriate notices, access controls, and purpose limitations are in place, can reduce the likelihood of unexpected findings.
For entities that will be subject to the cybersecurity audit requirements beginning in 2027, early attention to the forthcoming sample methodology and portal design will be valuable. Understanding the expected format and evidentiary standards before the first compliance deadline arrives will allow internal teams and external assessors to align their work product with agency expectations.
Finally, companies that receive outreach from the Audits Division should approach the interaction as an opportunity to establish a clear factual record. Open, efficient dialogue tends to produce better outcomes than purely formal or defensive postures. Where genuine compliance gaps exist, the remediation discussion that follows the draft report provides a structured path to address them before any escalation to enforcement.
Building Institutional Capacity Over Time
Ross’s first six months focused on establishing the basic operating model: recruiting process auditors and technologists, defining prioritization criteria, developing request and reporting templates, and launching the first sectoral examination. The next phase will test the division’s ability to run concurrent audits, produce useful public trend reporting, absorb the volume of cybersecurity audit submissions, and continuously refine technical testing methods in response to new technologies.
The Audits Division is therefore evolving from a startup unit inside a still-young agency into a standing capability that can generate both specific findings about individual organizations and broader intelligence about privacy practices across the California economy. How effectively it balances those dual roles—confidential company-level examination and public sector-level insight—will shape its contribution to the overall privacy regulatory landscape in the years ahead.
For regulated entities, the practical message is straightforward. Audits are becoming a regular feature of CalPrivacy’s oversight toolkit. Organizations that treat privacy compliance as a living operational discipline rather than a static documentation exercise will be better positioned when the division’s attention turns in their direction. Those that wait for an audit letter to begin serious self-assessment will face a steeper path to demonstrating that their practices meet the standards the agency is now equipped to examine in detail.