The California Privacy Protection Agency (“CalPrivacy”) announced on July 21, 2026, that its Audits Division launched the agency’s first formal sectoral privacy audit, targeting gig economy platforms operating in California that collect consumers’ personal information, including app-based transportation, delivery, and task services. The audit is intended to improve compliance with the State’s privacy law by identifying risks and vulnerabilities, producing agreed-upon remediations with the audited platforms, and highlighting strong compliance practices.
CalPrivacy is specifically examining whether gig platforms are honoring workers’ and consumers’ rights under the California Consumer Privacy Act (CCPA) when collecting their personal information, including consumers’ precise geolocation data, behavioral and performance metrics, biometric identifiers, financial information, and communications records – data that companies analyze to make decisions about dispatch assignments, performance ratings, earnings, and account status. The agency, acting under California Civil Code section 1798.199.40, will assess, among other things, whether platforms are processing access requests within the 45-day statutory window, providing consumers with complete responses, and implementing systems that enable workers to meaningfully exercise their privacy rights.