• CalPrivacy Targets Gig Economy Platforms In First CCPA Sectoral Audit

    By Scott Hall and Meaghan Henderson

    On July 21, 2026, the California Privacy Protection Agency (CalPrivacy) announced that its newly formed Audits Division has begun its first formal privacy audit, focused on gig economy platforms operating in California. This sectoral audit was initiated in response to hundreds of consumer complaints, as well as comments received during public rulemaking. It reflects CalPrivacy’s continued focus on active enforcement following several high-profile actions earlier in 2026.

    What Is A “Gig Economy Platform”?

    Gig economy platforms are digital applications and websites that connect independent workers with customers for short-term or project-based tasks. Common examples include ridesharing, food delivery, and task-based service platforms.

    Gig economy platforms collect personal information from both customers and the gig workers who provide services through their platforms. The personal information collected by these platforms may be extensive and highly sensitive, and may be used by algorithmic systems to make significant decisions affecting gig workers, including dispatch assignments, performance ratings, compensation, and account suspension or deactivation.

    What Is the Focus of CalPrivacy’s Audit?

    The audit will evaluate whether major gig economy platforms are complying with all obligations under the California Consumer Privacy Act (CCPA) and will focus on whether these platforms provide individuals with meaningful access to and control over their personal information. This emphasis reflects CalPrivacy’s view that access is a foundational right, allowing individuals to identify potential issues and meaningfully exercise other rights such as correction, deletion, and appeal.

    The CCPA’s protections apply to consumers, as well as to employees, job applicants, and independent contractors such as gig workers. Consistent with other California efforts to protect gig workers, the Audits Division also plans to closely examine whether platforms using algorithmic systems as described above are complying with workers’ access rights.

    Failure to comply with workers’ access rights not only violates the CCPA, but may also directly affect workers’ livelihoods. Without access to the information underlying significant decisions, workers may be unable to understand or challenge negative outcomes.

    What Businesses Should Do Now

    Companies that operate a gig economy platform in California or one that targets California residents should review their compliance with the CCPA, including their processes for responding to consumer and worker rights requests.

    Companies should confirm that they have systems in place that allow both consumers and workers to exercise their rights under the CCPA and that access requests are completed within the applicable 45-day statutory period.

    If your company has questions about compliance with the CCPA or whether the audit may apply to your business, the Coblentz Data Privacy & Cybersecurity team can help. Please contact Scott Hall or Meaghan Henderson for additional information or assistance.

  • New California Secretary of State Access Requirements for Third-Party Filings

    The California Secretary of State has changed how third parties may access its online systems to submit filings on behalf of business entities.

    The change is relevant to corporations and limited liability companies formed in California, as well as such entities formed outside California and registered to do business in California, that rely on attorneys, accountants, or other advisors to submit statutory filings.

    Effective July 1, 2026, an entity must grant a third party “Full Access” to its California Secretary of State account before that third party may submit certain filings on the entity’s behalf. Previously anyone was able to submit filings online on behalf of an entity without providing prior authorization. In addition, many documents, such as terminations/dissolutions, could only be processed via physical paper filings, which created processing backlogs and wait times. In an attempt to reduce fraudulent filings and expedite other filings, the Secretary of State has now locked down certain filings for those who have Full Access only. Full Access on the California Secretary of State’s bizfile Online portal[1] allows an authorized user of a business entity to perform certain online transactions, such as Statement of Information filings, conversions and terminations/dissolutions, but only once they have verified their authority with the entity-specific PIN which is mailed to the entity’s last known mailing address.

    Filings that currently require Full Access include:

    Domestic Limited Liability Companies
    •    Statement of Information
    •    Amendment or Attachment to Statement of Information
    •    Certificate of Dissolution
    •    Certificate of Cancellation
    •    Short Form Cancellation Certificate
    •    Conversion/Merger Filings

    Foreign Limited Liability Companies
    •    Statement of Information
    •    Amendment or Attachment to Statement of Information
    •    Certificate of Cancellation
    •    Conversion/Merger Filings

    Domestic Corporations
    •    Statement of Information
    •    Amendment or Attachment to Statement of Information
    •    Certificate of Election to Wind Up and Dissolve
    •    Certificate of Dissolution
    •    Short Form Dissolution Certificate
    •    Nonprofit Certificate of Election to Wind Up and Dissolve
    •    Nonprofit Certificate of Dissolution
    •    Nonprofit Short Form Dissolution Certificate
    •    Conversion/Merger Filings

    Foreign Corporations
    •    Statement of Information
    •    Amendment or Attachment to Statement of Information
    •    Certificate of Surrender
    •    Conversion/Merger Filings

    How to Grant a Third Party Full Access to CA SOS Account

    Obtaining the entity’s unique personal identification number, or PIN, is the first step in granting Full Access. To obtain a PIN for Full Access to an entity’s records, one will need to visit the California Secretary of State’s bizfile Online portal and log in or create an account. The account holder will then search for the entity, select its business record, and select the “Request Access” icon at the bottom of the entity’s profile panel. If the entity has not previously granted anyone access, the state will generate a unique PIN, which will be mailed to the entity’s last known mail address listed on the bizfile Online portal. Once this PIN is received, the account holder will log back into its bizfile account, search for and select the entity, and go back to the “Request Access” icon. The account holder then inputs the PIN to verify authorization and unlock full access to the entity’s records and available online filing functions. With Full Access, one is able to “Manage Full Access” which allows the account holder to assign access control to other users.

    What Businesses Should Do Now 

    Businesses should review who currently has access to their California Secretary of State accounts and determine whether any attorneys, accountants, or other advisors will need Full Access to submit filings on their behalf.

    Entities should address these access requirements well in advance of any filing deadline or transaction closing. Delays in obtaining a PIN or granting access could affect the timely submission of required filings or the entity’s ability to provide evidence of good standing in connection with a transaction.

    We will continue to monitor developments related to these requirements. In the meantime, please contact Peter Wang or Lori Sudowe with any questions.

     

    [1] https://bizfileonline.sos.ca.gov/

  • New Jersey Enacts the Nation’s Broadest Data Broker Law: What Your Business Should Know

    By Scott Hall and Meaghan Henderson

    New Jersey passed a data broker law (A.5328) that is in effect immediately and is more comprehensive than any similar state law passed to date. The law has two main parts, both with wide reach and significant consequences for noncompliance. Any company that sells personal data of New Jersey consumers should review this law to determine whether its requirements apply.

    Part 1 – Prohibition on the Sale of Sensitive Personal Data

    A.5328 prohibits the sale of New Jersey consumers’ sensitive personal data. “Sale” broadly includes sharing, disclosing, or transferring personal data for monetary or other valuable consideration. “Sensitive data” includes information concerning race or ethnicity, religious beliefs, health, financial accounts, sex life or sexual orientation, citizenship or immigration status, transgender or non-binary status, genetic or biometric identifiers, known children, and precise geolocation.

    This prohibition does not include a consent exception and applies to any company that sells sensitive personal data of New Jersey consumers, even if the company does not meet the applicability thresholds under New Jersey’s general privacy law.

    Selling, offering to sell, or licensing sensitive personal data may result in a civil penalty of $50,000 per record. Because personal data typically moves in high volumes, this could result in substantial penalties for noncompliance.

    Part 2 – Annual Registration and Fees for Data Brokers and Data Collectors

    Unlike other state data broker laws, New Jersey’s law creates a new category of entity—”data collectors”—separate from data brokers. Data collectors are entities that have a direct relationship with consumers but sell or license their personal data to a data broker.

    Both data brokers and data collectors must register annually with the New Jersey Division of Consumer Affairs in the Department of Law and Public Safety and provide information about their data practices. Registration fees range from $5,000 to $1.5 million, depending on the number of consumers involved.

    Failure to register, pay the registration fee, or provide, and maintain, required information may result in a civil penalty of $2,500 per day.

    Below are questions to help you determine whether your company is a “data broker” or “data collector” under New Jersey law.

    Is Your Company a “Data Broker” Under New Jersey Law?

    • Does your company knowingly collect or purchase personal data of New Jersey consumers?
    • Does your company sell or license that data to a third party?
    • Does your company have a direct relationship with the New Jersey consumers whose personal data it collects or purchases?

    If you answered “yes” to the first two questions and “no” to the third, your company is likely a “data broker” and may be subject to the annual registration and fee requirements.

    Is Your Company a “Data Collector” Under New Jersey Law?

    • Does your company knowingly collect personal data of New Jersey consumers?
    • Does your company sell or license that data to a data broker?
    • Does your company have a direct relationship with the New Jersey consumers whose personal data it collects or purchases?

    If you answered “yes” to all three questions, your company is likely a “data collector” and may be subject to the annual registration and fee requirements.

    What Businesses Should Do Now

    Although the public registration requirements do not take effect until March 27, 2027, companies should assess now whether their practices involving the sale, licensing, or sharing of personal data may trigger the law. The potential penalties are significant, and New Jersey regulators are actively reviewing compliance across all sectors.

    If your company has questions about whether this law applies to your business practices, the Coblentz Data Privacy & Cybersecurity team can help. Please contact Scott Hall or Meaghan Henderson for additional information or assistance.