By Scott Hall and Meaghan Henderson
On July 21, 2026, the California Privacy Protection Agency (CalPrivacy) announced that its newly formed Audits Division has begun its first formal privacy audit, focused on gig economy platforms operating in California. This sectoral audit was initiated in response to hundreds of consumer complaints, as well as comments received during public rulemaking. It reflects CalPrivacy’s continued focus on active enforcement following several high-profile actions earlier in 2026.
Gig economy platforms are digital applications and websites that connect independent workers with customers for short-term or project-based tasks. Common examples include ridesharing, food delivery, and task-based service platforms.
Gig economy platforms collect personal information from both customers and the gig workers who provide services through their platforms. The personal information collected by these platforms may be extensive and highly sensitive, and may be used by algorithmic systems to make significant decisions affecting gig workers, including dispatch assignments, performance ratings, compensation, and account suspension or deactivation.
The audit will evaluate whether major gig economy platforms are complying with all obligations under the California Consumer Privacy Act (CCPA) and will focus on whether these platforms provide individuals with meaningful access to and control over their personal information. This emphasis reflects CalPrivacy’s view that access is a foundational right, allowing individuals to identify potential issues and meaningfully exercise other rights such as correction, deletion, and appeal.
The CCPA’s protections apply to consumers, as well as to employees, job applicants, and independent contractors such as gig workers. Consistent with other California efforts to protect gig workers, the Audits Division also plans to closely examine whether platforms using algorithmic systems as described above are complying with workers’ access rights.
Failure to comply with workers’ access rights not only violates the CCPA, but may also directly affect workers’ livelihoods. Without access to the information underlying significant decisions, workers may be unable to understand or challenge negative outcomes.
Companies that operate a gig economy platform in California or one that targets California residents should review their compliance with the CCPA, including their processes for responding to consumer and worker rights requests.
Companies should confirm that they have systems in place that allow both consumers and workers to exercise their rights under the CCPA and that access requests are completed within the applicable 45-day statutory period.
If your company has questions about compliance with the CCPA or whether the audit may apply to your business, the Coblentz Data Privacy & Cybersecurity team can help. Please contact Scott Hall or Meaghan Henderson for additional information or assistance.