Skip to main content

California Privacy Protection Agency Launches First Formal Privacy Audit Targeting Gig Economy Platforms’ Compliance with Access Rights

What You Need To Know

  • The California Privacy Protection Agency’s new Audits Division launched its first formal audit, focusing on whether gig economy platforms are complying with consumers’ right to access their personal information.  
  • The audit will assess whether platforms are honoring access requests within the 45-day statutory window, providing complete responses, and giving workers and consumers functional ways to exercise their rights.  
  • Because the California Consumer Privacy Act (CCPA) extends consumer rights to employees and independent contractors, gig workers may request the personal data platforms use to make decisions about dispatch, ratings, earnings, and account status. Beginning January 1, 2027, workers will also be able to use that data as grounds to challenge decisions made by automated decision-making technologies. 
  • Although the audit targets gig economy platforms, businesses across all sectors should expect continued audit activity and consider taking steps now to strengthen their access request processes. 

The California Privacy Protection Agency (the Agency) recently announced the launch of its first formal privacy audit conducted by the Agency’s newly formed Audits Division. The audit targets gig economy platforms operating in California and focuses specifically on whether these platforms are complying with consumers’ right to access their personal information under the CCPA. The Agency’s announcement signals a heightened enforcement focus on access rights and suggests that the Agency views meaningful access to personal information as foundational to the exercise of other CCPA rights including, potentially, the right to appeal decisions made by automated decision-making technology (ADMT). 

The Audit’s Scope and Focus 

The Agency’s audit will examine major gig economy platforms, including app-based transportation, delivery, and task services, to evaluate whether they are meeting their obligations to honor consumers’ requests to know what data is being collected about them, how it is being used, and with whom it is being shared (also referred to as “access requests”). As the Agency notes, these platforms “collect extensive personal information from California consumers, including the independent contractor workers who power their services.” According to the Agency, this data may include, among other things, behavioral and performance metrics, financial information, and communications records. Algorithmic systems handle this data to “make consequential decisions about workers’ dispatch assignments, performance ratings, earnings, and account status, including suspension or deactivation.” 

The audit will specifically examine whether:  
 

  1. Access requests are being honored within the 45-day statutory response window 
  1. Responses to access requests are complete 
  1. Platforms have implemented systems that allow workers to exercise their rights in accordance with the CCPA 

The CCPA Right to Know: A Refresher 

The CCPA grants California consumers the right to request that a business disclose personal information it has collected about them, including the specific pieces of information collected, categories of personal information and their sources, categories of information sold or disclosed, categories of third-party recipients, and the business purposes for collection or sale. 

Submission Methods: Businesses must generally provide at least two methods for submitting access requests (including a toll-free number and, if the business has a website, a webform). Online-only businesses with direct consumer relationships need only provide an email address. 

Response Timelines: Businesses must confirm receipt within 10 business days and respond substantively within 45 calendar days (extendable by an additional 45 days with notice to the consumer). If the business cannot verify the consumer’s identity within 45 days, it may deny the request. 

Scope of Response: Businesses must provide all personal information collected about the consumer during at least the preceding 12 months, including information held by service providers and contractors. 

Unique Application to Employees and Independent Contractors 

The CCPA is unique among broadly applicable U.S. state privacy laws in that its consumer rights, including the right to know, extend to employees and independent contractors. The other state privacy laws exempt employee and business-to-business data from their scope. This distinction is particularly significant in the gig economy context: Workers who are classified as independent contractors can exercise CCPA access rights in relation to the platforms for which they work. 

The Agency underscores that this means, for example, that a gig worker whose account has been deactivated based on behavioral metrics may exercise their right to access their personal information, and then use the information disclosed to assess the basis for the decision. Similarly, a worker seeking to understand how their performance is being evaluated, or why they are receiving certain dispatch assignments, may request the personal information the platform collected and then use that information to evaluate how those determinations were made. 

Connection to Automated Decision-Making Technology 

Notably, the Agency’s announcement emphasizes the connection between access rights and the ability to contest decisions made by algorithmic systems. As the Agency’s chief privacy auditor stated: “You cannot contest a decision made by an algorithm without the underlying data.” This framing suggests the Agency views the right to know as a precondition for meaningfully exercising other CCPA rights including, potentially, the forthcoming rights related to ADMT. 

The CCPA regulations define ADMT as “any technology that processes personal information and uses computation to replace human decision-making or substantially replace human decision-making.” Examples of ADMT include AI-powered resume screening software that automatically rejects or ranks job applicants and algorithmic patient-triage systems that automatically deny or prioritize medical treatment or insurance coverage. While the ADMT-specific compliance requirements do not take effect until January 1, 2027, the Agency’s announcement suggests it views existing access rights as a mechanism for consumers to obtain information relevant to challenging algorithmic decisions in the interim. 

Technically, the current right to access information through a “request to know” is different from the ADMT-specific access and appeal rights taking effect in 2027. However, the Agency’s announcement suggests it views both as serving a similar purpose: enabling consumers and workers to obtain the information they need to challenge automated decisions. 

This audit marks the inaugural action of the Agency’s newly formed Audits Division, which may conduct announced or unannounced audits to investigate possible CCPA violations or assess businesses whose data practices present significant risk to consumer privacy. According to the Agency’s executive director, this audit is “responsive to hundreds of consumer complaints and also comments received during public rulemaking.”  

Takeaways for Businesses 

While the audit targets gig economy platforms, the Agency’s focus on access request compliance has implications for all businesses subject to the CCPA. Businesses should consider taking the following practical steps, which may help ensure compliance: 

Audit request intake mechanisms. Confirm that at least the minimum number of designated methods required by the CCPA for submitting access requests are provided. Verify that all designated methods are functional, links are not broken, and requests are being routed appropriately. Test these mechanisms regularly. 

Confirm timeline compliance. Review internal processes to ensure that (1) receipt confirmations are sent within 10 business days of receiving a request; (2) substantive responses are provided within 45 calendar days; and (3) if an extension is needed, the consumer is notified with an explanation before the initial 45-day period expires. 

Ensure completeness of responses. Establish internal procedures to gather responsive information from all relevant departments, including from service providers and contractors. Responses should address all categories of information consumers are entitled to receive. 

Address employee and contractor data. For businesses that engage employees or independent contractors in California, remember that these individuals have the same CCPA rights as consumers. This is particularly important for businesses that use algorithmic systems to make decisions affecting workers, as those workers may request access to the underlying data. 

Prepare for ADMT requirements. Although ADMT-specific requirements do not take effect until January 1, 2027, businesses using automated systems for significant decisions should begin documenting how those systems work, what data they process, and how outputs are used. 

Maintain records. The CCPA requires businesses to maintain records of consumer requests for at least 24 months, including the date, nature, manner of submission, response date, and basis for any denial. 

Monitor for additional enforcement activity. The Agency has signaled that this is the first in a series of sectoral audits. Businesses in other industries should consider monitoring the Agency’s enforcement priorities and the outcomes of this initial audit, which may provide guidance on the Agency’s expectations and common compliance gaps.