Find a lawyerOur capabilitiesYour career
Locations
Our capabilities
News

Select language:

Locations
Our capabilities
News

Select language:

hamburger menu showcase image
  1. Our thinking
  2. Blogs
  3. A Fresh Take
  4. CalPrivacy’s First Sectoral Audit: What to Know and How to Prepare
3MIN

CalPrivacy’s First Sectoral Audit: What to Know and How to Prepare

Subscribe
Aug 7 2026

The California Privacy Protection Agency (CalPrivacy) recently announced its first formal sectoral audit, targeting privacy compliance across gig economy platforms operating in California. This marks the agency’s first public use of its audit authority under California Civil Code section 1798.199.40 against an entire industry rather than a single business. The audit is uniquely significant because the California Consumer Privacy Act (CCPA), unlike comprehensive privacy laws in other states, extends protections to employees and independent contractors. Further, it focuses on a sector where platforms often collect extensive personal information on consumers and the workers who power the platforms. By focusing on privacy compliance in this context, CalPrivacy is signaling that businesses will be judged not only on formal compliance, but also on how effectively their governance, processes, and controls put those legal requirements into practice.

What a Sectoral Audit Looks For & Why it Matters

Similar to the FTC’s Section 6(b) market studies, CalPrivacy’s sectoral audit focuses on evaluating industry practices rather than a single enforcement target. As emphasized in the press release, this sectoral audit provides an opportunity to identify risks and vulnerabilities, “shed light” on widespread industry practices, and publish sector trend reporting that can inform the public. Further, Executive Director Tom Kemp described the audit as “an important milestone” for the newly formed Audits Division, explaining that its purpose is to “increase[] compliance through proactive engagement and review.” This suggests that the audit is intended not only to penalize violations, but also to raise the baseline of industry compliance by helping regulators understand how privacy obligations are operationalized across an industry.

The distinction between a single-business enforcement focus and an industry review is notable. Where a traditional investigation asks whether a business has complied with applicable privacy laws—often triggered by a particular incident, complaint, or event—a sectoral audit explores how a business implements privacy obligations across its business functions and whether it achieves compliance on an ongoing basis. For example, regulators may look beyond simply checking whether businesses fulfilled access or deletion requests and instead evaluate whether a business has built the underlying architecture to maintain compliance. Specifically, regulators may look at how businesses:

  • Receive, track, and fulfill access and deletion requests across systems
  • Monitor and enforce statutory deadlines
  • Establish privacy governance structures
  • Allocate privacy compliance responsibilities across teams and departments
  • Audit, document, and verify compliance with legal obligations.

In short, a sectoral audit looks past isolated compliance outcomes to examine the processes and accountability mechanisms that produce them.

What This Means for Organizations

For businesses subject to the CCPA, sectoral audits raise the bar from documented compliance to operational compliance. Boilerplate written policies are no longer enough. Regulators like CalPrivacy, will expect businesses to demonstrate how privacy responsibilities are assigned, how legal obligations are translated into day-to-day procedures, and how those procedures are monitored and refined over time. Whether sectoral audits become a regular feature of CalPrivacy’s oversight remains to be seen, but this inaugural review suggests the direction of travel.  

The Takeaway

Even before sectoral audits may become routine and expand to other industries, businesses would be well served to treat this first sectoral audit as a preview. Now is a sensible time to test whether privacy compliance is genuinely operationalized: whether responsibilities are clearly owned, whether policies are backed by working procedures, and whether the business can show its work if a regulator asks not just what it did, but how.

To receive the latest insights on US legal developments, subscribe to the Freshfields A Fresh Take Blog.

Tags

cybersecuritydata protectionusdata cybersecurity and tech regulationregulatory and compliance advisory

Authors

San Francisco, Silicon Valley

Megan M. Kayo

Partner
San Francisco

Christine Chong

Senior Associate
New York

Jackson Myers

Associate
Washington, DC

Alexandra Walsh

Associate
Latest Insights

Latest Insights

NAVIGATE TO
About usLocations and officesYour careerOur thinkingOur capabilitiesNews
CONNECT
Find a lawyerAlumniContact us
NEED HELP
Fraud and scamsComplaintsTerms and conditions
LEGAL
AccessibilityCookiesLegal noticesTransparency in supply chains statementResponsible procurementPrivacy

Select language:
Select language:
© 2026 Freshfields. Attorney Advertising: prior results do not guarantee a similar outcome