Regulations

Mine’s Fireside Chat with CalPrivacy: Inside Its First-Ever Privacy Audit

September 28, 2026

For the first time, California's privacy regulator didn't just publish the rules, it picked up the phone and started checking who's actually following them.

Gig platforms happened to be first in line. But the moment a regulator moves from writing policy to testing it in practice, every privacy program should be paying attention, whether or not they're anywhere near rideshare or delivery apps.

That's the conversation Mine sat down to have on August 18: A live fireside chat between Ron De Jesus, Mine's Chief Trust Officer, and CalPrivacy's Chief Privacy Auditor, digging into how this first sectoral audit actually works - what it's testing for, where it can lead, and what it means to be genuinely ready for one.

Here’s what we've learned.

‍

Why the Gig Economy, and What's Likely Next

CalPrivacy didn't pick a sector at random. Audit selection follows familiar regulatory logic: significant risk to consumer privacy or security, combined with any history of noncompliance.

To build that risk picture, the agency draws on a range of signals: public comments, consumer complaints, news coverage, and academic research.

Gig platforms check several of those boxes at once: they collect sensitive data at scale - location, biometric, behavioral, and financial - and use it to make consequential, sometimes livelihood-altering decisions about the workers who generate it.

That made the sector a natural starting point. But CalPrivacy has been clear that this is the first stop in a broader audit program, not a one-off.

The takeaway is straightforward: sector selection will change, but the risk-based logic behind it won't. Organizations handling sensitive data at scale, or using it to drive consequential decisions, should expect increasing scrutiny.

‍

An Audit Is Not the Same as Enforcement

The most important reframe from the conversation: an audit isn't an automatic enforcement action. Its goal is operational remediation - closing the gap between what a company says it does and what its systems actually do.

Individual audit findings generally stay confidential. What the agency may make public instead is aggregated trends and "excellent practices" drawn across audits, meant to inform the industry without exposing any one company's specific results.

That confidentiality has a limit, though. If a company doesn't cooperate, or its compliance posture points toward fines, the matter can be referred to CalPrivacy's enforcement arm, and enforcement actions can become public.

The distinction matters: an audit is designed to identify and remediate gaps, while enforcement addresses failures that warrant further action.

‍

Inside the Audit Team and Process

CalPrivacy's Audits Division is built around two complementary roles:

  • Auditors, who bring procedural and compliance rigor - statutory mapping, documentation review, process verification.
  • Technologists, who verify what's actually happening under the hood, testing whether the technical reality matches the paper trail.

The team is expected to grow, adding cybersecurity and other technical specialties as the program matures, a signal that audits will get more technically rigorous over time, not less.

Procedurally, the lifecycle is fairly structured: internal prioritization, an initial phone call, a formal opening letter with document requests or interrogatories, then (depending on scope) interviews, on-site visits, document review, and technical testing. It ends with a draft report laying out findings and proposed remediations, with timelines that flex based on how prepared and responsive the company is. 

Engaging with real transparency, rather than a defensive posture, tends to move the whole process along faster.

‍

The Recurring Theme: Right of Access

A large part of the conversation centered on the Right of Access - arguably the most foundational privacy right, since it's often the precondition for exercising every other one. The gaps auditors are specifically trained to spot:

  • Policies that exist on paper but aren't backed by working systems
  • Access mechanisms that technically exist but don't reliably fulfill requests
  • Responses that don't match what the company actually holds
  • Under-resourced or missing handling of exemptions, appeals, and authorized agents
  • "Asymmetric friction" - systems that make it easy to deny a request and hard to approve one

For smaller organizations without a large compliance function, the same advice scales down cleanly: lean on the regulator's own public guidance, and put more energy into getting legal and technical teams talking to each other than into producing another policy document. 

A policy without working infrastructure behind it won't survive a technologist's review.

‍

What This Means for You

The biggest takeaway from CalPrivacy's first audit is simple: privacy readiness has to hold up in practice, not just on paper.

As the audit program expands, organizations should be able to demonstrate that their privacy processes actually work - particularly when it comes to core rights like access.

For Right of Access, that means knowing that every request can produce a complete, accurate response based on the data your systems actually hold.

That's the standard Mine's DSR automation is built to help deliver: a Right of Access process that works in practice, so your team can approach regulatory scrutiny with evidence, accuracy, and confidence.

Ready to see what confidence looks like for your program? Schedule a demo.

‍

Ready to build your own autonomous kingdom?

Book a demo

Ready to build your own autonomous kingdom?

Book a demo