California privacy enforcement is entering a new phase
- Katarzyna Celińska

- 11 minutes ago
- 1 min read
There is a lot happening in California privacy right now.
CalPrivacy is moving from rulemaking and early enforcement toward a much more mature supervisory model built around audits, technical testing, sectoral reviews and increasingly operational compliance expectations.
New obligations are coming into force. Organizations will have more requirements to implement, more evidence to maintain, and more areas where they can be challenged by the regulator.

Photo: magnific
The Audit Division wants to use a risk and harm-based model, focusing on real-world failures in statutory rights rather than only checking whether policies and procedures exist.
The audit process may include:
document requests and interrogatories,
interviews with responsible personnel,
technical testing,
black-box testing of systems and data flows,
validation of privacy rights in practice,
draft findings and remediation discussions.
CalPrivacy has already launched its first sectoral audit into gig economy platforms, and is also looking at emerging issues such as data inference, reidentification and AI-related risks.
At the same time, DROP has entered an enforcement phase.
As of 1 August, data brokers are required to process consumer deletion requests submitted through DROP. In the first week, around 30% of registered data brokers had begun processing requests, with approximately 450,000 requests already submitted.
CalPrivacy has started formal rulemaking for independent DROP compliance audits, expected to apply on a triennial basis from 2028.
There is also the upcoming cybersecurity audit framework.
The first compliance wave begins 1 January 2027 for organizations with more than USD 100 million in annual gross revenue, with additional phases in 2028 and 2029. CalPrivacy is preparing a submission portal and methodology while expecting potentially thousands of audit submissions.
Author: Sebastian Burgemejster



Comments