What’s the point of an Audit Division if you never audit anybody? The CPPA certainly isn’t going to let anybody level that criticism towards them.
They just announced their first-ever sectoral audit this week, aimed at gig economy platforms and whether they honor workers' and riders' right to access the data collected about them. As CalPrivacy's Chief Privacy Auditor put it, “You can't contest an algorithm's decision without the data behind it.” Thus, the right of access serves as a springboard for the right to appeal the results of automated decision-making–and in many ways, all other data subject rights under the CCPA.
Previous CPPA investigations have focused on GPC compliance, sensitive data collection, and more, but this is the first time data subject rights have come under the microscope. The agency said they’ll focus on whether in-scope businesses are:
- Honoring requests within the 45-day statutory window
- Providing complete responses
- Allowing workers to exercise their rights through appropriate systems
The tricky one is that middle point. The difference between a complete response and an incomplete one can be quite the fine line depending on what data your organization collects from data subjects.
It’s a tall order for businesses that have waited until this moment to comply with the CCPA’s data subject rights requirements. But there’s no time like the present.
Best,
Arlo
Highlights From Osano
In Case You Missed It...
Product Update: Why We Built an AI That Passed the Bar Exam of Privacy
Privacy questions have a way of landing on whoever happens to be nearby. Marketing managers, ops leads, HR pros–these professionals never planned on becoming a privacy expert. When they have to field a question that’s out of their wheelhouse, they reach for ChatGPT; and that’s dangerous. So, we built a privacy-trained AI tailor made to support Osano users' compliance.
Events
Opted Out. Still Tracked. The Marketing & Consent Webinar Series
A three-part series exploring the practically universal problem of marketing data trackers continuing to fire even after consumer opt outs. Learn why 79% of websites have broken opt-outs in part one, “Your Consent Banner Is Lying to You” on July 16; how to fix broken opt-outs in part two, “A Blueprint for Simple, Compliant Data Collection” on July 23, and see how it all comes together in part three, “A Real-World Audit of Consent Gone Wrong/Right” on July 30.
Top Privacy Stories of the Week
LAPD Cuts Off Flock Safety After Audit Finds One-in-Three Alerts False
After a 98-page inspector-general audit found Flock Safety's license-plate readers flagged one in three "stolen vehicle" alerts incorrectly, the LAPD let its three-year contract with the company lapse. The larger issue, however, is that LA’s sanctuary city policies limit how the LAPD is permitted to cooperate with federal law enforcement–the cloud servers of the vendors the LAPD hires are not similarly bound. Flock data has repeatedly reached federal immigration agents in other cities despite local restrictions. LAPD is now negotiating for data ownership and civil penalties before resuming service.
CPPA Launches First Sectoral Audit, Targets Gig Economy Platforms
The California Privacy Protection Agency's Audits Division launched its first-ever sectoral audit this week, targeting gig economy platforms over whether they honor workers' and riders' right to access the data collected about them. Regulators framed the right of access as foundational—you can't contest an algorithmic decision without the data behind it.
Madison Square Garden Sues Wired Over Celebrity "Risk" Database Report
Madison Square Garden filed a defamation suit against Wired over its July 9 report alleging the venue kept an internal database tagging celebrity guests by "risk" level, including alleged sexual orientation and race categories. MSG calls it a distortion of an ordinary VIP relationship-management tool; Wired says it's standing by its reporting.
Seventh Circuit Vacates Clearview AI's Equity-for-Privacy Settlement
The Seventh Circuit vacated Clearview AI's novel biometric-privacy class settlement, which would have paid claimants via an equity stake in the company rather than cash. The court found no problem with the equity structure itself, but ruled that the settlement unfairly favored certain state subclasses without a representative for the disadvantaged nationwide class. The case returns to the district court.
Ernst & Young (EY) Discloses Data Breach Exposing Tax Data
Ernst & Young has disclosed a data breach that resulted in the theft of clients' personal information. From March 28 to April 12, attackers had access to a third-party support ticket system containing customer information related to their tax affairs.
Like What You See in the Privacy Insider newsletter?
There's more to explore:
🎙️The Privacy Insider Podcast
We go deeper into additional privacy topics with incredible guests monthly. Available on Spotify or Apple.
📱 The Osano Subreddit
Join our official subreddit to stay up to date on the latest news, analysis, guidance, and content from Osano!
đź“– The Privacy Insider: How to Embrace Data Privacy and Join the Next Wave of Trusted Brands
The book inspired by this newsletter: Osano CEO, Arlo Gilbert, covers the history of data privacy and how companies can start building a privacy program from the ground up. More details here.
If you’re interested in working at Osano, check out our Careers page!
Arlo Gilbert
Arlo Gilbert
Arlo Gilbert is the CIO & co-founder of Osano. A native of Austin, Texas, he has been building software companies for more than 25 years in categories including telecom, payments, procurement, and compliance. In 2005 Arlo invented voice commerce, he has testified before congress on technology issues, and is a frequent speaker on data privacy rights.
