CalPrivacy’s Audits Division: Evaluating Real-World Privacy Risks

Author: CalPrivacy Public & External Affairs Division
Published: Aug 05, 2026

The newly-formed Audits Division has posted “Emerging Technology, Inference, and Identifiability: CalPrivacy Audit Technologist Request for Input,” which poses technical questions and calls for input to support its development of audit framework and compliance inquiry functionalities. The purpose of this blog post is to describe the function of the Audits Division to consumers and empower them to understand the questions being explored.

When California voters passed the California Privacy Rights Act in 2020, it formed what is known today as CalPrivacy — a first-of-its-kind robust, independent, consumer privacy agency. Since then, CalPrivacy has been hard at work building the nation’s first dedicated privacy regulator — and in 2026 we hired our first Chief Privacy Auditor to establish the Audits Division.

The Audits Division’s job is to look under the hood. Think of us as the compliance inspectors. Just like a health inspector doesn’t wait for someone to go to the hospital before checking a restaurant kitchen, we don’t need to wait for violations before checking whether a business’s privacy practices comply with the law. Through audits, CalPrivacy will receive real data on how businesses operationalize privacy and cybersecurity for consumers, which will help the agency better protect Californians’ privacy.

Unlike enforcement investigations, audits will take on a proactive role with businesses. The audits will identify both areas of improvement and strong practices in privacy and cybersecurity, along with emerging risks, and learnings from the practical application of consumer rights. Together the audit and enforcement teams act as a compliance multiplier.

Technologists’ role

In the Audits Division, we thoughtfully examine business practices, and work to make sure that technology serves people’s needs and that companies respect their users’ digital privacy.

CalPrivacy Technologist Tina Yeung, PhD

Technologists are experts in technology that enable CalPrivacy’s Audits Division to evaluate whether businesses’ privacy infrastructures actually work in practice.

Technologists’ work includes:

  • Dissecting complex technical information so that auditors can assess compliance with the law
  • Identifying emerging technology risks
  • Creating strategies to evaluate business practices
  • Conducting research to inform the agency’s regulatory goals

By working together, auditors and technologists can evaluate privacy compliance based on specific systems that operate with real consumer data.

Why does this matter for you?

Most people will never file a complaint with a privacy regulator. Not because everything is fine, but because most people don’t have the time, technical knowledge, or visibility into backend systems to know whether something is wrong in the first place. The Audits Division can go looking ourselves, so that privacy protections apply broadly.

Request for input

With a newly launched Audits Division and a fresh team of Technologists eager to help operationalize Californians’ privacy rights, the division has posed a set of questions for researchers and practitioners to better understand California’s privacy landscape: “Emerging Technology, Inference, and Identifiability: CalPrivacy Audit Technologist Request for Input”. For full questions and context, please review the document. For the general public, we have created an extract written in common terms:

Inference

  • How do you determine if a business can produce or reveal something personal about a consumer based on the consumer’s behavior — even though a consumer never directly shared that information?
  • How do you tell whether a business’s guess about a consumer is just a coincidence versus a prediction the business actually used in a decision?
  • How do you understand whether a business combining multiple services into a single system creates new ways for sensitive information to be inferred, shared, or exposed?

Reidentification

  • How do you tell whether data a business calls “anonymous” can still be connected back to a real person?
  • How do businesses check whether their system is accidentally revealing personal information — and what can they do to reduce that risk?

As CalPrivacy works with researchers and practitioners on solving these important questions, we take more steps toward creating a safer, more privacy protective California for consumers.