California's rule giving people the right to opt out of automated employment decisions doesn't bind anyone until January 1, 2027. Sixteen months out, that reads like room to plan. On July 21, 2026, the California Privacy Protection Agency, now going by the nickname CalPrivacy, opened its first-ever sectoral audit anyway, and pointed it at gig economy platforms: the algorithms that decide who gets dispatched, what they earn, and when their account gets shut off. The agency didn't wait for its own deadline. Neither should you, if any system in your company makes that kind of call.
What CalPrivacy's first sectoral audit actually looks at
A sectoral audit is different from the complaint-driven cases the agency has run until now. It's a proactive review of a whole industry, meant to surface risks, log fixes and publish a trend report the rest of the market can read, rather than wait for one consumer to complain. CalPrivacy's own announcement names exactly what its first one checks on app-based transportation, delivery and task platforms: how they handle geolocation, biometric identification, financial information and communications records, and whether they meet the CCPA's statutory window for answering a consumer's access request. Then it names the decisions those platforms make with that data: "Algorithmic systems process this data to make consequential decisions about workers' dispatch assignments, performance ratings, earnings, and account status, including suspension or deactivation." Chief Privacy Auditor Sabrina Ross put the stakes plainly: "For gig workers in California, the right of access is vital because it may directly impact their livelihood." Executive Director Tom Kemp added that the audit is "responsive to hundreds of consumer complaints and also comments received during public rulemaking," and that it's the first in a planned series, not a one-off.
The enforcement pipeline behind it isn't small
This isn't one staffer acting on a hunch. CalPrivacy's 2025 annual report, published in February 2026, counts more than 10,000 consumer complaints since its online portal opened in 2023, up about 120% year over year, and describes hundreds of open investigations running at any given time. Agency headcount grew to 54 positions in 2025, up from just over 40 the year before, on a budget that rose to roughly $15.8 million, and the growth specifically included expanding the Enforcement Division's technologist bench, hiring people with computer-science PhDs to work alongside its litigators. That's the detail worth sitting with: the agency built the staff to read what an algorithm actually does, not just what a privacy policy says it does, before it opened an audit that reads exactly that kind of system.
The agency already fined a company over its job-applicant notices
ADMT enforcement hasn't started, but the CCPA rule requiring a notice to job applicants has applied since January 1, 2023, four years ahead of ADMT's own deadline, and CalPrivacy has already used it. In September 2025, the agency's board adopted a stipulated final order against Tractor Supply Company (Case No. ENF24-M-TR-04) requiring a $1,350,000 administrative fine, and one of its findings was a "deficient notice to job applicants": the company's careers-page disclosure didn't give California applicants what section 1798.145(m) requires them to know about their own CCPA rights. Nothing about that case turned on artificial intelligence. It turned on a pop-up on a jobs page nobody had checked against the statute since 2021. If your careers page hasn't had its privacy disclosure reviewed since before 2023, you're already inside the part of this law that's been enforceable, and fined, the longest.
"Employment" reaches far past gig platforms
It's tempting to read the audit as somebody else's problem if your company doesn't run a gig platform. The ADMT rules don't let you off that easily. Section 7001(ddd) of the regulations defines a "significant decision" to include the provision or denial of employment or independent contracting opportunities or compensation, and that reaches allocation of work and incentive pay, not only hiring, as what actually counts as ADMT lays out in full. A scheduling tool that assigns shifts, a routing system that hands out service calls, or a spreadsheet that computes bonus eligibility is the same shape of decision CalPrivacy is now walking through in gig platforms, whether or not anyone on your team would call it AI. The audit's own framing makes the connection explicit: dispatch, ratings, earnings and account status are the four things a covered employer's automated tools are most likely to touch, gig platform or not.
A worked example
Picture a 90-person facilities-services company that dispatches technicians through a scheduling app bought off the shelf in 2019. A ranking algorithm assigns jobs by proximity and customer rating; a dispatcher can override an assignment, but doing so means leaving the main queue screen and reopening a separate admin tool mid-shift, so in practice nobody does. A contractor whose rating drops below a threshold gets deactivated with one click and no review step. Nothing about this looks like an AI system anyone would think to inventory. It's exactly the shape of system CalPrivacy's audit walks through in an afternoon: who can see the rating data behind a deactivation, how long someone waits to find out why they were cut off, and whether the dispatcher or the ranking algorithm is actually making the call. Read against the human-involvement test in what actually counts as ADMT, a dispatcher who has to leave the queue to override anything does not plainly have the authority the rule asks for, which means the algorithm, not the person, is the one deciding.
What to fix before an audit reaches you
- Inventory every automated system that decides who gets work, what they're paid, or whether their access continues, using the same four categories the audit itself names: dispatch, ratings, earnings, deactivation.
- Turn on decision logging now. A worker who challenges a deactivation eighteen months from now needs a record of what data drove it, not a system that overwrote the input the moment the decision fired.
- Check whether overriding the algorithm actually takes less effort than accepting its answer. If it doesn't, you likely have the same human-involvement gap the worked example does.
- Read your careers page's privacy disclosure today, not after the ADMT deadline. It's the one piece of this that's already been fined.
- Build the pre-use notice and opt-out, or the human-appeal path that can replace it, for whichever of these decisions turns out to need one.
Not every automated scheduling tool fails the human-involvement test. A dispatcher with genuine, low-friction override authority may already clear it, and that's a cheaper thing to confirm than to guess wrong about. None of this requires running a gig platform either; it requires an honest look at whatever assigns work, sets pay, or ends access at your company. If you want a second read on which of your systems the audit's own categories would flag, tell us what the tool does, run it through our ADMT scoping checker, or get in touch to talk through the specific system.
Sources
- California Privacy Protection Agency (CalPrivacy): California Privacy Protection Agency Launches First Sectoral Audit, Targets Gig Economy Platforms (July 21, 2026)
- California Privacy Protection Agency (CalPrivacy): 2025 Annual Report (February 2026)
- California Privacy Protection Agency: Stipulated Final Order, In the Matter of Tractor Supply Company, Case No. ENF24-M-TR-04 (September 2025)