privacyhow-to

What California's Privacy Audit Found About Delivery Apps

CalPrivacy's first formal audit targets gig economy apps, revealing what Uber and DoorDash know about you — and what your CCPA rights let you delete.

On July 21, 2026, the California Privacy Protection Agency announced its first formal compliance audit under the California Consumer Privacy Act. The target: gig economy technology platforms — app-based transportation, delivery, and task services operating in California. The platforms under review include services that collectively operate in the daily lives of tens of millions of people who use them without a clear picture of what data they collect, how long they retain it, and who they share it with.

The audit matters for reasons beyond California. It’s the inaugural action from the CPPA’s new Audits Division, operating under authority the agency has held since 2023 but has now formally activated. The audit announcement — which describes what the agency plans to scrutinize — provides the most specific public accounting yet of what these apps know about the people who use them.


What Gig Economy Platforms Actually Collect

When you open a delivery or rideshare app and place an order, you see a simple transaction: you request something, someone brings it, you pay. The data infrastructure running beneath that transaction is considerably more detailed.

Precise location data, continuously. Navigation and delivery apps need your location when you’re actively using them. Many also collect it at other times. Background location access lets platforms understand your home address, workplace, and the neighborhoods you frequent — all inferred from movement data collected over months or years, not just while a delivery is in progress.

Identity documentation. Services that verify identity — driver onboarding processes, age verification for alcohol delivery, background check procedures — collect government-issued identification documents. Once uploaded, these documents are retained. The specific retention periods and whether scanned documents are stored in a form that creates risk in a data breach vary by platform.

Payment and financial data. Credit and debit card numbers, bank account details for worker direct deposit, purchase history, and spending patterns. For frequent users, a delivery app’s payment history is a detailed record of purchasing behavior going back years.

Communications. Many gig platforms record and retain communications between users and workers — the chat messages in the app, in-app calls, delivery instructions. These records exist in platform databases and are accessible to law enforcement through standard legal process.

Behavioral and performance data for workers. For people who work on these platforms, the data collection is extensive: acceptance rates, completion rates, customer ratings, tip amounts, time spent in the app, number of orders declined, geographic range, peak earning hours. This performance data drives the algorithmic systems that determine order routing, deactivation risk, and earnings opportunities for each worker.

Inferred attributes. Platforms may infer demographic information, lifestyle patterns, and purchasing preferences from behavioral data. These inferences don’t require asking the user a single question; they’re derived from the patterns in collected data. Whether these inferences are accurate matters less than whether they affect how the platform’s algorithms treat you.


What the CPPA Is Examining

The CPPA’s audit will evaluate whether platforms are complying with CCPA’s core requirements. The agency announced it will examine:

Data subject request responses. Under CCPA, California residents have the right to know what personal information a company holds about them, the right to delete it, the right to correct it, and the right to opt out of its sale. The audit examines whether platforms respond to these requests within the required 45-day window, whether responses are complete, and whether the opt-out mechanisms actually function as described.

Worker privacy rights specifically. The CCPA applies to any California consumer — not just customers of a business. The audit explicitly extends scrutiny to whether platforms honor privacy rights for workers, not just passengers or delivery recipients. This inclusion is significant: gig workers generate some of the most sensitive data on these platforms, including their precise location at all times during work, their performance metrics, and potentially their financial situation derived from earning patterns.

Purpose limitation. CCPA requires that personal data be used for the purposes disclosed at collection. If an app collects location data “to provide navigation,” it may not then use that data to train an algorithmic model used for pricing decisions or deactivation without disclosing this secondary use. The audit will examine whether the purposes stated in privacy disclosures actually match the purposes for which data is used internally.

Data retention practices. California law doesn’t prescribe specific retention periods, but it requires that data not be kept “longer than reasonably necessary for the disclosed purpose.” The audit will examine how platforms define reasonable retention periods for each category of data they collect — particularly for data about completed transactions and historical location records.

Third-party sharing. Gig platforms share data with significant numbers of third parties: payment processors, background check services, insurance companies, advertising partners, analytics providers, and in some cases law enforcement. The audit examines whether sharing practices are accurately described in privacy disclosures and whether the appropriate safeguards are in place.


Exercising Your Rights Against These Platforms

If you’re a California resident, CCPA gives you actionable rights against any of the platforms being audited. Here’s how to use each of them.

Right to Know

You can submit a “request to know” asking a platform to disclose:

  • What categories of personal information it has collected about you
  • The specific pieces of personal information it holds (in a portable format you can review)
  • Where that information came from
  • The business purposes for which it was collected
  • Which categories of third parties it has been shared with

Major platforms maintain privacy portals or have published specific email addresses for submitting these requests. Uber, DoorDash, Lyft, and Instacart all maintain user-facing data access tools, either in their app settings under a privacy section or linked from their privacy policy pages. Platforms are required to respond within 45 days, with one possible 45-day extension if they notify you.

When you receive the response, the volume of data often surprises people. A multi-year user of a rideshare app can receive a file containing hundreds or thousands of individual trip records with precise pickup and dropoff coordinates, every in-app message sent and received, every rating given and received, every search query, and every payment method linked to the account.

Right to Delete

You can request deletion of your personal information. The platform must delete it from its active systems and instruct service providers holding the data on its behalf to delete it as well. Some statutory exceptions apply — data needed to complete a pending transaction, data required for security purposes, data the platform is legally required to retain — but a deletion request triggers a real obligation to remove what isn’t legally required to be kept.

One important distinction: deleting your data is separate from closing your account. Closing an account typically triggers account-level data removal, but not always comprehensive deletion of all associated data from all systems. A formal deletion request under CCPA is the mechanism that creates a specific legal obligation with defined exceptions and required timelines.

Right to Opt Out of Sale or Sharing

If a platform is “selling” your personal information or “sharing” it for cross-context behavioral advertising — which under CCPA includes making it available to advertising networks for targeting purposes — you can opt out. Look for a “Do Not Sell or Share My Personal Information” link, which CCPA requires to be accessible from the platform’s homepage.

California residents can also send a Global Privacy Control (GPC) signal, which browser extensions and privacy-focused browsers can transmit automatically to every site you visit. Platforms subject to CCPA are legally required to honor the GPC signal as an opt-out from sale and sharing. This is a more automated approach than submitting individual opt-out requests to each platform separately.

Right to Correct

If a platform has inaccurate personal information about you — an address on file that’s outdated, an incorrect date of birth, a payment method linked to the wrong person — you can request correction. This is distinct from the right to delete: you’re asking for accuracy, not removal.


What the Audit Might Actually Produce

Formal compliance audits create pressure before any violation is found or any penalty is issued. Companies under audit typically accelerate internal reviews of their data practices and make changes they’ve been deferring, because demonstrating compliance during an audit is easier than defending a finding of non-compliance after it.

For consumers and workers, one predictable effect of this kind of regulatory attention is improved data subject request handling. It’s easier for a company to demonstrate compliance by showing functional, complete request workflows than by arguing that inadequate workflows meet the standard. The first formal audit tends to improve request handling not only at the companies directly audited but across the sector, because similar companies assume they could be next.

The CPPA has indicated this is the first in a planned series of sectoral audits, with more categories to follow. Gig economy platforms were selected as the first target partly because they collect an unusually wide range of sensitive data — location, identity, financial information, communications — and partly because the worker-versus-consumer distinction makes them an interesting test case for how CCPA’s consumer protection framework extends to non-traditional relationships.


The Broader Pattern: Consumer Rights in Commercial Relationships

The gig economy represents a genuinely new kind of commercial relationship, and privacy law has been slow to catch up to it. Traditional consumer protection frameworks focused on protecting customers from business practices. Gig platforms have large populations of people who are simultaneously customers and workers, and the data collected about them in both roles creates different regulatory considerations.

The CPPA’s explicit inclusion of worker privacy in the audit scope signals that California is treating the customer-versus-worker distinction as less important than the underlying privacy interest: a person generating sensitive data on a platform has rights over that data regardless of whether they’re receiving a service or providing one.

What doesn’t follow from the audit, on its own, is any obligation on platforms to limit what they collect in the first place. The CCPA framework is primarily a rights-based approach — you can know what’s been collected, you can delete it, you can opt out of sale — rather than a data minimization mandate. The audit won’t necessarily produce findings that platforms collected too much data; it will produce findings about whether platforms honored the rights they’re legally required to provide over data they collected.

For users who want to limit collection rather than manage data after it’s been collected, the most effective steps happen before or during app use: reviewing location permissions before granting them, using location access only when strictly necessary, being deliberate about which services you connect to the platform, and periodically submitting deletion requests for historical data you no longer need the platform to retain.


Why the Announcement Itself Is Useful

Even before the audit produces findings, the announcement is informative. The categories of data practices the CPPA chose to examine — data subject request responses, worker rights, purpose limitation, retention, third-party sharing — are a regulatory checklist of the practices most worth scrutinizing in any data-intensive consumer platform.

You don’t have to wait for the audit findings to apply that checklist yourself: submit a right-to-know request to the gig platforms you use and see what comes back. Review what data they say they retain and for how long. Check whether the purposes they describe for data collection match your intuition about how the platform actually uses information about you.

The CPPA designed the audit to answer those questions at a regulatory scale. You can answer them at a personal scale right now.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts