Skip to Content

What to expect from CalPrivacy's Audits Division

In an exclusive interview with the IAPP, California Privacy Protection Agency Chief Auditor Sabrina Boyson Ross discussed her outlook on the unit's process and the misconceptions around its role.

Published
Subscribe to IAPP newsletters

Contributors:

Joe Duball

News Editor

IAPP

Since its establishment in 2020, the California Privacy Protection Agency has made headlines with its enforcement work and rulemaking under the California Consumer Privacy Act and the Delete Act. That work will remain prominent in the years to come, but the efforts of CalPrivacy's Audits Division will become an equally crucial part of the agency's anatomy.

CalPrivacy Chief Auditor Sabrina Boyson Ross was appointed in February and has been building up the unit's personnel and processes since, leading to the launch of the division's first formal sectoral audit of gig economy platforms in July. CalPrivacy characterizes its audit authority as "an opportunity to identify risks and vulnerabilities and agree upon remediations, shed light on strong practices, and publish sector trend reporting that can inform the public."

In an exclusive interview with the IAPP, Ross highlighted that while her unit's work may lead to enforcement actions, its objectives focus more on fact-finding and creating a base knowledge of current privacy practices that can be useful to a range of stakeholders, including companies and legislators.

"We can take a proactive approach to understanding the state of compliance," she said, noting her team can be broad with its reviews in order to glean important compliance trends. "There's a public education piece that I hope we can fulfill."

Ross has seen the maturation of privacy practices firsthand since breaking into the space in 2009. She held prominent privacy roles at Apple, Meta, Uber and Nauto while also working as outside counsel prior to that.

The wide-ranging experience gives her a unique perspective in the move to the regulatory side. An "appreciation for what it means to do privacy well" is one aspect to support her role, but the hands-on experience in the compliance trenches will be crucial.

"It all helps me know where to look," she said. "I know where things are kept and what documents to look for. It informs hopefully a sophisticated approach to audit."

Audit overview

Reasons for opening an audit against a given company is a multifactored process outlined in the CCPA. Ross boiled those factors down to recognizing areas of potential harm, highlighting the gig economy audit opened due to the "intersectionality with privacy rights and access to economic rights."

A majority of companies Ross and her team have reached out to thus far have immediately tried to decipher the audit's connection to potential enforcement. However, she characterized the initial correspondence as "reaching out for a friendly one-on-one" with the aim to establish the intent of the interaction.

Then comes the "nuts and bolts," which are typically outlined in a formal introduction letter. Those preliminary inquiries include document requests, interrogatories or requests for interviews

"We encourage (inquiries) to be a conversation with companies because we really are looking for the most efficient way to get to a shared understanding of the facts," Ross said, adding there are "creative" ways to achieve that understanding but they only come through open dialogue.

The initial collection of facts and materials spur follow-ups, ranging from questions to testing. A draft report with findings and remediations is then sent to the company, which can then discuss the areas of agreement and disagreement with the auditor's assessment before a report is finalized.

While individual reports will not be made public, findings from sectoral reports will be made available. Ross said those reports will cover any noteworthy discoveries, including "broad strokes of phenomenal practices" and "trends in (areas of) improvement."

Ross indicated her team breaks along two lines — between auditors who are "deeply expert in process" and technologists. However, she envisions a "diversification" in subject expertise over time, specifically with automated decision-making technology rules and cybersecurity audits on the horizon.

Technologists play a unique role for the unit, with Ross indicating any technical testing the team may need to carry out is arguably the most complex component of any audit.

"Understanding the technical testing that is available to us in certain areas is deeply exciting and somewhat novel," she said. "There's a lot of interesting ground to be laid there."

As an example, she highlighted how her unit must weigh the pros and cons between testing techniques. She mentioned black box testing — evaluating a given system's external behavior, outputs, and data flows without prior knowledge of its internal code or overall design — versus real-time testing accounts among the considerations.

With regard to what trends audits might uncover, recurring themes and blind spots can vary. Calling back to her in-house and outside counsel experiences, Ross said employee privacy matters are a key area that might go overlooked and subsequently called out in an audit.

"I think companies aren't necessarily used to thinking about it (employee privacy) quite as deeply," she said. "It's not as extensively regulated as consumer privacy. It's like there's a change, in part because of AI and lots of other reasons, in how much attention is being paid to employee privacy."

Current agenda

The gig economy audit is top of mind for the Ross team, but it won't take all of the unit's attention. The Audits Division has full staffing now and is capable of performing multiple audits at once.

She will cover more specifics about the first sectoral audit in her inaugural presentation to the CalPrivacy Board at its 7 Aug. meeting. That discussion will also brief board members on other insights from Ross' first six months on the job.

"Everything from hiring and infrastructure to our foundational approach. What is our theory of how we prioritize audits? What do we have currently public?" Ross said. "I'll talk a little bit at the end about where we're going, which is more like building capacity on the cybersecurity audits and their risk assessments, and some other trajectory thoughts for the division."

An additional point of conversation with the board will be a new request for information from the Audits Division on data inference and reidentification capabilities of emerging technologies. CalPrivacy described the RFI, opened 5 Aug., as seeking technical input toward "a deeper understanding of inferences that may be probabilistic, latent, or emergent from model behavior rather than explicitly designed outputs" and details on "new vectors for reidentification."

"This is an effort to ensure that we have really high connectivity with the research community in areas that are evolving really rapidly," Ross told the IAPP. "It will help develop audit methodologies that are responsive to new technologies, where inferences may not be labeled as explicitly, etc. I would hope it'll be the first in a series. I could envision doing one on how AI is changing cybersecurity and have that on technologists' radar as folks are starting to prepare for cybersecurity audits."

The first compliance wave for the three-tier cybersecurity audit framework begins 1 Jan. 2027. Organizations with more than USD100 million in annual gross revenue are staked to that first compliance date while the other phases begin January 2028 and 2029.

The Audits Division will use the coming months to buildout the audit submission portal and a sample methodology for covered entities to consider ahead of the compliance deadline. That work comes with balancing existing audit work with personnel allocations, on which Ross is laser-focused.

"Once we request to companies to receive the underlying cybersecurity audit, I believe they have 30 days to provide the documentation. I'll have to do some workflow assessment of how time intensive that is," she said. "It's a very different style of audit and oversight, so I am deep in resource assessment mode of what is feasible when we're we're expecting many thousands of submissions."

CPE credit badge

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.

Submit for CPEs

Contributors:

Joe Duball

News Editor

IAPP

Tags:

EnforcementProgram managementRisk managementTesting and evaluationCCPA/CPRAPrivacyAI governance

Related Stories