
Most dealers have heard of the California Consumer Privacy Act (CCPA), even if they have never done business in California. They know the law was the first of the now 23 state privacy laws that have granted broad rights to consumers in those states, generated a wave of website privacy lawsuits, and prompted businesses across the country to revisit their privacy policies. What many dealers do not realize, however, is that California has gone a step further than virtually every other state by creating a dedicated agency whose only job is enforcing the California privacy law.
That agency, the California Privacy Protection Agency (CPPA, a.k.a., CalPrivacy), is still relatively new. While it was created several years ago, it has only recently begun building the enforcement infrastructure that lawmakers envisioned. The agency has expanded its enforcement staff, continued issuing regulations, and recently established a dedicated Audits Division led by its first Chief Privacy Auditor. In other words, California is no longer simply waiting for privacy complaints to arrive, it is actively building an organization designed to proactively examine whether businesses are complying with the law.
A Dedicated Privacy Regulator
Unlike most state privacy laws, which are enforced by an Attorney General’s office juggling countless other responsibilities, California has regulators who wake up every morning with privacy compliance as their primary mission. That specialization matters because it allows the agency to devote resources to developing expertise, pursuing investigations, and now conducting audits of businesses that fall within the law’s scope.
You Don’t Have to Be Accused of Anything
Perhaps the most surprising aspect of the CPPA’s authority is that it does not necessarily need to suspect you violated the law before asking questions. The CCPA and its regulations (Cal. Civ. Code § 1798.199.40(f); 11 CCR § 7304) expressly authorizes the agency to conduct audits to determine whether businesses are complying with the statute. That means a business could be selected for an audit without first being the subject of a consumer complaint or a suspected legal violation.
In its first action of its kind, the CPPA’s audit division recently launched the first formal sectoral audit of gig economy platforms in July. That means that the division’s auditors are actively auditing businesses of all kinds in this sector, looking for compliance with the CCPA. There are unconfirmed reports of activity along similar lines with respect to dealers in California as well.
From the perspective of many businesses, that can feel a lot like a fishing expedition. Rather than responding to evidence of wrongdoing, regulators may request information about your privacy program, your data collection practices, your website technologies, your vendor relationships, your consumer request procedures, and your internal policies simply to evaluate whether your compliance program measures up. The agency would likely describe these audits as proactive oversight and an open dialogue, rather than investigations, but the practical reality is the same: regulators may come knocking even when you believe you have done nothing wrong – and what they find may become the basis of an enforcement action.
That authority represents a significant shift in how businesses should think about privacy compliance. Many organizations still view privacy laws as something that becomes important only after a complaint, data breach, lawsuit, or enforcement action arises. California’s audit authority flips that assumption on its head by giving regulators the ability to proactively examine compliance programs before anyone has alleged a violation.
California’s Reach Extends Beyond California
The enforcement landscape is becoming even more challenging because California is not acting alone. Privacy regulators around the country have become increasingly collaborative. One indication of that is the “privacy consortium,” that includes the California Privacy Protection Agency and state Attorneys General from California, Colorado, Connecticut, Delaware, Indiana, Minnesota, New Hampshire, New Jersey, and Oregon.
This effort has resulted in several privacy “sweeps” (discussed here and here) related to data brokers and website privacy functionality. Attorneys general in other states are leveraging these California resources to enforce their own state privacy laws. Information sharing, joint investigations, and coordinated enforcement efforts are becoming more common, meaning businesses should not think of privacy enforcement as confined by state borders. As agencies gain experience and begin working together, businesses may find themselves responding to coordinated regulatory scrutiny instead of isolated state investigations.
What an Audit Could Look Like
So what might an audit actually examine? While the CPPA has not published a dealership-specific checklist, public statements suggest regulators will focus on whether businesses actually comply with the promises they make. That includes evaluating privacy notices, consumer rights procedures, opt-out mechanisms, data retention practices, vendor management, and the technologies operating behind the scenes on a company’s website. In many respects, these are the same issues that have fueled the recent surge of website tracking litigation against dealerships, except that government regulators now have the authority to ask much broader questions about a company’s overall privacy governance.
Preparing Before the Questions Come
The emergence of the Audits Division also reflects a broader evolution in privacy regulation. California increasingly appears to be adopting a model more familiar in heavily regulated industries, where agencies do not simply punish violations after the fact but also examine compliance programs proactively. Financial institutions, for example, have long operated under examination regimes where regulators periodically review compliance systems. California’s privacy regulators appear to be moving in a similar direction.
For dealerships, the practical takeaway is straightforward. Privacy compliance should no longer be viewed as simply posting a privacy policy or updating website disclosures once a year. Dealers should understand what technologies are operating on their websites, what information is being collected, which vendors receive that information, how consumer requests are handled, and whether those processes actually function as intended. And you must be ready to demonstrate and describe these procedures for regulators.
Whether any particular dealership will be selected for an audit is impossible to predict. What is clear, however, is that California now has both the statutory authority and the organizational structure to conduct them. As privacy enforcement continues to mature—and as regulators increasingly cooperate across state lines—dealers must treat privacy compliance as an ongoing operational responsibility rather than a project that can wait until after the government comes calling.
How ComplyAuto Can Help
Preparing for a privacy audit starts long before an auditor comes knocking. ComplyAuto helps tens of thousands of dealerships nationwide operationalize privacy compliance by identifying the data and tracking technologies in use, managing consumer privacy requests and opt-out obligations, maintaining required disclosures, identifying their vendors and how they share data with them, and helping dealers document their compliance efforts. With regulators increasingly focused on whether businesses can demonstrate compliance, having a structured privacy program in place can make a significant difference. Contact ComplyAuto today to learn how we can help your dealership prepare for this new era of proactive privacy enforcement.