What an audit actually tests
A useful CCPA compliance audit compares what the company says with what its systems do. That means tracing personal information from collection through storage, sharing, and deletion, and scanning websites and apps with tools that show which trackers fire and where the data goes. California regulators have focused on whether opt-out requests and browser privacy signals are honored in practice and whether consent screens steer people toward one choice. Consumer request handling is tested by following sample requests through each step, including identity verification and the final reply. Employee, job applicant, and business-contact data belong in the review too, since the law covers them.
Newer audit and assessment rules
The California Privacy Protection Agency has adopted regulations requiring some businesses to perform cybersecurity audits and risk assessments and addressing the use of automated decision-making technology, with obligations phased in over several years based on a business's size and activities. Whether and when they apply to you depends on thresholds and dates that should be checked against the current text. A general privacy review does not automatically satisfy these formal requirements, which carry their own rules on independence, scope, and reporting. Still, an internal audit is a sensible moment to prepare, because the data inventory and vendor review it produces are the foundation for the formal work.
Running the audit
Scoping comes first: which entities, brands, websites, and data sets are included, and whether other states' privacy laws should be covered in the same pass. Engaging the review through counsel can help keep candid findings protected, although privilege depends on the purpose and structure of the work and never covers the underlying facts. Findings should be ranked by enforcement exposure and by the cost to fix, not simply listed. Our starting conversation covers any existing data map, the vendors with access to personal information, consumer complaints or regulator letters already received, and who inside the company will own the fixes once the audit ends.