What is a privacy tabletop exercise? How to prepare for CalPrivacy audits

In the latest Privacy Huddle, Colleen Barry is joined by Alysa Hutnik, Partner at Kelley Drye and a go-to voice on California enforcement, to unpack CalPrivacy's first sectoral audit of gig platforms—and what it really means for privacy rights readiness. They get practical on privacy tabletop exercises: how to pressure-test your program before an audit request lands.
stream this episode on

Summary

CalPrivacy's first sectoral audit — aimed at gig economy platforms and framed around privacy rights fulfillment — is less a one-off headline than a signal that audit-driven scrutiny is becoming a standing feature of California privacy enforcement. The agency already has an audits division and a chief auditor, and the authority to examine how companies intake, process, and fulfill consumer (and worker) privacy rights is broad. Reading the press release narrowly as “access requests for gig platforms only” understates the likely scope: end-to-end rights handling, including opt-outs and Global Privacy Control, and readiness to demonstrate how those obligations actually work in practice.

For in-house teams, the practical response is to treat an audit request as foreseeable and to prepare before one arrives. That means building a demonstrable privacy program story — policies, processes, checklists, training, stakeholder roles, and evidence — rather than scrambling to assemble fragments under a deadline. Privacy tabletop exercises, borrowed from the cybersecurity playbook, are a concrete way to pressure-test that story: start small (for example, opt-out flows), involve an objective reviewer, find gaps without panic, and expand to other risk areas over successive quarters.

Preparation also has spillover value beyond CalPrivacy. Strong documentation and operational controls help with investigations, demand letters, and litigation discovery risk, while cross-functional buy-in (especially from marketing and other fast-moving teams) is easier when framed as unlocking data use safely. Frequency should scale with company size, complexity, and data risk — annual or quarterly deep-dives on priority topics often beat a single mile-wide exercise. As regulators staff up and sectoral audits continue, companies that can show a durable, risk-based compliance narrative will be better positioned than those relying on minimum viable privacy.

Transript

Colleen

Alright. Good morning, Alyssa. How are you doing today?

Alysa

Good morning. TGIF.

Colleen

Absolutely. I'm excited it's Friday too. Folks, in case you are noticing my background, I have a different background today. It's a lake life weekend for me in the Midwest.

I'm excited to soak it in. Weekends of summer are counting down. You must be excited. It's Friday too, Alisa.

Alysa

I am both excited, and I'm in DC where we've had crazy storms and hot humidity, and today is actually a beautiful day. So I am just I'm appreciating it.

Colleen

Good. I love it. Well, it's been another another week of headlines in the privacy community. And this week, we had a big one with Cal Privacy announcing their first audit. Alisa, was this one a surprise to you? You gotta be honest with us. Right?

Alysa

I'm on the hot seat. It was not a surprise. You know, by the time you get a press release, there are things that have been percolating. And if we just zoom out, this is an agency, the only agency in the whole country that has it's devoted to privacy, and it has a whole division that is focused on audits.

It hired a chief auditor six months ago. What was it gonna do? Of course. It has a reason to be.

We were going to get audits. And you know what? We have audits now. And I think there's a lot of hubbub about this first one.

This is just the first of of many going forward. And I think that's just the reality we need to accept and prepare for.

Colleen

Yep. Absolutely. Well, folks, we wanna spend this huddle breaking down the audit, talking about what it looks like when you might get a request, maybe ways to think about preparing for the risks associated or what they might look into. So let's let's get into it and break it down.

Obviously, I'm joined by one of my favorite guests here, Elisa Hutnick. And, of course, if you've been listening, this is the privacy huddle. My name is Colleen Barry, and the privacy huddle is our weekly show where we talk about privacy headlines, tips, tricks, best practices, you name it. So Elisa and I are hoping to have a fun conversation today about, audits and what it might look like.

So back to the news. Let's talk about this. So so the Cal Privacy has introduced their first audit. Alisa, can you break down for us what this one entails, what they're focused on, just kind of the headlines?

Alysa

Yeah. Sure. So one, I think it's always good to know, well, what is it what what authority does this does the agency in this division in particular have? Because when you get a multipage set of information and document requests that look like a a pretty heavy lift, I think the first question the first reaction is, can this be?

Is this is this do I have to do this? And the rules, the statute, and the rules in particular are really broad. The agency can audit to check if a company is complying with the California privacy protection the California all the acronyms. I'll be off of the suit.

I'm just gonna CCPA.

And so we're at the start of it. They've sent out they did the press release as we see, and they're focusing on the gig economy. But, really, they're looking at privacy rights flow. That's the emphasis.

There was certainly highlights of access requests and looking into that, but it's not limited to that. It's really about all the different private decent amount of all the different privacy rights, how our company is receiving them, intaking them, how are they processing them, how are they responding to them, how are they fulfilling them, including opt out, which we talk about a lot, including global privacy control. Right? It it's the gamut.

But I would say when I think of a privacy program, there's different buckets. And one of those buckets is privacy rights just collectively. And so I always think if I'm on the in house or the privacy practitioners seat, I'm thinking if I get one of these audits requests, what would I have to show for it? Right?

And are you ready to be able to show and do a strong demonstration of how you're addressing those obligations?

Colleen

Yeah. So let's bounce back to clarify the scope of this because I think that's interesting. Right? Historically, we've talked about that in the US now, especially in California, the number one most enforced priority seems to be opt out of sale or do not sell our share.

If you just read this press release, you think, oh, okay. So the first audit is on gig economy and gig platforms, and it's for access requests. If you just read the press release. Right?

But that you're saying is way too narrow to think about what she's actually after here or what the agency's after.

Alysa

This is where I pull on my, like, annoying lawyer hat. You gotta read the fine print. Yeah.

Nope. It's not just that one thing. We're we're looking at privacy rights, really kind of an end to end privacy rights experience, front end and back end.

Colleen

Got it. And Okay.

Alysa

Also just say, like, a few other little sprinkling type of issues that they seem to be curious about too.

Colleen

Okay. Makes sense. So let's talk about how this happens with the business. Right? It it was clear in the press release that this is just the first in many sectoral audits.

Right? So probably safe to say, don't ignore it. Don't see I oh, I'm not we're not a gig platform. I can ignore this.

Right? That's certainly not the case.

Talk to us a little bit about, like and you've been in this industry a long time, Alisa, whether it's Cal privacy audit, something else. Like, what does it actually feel like and look like if your company is investigated in this situation? What do you get?

Alysa

Right. What do you do? That kind of thing. Oh gosh. One, I always kinda feel like everyone's not it.

You know? Like, that that they don't they're just gonna count on, I am in the herd. Do not see me. There is nothing to see here.

I'm invisible. So, like, that's one. And I think there's a really strong embodiment of that feeling. So there's a shock and awe when you get an investigation and certainly now when you get an audit.

Like, there's just that process of, is this real? Oh, I have to deal with this. And so I will just say it's good not to be surprised. And so the more that a company can think about, we will get one of these.

You know? Odds are at some point along the way, I'd actually rather get the audit than the investigation, right, just because the whole premise of it is different.

So one, I think it's internally communicating. You are going to get one of these at some point. Step two is, well, wouldn't you rather figure out how you're gonna respond to this when you have the luxury of time and nobody actually putting a spotlight on your practices? And so in the same way with data security, we were doing tabletops and cyber audits and pen tests and all the types of things that you would give you could get confidence that you had a pretty robust program.

We are so much at the point now where the the MVP, the minimum viable approach to this is it just doesn't cut it. And really thinking about if you get one of these, truly, where would I find everything? Is it a race to go pull a little here, a little there, or do you have essentially an organized digital binder of these are the tenants of my privacy program? When I talk about privacy rights completion, let me think about the different components.

Who are the stakeholders? Where would I pull those? Is there a memorialized, demonstrable story to to show for it? And when you actually do that, I think you realize where there are gaps or sometimes there's just opportunities.

Oh, I you know, we we do that, but we don't have anything in writing to show for it. How it it would be a trust us. This is really happening. And so I think the exercise, you start filling in a lot of the details, and it just gets stronger as a result.

It becomes a program as opposed to ad hoc different types of practices.

Colleen

Yeah. Let's go back. Let's break this down a little bit back to what you said at first.

You know, seeing this news, if you're an in house counsel, you'd kinda let folks know this is happening, or this is what we might need to be prepared for. So, Alisa, if you were an in house counsel and you saw this news, would you be using this as an opportunity to kind of let your executive team know, like, we need to up our investment, or this is what's happening?

Or would would you be using this announcement as some kind of opportunity to get more attention on the issue?

Alysa

You would, but I also think I have such empathy for for the in house privacy role here because I think privacy lawyers have been saying for a long time, it's coming. There are all these laws. We have so many more states of laws. And then and there was a lot of investment initially.

And then a lot of companies maybe took their foot off the gas a bit because they weren't seeing necessarily the kind of headlines or mass exposure that they thought. And so everybody has needs. AI became really exciting. Let's go put the resources there.

And, you know, it's kind of the calm before the storm in a lot of ways. And so I think you don't wanna sound like Chicken Little and the sky is, know, everything. You but it is material to business risk. It's material to organization risk.

It's material to a lot of business opportunities, right, that are really critical critically reliant on how you're gonna use data. So I think there's a how do we speak to this internally? This is development, but what's the bigger picture? Right?

We this is a we have a data strategy as a company. So what is what are those risks? What are those material risks to our data strategy? Well, step one is, are we likely to have to defend our data practices?

What's the probability of that? What's the magnitude? What if it doesn't go right? What are the consequences reputationally, financially?

I think this upped the magnitude and upped the probability that you will have to explain that. And then take one step further. What is the output of an audit? Is all of that gonna be privileged?

How much of that is really a business compliance function? We see so much privacy litigation. We've talked about wiretap suits. How much do some of those documents become potential, if you're not careful, become potential just discovery gold mines?

And so I am I'm I'm thoughtful not just about the audit, but how do you prepare both internally, of course, to, like, raise culture, raise awareness of the issues. But what is what is the other opportunity plaintiff's attorneys are always looking for? You know, where is there some room there to to push? And I think you have to be really thoughtful and strategic holistically.

Colleen

Yeah. Okay. Interesting. So as we think about how an in house counsel would prepare, kinda gather these materials, so, like, as you were going into where's my binder? What's in my binder? How do I think about this?

I like a phrase that you've used in the past in terms of what the exercise looks like, right, and and that being think about what a privacy tabletop looks like for your organization or that exercise. And, for me, at least, that's a very familiar term or concept when it comes to cyber. Right? You hear that all the time in cyber doing a security tabletop.

Right? What does our organization do in the event of a breach? Right? At least from my perspective, I haven't heard it referred to as much in privacy, but I'd I'd love to know your perspective.

Do you think how many organizations are actually conducting privacy tabletop exercises these days?

Alysa

Not many. Okay. Right. They're they're not.

Colleen

A great idea. But yeah.

Alysa

I I mean, so I have done some, and I am very much a proponent and really recommending it left left, right, and center. But at the end of the day, it's do you have a program? And everyone's, yes. Yes.

I have a program. How do you show it? How do you demonstrate it? We have talked so much about when you're investigated and you have to really tell the story to the enforcer and tell the story and show even if it wasn't perfect.

Here, I had policies. I had processes. I had checklists. I had training. Stakeholders knew what their obligations were.

You are telling a story, and there's a whole lot of discretion on the other side. And the more compelling your compliance story is, then that really motivates. And so it's the same exercise for the audit. Right?

You are Right. What do I have? And having high confidence, you have all those pieces that you can connect together to make the puzzle make sense.

Colleen

So if an organization were thinking about, okay. Privacy tabletop, that sounds smart. I don't know if or when I'm gonna get one of these investigations.

What would be some initial practical steps you'd recommend to thinking about conducting that privacy tabletop exercise? Like, what stakeholders should be there in those first meetings, or how do we kind of fumble our way through it?

Like, what does that look like actually?

Alysa

So one, I you know, sometimes people get paralyzed by the idea of something just sounds so big or cumbersome or expensive or hard. And I would just throw that to the side and say, this is pressure testing. Whatever resources or limited resources or time you have, then, you know, start small and start figuring out one issue. Right?

We've talked about opt outs. What if you just did a really focused on what does our opt out compliance look like? And if we had to demonstrate it, do we have policies? Do we have compliance checklists?

Do I have training? You can work with outside counsel. You can work with the inside counsel. You can work with other kinds of professionals.

But at the end of the day, you want an objective view. You want the exercise of having to pull the different pieces that tell the story, and you want the objective view to review that and say, this was good.

This was not so good. Oh, I see an issue here.

And just know that if you're doing that, we're gonna see gaps. That's okay. You don't need to stick stick your head in the sand and, you know, worry about admission for finding a gap and fixing it. These these programs require so many different components to make it whole. And, of course, it's never gonna be perfect. So do the practice of finding the gaps and continually in a dynamic way, make it better over time, continually making it better. That is a pro that's realistic.

And it it's just it's it's really important to be able to tell your story in an effective way.

Colleen

Do you think it's gonna be possible for in house counsel to get buy in from other departments, like marketing or other, to participate in this kind of exercise, or do you think at first pass, just do it with your privacy team and then kind of extend out? Like, how do you think about steps to involving more of the organization or even if you'll get the buy in to do that?

Alysa

Yeah. So this is where I feel like as a parent, there's so many skills that I learned as being a parent where how do you motivate? And so, you know, I think of marketing teams and them wanting to move very fast on certain use cases. And we're doing the risk risk impact assessment.

We're trying to figure out what are the right mitigations. Some of that takes time. It's very factually intensive. Well, if we were to focus in on what does our compliance structure look like and get their buy in and training, you learn a whole lot of things along that way and start formalizing that actually can help you streamline certain things and unlock certain types of use cases that you can move faster.

So how do I get buy in? Help me help you.

Right? You want to do these things that are really important for really important revenue drivers. This is a way we can get there and manage that overall risk. It's a it's a meaningful risk mitigation measure to know that we've got the compliance infrastructure that matches the revenue generating infrastructure and that we've got some some apples to apples there.

Colleen

Yeah. Okay. That makes sense. What do you think as far as time commitment or frequency? What's the ideal situation that a privacy team is working up to with conducting or simulating these kind of audit instances?

Alysa

Yeah.

So we have a lot of historical guides that I think are really important.

You know, we these are new laws. It's a new development. We always think we're reinventing the wheel. You know, it's it's a whole new thing.

And I go back to think of consumer protection where it was always about size and scale and complexity of the company. And so on your sliding scale, the bigger, the more complicated, the more risk in then there's gonna be some higher expectations, and you're probably gonna wanna do something on a more frequent basis. But I would also focus on what kind of data, what kind of practices we have from a what are most concerning from a privacy standpoint and prioritize that. If they stay the same and you've got really robust controls, then that would argue you don't need to do it as frequently.

You know, maybe it is an annual thing. Maybe it's a quarterly thing, but we keep it really focused and narrow and just hit a few bunch of different areas. Instead of going kind of the mile wide, go go pretty deep on a few priority topics and then continue doing that over time. Right?

That is you're you are building the house as you go along. Right. It doesn't have to be done overnight.

Colleen

Yeah. And that's occurring to me as you talk too. Like, maybe one quarter, you're like, let's let's get the tabletop done this quarter, and let's just focus on the opt out flows. And then next quarter, we'll do something else. Right?

If you could break it down into those narrow issues.

Alysa

Right. And I just always say, what are the benefits that come along with this? We've talked about wiretap and litigation risk. Well, if you do it here, you're also probably helping yourself in mitigating other types of risk risk.

So where can I get a lot more value and benefit from the exercise other than just, yep? Let me check the box. I've done the audit. There there's a whole lot I think that that you can really, appreciate and be able to say, this is the ROI from that exercise.

Colleen

Yeah. There truly are so many reasons to do it now. Right? It's not just how privacy said the magic word audit. Right? And now, I mean, look at the litigation landscape.

Right. That's almost even more reason to do it. I don't know about you, Alisa, but when we speak with prospects, you know, potential customers coming in to Ketch, the demand letters are still the number one kind of fire drill topic that we see over concern about these regulations.

Alysa

And that continues to cause a whole lot of confusion as to what do they need to do that's right. I mean, I still see fixes that I see are problematic. So, I mean, in the era of confusion and not necessarily getting clear and constructive advice, we are still all over the map. And so that's just that is an area. I'm gonna not pass the opportunity to say, get sophisticated on it. If you want to make sure that you've got the best posture you can, that's also practical.

Colleen

Yeah. Absolutely. So, back to Cal privacy, I mean, this is the first sectorial audit announcement. I gotta say, from my perspective, it's the timeline here is so fast compared to you know, like, I think about when CCPA first passed and then how long it took to see enforcement, and then they hired their first chief privacy auditor, and now we already see the first audit announcement. I I think you can see that that agency, they're just the speed is increasing at a crazy rate. Right?

Alysa

Right. Yeah. Resources. Right. It's priority, and there have been resources, and they are they're set up now.

Colleen

Yeah. Exactly. Which we've been seeing at the conferences the last couple years. Right? For for eighteen months now, every regulator has been raising their hand saying, yes.

We are trying to hire technologists. Yes. We are trying to hire more people. So now it's happening.

Alysa

Exactly.

Right. And just to be clear on that, they are hiring, but they're also using contracted ones too. So I just think from a staffing up and how they are supported for enforcement and audits, again, this is a priority, and they they've got they've got the manpower, female power all behind them being able to push forward.

Colleen

Exactly. So, I mean, I have to ask you to put your predictor hat on, Elisa. I mean, you can you can say no comment if you want, but, like, there's gonna be more sectoral audits coming out, I think, pretty soon. Right?

Alysa

I don't think we're gonna see a stop to this clip if you ask me. I don't think we're gonna see a stop to it, but what's helpful coming out of it, I think we're actually gonna see some guidance. Because that's part of, I think, one of the real challenges on the enforcement side.

We can glean from the settlements, but they're not there to do underground rulemaking. And so there is a hunger for what's enough, what's sufficient, how is the agency interpreting things. And so I I think getting outputs from the audit division are gonna be really helpful to industry to lift compliance and lift awareness of what we need to do. And I think as we hit each of these different topics, that's really gonna help.

And and nobody's heard from Sabrina. Right? Like, I've had discussions. Various folks have had, like, your one on one discussions.

Colleen

I am so excited that she's gonna speak October fifteenth at our US privacy summit event. So that's you know, it's just a really great opportunity to like, what is she thinking? How is she running that division? What are some of her priorities?

Are some of her inputs that really motivate some of those priorities? I'm really interested in to to just have that discussion and hear what she has to say.

So true. The timing could not be more perfect, folks. Like, at the US privacy summit on October fifteenth in San Francisco, Sabrina Ross is gonna be on stage in a one to one fireside chat, for this great one day event. So we will make sure the link is in the comments.

You must register if you haven't yet. It is a free one day event packed with industry leaders, regulators, all that kind of stuff. All you need to do is get yourself there. So, folks, we would love to see you at the US privacy summit.

You must must attend.

Just fantastic. Yeah. I I I, it's it's very interesting to see. I was speaking with, a head of internal in cow in house counsel at another event a few weeks ago, and he was lamenting kind of what you're saying, Alisa, with in other areas of law, there have been so much so much more history and examples of orders and settlements and things and so many more examples of this is how you do it.

This is what you do. And he was just lamenting, like, even though we have seen an increase in the clip of orders, there's still not that much to go off of. And so he's, like, hungry for more examples of Yeah. What do these regulations mean.

Alysa

I hear that, but so many of these enforcers, they've been enforcing unfair deceptive trade practice laws for for many, many And we've got so many settlements and so much so much to pull from to really interpret and really think about how they are likely to to look at certain obligations. So I would just I would continue to not have a narrow view and think about what is analogous, what really helps motivate how they're gonna look at it, and then really pressure test. Are you sometimes we we form a conclusion because of denial because it can't be. We don't want that that outcome. And I would caution.

Let's not do that. And maybe it sounds very daunting, but there's always some practical ways, really reasonable risk based ways to approach what we think is actually the durable strategy as to complaints.

Colleen

Folks. Great. I love it.

And I agree. There's ways to make this practical in small steps and just just bite off pieces at a time. And there's there's so much just practical, I think, knowledge you can apply to these things. You don't have to have everything spelled out perfectly.

Alysa

Right. I will I will tell you, years ago, I had an FTC investigation and, you know, messy breach.

Things were not perfect, But they were able to just show truly policies, procedures, meaningful training, that there was monitoring, that there were internal audits, and there was, you know, there were some things that got let not perfect, but they detected it. They remediated it. There was essentially a look back. How do we make sure this doesn't happen again?

And we could tell that story, and that was informally closed. The it it was enough to really motivate the enforcer to say, alright. You know what? This is not a good use of our resources to really escalate this.

And I you don't know that that's ever, like, gonna be the outcome, but you can certainly set the odds in your favor to do all the things in your control, and that is prepared.

Colleen

I love it. Well, Elisa, thank you as always for spending the time with us. Such a great chat. Folks, if you haven't I found this conversation very enlightening. If you haven't thought about what a privacy tabletop could look like for your organization, I think something to consider. At least the exercise of it will help you think about how prepared you are on these issues.

We'll drop some resources in the comments, folks. As I mentioned, these are conducted often in cyber, and so I think there's a lot of resources out there already for how to cobble these things together in the early paces, and no reason we can't apply some lessons from other industries that have been around a lot longer than consumer privacy.

So, Alisa, thanks for joining us. Any final words of wisdom?

Alysa

Oh, what's gonna happen next week? You know? I no wisdom. Just me managing my whiplash and just with PowerBar and staying hydrated and and ready.

You know? We're this is an exciting time in the privacy space, and I just I have optimism. I know a lot of folks are stressed, and some folks can get burned out really easily by all of the the activity. But at the end of the day and I feel it really at the summit.

Like, this community, I just don't think that there's a better community. It's really smart, really thoughtful group of people who really wanna do the right thing. So I'm I'm excited.

Colleen

There is something so cool about everybody had to learn together in this community. Yes. Right?

Like, everyone started the same Right. Right.

Yeah. And so it I think it it afforded so many people an opportunity to, like, move into this new area right as the laws were forming and and just, like yeah. So because of that, it's become so diverse and communal, and it's really nice.

Alysa

I love it.

Colleen

Yep. Yeah. Me too. Well, Lisa, it's been a pleasure. Folks, hope you learned something. We'll drop some resources in the comments, and everybody have a good one. See you next time on the private Seattle.

Subscribe
to the
Ketch Up newsletter

Trend watching, best practices, case studies, latest Privacy Huddles and more. Once a month, straight to your inbox:

Related episodes

view all episodes