Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The terms authorize Progressive to act on any instructions submitted under a user's credentials, disclaim liability for unauthorized access except where caused by Progressive's gross negligence or intentional misconduct, and reserve the right to block site access without prior notice.
This analysis describes what Progressive's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that Progressive bears no liability for credential-based unauthorized access except in cases of its own gross negligence, and that Progressive may suspend account access without prior notice at its discretion, creating operational exposure for users who rely on site access for account management.
Interpretive note: The enforceability of the liability disclaimer for ordinary negligence-related unauthorized access depends on applicable state data security and insurance regulatory frameworks that may impose independent obligations.
Under these terms, Progressive may act on any instructions submitted under a user's login credentials and may block site access without advance notice; the agreement disclaims Progressive's liability for unauthorized account access unless directly caused by Progressive's gross negligence or intentional misconduct.
Cross-platform context
See how other platforms handle Password Registration and Account Security and similar clauses.
Compare across platforms →Monitoring
Progressive has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Progressive is entitled to act on instructions received under your User ID and password. Progressive is not liable for any unauthorized access to your personal information that is not the direct result of gross negligence or intentional misconduct on the part of Progressive. You will keep your password confidential and you will notify Progressive immediately if you believe someone else has obtained your User ID and password or any unauthorized access to the online service site has occurred or may occur. Progressive may block access to the online service site without prior notice if we believe your User ID and password are being used by someone other than you, if any unauthorized access to your personal information has occurred or may occur, or for other reasons.Excerpt from Progressive's Terms of Use
1. REGULATORY LANDSCAPE: State insurance data security laws, including statutes modeled on the NAIC Insurance Data Security Model Law, impose affirmative obligations on insurers to implement information security programs that protect nonpublic information. These statutory obligations operate independently of the contractual liability disclaimer and may require Progressive to maintain security standards beyond what the disclaimer suggests. The Gramm-Leach-Bliley Act's Safeguards Rule may also apply to insurance-related consumer financial data. 2. GOVERNANCE EXPOSURE: Medium. The combination of acting on credentials without additional authentication verification and disclaiming liability for unauthorized access except for gross negligence creates potential exposure in account takeover scenarios. Regulatory frameworks governing insurance data security impose independent obligations that may not be waivable through website terms. 3. JURISDICTION FLAGS: California's Consumer Privacy Rights Act and New York's SHIELD Act impose data security obligations that may limit the effectiveness of this liability disclaimer in those jurisdictions. Illinois and other states with active data security enforcement may similarly impose independent obligations. 4. CONTRACT AND VENDOR IMPLICATIONS: The clause authorizing Progressive to act on instructions received under any user credentials without additional verification is operationally significant for insurance policyholders who may have sensitive policy changes, payment instructions, or claims actions processed through authenticated sessions. 5. COMPLIANCE CONSIDERATIONS: Legal and compliance teams should evaluate whether the authentication mechanisms supporting Progressive's password-protected portals satisfy applicable insurance data security regulations and whether the disclaimer adequately discloses the scope of user responsibility for credential security under applicable state consumer protection and data security statutes.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes that Progressive bears no liability for credential-based unauthorized access except in cases of its own gross negligence, and that Progressive may suspend account access without prior notice at its discretion, creating operational exposure for users who rely on site access for account management.
Under these terms, Progressive may act on any instructions submitted under a user's login credentials and may block site access without advance notice; the agreement disclaims Progressive's liability for unauthorized account access unless directly caused by Progressive's gross negligence or intentional misconduct.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Progressive.