8 Total
0 High severity
6 Medium severity
2 Low severity
Summary

This document establishes State Farm's practices for collecting, using, and sharing personal information across its insurance and financial services subsidiaries. State Farm collects personal information including driving records, claim histories, credit information, and precise location data through its mobile app and telematics programs, and shares this information within its family of companies and with marketing partners. Customers may request limitations on the sharing of specific information categories within the State Farm family of companies by contacting 1-800-865-6035 or their State Farm agent.

Technical / Legal Breakdown

This document is State Farm's Notice of Privacy Policy, governing the collection, use, and sharing of 'customer information' (defined as all nonpublic personally identifiable information) across the State Farm family of companies, with stated compliance obligations under federal and state insurance privacy laws. The policy states that State Farm does not sell customer information and does not permit third parties acting on its behalf to use customer information for their own marketing, while the terms authorize sharing of customer information within the State Farm family of companies, with agents, consumer reporting agencies, marketing partners, and parties involved in business transfers, for purposes including underwriting, claims processing, fraud prevention, and offering additional products and services. A notable provision authorizes State Farm to develop anonymized or de-identified data from customer information and share it with third-party service providers or unaffiliated entities for analysis and commercial purposes, which is operationally distinct in that de-identification standards and downstream use controls are not specified in the document text itself. The policy engages the Gramm-Leach-Bliley Act (GLBA) and state insurance privacy regulations as its primary legal framework, with additional state-specific disclosures for California (CCPA), Nevada (do-not-call), Vermont (intra-family sharing restrictions), Washington, Illinois, and New York; the GLBA opt-out mechanism for intra-family sharing is present but the policy notes material limitations on the scope of that opt-out. Tracking technologies, precise location data collection via Drive Safe and Save and the State Farm mobile application, and the stated non-support for browser 'do not track' signals create additional compliance surface area under state privacy laws and FTC guidance.

Institutional Analysis

Institutional analysis available with Compliance

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Compliance.

Start Compliance free trial
Medium — 6 provisions
Low — 2 provisions

Monitoring

State Farm has updated this document before.

Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →

Compliance Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Compliance includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Compliance free trial

Cross-platform context

See how other platforms handle De-Identified Data Commercial Sharing and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
FCRA
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
GLBA
United States Federal
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured May 5, 2026 06:23 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000597
Version ID CA-V-001271
SHA-256 47dc16a2b94105aa5b0ddcb565585f0f6b0103844333f36f7c082536142ce056
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans