State Farm · State Farm Privacy Policy · View original document ↗

De-Identified Data Commercial Use and Third-Party Sharing

Medium severity Medium confidence Explicitdocumentlanguage Unique · 0 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for State Farm Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

State Farm can strip identifying details from your personal information and then share or sell that processed data with outside companies for business and commercial analysis purposes.

This analysis describes what State Farm's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

The standard applied to de-identification is described only as 'reasonable efforts,' which may not meet the specific technical thresholds required under some state privacy laws; data shared with unaffiliated entities under this provision falls outside the policy's stated non-sale commitment.

Interpretive note: The 'reasonable efforts' de-identification standard is not defined in the document, and whether it satisfies applicable state privacy law thresholds depends on jurisdiction-specific technical requirements and enforcement interpretation.

Consumer impact (what this means for users)

Your personal information may be converted into a form State Farm considers de-identified and then shared broadly with third parties for commercial purposes, with the specific de-identification standard and downstream use controls not detailed in this document.

How other platforms handle this

Lime Medium

We may share your information with third-party advertising partners to provide you with targeted advertising. We also work with third-party analytics providers who help us understand how users interact with our Services. These third parties may use cookies, web beacons, and similar tracking technolo...

Oura Medium

We process personal data you provide to Oura to enable third party integrations, services, features, and offerings. For example, with your permission, our Services may integrate with third-party services like Google Health Connect and Apple HealthKit, or those of our partners. Oura takes measures to...

HubSpot Medium

We may share your personal data with third-party vendors, service providers, contractors, or agents who perform services for us or on our behalf and require access to such information to do that work. We may also share your personal data with advertising partners to display relevant advertising to y...

See all platforms with this clause type →

Monitoring

State Farm has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
develop either anonymized data or de-identified data by making reasonable efforts to remove personally identifiable information so the information is no longer customer information. We develop this data for certain purposes, such as analysis to understand more about our customers and our industry, or for other commercial purposes as permitted by law. We share and use this data within our State Farm family of companies, with third party service providers, or with other unaffiliated entities.

— Excerpt from State Farm's State Farm Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

REGULATORY LANDSCAPE: This provision engages the CPRA, which defines de-identified data with specificity and imposes technical and organizational requirements; the policy's 'reasonable efforts' standard may not satisfy CPRA's de-identification criteria. The FTC Act's prohibition on unfair or deceptive practices is also relevant if consumers understand the non-sale commitment to cover de-identified data. State-level privacy laws in Washington, Virginia, Colorado, and Connecticut similarly condition de-identification exemptions on defined technical standards. GOVERNANCE EXPOSURE: High. The use of 'reasonable efforts' rather than a defined technical standard (such as NIST or ISO anonymization frameworks) creates regulatory exposure across multiple jurisdictions. If de-identified data is later re-identified by a recipient, liability questions arise regarding State Farm's adequacy of the de-identification process. JURISDICTION FLAGS: California creates the highest exposure given CPRA's explicit de-identification standards. Washington's My Health Data Act may apply if any de-identified data derives from health-related insurance information. Illinois and New York state privacy frameworks may also engage depending on data types involved. CONTRACT AND VENDOR IMPLICATIONS: Contracts with unaffiliated entities receiving de-identified data should be reviewed to confirm they include re-identification prohibitions and downstream use restrictions. The policy does not assert audit rights over recipient entities, which is a gap relative to some industry practices. COMPLIANCE CONSIDERATIONS: Compliance teams should document the specific de-identification methodology applied to confirm it meets the most stringent applicable state standard. Data mapping should track which customer data flows into de-identification pipelines and which third parties receive the output. Regular review of recipient contracts is advisable.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC holds enforcement authority over unfair or deceptive data practices for non-bank financial institutions, including representations about data de-identification and commercial sharing practices.
    File a complaint →
  • State AG
    State attorneys general in California, Washington, Illinois, and other states with consumer privacy laws have enforcement authority over de-identification practices that may not meet state-defined standards.
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
FCRA
United States Federal
FTC Act Section 5
United States Federal
GDPR
European Union
GLBA
United States Federal
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
State Farm Privacy Policy
Entity
State Farm
Document last updated
May 5, 2026
Tracking information
First tracked
May 7, 2026
Last verified
May 9, 2026
Record ID
CA-P-007555
Document ID
CA-D-00597
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
f2ccf7b683bd01b58b07475a3f1bd9b1cef53966b7e4e17b8f3596adbeb0120b
Analysis generated
May 7, 2026 08:30 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: State Farm
Document: State Farm Privacy Policy
Record ID: CA-P-007555
Captured: 2026-05-07 08:30:05 UTC
SHA-256: f2ccf7b683bd01b5…
URL: https://conductatlas.com/platform/state-farm/state-farm-privacy-policy/de-identified-data-commercial-use-and-third-party-sharing/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Related Analysis

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does State Farm's De-Identified Data Commercial Use and Third-Party Sharing clause do?

The standard applied to de-identification is described only as 'reasonable efforts,' which may not meet the specific technical thresholds required under some state privacy laws; data shared with unaffiliated entities under this provision falls outside the policy's stated non-sale commitment.

How does this clause affect you?

Your personal information may be converted into a form State Farm considers de-identified and then shared broadly with third parties for commercial purposes, with the specific de-identification standard and downstream use controls not detailed in this document.

Is ConductAtlas affiliated with State Farm?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by State Farm.