What is Personal Information?
Personal Information is information about an identifiable individual. Personal Information includes facts, which, when combined with other information, can identify an individual. It can include:
- Contact information (name, address, telephone number, email address)
- Date of birth
- Marital status
- Information about your residence, like square footage or mortgage holder information
- Driver’s licence information
- Information about your vehicle and driving behaviours such as Vehicle Identification Number (VIN), prior accidents/highway traffic violations, if enrolled in our Drivewise program, time of use and driving activity (e.g. hard stops)
- Bank account information
- Credit card number
Personal Information does not include information that cannot identify an actual individual.
What Personal Information does this Policy apply to?
How is my Personal Information used?
The Personal Information we collect is used to:
+ Provide Products and Services
When you provide your Personal Information to Allstate, this allows Allstate to:
- Evaluate your coverage needs
- Assess risk and underwrite insurance risks
- Verify your identity
- Verify the ownership of real and personal property
- Provide a quote for insurance to you
- Send policy documents, renewal offers, policy change information, and any other administrative documentation regarding your policy or policies
- Process payment for your insurance policy or policies
- Communicate with you, solicit feedback regarding our products and services, and to respond to your inquiries
- Adjust and investigate claims, including the co-ordination of medical assessments and review of records containing Personal Health Information
- Settle claims
+ Comply with Legal Obligations
As an insurance company, Allstate must comply with applicable federal and provincial legislation and regulations. Various statutes and regulations have reporting requirements, which may require Allstate to disclose your Personal Information to government agencies or bodies.
+ Conduct Business Operations, Market Research and Advertising
Allstate collects Personal Information in order to:
- Provide secure premises for its customers, employees, and the public
- Manage and upgrade Allstate websites and apps
- Verify data, conduct data analysis, and compile statistics
- Determine premiums for insurance products
- Assess risk and consumer behaviour to understand current and future consumer interests
- Develop products, services, contests, and events
- Collaborate with strategic business partners via third party vendors to market insurance, auto, home and related products and services.
- Promote, advertise or market products, services, discounts, events, and contests offered by Allstate or companies with whom Allstate maintains business relationships
- Detect, prevent, and suppress fraud and other illegal activity
Special Note Regarding Personal Health Information
If Allstate collects Personal Health Information, as defined in law, either from you or from a Third Party with your prior written consent, it will be used for the adjusting and management of your claim. Allstate does not use Personal Health Information for any purpose other than in relation to a claim made by you.
How is my Personal Information collected?
+ From You
- Present interest-based ads to you;
- Present content relevant to your province of residence;
- Pre-populate data fields for you if you have previously entered information into that data field in the past;
- Analyze browsing behaviour to improve our online content
+ From Government Bodies and Law Enforcement Services
If you apply for insurance with Allstate, we may also collect Personal Information for verification and investigation purposes from government bodies and law enforcement services. Personal Information we collect from these sources may include:
- Motor vehicle records;
- Driving history records;
- Vehicle ownership records;
- Records regarding the identity and existence of lienholders, leaseholders, and mortgage holders;
- Motor Vehicle Accident records;
- Decoded provincial health insurance billing records;
- Witness statements
+ From Third Party Service Providers
Allstate may also collect Personal Information from third party service providers, including but not limited to:
- Industry data banks
- Third party websites where you have entered your Personal Information for the purpose of receiving an insurance quote or marketing materials
- Credit reporting agencies Property inspectors
- Healthcare providers
- Information technology support providers
- Claims Support and Investigation Services
+ Video Surveillance
For the safety of the public, Allstate customers, and Allstate employees, our premises may be outfitted with video surveillance systems. Video surveillance is collected strictly for security purposes and will not be disclosed to Third Parties unless required by law except in efforts to prevent fraud.
Can I withdraw my consent to the use of my Personal Information?
You may, at any time, withdraw consent to the use of your Personal Information, subject to certain limitations, which may vary depending on whether you are a current Allstate policy holder or have an ongoing claim with Allstate:
+ I Am Not Yet Insured With Allstate
If you are not already insured with Allstate and you withdraw your consent to the use and/or disclosure of Personal Information, Allstate will not be able to offer you an insurance policy.
+ I Am An Allstate Policyholder
If you are insured with Allstate, you may not withdraw your consent to the use or disclosure of your Personal Information contained on an Application for Insurance; Personal Information required for the administration of your policy; or Personal Information required for the processing of any claim(s). Allstate cannot continue to insure individuals who do not consent to the use and disclosure of Personal Information required in any Application for Insurance. Further, in order to adjust claims, Personal Information, including but not limited to Personal Health Information, may be required. Insurance legislation and/or regulation in your province of residence contain provisions which govern your obligation to provide information to your insurer in the event you make a claim for coverage from your insurer. This information may include Personal Information.
+ I Am No Longer Insured By Allstate and I Do Not Have Any Ongoing Claims
If you were insured with Allstate in the past and you do not have any ongoing claims, you can choose to withdraw your consent to the use and/or disclosure of your Personal Information after your policy has been terminated and any claims have been fully resolved. Please note, however, that you may experience inconsistency in your premium with future insurers because we will be unable to verify your previous Allstate policy and/or claim history during your insured term(s) with us.
+ Personal Information for Marketing and Advertising Purposes
You may withdraw your consent to the collection, use and disclosure of Personal Information for marketing and advertising purposes at any time, regardless of whether you are a customer of Allstate.
Any request for withdrawal of your consent must be in writing, sent to the Privacy Office.
27 Allstate Parkway Suite 100
Markham, ON L3R 5P8
To quickly and easily unsubscribe from future marketing e-mails, you can also click on this link.
Is my Personal Information disclosed to others?
We do not sell your Personal Information to Third Parties.
We may disclose Personal Information to the following Third Parties:
a) Other insurance companies
b) Consumer reporting agencies
c) Insurance industry databanks
d) Vehicle history databanks
e) Government bodies
f) Educational and research institutions
g) Benefit providers, contractors, and repair services
h) Adjusting, claims support, and legal service providers
i) Healthcare professionals and assessment facilities
j) Law enforcement agencies and/or bodies
k) Information technology support service providers
l) Payment processing providers
m) Telematics service providers
n) Select businesses with which Allstate maintains relationships or with whom Allstate has marketing agreements
Allstate may use affiliated service providers outside of Canada, including the Northern Ireland and India, who may have access to your Personal Information. Only individuals authorized to perform specified services will have access to your Personal Information.
Should there be a legal requirement, it is our policy to disclose Personal Information only when and to the extent legally required.
What measures do you take to ensure that my Personal Information is protected?
Allstate complies with all federal and provincial legislation regarding the collection, use, disclosure and protection of Personal information.
Allstate develops and maintains physical, procedural, and technical security measures to protect against theft, loss, and/or unauthorized access, use, alteration, destruction, or disclosure of Personal Information. These measures apply to our Corporate Head Office, agencies, storage facilities, and property.
The following are some examples of what we do to protect Personal Information:
Only Allstate employees have access to Allstate premises or property that contain Personal Information. All others must be escorted by an Allstate employee.
- Electronic devices, including computers and mobile devices, are password protected and passwords must be changed on a regular basis
- Before entering into agreements with Third Party Service Providers, Allstate evaluates whether security standards and data handling procedures satisfy its requirements.
- Allstate requires Third Party Service Providers that it contracts to enter into confidentiality agreements and/or agreements which have clauses concerning confidential information.
- Personal Information located offsite is stored in a secure location.
- Allstate premises are outfitted with surveillance cameras.
- Security audits are conducted on information technology systems on a regular basis.
What measures are in place to protect my information and/or address a concern?
Allstate has a Privacy Incident Response Process that is triggered when there is suspected privacy incident involving the loss, theft or unauthorized access, disclosure, copying, use or modification of Personal Information. The Privacy Incident Response Process is activated regardless of the source of the notification.
The Privacy Incident Response Process involves, but is not limited to:
1. The implementation of immediate additional protective action extending to all affected Personal Information;
2. Assessment of which teams, locations and business units should be notified and/or involved;
3. Investigation into the causes of the incident and the exposure(s) that have taken place and/or may have taken place.
4. Notification of affected individuals so that necessary changes can be made to prevent further unauthorized
How long do you keep Personal Information?
Our current Record Information Management Practices are under review. Our target completion date of this review is January 2019.
As part of our Record Information Management Practice Review, we are determining appropriate retention periods which consider legal requirements and the purposes for which Personal Information was collected.
Where is my Personal Information stored?
The majority of our records are stored in the province in which you do business with us. Personal Information that you provide when applying for insurance or when making claim is kept in a designated file or record specific to you.
Hard copy records may be maintained at our head office in Markham, Ontario at an Allstate agency, or at a secure storage facility.
We keep Personal Information in electronically recorded formats on our servers in Canada. Some Personal Information is also securely transmitted in electronic formats to Allstate Insurance Company servers in the United States of America. Allstate Insurance Company, Allstate’s parent company, has strict security standards in place for the transmission and storage of all data. Information stored in the United States of America is subject to the laws and regulations of the United States of America.
From time to time, Allstate may contract a Third Party Service Provider with servers in other countries who may keep Personal Information in electronically recorded formats on our servers in Canada and the United States. Any Third Party Service Provider we contract is required, at a minimum, to have the same security measures in place as we do. Our vendor selection is rigorous to ensure secure and appropriate protection of data, including Personal Information. Third Party Service Providers must agree to confidentiality clauses that safeguard Personal Information in any contract with Allstate.
Who do I contact if I want a copy of my Personal Information?
Allstate will make reasonable best efforts to provide you with Personal Information that you request. You are entitled to be informed of the existence, use, and disclosure of your Personal Information, subject to certain legal caveats. Allstate may decline access to Personal Information where it would reveal Personal Information about another individual; if legal or regulatory requirements prohibit Allstate from providing access to it; or if the Personal Information at issue is privileged as a result of legal proceedings.
For inquiries regarding access to your Personal Information, please contact Privacy Office. The Privacy Office is pleased to provide you with a right of access and review of your Personal Information in compliance with applicable law, and will make every effort to provide the Personal Information you have requested in a timely manner. You will be required to verify your identity before any of your Personal Information is released. In the event that there is any misinformation in your Personal Information, you are entitled to be given an opportunity to correct it.
Telephone (Toll Free):
Mail or Courier:
Privacy Office 27 Allstate Parkway Suite 100 Markham, ON L3R 5P8
Who do I contact if I have a privacy complaint?
If you have a privacy complaint, please contact the Privacy Office
Telephone (Toll Free):
Mail or Courier:
Privacy Office 27 Allstate Parkway Suite 100 Markham, ON L3R 5P8
Who is Allstate’s Privacy Officer?
Barb Hupman, Privacy Officer
Telephone: 1-855-877-4080 or 905-946-7735
Mail or Courier: Privacy Office, 27 Allstate Parkway, Suite 100, Markham, ON L3R 5P8