Skip to main content

    Data Breach Notification Policy

    Our commitment to transparency and rapid response in the event of a security incident. We take the protection of your data seriously.

    Our Commitment

    At Ally, we implement comprehensive security measures to protect your personal data. However, we recognize that no system is completely immune to security threats. This policy outlines how we respond to and communicate about data security incidents.

    We are committed to:

    • Promptly detecting and responding to any security incidents
    • Containing breaches and minimizing impact as quickly as possible
    • Transparently communicating with affected users
    • Complying with all applicable data breach notification laws
    • Learning from incidents to continuously improve our security

    Notification Timeline

    Immediate Response

    0-24 hours

    Upon discovering a potential data breach, our security team immediately initiates our incident response procedure, containing the breach and beginning investigation.

    Assessment & Documentation

    24-48 hours

    We assess the scope, impact, and nature of the breach, document all findings, and determine which users and data may be affected.

    Regulatory Notification

    Within 72 hours

    For breaches affecting EU residents, we notify the relevant supervisory authority within 72 hours as required by GDPR, unless the breach is unlikely to result in risk to individuals.

    User Notification

    Without undue delay

    If the breach is likely to result in high risk to your rights and freedoms, we notify affected users directly via email with details about the breach and recommended protective actions.

    What You'll Be Notified About

    If we determine that a breach requires notification, we will provide you with the following information:

    Nature of the Breach

    What happened, when it occurred, and how we discovered it.

    Data Affected

    The categories of personal data that were or may have been compromised.

    Actions Taken

    Steps we've taken to contain the breach and prevent future incidents.

    Your Next Steps

    Recommended actions you can take to protect yourself.

    How We Will Contact You

    In the event of a data breach affecting your account, we will contact you through:

    • Email: Direct notification to the email address associated with your account
    • In-App Notification: A prominent notice when you log into Ally
    • Status Page: Updates on our system status page

    For widespread incidents, we may also post updates on our website and social media channels.

    Legal Compliance

    Our breach notification procedures comply with applicable data protection laws, including:

    GDPR (EU/EEA)

    Notification to supervisory authorities within 72 hours. Notification to affected individuals without undue delay when high risk exists.

    CCPA/CPRA (California)

    Notification to affected California residents in the most expedient time possible and without unreasonable delay.

    Prevention Measures

    We continuously work to prevent security incidents through:

    • End-to-end encryption for data in transit and at rest
    • Regular security audits and penetration testing
    • Employee security training and awareness programs
    • Multi-factor authentication for administrative access
    • 24/7 monitoring and intrusion detection systems
    • Regular software updates and security patches
    • Strict access controls and the principle of least privilege

    For more details about our security practices, visit our Security page and Trust Center.

    Report a Security Concern

    If you believe you've discovered a security vulnerability or have concerns about your account security, please contact us immediately.