Data Breach Notification Policy
Our commitment to transparency and rapid response in the event of a security incident. We take the protection of your data seriously.
Our Commitment
At Ally, we implement comprehensive security measures to protect your personal data. However, we recognize that no system is completely immune to security threats. This policy outlines how we respond to and communicate about data security incidents.
We are committed to:
- Promptly detecting and responding to any security incidents
- Containing breaches and minimizing impact as quickly as possible
- Transparently communicating with affected users
- Complying with all applicable data breach notification laws
- Learning from incidents to continuously improve our security
Notification Timeline
Immediate Response
0-24 hoursUpon discovering a potential data breach, our security team immediately initiates our incident response procedure, containing the breach and beginning investigation.
Assessment & Documentation
24-48 hoursWe assess the scope, impact, and nature of the breach, document all findings, and determine which users and data may be affected.
Regulatory Notification
Within 72 hoursFor breaches affecting EU residents, we notify the relevant supervisory authority within 72 hours as required by GDPR, unless the breach is unlikely to result in risk to individuals.
User Notification
Without undue delayIf the breach is likely to result in high risk to your rights and freedoms, we notify affected users directly via email with details about the breach and recommended protective actions.
What You'll Be Notified About
If we determine that a breach requires notification, we will provide you with the following information:
Nature of the Breach
What happened, when it occurred, and how we discovered it.
Data Affected
The categories of personal data that were or may have been compromised.
Actions Taken
Steps we've taken to contain the breach and prevent future incidents.
Your Next Steps
Recommended actions you can take to protect yourself.
How We Will Contact You
In the event of a data breach affecting your account, we will contact you through:
- Email: Direct notification to the email address associated with your account
- In-App Notification: A prominent notice when you log into Ally
- Status Page: Updates on our system status page
For widespread incidents, we may also post updates on our website and social media channels.
Legal Compliance
Our breach notification procedures comply with applicable data protection laws, including:
GDPR (EU/EEA)
Notification to supervisory authorities within 72 hours. Notification to affected individuals without undue delay when high risk exists.
CCPA/CPRA (California)
Notification to affected California residents in the most expedient time possible and without unreasonable delay.
Prevention Measures
We continuously work to prevent security incidents through:
- End-to-end encryption for data in transit and at rest
- Regular security audits and penetration testing
- Employee security training and awareness programs
- Multi-factor authentication for administrative access
- 24/7 monitoring and intrusion detection systems
- Regular software updates and security patches
- Strict access controls and the principle of least privilege
For more details about our security practices, visit our Security page and Trust Center.
Report a Security Concern
If you believe you've discovered a security vulnerability or have concerns about your account security, please contact us immediately.