On-Prem

Personal Tech

Allstate accused of quietly paying app makers for driver data

Insurance giant sued by Texas for using surveillance without consent to jack up premiums, deny coverage


Texas Attorney General Ken Paxton on Monday filed a lawsuit against Allstate Corporation and its mobile analytics subsidiary, Arity, alleging the American insurance giant conspired with mobile app developers to collect telematics data on millions of motorists without consent, in violation of consumer protection laws.

Allstate then allegedly used this data against those drivers to justify rate increases, deny coverage, or to drop coverage.

"Our investigation revealed that Allstate and Arity paid mobile apps millions of dollars to install Allstate’s tracking software," said Attorney General Paxton in a statement. "The personal data of millions of Americans was sold to insurance companies without their knowledge or consent in violation of the law. Texans deserve better and we will hold all these companies accountable."

According to the complaint [PDF], Allstate paid app developers to integrate the Arity Driving Engine SDK, a software library that, as explained in the documentation, "enables a mobile app to detect, record, and score your end-user's driving behavior."

Mobile apps that implemented the SDK Routely (now owned by Allstate), Life360, GasBuddy, and Fuel Rewards – are alleged to have collected:

Those apps – some named in prior privacy lawsuits over the sale of location data – initially request permission from users to access location data in conjunction with app features. "But after an app integrated the Arity SDK, if an app user allowed the app to access their location information for those same in-app features, the user was also unwittingly enabling Defendants to collect the Arity SDK Data via the Arity SDK," the complaint says.

Because the Artity SDK data alone could not reliably identify drivers, Allstate is alleged to have licensed the personal data available to the apps – first and last name, phone number, address, zip code, mobile ad-ID (MAID), device ID, and ad-ID – and to have combined the data sets to profile drivers.

Yet the use of this data, it's claimed, was misapplied. For instance, Allstate could not be certain that individuals surveilled through these mobile apps were operating a vehicle. Nonetheless, the detection of telematics sensor data that suggested erratic careless driving would be held against users of these apps, even if they weren't driving.

"For example, if a person was a passenger in a bus, a taxi, or in a friend’s car, and that vehicle’s driver sped, hard braked, or made a sharp turn, Defendants would conclude that the passenger, not the actual driver, engaged in 'bad' driving behavior based on the Arity SDK Data," the complaint explains. "Defendants would then subsequently sell and share the data so it could be used to inform decisions about that passenger’s insurability based on their 'bad' driving behavior."

In one publicly reported instance of this last October, a man posting to the Roller Coaster Enthusiasts Club group on Facebook wrote, "My insurance company mistakenly believed I was driving my car when, in reality, I was riding the roller coaster The Beast at Kings Island. Those red dots indicate where the app incorrectly assessed my cornering and braking skills and lowered my driving score."

To improve the accuracy of its data, Allstate is alleged to have purchased info about drivers from car manufacturers, such as Toyota, Lexus, Mazda, Chrysler, Dodge, Fiat, Jeep, Maserati, and Ram – without the consent of those drivers.

In August, Paxton filed a lawsuit against General Motors, claiming that the car company has been unlawfully collecting data about drivers of its cars and selling that information to insurance companies.

The Allstate/Arity complaint goes on to allege that the privacy notices presented to app users failed to disclose the extent of data collection and sharing and inaccurately stated that Allstate and Arity "do not sell personal information for monetary value."

The companies are charged with violations of the Texas Data Privacy and Security Act, Data Broker Law, and unfair competition/deceptive behavior under the state insurance code.

An Allstate spokesperson told The Register, "Arity helps consumers get the most accurate auto insurance price after they consent in a simple and transparent way that fully complies with all laws and regulations." ®

Send us news
24 Comments

GM parks claims that driver location data was given to insurers, pushing up premiums

We'll defo ask for permission next time, automaker tells FTC

Uncle Sam now targets six landlord giants in war on alleged algorithmic rent fixing

One of ya is gonna sing like a canary, prosecutors say

Free-software warriors celebrate landmark case that enforced GNU LGPL

On the Fritz: German router maker AVM lets device rights case end after coughing up source code

Apple's interoperability efforts aren't meeting spirit or letter of EU law, advocacy groups argue

Free Software Foundation Europe and others urge European Commission to double down on DMA

UK government pledges law against sexually explicit deepfakes

Not just making them, but sharing them too

Sonos CEO steps down after smart speaker app upgrade hit bum note

Board appoints interim leader to stay in tune with its turnaround song, both execs hear sweet sound of cash landing in the bank

Apple auto-opts everyone into having their photos analyzed by AI for landmarks

Homomorphic-based Enhanced Visual Search is so privacy-preserving, iPhone giant activated it without asking

Price-fixing-as-a-service: The claim against healthcare cost-cruncher MultiPlan

Attorney Jennifer Scullion on allegations of algorithmic suppression of competition

Google reports halving code migration time with AI help

Chocolate Factory slurps own dogfood, sheds drudgery in specific areas

Megan, AI recruiting agent, is on the job, giving bosses fewer reasons to hire in HR

She doesn't feel pity, remorse, or fear, but she'll craft a polite email message as she turns you down

Trump’s Department of Government Efficiency emerges with tech modernization mission

US Digital Service re-named and told to audit government tech and work on data-sharing

Microsoft eggheads say AI can never be made secure – after testing Redmond's own products

If you want a picture of the future, imagine your infosec team stamping on software forever