Notice to California Residents
California Consumer Privacy Act (CCPA): Subject to certain exceptions, the CCPA as amended by the California Privacy Rights Act, gives California residents certain privacy rights with respect to some of the personal information we collect. These rights are:
- The right to notice of the personal information we collect.
- The right to know the categories, sources and specific pieces of personal information we have collected about you, including our business or commercial purpose for collecting, selling or sharing the information, the categories of personal information that we sell or share, the categories of personal information that we disclose for business purposes, and the categories of third parties with whom we disclose that personal information.
- The right to delete some or all of the personal information we collect, subject to certain exceptions.
- The right to correct inaccurate personal information that we maintain about you, taking into account the nature of the personal information and the processing purposes.
- The right to opt-out of our sale or sharing of your personal information, as those terms are defined under the CCPA.
- The right to limit the use and disclosure of sensitive personal information, as those terms are defined under the CCPA, which are necessary to provide you services and other purposes permitted under the CCPA,
- The right not to be discriminated against for exercising these rights.
This section describes these rights, the steps you must take to exercise these rights, how we will verify your identity, and how we will respond to your requests.
Your rights under the CCPA are limited. These rights do not apply to publicly available information from government records, de-identified information or aggregated consumer information, and information we collect in order to provide you with a financial, health or life insurance product or service.
(a) Notice of Collection: We collect personal information about California residents from a variety of sources and use it for purposes related to our business. A full description of the sources from which we collect your personal information as well as the purposes for which we collect your personal information is provided in the section below the chart. The personal information we collect includes not only clear personal identifiers, but also any information that directly or indirectly can be associated with, or linked to, our consumers or their households. Below are the categories of personal information, including sensitive personal information, we may collect about our consumers, the length of time we intend to retain each category of personal information, or the criteria used to determine the retention period, and the types of third parties with whom we have disclosed, sold or shared personal information in the past 12 months. We may collect similar information about your spouse, children, friends and beneficiaries.
Categories of Personal Information We collect |
Disclosure for Business Purpose |
Disclosure for Sale or Sharing |
Retention |
Personal Identifiers: your name, alias, postal address, email address, unique personal identifier, online identifier, account name, Internet Protocol address, social security number, driver’s license number, passport number, or other similar identifiers. |
- Affiliates - Group policy sponsors, such as employers and affinity groups - Insurance producer/agents - Service providers - Reinsurers and other insurance companies - Joint marketing partners - Consumer reporting agencies - Government, judicial and law enforcement agencies and their agents - Industry self-regulatory bodies - Attorneys, accountants and auditors - Your fiduciary or legal representatives - Persons holding a legal or beneficial interest relating to you - Advertising networks - Data analytics providers - Social networks - Internet service providers - Consumer data resellers |
- Joint marketing partners - Advertising networks - Data analytics providers - Social networks |
We retain your personal information for as long as necessary to achieve the purposes for which we collected the information and as needed to comply with our legal obligations. |
Additional personal identifiers: your signature, physical characteristics or description, insurance policy number, bank account, credit card and debit card number, or any other financial information, medical information, and health, life or other insurance information, including your claims history |
- Affiliates - Group policy sponsors, such as employers and affinity groups - Insurance producer/agents - Service providers - Reinsurers and other insurance companies - Joint marketing partners - Consumer reporting agencies - Government, judicial and law enforcement agencies and their agents - Industry self-regulatory bodies - Attorneys, accountants and auditors - Your fiduciary or legal representatives - Persons holding a legal or beneficial interest relating to you - Advertising networks - Data analytics providers - Social networks - Internet service providers - Consumer data resellers |
|
We retain your personal information for as long as necessary to achieve the purposes for which we collected the information and as needed to comply with our legal obligations. |
Protected classification characteristics under federal or California law: your age, gender, familial status, disability, sex, national origin, religion, color, race, sexual orientation, gender identity and gender expression, marital status, veteran status, medical condition, ancestry, source of income, and genetic information |
- Affiliates - Group policy sponsors, such as employers and affinity groups - Insurance producer/agents - Service providers - Reinsurers and other insurance companies - Joint marketing partners - Consumer reporting agencies - Government, judicial and law enforcement agencies and their agents - Industry self-regulatory bodies - Attorneys, accountants and auditors - Your fiduciary or legal representatives - Persons holding a legal or beneficial interest relating to you - Advertising networks - Data analytics providers - Social networks - Internet service providers - Consumer data resellers |
|
We retain your personal information for as long as necessary to achieve the purposes for which we collected the information and as needed to comply with our legal obligations. |
Commercial information: records of your personal property, products or services you have purchased or considered, and other histories or tendencies to purchase or consume particular products and services |
- Affiliates - Group policy sponsors, such as employers and affinity groups - Insurance producer/agents - Service providers - Reinsurers and other insurance companies - Joint marketing partners - Consumer reporting agencies - Government, judicial and law enforcement agencies and their agents - Industry self-regulatory bodies - Attorneys, accountants and auditors - Your fiduciary or legal representatives - Persons holding a legal or beneficial interest relating to you Advertising networks - Data analytics providers - Social networks - Internet service providers - Consumer data resellers |
- Joint marketing partners - Advertising networks - Data analytics providers - Social networks |
We retain your personal information for as long as necessary to achieve the purposes for which we collected the information and as needed to comply with our legal obligations. |
Biometric information: physiological, biological or behavioral characteristics that can be used to identify you, such as fingerprints, retina scans, photos used for facial recognition and genetic information |
- Affiliates - Group policy sponsors, such as employers and affinity groups - Insurance producer/agents - Service providers - Reinsurers and other insurance companies - Joint marketing partners - Consumer reporting agencies - Government, judicial and law enforcement agencies and their agents - Industry self-regulatory bodies - Attorneys, accountants and auditors - Your fiduciary or legal representatives - Persons holding a legal or beneficial interest relating to you Advertising networks - Data analytics providers - Social networks - Internet service providers - Consumer data resellers |
|
We retain your personal information for as long as necessary to achieve the purposes for which we collected the information and as needed to comply with our legal obligations. |
Internet or other electronic network activity information: browsing history, search history, and information about your interaction with a Web site, online application and advertisements |
- Affiliates - Group policy sponsors, such as employers and affinity groups - Insurance producer/agents - Service providers - Reinsurers and other insurance companies - Joint marketing partners - Consumer reporting agencies - Government, judicial and law enforcement agencies and their agents - Industry self-regulatory bodies - Attorneys, accountants and auditors - Your fiduciary or legal representatives - Persons holding a legal or beneficial interest relating to you Advertising networks - Data analytics providers - Social networks - Internet service providers - Consumer data resellers |
- Joint marketing partners - Advertising networks - Data analytics providers - Social networks |
We retain your personal information for as long as necessary to achieve the purposes for which we collected the information and as needed to comply with our legal obligations. |
Geolocation data |
- Affiliates - Group policy sponsors, such as employers and affinity groups - Insurance producer/agents - Service providers - Reinsurers and other insurance companies - Joint marketing partners - Consumer reporting agencies - Government, judicial and law enforcement agencies and their agents - Industry self-regulatory bodies - Attorneys, accountants and auditors - Your fiduciary or legal representatives - Persons holding a legal or beneficial interest relating to you - Advertising networks - Data analytics providers - Social networks - Internet service providers - Consumer data resellers |
|
We retain your personal information for as long as necessary to achieve the purposes for which we collected the information and as needed to comply with our legal obligations. |
Sensory information: Audio, electronic, visual, thermal, olfactory or similar information, including voice signatures and recorded calls |
- Affiliates - Group policy sponsors, such as employers and affinity groups - Insurance producer/agents - Service providers - Reinsurers and other insurance companies - Joint marketing partners - Consumer reporting agencies - Government, judicial and law enforcement agencies and their agents - Industry self-regulatory bodies - Attorneys, accountants and auditors - Your fiduciary or legal representatives - Persons holding a legal or beneficial interest relating to you - Advertising networks - Data analytics providers - Social networks - Internet service providers - Consumer data resellers |
|
We retain your personal information for as long as necessary to achieve the purposes for which we collected the information and as needed to comply with our legal obligations. |
Professional or employment-related information: such as your job title |
- Affiliates - Group policy sponsors, such as employers and affinity groups - Insurance producer/agents - Service providers - Reinsurers and other insurance companies - Joint marketing partners - Consumer reporting agencies - Government, judicial and law enforcement agencies and their agents - Industry self-regulatory bodies - Attorneys, accountants and auditors - Your fiduciary or legal representatives - Persons holding a legal or beneficial interest relating to you - Advertising networks - Data analytics providers - Social networks - Internet service providers - Consumer data resellers |
|
We retain your personal information for as long as necessary to achieve the purposes for which we collected the information and as needed to comply with our legal obligations. |
Educational information not publicly available: your level of education, schools attended, your degrees and disciplinary history |
- Affiliates - Group policy sponsors, such as employers and affinity groups - Insurance producer/agents - Service providers - Reinsurers and other insurance companies - Joint marketing partners - Consumer reporting agencies - Government, judicial and law enforcement agencies and their agents - Industry self-regulatory bodies - Attorneys, accountants and auditors - Your fiduciary or legal representatives - Persons holding a legal or beneficial interest relating to you Advertising networks - Data analytics providers - Social networks - Internet service providers - Consumer data resellers |
|
We retain your personal information for as long as necessary to achieve the purposes for which we collected the information and as needed to comply with our legal obligations. |
Inferences drawn from any of the above categories of information to create a profile about you: Information about your preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes. |
- Affiliates - Group policy sponsors, such as employers and affinity groups - Insurance producer/agents - Service providers - Reinsurers and other insurance companies - Joint marketing partners - Consumer reporting agencies - Government, judicial and law enforcement agencies and their agents - Industry self-regulatory bodies - Attorneys, accountants and auditors - Your fiduciary or legal representatives - Persons holding a legal or beneficial interest relating to you - Advertising networks - Data analytics providers - Social networks - Internet service providers - Consumer data resellers |
- Joint marketing partners - Advertising networks - Data analytics providers - Social networks |
We retain your personal information for as long as necessary to achieve the purposes for which we collected the information and as needed to comply with our legal obligations. |
Sensitive personal information: Personal information relating to a consumer that reveals:
- Social Security, driver’s license numbers, state identification card, and passport numbers;
- financial account, debit card, or credit card numbers in combination with required security or access codes, passwords, or credentials allowing access to an account;
- account login in combination with required security or access codes, passwords, or credentials allowing access to the account;
- precise geolocation (i.e., information used or intended to be used to locate a consumer within a geographic area equal to or less than approximately 1/8 square mile);
- information about racial or ethnic origin, religious beliefs, philosophical beliefs, or union membership;
- contents of consumers’ mail, emails, or text messages, unless the business is the intended recipient of that information; and
- genetic data.
Sensitive personal information also includes:
- the processing of biometric information for the purpose of uniquely identifying a consumer;
- personal information collected and analyzed concerning a consumer’s health; and
- personal information collected and analyzed concerning a consumer’s sex life or sexual orientation.
|
- Affiliates - Group policy sponsors, such as employers and affinity groups - Insurance producer/agents - Service providers - Reinsurers and other insurance companies - Consumer reporting agencies - Government, judicial and law enforcement agencies and their agents - Industry self-regulatory bodies - Attorneys, accountants and auditors - Your fiduciary or legal representatives - Persons holding a legal or beneficial interest relating to you |
|
We retain your personal information for as long as necessary to achieve the purposes for which we collected the information and as needed to comply with our legal obligations. |
- Sources from which we collect your personal information: We may collect your personal information from:
- You or from others on your behalf
- Insurance producer/agent
- Consumer reporting agencies
- Our service providers
- Our affiliates
- Government agencies
- Public records
- Information clearinghouses
- Consumer data resellers
- Other insurers
- Your social media sites
- Internet service providers
- Purposes for which we use your personal information: We may use each of the categories of personal information listed in the chart above for the following business purposes: (i) respond to your requests; (ii) allow us to offer and issue you an insurance policy and to manage your policies and claims; (iii) allow us to service your policies (iv) give you information and statements about your account; (v) provide customer service (e.g., to resolve disputes, problems with your account/profile or the services); (vi) personalize your experience by providing information and content about Aflac products and services to you that we believe may be of interest to you; (vii) operate our promotions (e.g., provide you with entries to and information regarding our sweepstakes and contests); (viii) manage, administer and improve our operations, technology and services, including services via employers, brokers, agents and enrollment systems; (ix) conduct surveys; (x) allow you to use our online technologies; (xi) provide you with a safe, efficient, and customized experience; (xii) meet our legal and compliance obligations, including defend legal claims, obtain audits, respond to court orders and in legal investigations; (xiv) detect security incidents; (xv) perform data analytics; (xvi) conduct institutional risk assessments, risk modeling and statistical analysis and for mergers and reorganizations; (xvii) obtain reinsurance; and (xviii) report to consumer reporting agencies. Please note that we do not use or disclose sensitive personal information for purposes other than those expressly permitted under California law.
- Purposes for which we may sell or share your personal information: (i)advertising; (ii) personalize your experience by providing information and content about Aflac products and services to you that we believe may be of interest to you; (iii) operate our promotions (e.g., provide you with entries to and information regarding our sweepstakes and contests); (iv) perform data analytics.
- Purposes for which we may use your sensitive personal information: (i) to provide our products and services requested by you; (ii) to prevent, detect, and investigate security incidents; (iii) to resist malicious malware, deceptive, fraudulent, or illegal activities directed at us and to prosecute those responsible for such actions (as reasonably necessary and proportionate) (iv) to ensure the physical safety of natural persons (as reasonably necessary and proportionate); (v) for short-term transient use, including but not limited to, nonpersonalized advertising as part of your interaction with us (excludes disclosure to a third-party, building of profiles about you, or altering your experience outside of current interaction with us); (vi) to perform services on our behalf, including but not limited to maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying your information, processing payments, providing analytic services, providing storage, or providing similar services; (vii) to verify and maintain the quality or safety of a product, service, or device owned or controlled by us, to improve, upgrade, the service or device owned or controlled by us (as reasonably necessary and proportionate).
(b) Your Right to Know and Access the Personal Information We Collected: You have the right to request that we disclose certain personal information to you about our collection and use of your personal information. Once we receive and confirm your verifiable consumer request, we will disclose to you upon request (subject to certain exceptions):
- The categories of personal information we collected about you;
- The categories of sources for the personal information we collected about you;
- Our business or commercial purpose for collecting, selling, or sharing that personal information;
- The categories of third parties to whom we have disclosed that personal information;
- The specific pieces of personal information we have collected about you;
- The categories of personal information that we sold, and for each category identified, the categories of third parties to whom we sold that particular category of personal information; and
- The categories of personal information that the business disclosed for a business purpose and for each category identified, the categories of third parties to whom it disclosed that particular category of personal information.
(c) Your Right to Delete Your Personal Information We Collected: You have the right to request that we delete the personal information that we have collected and retained about you, subject to certain exceptions. Once we receive and confirm your verifiable consumer request, we will delete (and notify our service providers and/or contractors to delete) your personal information from our records, unless an exception applies. We will also notify all third parties to whom we have sold or shared your personal information to delete it to the extent required by law.
(d) Your Right to Correct Your Personal Information We Collected: You have the right to request that we correct any inaccurate personal information that we maintain about you, taking into account the nature of the personal information and the purposes of the processing of the personal information. Once we receive and confirm your verifiable consumer request, we will use commercially reasonably efforts to correct the inaccurate information.
(e) Your Right to Opt-Out of the Sale or Sharing of Personal Information: You have the right to request that we not share your personal information to third parties in exchange for monetary or other valuable consideration or to not share your personal information for cross-contextual behavioral advertising with third parties. If you would like to exercise this right to not sell or share your personal information, please click here: DO NOT SELL OR SHARE MY PERSONAL INFORMATION.
(f) Your Right to Limit the Use and Disclosure of Sensitive Personal Information: You have the right to request that we limit the use and disclosure of sensitive personal information for purposes other than those necessary to provide our services and those purposes otherwise permitted under the CCPA. If you would like to exercise this right to limit the use and disclosure of sensitive personal information, please click here: LIMIT THE USE OF MY SENSITIVE PERSONAL INFORMATION. Once we receive your request, we will record your preference to limit the use and disclosure of sensitive personal information.
(g) Your Ability to Opt-out of Third-Party Cookies: We may allow third-party advertising cookies to be placed on your browser or mobile device when you visit our website. As explained in our Cookies and Tracking Technologies Policy, we and our third-party service providers may use cookies to deliver content, including ads, relevant to your interests on our Site and third party sites based on how you interact with our advertisements or content. In addition, our Ad Network partners may deliver ads to you using cookies to uniquely distinguish your web browser and keep track of your browsing history in order to serve ads to you on your web browser. In some cases, these cookies facilitate the sale or sharing of your personal information to third parties. In accordance with your rights, you may opt-out of third party cookies by following the instructions in our Cookies and Tracking Technology Policy.
(h) How to Exercise Your Rights:
- Authorized Agent: You may designate an authorized agent to submit a request to know, request to correct, request to delete, a request to opt-out of sales / sharing, or a request to limit the use and disclosure of sensitive personal information on your behalf. If that agent is not already authorized to access your account in your profile, please submit a notarized special power of attorney in writing that provides the authorized agent with permission to make a request to know or a request to delete on your behalf. We may also ask you to verify your identity directly with us. We will deny a request from an authorized agent that does not submit proof that they have been authorized by you to act on your behalf.
- We provide consumers with a web-link and a toll-free telephone number for submitting requests under the CCPA. You, or your authorized agent, may exercise your individual rights at any time by selecting your preferred method and following the instruction provided:
- • Initiate an individual rights request to limit the use and disclosure of sensitive personal information, access, correct, or delete personal information by clicking here and completing the online form; or
- Initiate an individual rights request by calling our toll-free number 1-855-768-9730.
- Initiate an individual rights request not to sell or share my personal information by clicking DO NOT SELL OR SHARE MY PERSONAL INFOFORMATION and completing the online form;
You may also mail a request to Aflac at: Aflac Worldwide Headquarters
Attn: Privacy Office
1932 Wynnton Road
Columbus, GA 31999
Aflac Group
Attn: Privacy Office
Post Office Box 427
Columbia, SC 29202
- Aflac is not required to respond to your requests for individual access requests and/or to provide (where applicable) your personal information more than twice within a 12-month period.
- If we deny your request in whole or in part, we will provide you with an explanation or direct you to our general business practices for collecting personal information, if permitted under the CCPA. Under no circumstances will we provide the requestor with a consumer’s Social Security number, driver’s license number or other government-issued identification number, financial account numbers, any health insurance or medical identification numbers, any account passwords, any security questions and answers, or unique biometric data generated from measurements or technical analysis of human characteristics.
- We will use reasonable security measures when transmitting information to a consumer.
- In no event will Aflac discriminate against any consumer who exercises any of their privacy rights found under the CCPA. Unless permitted by law, we will not do any of the following to you if you exercise your CCPA rights:
- Deny you goods or services
- Charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties
- Provide you a different level or quality of goods or services
- Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services
For additional information regarding our privacy practices, please refer to our Privacy Center.
(i) How We Will Verify Your Identity: Only you, or an authorized agent, may submit a request to know, to correct, or to delete your personal information. You may also make a request on behalf of your minor child. You may only make a verifiable consumer request for access or data portability twice within a 12-month period. The verifiable consumer request must:
- Provide sufficient information that allows us to reasonably verify you are the person about whom we collected Personal Information or an authorized representative
- Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it
We cannot respond to your request or provide you with personal information if we cannot verify your identity or authority to make the request and confirm the personal information relates to you. Making a verifiable consumer request does not require you to create an account with us. We will use the personal information you provide to us when submitting a consumer request only to verify the requestor's identity or authority to make the request.
We will require the following information to verify your identity:
- For requests made online: We will require you to upload a photo identification card (passport, driving license) so that we can correctly match it with information we have previously collected about you. We will also require you to attest that you are the person you claim to be.
- For requests made by phone: In order to submit your request over the phone, you must have a valid phone number and a valid email address.
- For requests made by mail: You must submit proof of your identity.
- Additional information we may request to verify your identity: When we request additional information from you to verify your identity, we may request other account information, answers to security questions, your name, government identification number, date of birth, contact information, or other personal identifying information.
(j) How We Will Respond to Your Request: We intend to confirm receipt of your request to know, delete, or correct your personal information within 10 days and to respond to a verified request within 45 days of its receipt. If we require more time (up to 90 days), we will inform you of the reason and extension period in writing. We will deliver our written response by mail or electronically, at your option. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For requests to know the specific pieces of information we have collected, we will select a format to provide your personal information that is readily useable and should allow you to transmit the information from one entity to another entity without hindrance.
We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
(k) Residents of the State of California may request a list of categories of all third-parties with whom our Site has disclosed certain personal information (as defined by California law) during the preceding year for those third-parties’ direct marketing purposes. If you are a California resident and want such a list, please contact us at privacyoffice@aflac.com. For all requests, you must put the statement “Your California Privacy Rights” in the body of your request, as well as your name, street address, city, state, and zip code. In the body of your request, please provide enough information for us to determine if this applies to you. You need to attest to the fact that you are a California resident and provide a current California address for our response. Please note that we will not accept requests via the telephone, mail, or by facsimile, and we are not responsible for notices that are not labeled or sent properly, or that do not have complete information.
(l) How We Respond to Do Not Track Signals for California Residents: California Business & Professions Code Section 22575(b) (as amended effective January 1, 2014) provides that California residents are entitled to know how Aflac responds to “Do Not Track” browser settings. Aflac does not currently take actions to respond to Do Not Track signals because a uniform technological standard has not yet been developed. We continue to review new technologies and may adopt a standard once one is created.