Privacy compliance for Australian car dealers: you take a licence for every test drive and broker finance for buyers.
A car dealership collects a driver's licence or photo ID for every test drive, gathers income and bank details to broker finance, and often runs cameras across the yard and showroom. That is a concentrated pool of identity and financial data about people who were only shopping for a car. Whether the federal Privacy Act binds your business depends on your turnover and how you operate, but your state's surveillance-devices law governs your cameras either way. This page is about handling that data responsibly, honestly, and without inventing a deadline you do not face.
General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.
Are you covered by the Privacy Act? The honest answer for dealers
There is no anti-money-laundering trigger for car dealers and no single 2026 switch-on date. Here is the honest position:
- Turnover over A$3 million? Your dealership is a covered APP entity and the Australian Privacy Principles apply.
- A smaller independent dealer under A$3 million? You may fall within the small-business exemption (s 6D), so the APPs may not bind your whole business. The exemption can be lost if you disclose customers' personal information to a third party for a benefit (s 6D(4)(c)), and a dealer who brokers finance and passes a buyer's details to lenders or insurers for a commission engages those words on their face. But s 6D(7) carves out disclosures the customer consented to, and a signed finance application is normally exactly that consent, so in the ordinary case the exemption is likely to survive. It is fact-specific and turns on your own paperwork confirm against how your dealership actually operates. Read: does the Privacy Act apply to car dealers?
- Your yard and showroom cameras are governed regardless. State surveillance-devices law binds your cameras whether or not the Privacy Act reaches your business, so "we are a small dealer" is not an answer to a surveillance-law problem.
So the honest first step is not to assume you are exempt, and to remember the camera rules apply either way.
Why a dealer's data is unusually exposed
You hold, across the yard, a concentrated set of high-value personal and financial information:
- Driver-licence and ID captures from every test drive and finance enquiry.
- Finance and insurance data: income, bank details, and the results of finance applications you broker to lenders. Read: finance and insurance data at a dealership
- Trade-in and PPSR data, including details about a vehicle's previous owner.
- CCTV, and increasingly facial-recognition or number-plate cameras, across the yard and showroom. Read: yard CCTV and facial recognition
A breach of this exposes people to identity theft and financial fraud, which is exactly what makes it serious. Read: a data-breach response plan for car dealers
The issues no generic template handles
1. The test-drive licence. Taking a driver's licence for a test drive is a collection of personal information, and often the dealership photographs or photocopies it and keeps the copy. The privacy discipline is to tell the customer why you are taking it (APP 5), collect only what you actually need, and prefer sighting and recording the details over keeping a photo pile. Most templates never mention it. Read: the test-drive licence and your privacy duties
2. Yard cameras and facial recognition. CCTV across a dealership is governed first by your state's surveillance-devices law, which binds you regardless of turnover, and facial-recognition or number-plate cameras raise the bar sharply because a facial template is sensitive information. The OAIC's facial-recognition enforcement (the Bunnings determination) is the clear warning. Read: yard CCTV and facial recognition
3. Brokering finance. When you take a buyer's income and bank details and pass them to lenders and insurers, you are collecting and disclosing sensitive financial information to third parties, which brings APP 6 and, if anything goes offshore, APP 8 into play. Privacy law governs how you handle that data; it is separate from credit law, and we keep to the privacy side. Read: finance and insurance data
What a car dealer actually needs
1. A privacy policy written for a dealership, covering test-drive ID, finance data, trade-ins and CCTV, not a generic website template. 2. Collection notices (APP 5) for the real points: the test drive, the finance enquiry, and the cameras. 3. A CCTV and surveillance procedure scoped to your state, with the facial-recognition risk called out. 4. A data-breach response plan for the identity and financial data you hold. 5. A retention and destruction schedule. There is no AML record-keeping floor here; you keep business records for the ATO's general period, and any state motor-dealer licensing records for the period your licence requires, then destroy customer identity data you no longer need.
Generic generators cover none of this: not the licence capture, not the finance flow, not state surveillance law.
What Privaproof is building for car dealers
A dedicated, car-dealer-specific privacy document set, written for how a dealership actually collects and holds data, and kept current as the law changes.
- Written for dealers: test-drive ID, finance and insurance data, trade-ins, yard CCTV, marketing re-contact.
- Practical, plain-English documents you tailor to your business, with guidance built in.
- Kept current: while your subscription is active, we monitor the law and aim to provide updated versions as it changes. This is not a guarantee of compliance, and does not replace your own legal advice.
These are compliance tools and templates you tailor to your own business. They are general information, not legal advice, and are not independently reviewed by a solicitor. For advice on your specific circumstances, consult a qualified Australian legal practitioner.
Join the founding list
Be first to know when the Car-Dealer Kit opens, and get the plain-English updates as the law moves. No cost, no obligation.
✓ You’re on the founding list. We’ll email you as the changes land.
We never sell your data. See our Privacy Policy.
Keep reading
- Does the Privacy Act apply to car dealers?
- The test-drive licence and your privacy duties
- Yard CCTV and facial recognition at a dealership
- Finance and insurance data at a dealership
- What a car dealer's privacy policy must cover
- The collection notice a dealership needs
- Trade-ins, PPSR and privacy
- A data-breach response plan for car dealers
- How long should a car dealer keep customer records?
- Car dealers, offshore finance and cloud tools: your APP 8 duty
- Marketing to test-drivers: the Spam Act rules
- What does privacy compliance cost a car dealer?
- Consent to collect a customer's ID at a dealership
General information and compliance tools, not legal advice. Privaproof is not a law practice and does not provide legal advice. Whether the Privacy Act 1988 (Cth) applies to your business depends on your turnover and how you operate; state surveillance-devices law applies to your cameras separately and varies by jurisdiction. Privaproof's car-dealer documents are self-authored and are not independently reviewed by a solicitor. The law changes over time, so check you are working from a current version.