Skip to content

Privacy compliance for Australian car dealers: you take a licence for every test drive and broker finance for buyers.

A car dealership collects a driver's licence or photo ID for every test drive, gathers income and bank details to broker finance, and often runs cameras across the yard and showroom. That is a concentrated pool of identity and financial data about people who were only shopping for a car. Whether the federal Privacy Act binds your business depends on your turnover and how you operate, but your state's surveillance-devices law governs your cameras either way. This page is about handling that data responsibly, honestly, and without inventing a deadline you do not face.

General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.

Are you covered by the Privacy Act? The honest answer for dealers

There is no anti-money-laundering trigger for car dealers and no single 2026 switch-on date. Here is the honest position:

So the honest first step is not to assume you are exempt, and to remember the camera rules apply either way.

Why a dealer's data is unusually exposed

You hold, across the yard, a concentrated set of high-value personal and financial information:

A breach of this exposes people to identity theft and financial fraud, which is exactly what makes it serious. Read: a data-breach response plan for car dealers

The issues no generic template handles

1. The test-drive licence. Taking a driver's licence for a test drive is a collection of personal information, and often the dealership photographs or photocopies it and keeps the copy. The privacy discipline is to tell the customer why you are taking it (APP 5), collect only what you actually need, and prefer sighting and recording the details over keeping a photo pile. Most templates never mention it. Read: the test-drive licence and your privacy duties

2. Yard cameras and facial recognition. CCTV across a dealership is governed first by your state's surveillance-devices law, which binds you regardless of turnover, and facial-recognition or number-plate cameras raise the bar sharply because a facial template is sensitive information. The OAIC's facial-recognition enforcement (the Bunnings determination) is the clear warning. Read: yard CCTV and facial recognition

3. Brokering finance. When you take a buyer's income and bank details and pass them to lenders and insurers, you are collecting and disclosing sensitive financial information to third parties, which brings APP 6 and, if anything goes offshore, APP 8 into play. Privacy law governs how you handle that data; it is separate from credit law, and we keep to the privacy side. Read: finance and insurance data

What a car dealer actually needs

1. A privacy policy written for a dealership, covering test-drive ID, finance data, trade-ins and CCTV, not a generic website template. 2. Collection notices (APP 5) for the real points: the test drive, the finance enquiry, and the cameras. 3. A CCTV and surveillance procedure scoped to your state, with the facial-recognition risk called out. 4. A data-breach response plan for the identity and financial data you hold. 5. A retention and destruction schedule. There is no AML record-keeping floor here; you keep business records for the ATO's general period, and any state motor-dealer licensing records for the period your licence requires, then destroy customer identity data you no longer need.

Generic generators cover none of this: not the licence capture, not the finance flow, not state surveillance law.

What Privaproof is building for car dealers

A dedicated, car-dealer-specific privacy document set, written for how a dealership actually collects and holds data, and kept current as the law changes.

These are compliance tools and templates you tailor to your own business. They are general information, not legal advice, and are not independently reviewed by a solicitor. For advice on your specific circumstances, consult a qualified Australian legal practitioner.

Join the founding list

Be first to know when the Car-Dealer Kit opens, and get the plain-English updates as the law moves. No cost, no obligation.

We never sell your data. See our Privacy Policy.

Keep reading


General information and compliance tools, not legal advice. Privaproof is not a law practice and does not provide legal advice. Whether the Privacy Act 1988 (Cth) applies to your business depends on your turnover and how you operate; state surveillance-devices law applies to your cameras separately and varies by jurisdiction. Privaproof's car-dealer documents are self-authored and are not independently reviewed by a solicitor. The law changes over time, so check you are working from a current version.