A data-breach response plan for car dealers (the NDB scheme)
A dealership holds driver licences, income and bank details, and finance paperwork, which is precisely the identity and financial data that enables fraud if it leaks. Under the Notifiable Data Breaches scheme, if customer personal information is involved in an eligible data breach that is likely to result in serious harm, you must assess it and, if it qualifies, notify the Office of the Australian Information Commissioner and the affected customers. A plan you can run under pressure is the point.
By Jon Oates, Founder of Privaproof · Last updated
General information, not legal advice. Privaproof is not a law practice.
Why a dealership is exposed
Most breaches turn on how harmful the exposed data is, and a dealer's files are full of the harmful kind: licence images, dates of birth, and the income and bank details you take to broker finance. That data is enough to enable identity theft and financial fraud, so a dealership breach is both more likely to be notifiable and more urgent to contain. The risk is worse because so much of it ends up on salespeople's phones, in shared inboxes and in unlocked filing cabinets. Read: finance and insurance data
When a breach is notifiable
Broadly, an eligible data breach is where:
- there is unauthorised access to, or disclosure of, personal information, or a loss of it, and
- a reasonable person would conclude it is likely to result in serious harm to any of the individuals, and
- you have not been able to prevent that likely serious harm through remedial action.
If those hold, you notify. Prompt containment that removes the likely serious harm can take a breach out of notifiable territory, which is why speed matters.
The four-step plan
1. Contain. Stop the exposure: recover the data, revoke access, reset credentials, secure the system or the paperwork. Finance data leaking is the worst case, so contain it first.
2. Assess. Work out what data, whose, and the risk of serious harm. Assess expeditiously and, where needed, within 30 days. Licence and finance data skews toward serious harm, so assess on that footing.
3. Notify, if it qualifies. If it is an eligible data breach, notify the OAIC with a statement and notify the affected customers about what happened, the information involved and the steps they can take (for example watching for fraud on their accounts).
4. Review. Fix the cause, the phone full of licence photos, the shared finance inbox, the offshore provider's gap, so it cannot recur.
The dealer-specific traps
- Finance data is the high-harm case. A breach of bank and income details leans strongly toward serious harm; treat it as high-priority for notification.
- Third-party and offshore breaches are still yours. If the breached data sat with a finance aggregator, CRM or cloud tool, including offshore, it is still your responsibility, and the APP 8 accountability rule can make their mishandling your breach. Read: offshore finance and cloud tools
- Loose licence photos. The pile of test-drive licence images on phones and drives is both an over-retention problem and a breach waiting to happen. Read: the test-drive licence
This is general information and document templates you tailor to your own business, not legal advice.
Common questions
A salesperson lost a phone with licence photos on it. Is that notifiable?
It is a potential eligible data breach (loss of personal information). Whether you must notify depends on the data, the likelihood of serious harm and whether you can contain it (for example a remote wipe) so serious harm is no longer likely. Assess it quickly. It is also a reason not to keep licence photos on phones in the first place.
The breach was our finance software provider's, not ours. Are we on the hook?
Generally yes for the customer data you are responsible for. Holding data with a third party, onshore or offshore, does not move the obligation off you. Build breach-notification into your provider contracts.
How long do we have to act?
Assess expeditiously and, where an assessment is needed, complete it within 30 days, but move faster where you can, both to contain and because notification, if required, should not wait.
This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. Whether a particular incident is a notifiable data breach depends on the facts. Privaproof's car-dealer documents are self-authored and are not independently reviewed by a solicitor. For advice on your specific circumstances, consult a qualified Australian legal practitioner.