What a car dealer's privacy policy must cover
If the Australian Privacy Principles apply to your dealership, your privacy policy is an APP 1.3 document, and a generic template will miss the things that actually matter for a car yard: that you take a licence for every test drive, that you disclose finance details to lenders and insurers, that you hold trade-in and previous-owner data, that you run cameras (and maybe facial recognition) across the yard, and that from 10 December 2026 you may need to disclose automated decisions that could significantly affect a customer's rights or interests. This is what a policy written for a dealership needs to address.
By Jon Oates, Founder of Privaproof · Last updated
General information, not legal advice. Privaproof is not a law practice.
The APP 1 baseline
APP 1.3 requires an APP entity to have a "clearly expressed and up-to-date" privacy policy, and APP 1.4 lists seven contents: what you collect and hold, how you collect and hold it, the purposes you collect, hold, use and disclose for, how someone accesses, corrects and complains, whether you are likely to disclose overseas, and if so the countries, "if it is practicable to specify those countries". It binds APP entities, so a genuinely exempt dealership need not have one. Where it does bind you, APP 1.3 and 1.4 are on the short list at s 13K(1)(b) that the Commissioner can act on directly, and s 13K(4) caps the civil penalty at 200 penalty units. What follows is what a car dealer has to add.
The dealer-specific parts a generic template leaves out
- Test-drive and enquiry ID. Your policy should be honest that you collect a driver's licence or photo ID for test drives, why, and how you handle it. Read: the test-drive licence
- Finance and insurance data, and disclosure to lenders. The core disclosure at a dealership is passing a buyer's income, bank and ID details to lenders and insurers to arrange finance. APP 1.4(c) requires the policy to state the purposes you disclose for; the duty to name the recipients or their types sits in APP 5.2(f), in your collection notice. Keep both to the privacy handling, not credit law. Read: finance and insurance data
- Trade-in and previous-owner data. Trade-ins bring vehicle and sometimes previous-owner information, which the policy should acknowledge. Read: trade-ins, PPSR and privacy
- CCTV and facial recognition. The policy should reflect that you run cameras. Facial recognition is a different thing: a biometric template is sensitive information (s 6(1)), and APP 3.3 will not let you collect it without consent and without it being reasonably necessary for your functions. Number-plate capture and state surveillance-devices law sit alongside that. Read: yard CCTV and facial recognition
- Overseas disclosure. If any finance, CRM or cloud tool processes data offshore, APP 1.4(f) requires the policy to say whether you are likely to disclose overseas, and APP 1.4(g) requires the countries, "if it is practicable to specify those countries". Does yours name one? Read: offshore finance and cloud tools
- Automated decision-making (from 10 December 2026). APP 1.7 bites where a computer program makes, or does something substantially and directly related to making, a decision that "could reasonably be expected to significantly affect the rights or interests of an individual", automated finance pre-qualification being the dealership case. The policy must then set out the kinds of information used, the decisions made solely by the program, and the decisions where it does a related thing (APP 1.8). Approvals count as much as refusals (APP 1.9(c)).
- Retention. There is no anti-money-laundering record-keeping floor here; the policy and your practice should reflect a real retention limit for customer identity and finance data. Read: how long to keep customer records
Where the coverage question fits
A privacy policy only bites if the APPs apply to you. Over A$3 million turnover you are covered. Under it, the limb to check is s 6D(4)(c), disclosing personal information about someone to anyone else "for a benefit, service or advantage", which is what passing a buyer's details to a lender for a commission looks like. But s 6D(7) carves that out where the customer consented, and a signed finance application is normally exactly that consent, so in the ordinary case the exemption is likely to survive. Buying a lead list runs the other limb (s 6D(4)(d), carve-out s 6D(8)). So the question is not whether you broker finance. It is what your finance consent says. Read: does the Privacy Act apply to car dealers?
Common questions
Can we use a generic privacy-policy generator?
You can generate the baseline. The test is APP 1.4(a) and (c): does the policy name the kinds of personal information you actually collect, and the purposes you actually disclose it for? Open yours and look for the test-drive licence, the disclosure to lenders and insurers, the yard cameras, and from 10 December 2026 the automated decisions. APP 1.4 is a contents requirement, not a formatting one, so a policy that describes a business you are not is not a compliant policy.
Do we need to mention the finance lenders by name?
No. APP 1.4 has no recipient limb at all: 1.4(c) asks for the purposes you disclose for. The wording about "the types of any other APP entities, bodies or persons" you usually disclose to is APP 5.2(f), and it belongs in your collection notice. So describe types, finance lenders and insurers, rather than an exhaustive list, keep it current, and be plain that finance details go to lenders and insurers to arrange the finance the customer asked for.
How often should we update the policy?
Whenever your practice or the law changes. APP 1.3 makes that a standing duty: the policy has to be "clearly expressed and up-to-date", not accurate on the day you bought it. The 10 December 2026 automated-decision rule is the next dated change to reflect. This is what a kit that is kept current as the law changes handles for you.
This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. For advice on your specific circumstances, consult a qualified Australian legal practitioner.