Skip to content

What a car dealer's privacy policy must cover

If the Australian Privacy Principles apply to your dealership, your privacy policy is an APP 1.3 document, and a generic template will miss the things that actually matter for a car yard: that you take a licence for every test drive, that you disclose finance details to lenders and insurers, that you hold trade-in and previous-owner data, that you run cameras (and maybe facial recognition) across the yard, and that from 10 December 2026 you may need to disclose automated decisions that could significantly affect a customer's rights or interests. This is what a policy written for a dealership needs to address.

By Jon Oates, Founder of Privaproof · Last updated

General information, not legal advice. Privaproof is not a law practice.

The APP 1 baseline

APP 1.3 requires an APP entity to have a "clearly expressed and up-to-date" privacy policy, and APP 1.4 lists seven contents: what you collect and hold, how you collect and hold it, the purposes you collect, hold, use and disclose for, how someone accesses, corrects and complains, whether you are likely to disclose overseas, and if so the countries, "if it is practicable to specify those countries". It binds APP entities, so a genuinely exempt dealership need not have one. Where it does bind you, APP 1.3 and 1.4 are on the short list at s 13K(1)(b) that the Commissioner can act on directly, and s 13K(4) caps the civil penalty at 200 penalty units. What follows is what a car dealer has to add.

The dealer-specific parts a generic template leaves out

Where the coverage question fits

A privacy policy only bites if the APPs apply to you. Over A$3 million turnover you are covered. Under it, the limb to check is s 6D(4)(c), disclosing personal information about someone to anyone else "for a benefit, service or advantage", which is what passing a buyer's details to a lender for a commission looks like. But s 6D(7) carves that out where the customer consented, and a signed finance application is normally exactly that consent, so in the ordinary case the exemption is likely to survive. Buying a lead list runs the other limb (s 6D(4)(d), carve-out s 6D(8)). So the question is not whether you broker finance. It is what your finance consent says. Read: does the Privacy Act apply to car dealers?

Common questions

Can we use a generic privacy-policy generator?

You can generate the baseline. The test is APP 1.4(a) and (c): does the policy name the kinds of personal information you actually collect, and the purposes you actually disclose it for? Open yours and look for the test-drive licence, the disclosure to lenders and insurers, the yard cameras, and from 10 December 2026 the automated decisions. APP 1.4 is a contents requirement, not a formatting one, so a policy that describes a business you are not is not a compliant policy.

Do we need to mention the finance lenders by name?

No. APP 1.4 has no recipient limb at all: 1.4(c) asks for the purposes you disclose for. The wording about "the types of any other APP entities, bodies or persons" you usually disclose to is APP 5.2(f), and it belongs in your collection notice. So describe types, finance lenders and insurers, rather than an exhaustive list, keep it current, and be plain that finance details go to lenders and insurers to arrange the finance the customer asked for.

How often should we update the policy?

Whenever your practice or the law changes. APP 1.3 makes that a standing duty: the policy has to be "clearly expressed and up-to-date", not accurate on the day you bought it. The 10 December 2026 automated-decision rule is the next dated change to reflect. This is what a kit that is kept current as the law changes handles for you.


This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. For advice on your specific circumstances, consult a qualified Australian legal practitioner.

Keep reading