What a car dealer's privacy policy must cover
A dealership's privacy policy is an APP 1 document, but a generic template will miss the things that actually matter for a car yard: that you take a licence for every test drive, that you disclose finance details to lenders and insurers, that you hold trade-in and previous-owner data, that you run cameras (and maybe facial recognition) across the yard, and that from 10 December 2026 you may need to disclose the automated decisions your tools make. This is what a policy written for a dealership needs to address.
By Jon Oates, Founder of Privaproof · Last updated
General information, not legal advice. Privaproof is not a law practice.
The APP 1 baseline
Under APP 1, a covered business must have a clear, current privacy policy setting out, in general terms, what personal information it collects and holds, how and why it collects it, how it is used and disclosed, how a person can access, correct and complain, and whether information is likely to be disclosed overseas. That applies to a dealership like any other business. What follows is what a car dealer has to add.
The dealer-specific parts a generic template leaves out
- Test-drive and enquiry ID. Your policy should be honest that you collect a driver's licence or photo ID for test drives, why, and how you handle it. Read: the test-drive licence
- Finance and insurance data, and disclosure to lenders. The core disclosure at a dealership is passing a buyer's income, bank and ID details to lenders and insurers to arrange finance. The policy must say you do this and to whom in general terms, and it should keep to the privacy handling, not credit law. Read: finance and insurance data
- Trade-in and previous-owner data. Trade-ins bring vehicle and sometimes previous-owner information, which the policy should acknowledge. Read: trade-ins, PPSR and privacy
- CCTV and facial recognition. The policy should reflect that you run cameras, and if you use facial-recognition or number-plate technology, that is a much higher-risk collection that needs its own basis and notice. Read: yard CCTV and facial recognition
- Overseas disclosure. If any finance, CRM or cloud tool processes data offshore, the policy must disclose the likelihood of overseas disclosure. Read: offshore finance and cloud tools
- Automated decision-making (from 10 December 2026). If you use tools that score or decide about people, for example automated finance pre-qualification, from 10 December 2026 your privacy policy must disclose that automated decision-making, the kinds of decisions and the kinds of information used.
- Retention. There is no anti-money-laundering record-keeping floor here; the policy and your practice should reflect a real retention limit for customer identity and finance data. Read: how long to keep customer records
Where the coverage question fits
A privacy policy only bites if the APPs apply to you, and for a dealership that often turns on turnover and whether you broker finance for a benefit. If you do, assume you need a compliant policy. Read: does the Privacy Act apply to car dealers?
Common questions
Can we use a generic privacy-policy generator?
You can generate the baseline, but it will not cover the test-drive licence, the finance disclosure to lenders, trade-ins, CCTV and facial recognition, or the automated-decision disclosure, which are the parts that make a dealer's policy accurate. A policy describing a business you are not is worse than none.
Do we need to mention the finance lenders by name?
Generally you describe the types of third parties you disclose to (finance lenders and insurers) rather than an exhaustive list, and you keep it current. Be transparent that finance details go to lenders and insurers to arrange the finance the customer asked for.
How often should we update the policy?
Whenever your practice or the law changes. The 10 December 2026 automated-decision rule is a concrete example many dealers will need to reflect. This is what a kit that is kept current as the law changes handles for you.
This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. Privaproof's car-dealer documents are self-authored and are not independently reviewed by a solicitor. For advice on your specific circumstances, consult a qualified Australian legal practitioner.