Skip to content

Consent to collect a customer's ID at a dealership: what you actually need

A common dealership myth is that you need signed consent for everything you collect. You do not. For a test-drive licence and ordinary customer details, the rule is to collect only what is reasonably necessary, by lawful and fair means, and to take reasonable steps to notify the customer. Consent is the higher bar, and it applies to sensitive information, which is a closed list in s 6(1) of the Privacy Act: a facial-recognition scan is on it, a driver licence and a finance form are not.

By Jon Oates, Founder of Privaproof · Last updated

General information, not legal advice. Privaproof is not a law practice.

Two different requirements often get merged:

So for a test-drive licence, ordinary contact details, and even the income and bank details you take for finance, the requirement is usually to collect only what you need and to notify, not to obtain a separate signed consent. Finance data is high-value and needs care, but it is not sensitive information in the Privacy Act's special sense.

The collection rules for customer ID

Common questions

Usually not a formal signed consent, provided you genuinely need it and you notify the customer. The controls for an ordinary licence are necessity and notice: collect only what you need, by fair means, and cover it in your collection notice. Better still, sight it rather than keeping a photo.

Financial information is not sensitive information in the Privacy Act's technical sense, so it does not carry the consent bar that, say, facial recognition does. It is high-value and needs strong security and a clear notice that you disclose it to lenders, but the baseline is notice and necessity, not a separate signed consent. Read: finance and insurance data

Most clearly when you use facial recognition or other biometric technology, because biometric information used for automated verification or identification is sensitive information (s 6(1)(d)) and APP 3.3 puts consent in front of it. For ordinary ID and finance data, notice and necessity are the rule. There is also one place where consent does not help you at all: a state licence number is a government related identifier, APP 9.1 bars an organisation from adopting it as its own identifier for that customer, and the OAIC states that an individual cannot consent to that adoption (APP Guidelines chapter 9, paragraph 9.3). Using the number to verify identity is a different act and is permitted where reasonably necessary (APP 9.2(a); the OAIC gives driver licences and passports as exactly that use, paragraph 9.26). So the question worth asking your DMS supplier is whether the licence number is the customer record key, or just a field you checked and moved on from.


This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. For advice on your specific circumstances, consult a qualified Australian legal practitioner.

Keep reading