Consent to collect a customer's ID at a dealership: what you actually need
A common dealership myth is that you need signed consent for everything you collect. You do not. For a test-drive licence and ordinary customer details, the rule is to collect only what is reasonably necessary, by lawful and fair means, and to take reasonable steps to notify the customer. Consent is the higher bar, and it applies to sensitive information, which is a closed list in s 6(1) of the Privacy Act: a facial-recognition scan is on it, a driver licence and a finance form are not.
By Jon Oates, Founder of Privaproof · Last updated
General information, not legal advice. Privaproof is not a law practice.
Notice is the baseline, consent is the higher bar
Two different requirements often get merged:
- Collection notice (APP 5.1) applies whenever you collect personal information. At or before collection you must take such steps as are reasonable in the circumstances to make the customer aware of the matters in APP 5.2, which include who you are, why you are collecting, and who you disclose to. This is notice, not consent. Read: the collection notice a dealership needs
- Consent is a stronger step, required for particular things, most notably sensitive information, which under APP 3.3(a) needs consent as well as being reasonably necessary for your functions or activities, unless an APP 3.4 exception applies. Note what consent is: s 6(1) defines it as "express consent or implied consent", so it is not a synonym for a signature.
So for a test-drive licence, ordinary contact details, and even the income and bank details you take for finance, the requirement is usually to collect only what you need and to notify, not to obtain a separate signed consent. Finance data is high-value and needs care, but it is not sensitive information in the Privacy Act's special sense.
The collection rules for customer ID
- Only what is reasonably necessary (APP 3.2). For an organisation the test is that the information is reasonably necessary for one or more of your functions or activities, so collect the ID and detail you actually need to run the test drive or arrange the finance, not more. Read: the test-drive licence
- By lawful and fair means (APP 3.5). Collect openly and fairly. APP 3.6 adds that you must collect about a person from that person unless it is unreasonable or impracticable to do so, so a third-party check needs that judgment as well as a notice that covers it (APP 5.2(b)).
- The one place consent bites: facial recognition. Biometric information is sensitive information where it is to be used for automated biometric verification or identification (s 6(1)(d)), and a biometric template is sensitive in its own right (s 6(1)(e)). That is exactly what facial recognition in a yard produces, and APP 3.3 then requires consent and real necessity, a much higher standard. This is the collection at a dealership where consent genuinely matters. Read: yard CCTV and facial recognition
Common questions
Do we need written consent to take a licence for a test drive?
Usually not a formal signed consent, provided you genuinely need it and you notify the customer. The controls for an ordinary licence are necessity and notice: collect only what you need, by fair means, and cover it in your collection notice. Better still, sight it rather than keeping a photo.
Is a customer's finance information sensitive, so we need consent?
Financial information is not sensitive information in the Privacy Act's technical sense, so it does not carry the consent bar that, say, facial recognition does. It is high-value and needs strong security and a clear notice that you disclose it to lenders, but the baseline is notice and necessity, not a separate signed consent. Read: finance and insurance data
When does consent actually matter for us?
Most clearly when you use facial recognition or other biometric technology, because biometric information used for automated verification or identification is sensitive information (s 6(1)(d)) and APP 3.3 puts consent in front of it. For ordinary ID and finance data, notice and necessity are the rule. There is also one place where consent does not help you at all: a state licence number is a government related identifier, APP 9.1 bars an organisation from adopting it as its own identifier for that customer, and the OAIC states that an individual cannot consent to that adoption (APP Guidelines chapter 9, paragraph 9.3). Using the number to verify identity is a different act and is permitted where reasonably necessary (APP 9.2(a); the OAIC gives driver licences and passports as exactly that use, paragraph 9.26). So the question worth asking your DMS supplier is whether the licence number is the customer record key, or just a field you checked and moved on from.
This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. For advice on your specific circumstances, consult a qualified Australian legal practitioner.