Skip to content

Privacy in the Fast Lane: The OAIC’s and ACCC’s 2026 Automotive Compliance Sweep

Market Insights

Why this matters to you

Car dealerships and car rental companies are two sectors expressly named in the Office of the Australian Information Commissioner’s (OAIC) first-ever privacy compliance sweep, which began in January 2026.

Following 2024 amendments to the Privacy Act 1988 (Cth) (Privacy Act), the OAIC can issue compliance and infringement notices for non-compliant privacy policies, reported at up to $66,000 per contravention. More significantly, the OAIC has shifted from education and conciliation towards proactive, Commissioner-initiated enforcement.

The Australian Competition and Consumer Commission (ACCC) has also explicitly named the motor vehicle sector as an enforcement focus for 2026-27. It will push for high penalties where deliberate conduct causes significant harm, and will target the accountability of senior executives where a poor compliance culture exists.

What the sweep is looking at

The OAIC is reviewing the privacy policies of around 60 businesses across six sectors that collect personal information in-person, including dealerships and car rental companies. The review tests compliance with Australian Privacy Principle (APP) 1.4, which requires a clear, accurate, up-to-date policy covering how personal information is collected, used, disclosed, stored and destroyed.

Test drive check-ins, rental counters and finance discussions all require customers to hand over identity documents quickly, often before they have a real chance to read a policy or ask questions. The OAIC calls this a ‘power and information asymmetry: customers feel they have no real choice but to comply on the spot,

This makes customers vulnerable to overcollection, and their information being mishandled or retained too long. The sweep tests whether a business’s privacy policy accurately reflects what happens at the counter, in the showroom and in the finance office, and whether those practices are appropriate in the first place.

The overcollection risk

A central theme in the sweep is proportionality. Personal information should only be collected where reasonably necessary, and ‘we’ve always asked for it’ is not a defence.

Test-drive, finance and leasing documents may create compliance risk where they seek more information than is reasonably necessary for the transaction. This may arise, for example, where financial or sensitive information is collected at an early stage rather than when a genuine need for it arises. Businesses should therefore consider whether the information requested in each field is reasonably necessary for the relevant transaction and whether it needs to be collected at that time.

Current investigations

For manufacturers, importers, dealers and fleet operators, the sweep is the first, most visible phase of a larger regulatory program. The OAIC has confirmed two active investigations into Asia-based manufacturers over connected vehicle data, since identified in the media as Toyota and Hyundai.

The investigations examine three issues:

a) whether the data collected exceeds what the vehicle’s functions genuinely require, and whether consent was adequate;

b) whether data is disclosed to third parties for secondary purposes, including marketing, without consent; and

c) whether data no longer needed is properly destroyed or de-identified.

A connected vehicle is, in simple terms, any vehicle with an internet connection that collects or shares data with drivers, manufacturers, fleet operators or third-party services. This includes both electric and fuel-based vehicles with features such as remote start, GPS navigation, driver monitoring, smartphone pairing and infotainment systems. Connected vehicles will soon account for most new car sales, and each one continuously generates GPS, camera, microphone, driver-behaviour and telematics data, much of it personal information under the Privacy Act.

Only around two in ten drivers know their vehicle transmits data to the manufacturer at all. Secondary use is a particular concern. CHOICE research found that voice data had been shared to a third-party AI training company on an aggregated and de-identified basis.

Any reliance on connected vehicle data for insurance, marketing or AI purposes needs a clear legal basis, not a bundled or default consent. Dealers and fleet managers should also note that they can carry their own Privacy Act obligations for connected vehicle data even where the manufacturer controls the underlying systems.

The regulatory focus on data use will also extend to automated decision-making. From 10 December 2026, new APP 1.7 will require privacy policies to disclose certain automated decisions that could significantly affect an individual’s rights or interests. Relevant automotive applications include credit assessment, lead scoring, profiling and driver risk assessment. Businesses should determine whether their privacy policies will need to be updated ahead of that deadline. See our earlier alert on the topic: Preparing for the new automated decision-making disclosure requirements(opens in new tab)

Consumer law issues

The privacy sweep coincides with the ACCC naming motor vehicles as a specific focus of its 2026-27 Compliance and Enforcement Priorities, a continuing focus from prior years.

The ACCC has identified compliance with consumer guarantees as a key concern in the automotive sector, with difficulties accessing those rights remaining among the most common issues reported to it, particularly given the significant cost of purchasing a vehicle.

The Australian Automotive Aftermarket Association has separately found that up to 60% of consumers may be misinformed or uncertain about how their statutory rights under the Australian Consumer Law (ACL) interact with manufacturer and extended warranties. Those rights arise automatically, cannot be excluded, and apply regardless of warranty status or who services the vehicle. Warranty documents, extended warranty terms and service communications that suggest otherwise, or that overstate limits on the right to repair, replacement or refund for a major failure, are a direct compliance risk.

The ACCC’s unfair contract terms (UCT) focus targets harmful cancellation practices specifically: automatic renewals, early termination fees, and clauses that prevent or restrict cancellation. These commonly appear in extended warranty products, subscription services and vehicle finance agreements. The ACCC is also maintaining scrutiny of greenwashing, including claims about emissions, fuel efficiency and EV range.

Privacy and consumer law risks often arise in the same customer-facing documents, including finance forms, warranty booklets, subscription terms and leasing agreements. A deficiency in one area may therefore indicate broader compliance issues.

How to prepare

The OAIC’s increased investigative activity and the ACCC’s parallel focus on the automotive sector create overlapping regulatory exposure. Businesses should consider the following priority areas.

ACTIONWHAT IT COVERS
Privacy policy audit

  • Consider whether the privacy policy accurately describes the types of personal information collected at each customer touchpoint (enquiry, test drive, finance, leasing, connected services and aftersales), how it is used and disclosed (including to manufacturers, financiers, insurers and marketing providers), whether it is disclosed overseas, and how individuals can access, correct or complain.

Form review

  • Assess whether each data field on test drive, finance, credit and leasing forms is reasonably necessary for that transaction. Consider removing or deferring collection of anything not required at that point, particularly identity documents, financial details or sensitive information sought up-front.

Consumer law cross-check

  • Review warranty, extended warranty, subscription, finance and service communications. Consider whether consumer guarantee rights are being tied to warranty status or authorised servicing.

  • Assess UCT risk (automatic renewals, exit fees, restrictive cancellation).

  • Consider whether marketing materials give rise to greenwashing risk (emissions, EV range and fuel efficiency claims should be substantiated).


Staff training

  • Consider whether front-line staff can explain to customers why personal information is collected and what happens to it. Training should address the power-asymmetry dynamic at in-person collection points. Consumer law training should also guard against making misrepresentations about consumer rights. 

Data retention review

  • Review whether retention periods for identity documents and personal information are documented, justified and consistently applied. Consider whether timely destruction or de-identification is occurring, particularly when vehicles are sold, returned from lease or transferred within a fleet.

Franchise network consistency

  • Consider whether privacy policies, collection notices, consent mechanisms, warranty terms and finance agreements are applied consistently across all dealership and franchise locations. The OAIC has flagged inconsistent franchise-level practices as an area of regulatory attention.

Connected vehicle data mapping

  • Consider mapping what data vehicles collect (GPS, cameras, microphones, telematics, driver behaviour), where it is transmitted (including cross-border) and who receives it.

  • Assess whether secondary uses (insurance, marketing, AI training, data brokers) rely on specific, informed consent rather than bundled or default opt-ins. Note that dealers and fleet operators may attract Privacy Act obligations even where the manufacturer controls the underlying systems.

ADM readiness

  • Consider whether automated decision-making is used in credit assessment, lead scoring, profiling, pricing or driver risk assessments, and whether those systems substantially assist decisions affecting individuals' rights or interests. Privacy policies may need to be updated to disclose these uses ahead of the 10 December 2026 APP 1.7 deadline.

Next steps

Given the overlapping regulatory focus from both the OAIC and the ACCC, automotive businesses should consider:

  • auditing privacy policies against APP 1.4 requirements;
  • reviewing test drive, finance and leasing forms for overcollection;
  • cross-checking warranty, subscription and finance terms against ACL and UCT requirements;
  • training front-line staff on privacy obligations and consumer guarantee rights;
  • reviewing data retention practices and franchise network consistency; and
  • mapping connected vehicle data flows and preparing for APP 1.7 (ADM disclosure) by 10 December 2026.

HWLE’s Privacy, Data Protection and Cyber Security team advises on the privacy and data protection laws of each Australian jurisdiction and has considerable experience helping automotive clients manage their compliance obligations, including the interaction between Australian privacy law, consumer law and cross-border data requirements. Please contact a member of our team to discuss how these developments apply to your business and how we can assist.

This article was written by Luke Dale, Partner, Simon Ellis, Partner, Evan Stents, Partner, Maria Townsend, Partner, and Christopher Power, Solicitor. 

Important Disclaimer: The material contained in this publication is of general nature only and is based on the law as of the date of publication. It is not, nor is intended to be legal advice. If you wish to take any action based on the content of this publication we recommend that you seek professional advice.

Subscribe for publications + events

HWLE regularly publishes articles and newsletters to keep our clients up to date on the latest legal developments and what this means for your business. To receive these updates via email, please complete the subscription form and indicate which areas of law you would like to receive information on.

* indicates required fields

This field is for validation purposes and should be left unchanged.
Interests **
This field is hidden when viewing the form
Email preferences*
What type of content would you like to receive from us?