Privacy in the Fast Lane: The OAIC’s and ACCC’s 2026 Automotive Compliance Sweep
Market Insights
Why this matters to you
Car dealerships and car rental companies are two sectors expressly named in the Office of the Australian Information Commissioner’s (OAIC) first-ever privacy compliance sweep, which began in January 2026.
Following 2024 amendments to the Privacy Act 1988 (Cth) (Privacy Act), the OAIC can issue compliance and infringement notices for non-compliant privacy policies, reported at up to $66,000 per contravention. More significantly, the OAIC has shifted from education and conciliation towards proactive, Commissioner-initiated enforcement.
The Australian Competition and Consumer Commission (ACCC) has also explicitly named the motor vehicle sector as an enforcement focus for 2026-27. It will push for high penalties where deliberate conduct causes significant harm, and will target the accountability of senior executives where a poor compliance culture exists.
What the sweep is looking at
The OAIC is reviewing the privacy policies of around 60 businesses across six sectors that collect personal information in-person, including dealerships and car rental companies. The review tests compliance with Australian Privacy Principle (APP) 1.4, which requires a clear, accurate, up-to-date policy covering how personal information is collected, used, disclosed, stored and destroyed.
Test drive check-ins, rental counters and finance discussions all require customers to hand over identity documents quickly, often before they have a real chance to read a policy or ask questions. The OAIC calls this a ‘power and information asymmetry: customers feel they have no real choice but to comply on the spot,
This makes customers vulnerable to overcollection, and their information being mishandled or retained too long. The sweep tests whether a business’s privacy policy accurately reflects what happens at the counter, in the showroom and in the finance office, and whether those practices are appropriate in the first place.
The overcollection risk
A central theme in the sweep is proportionality. Personal information should only be collected where reasonably necessary, and ‘we’ve always asked for it’ is not a defence.
Test-drive, finance and leasing documents may create compliance risk where they seek more information than is reasonably necessary for the transaction. This may arise, for example, where financial or sensitive information is collected at an early stage rather than when a genuine need for it arises. Businesses should therefore consider whether the information requested in each field is reasonably necessary for the relevant transaction and whether it needs to be collected at that time.
Current investigations
For manufacturers, importers, dealers and fleet operators, the sweep is the first, most visible phase of a larger regulatory program. The OAIC has confirmed two active investigations into Asia-based manufacturers over connected vehicle data, since identified in the media as Toyota and Hyundai.
The investigations examine three issues:
a) whether the data collected exceeds what the vehicle’s functions genuinely require, and whether consent was adequate;
b) whether data is disclosed to third parties for secondary purposes, including marketing, without consent; and
c) whether data no longer needed is properly destroyed or de-identified.
A connected vehicle is, in simple terms, any vehicle with an internet connection that collects or shares data with drivers, manufacturers, fleet operators or third-party services. This includes both electric and fuel-based vehicles with features such as remote start, GPS navigation, driver monitoring, smartphone pairing and infotainment systems. Connected vehicles will soon account for most new car sales, and each one continuously generates GPS, camera, microphone, driver-behaviour and telematics data, much of it personal information under the Privacy Act.
Only around two in ten drivers know their vehicle transmits data to the manufacturer at all. Secondary use is a particular concern. CHOICE research found that voice data had been shared to a third-party AI training company on an aggregated and de-identified basis.
Any reliance on connected vehicle data for insurance, marketing or AI purposes needs a clear legal basis, not a bundled or default consent. Dealers and fleet managers should also note that they can carry their own Privacy Act obligations for connected vehicle data even where the manufacturer controls the underlying systems.
The regulatory focus on data use will also extend to automated decision-making. From 10 December 2026, new APP 1.7 will require privacy policies to disclose certain automated decisions that could significantly affect an individual’s rights or interests. Relevant automotive applications include credit assessment, lead scoring, profiling and driver risk assessment. Businesses should determine whether their privacy policies will need to be updated ahead of that deadline. See our earlier alert on the topic: Preparing for the new automated decision-making disclosure requirements(opens in new tab)
Consumer law issues
The privacy sweep coincides with the ACCC naming motor vehicles as a specific focus of its 2026-27 Compliance and Enforcement Priorities, a continuing focus from prior years.
The ACCC has identified compliance with consumer guarantees as a key concern in the automotive sector, with difficulties accessing those rights remaining among the most common issues reported to it, particularly given the significant cost of purchasing a vehicle.
The Australian Automotive Aftermarket Association has separately found that up to 60% of consumers may be misinformed or uncertain about how their statutory rights under the Australian Consumer Law (ACL) interact with manufacturer and extended warranties. Those rights arise automatically, cannot be excluded, and apply regardless of warranty status or who services the vehicle. Warranty documents, extended warranty terms and service communications that suggest otherwise, or that overstate limits on the right to repair, replacement or refund for a major failure, are a direct compliance risk.
The ACCC’s unfair contract terms (UCT) focus targets harmful cancellation practices specifically: automatic renewals, early termination fees, and clauses that prevent or restrict cancellation. These commonly appear in extended warranty products, subscription services and vehicle finance agreements. The ACCC is also maintaining scrutiny of greenwashing, including claims about emissions, fuel efficiency and EV range.
Privacy and consumer law risks often arise in the same customer-facing documents, including finance forms, warranty booklets, subscription terms and leasing agreements. A deficiency in one area may therefore indicate broader compliance issues.
How to prepare
The OAIC’s increased investigative activity and the ACCC’s parallel focus on the automotive sector create overlapping regulatory exposure. Businesses should consider the following priority areas.
| ACTION | WHAT IT COVERS |
|---|---|
| Privacy policy audit |
|
| Form review |
|
| Consumer law cross-check |
|
| Staff training |
|
| Data retention review |
|
| Franchise network consistency |
|
| Connected vehicle data mapping |
|
| ADM readiness |
|
Next steps
Given the overlapping regulatory focus from both the OAIC and the ACCC, automotive businesses should consider:
- auditing privacy policies against APP 1.4 requirements;
- reviewing test drive, finance and leasing forms for overcollection;
- cross-checking warranty, subscription and finance terms against ACL and UCT requirements;
- training front-line staff on privacy obligations and consumer guarantee rights;
- reviewing data retention practices and franchise network consistency; and
- mapping connected vehicle data flows and preparing for APP 1.7 (ADM disclosure) by 10 December 2026.
HWLE’s Privacy, Data Protection and Cyber Security team advises on the privacy and data protection laws of each Australian jurisdiction and has considerable experience helping automotive clients manage their compliance obligations, including the interaction between Australian privacy law, consumer law and cross-border data requirements. Please contact a member of our team to discuss how these developments apply to your business and how we can assist.
This article was written by Luke Dale, Partner, Simon Ellis, Partner, Evan Stents, Partner, Maria Townsend, Partner, and Christopher Power, Solicitor.
Subscribe for publications + events
HWLE regularly publishes articles and newsletters to keep our clients up to date on the latest legal developments and what this means for your business. To receive these updates via email, please complete the subscription form and indicate which areas of law you would like to receive information on.
* indicates required fields



