Why this matters now
Dealerships hold sensitive personal information: finance applications, driver licences, trade-in details, sometimes health-related concession data. Deploying AI on top of this stack moves your obligations under the Privacy Act 1988 into sharper focus.
The 13 APPs in dealer terms
APP 1 (open and transparent management), APP 3 (collection of solicited personal information), APP 5 (notification of collection), APP 6 (use and disclosure), APP 8 (cross-border disclosure), APP 11 (security) and APP 12 (access) are the ones that change the most when AI enters the workflow. Each requires a documented control.
Cross-border data flows
APP 8 makes you accountable for what an overseas recipient does with personal information unless a narrow exception applies. Most US-built AI tools route through US infrastructure. SpectraIQ keeps customer data in AWS Sydney by default.
Consent and the Spam Act
The Spam Act 2003 governs commercial electronic messages, express or inferred consent, sender identification, and a functional unsubscribe. AI-driven SMS follow-ups are commercial messages.
Practical checklist
Privacy Impact Assessment on file. APP-aligned privacy collection notice updated. Data flow diagram including the AI vendor. DPA executed. Breach response plan tested. Annual access review documented.
