The short answer
This guide is general information, not legal advice. Your club should check its own position with the Office of the Australian Information Commissioner (OAIC) or a lawyer.
The Privacy Act 1988 applies to many organisations, but the OAIC says most small businesses and not-for-profits with an annual turnover of $3 million or less are not covered, unless an exception applies. Many motor vehicle clubs will be below that figure. Whatever the legal position, members trust the committee with their details, and good practice protects them either way.
The OAIC statements in this guide were checked 4 October 2026, on the OAIC pages listed in the sources at the end. The law and the OAIC’s guidance can change, so check the current pages before relying on them.
What personal information clubs hold
A motor vehicle club holds more personal information than most committees realise. Personal information is information about an identifiable person.
A typical club holds:
| Kind of record | Examples |
|---|---|
| Contact details | Names, home addresses, phone numbers, email addresses |
| Membership | Membership type, join date, renewal history, status |
| Money | Invoices, payments, amounts owing |
| Vehicles | Plate, make, model, year, VIN, engine details, linked to an owner |
| Scheme records | Log books issued, MR334 forms, reports to the Registrar |
| Authorised persons | Nomination details, including full name, address and SA client or licence number (the Code, clause 2.9) |
| Meetings and events | Minutes, attendance, RSVPs, photos |
Some of this is sensitive in practice even when it is not in law. A list linking names, home addresses and valuable historic vehicles is the kind of information a thief would value. Treat it with care.
The Privacy Act and the Australian Privacy Principles
The Privacy Act 1988 is the main federal privacy law. The OAIC describes it as introduced “to promote and protect the privacy of individuals and to regulate how Australian Government agencies and organisations with an annual turnover of more than $3 million, and some other organisations, handle personal information”.
The heart of the Act is the 13 Australian Privacy Principles (APPs). The OAIC describes them as principles-based law, which gives organisations flexibility to fit them to how they work. They apply to any organisation or agency the Act covers.
The APPs a club committee would recognise most easily are:
| Principle | What it covers (OAIC summary) |
|---|---|
| APP 1 | Open and transparent management of personal information |
| APP 3 | Collection of solicited personal information |
| APP 5 | Telling people about certain matters when you collect their information |
| APP 6 | Use or disclosure of personal information |
| APP 7 | Direct marketing |
| APP 10 | Taking reasonable steps to keep information accurate, up to date and complete |
| APP 11 | Taking reasonable steps to protect information from misuse, interference, loss and unauthorised access, modification or disclosure |
| APP 12 | Giving people access to information held about them |
| APP 13 | Correcting information held about people |
The full list and the OAIC’s guidelines on each principle are on the OAIC website.
Does the Act apply to your club?
It depends mainly on your club’s annual turnover, and also on what the club does. The OAIC’s guidance points to the questions below. Work through them, then confirm your answer with the OAIC or a lawyer.
The small business exemption
The OAIC says the Privacy Act applies to a not-for-profit if its annual turnover is greater than $3 million. For this purpose, the OAIC says annual turnover “includes all income from all sources. It does not include assets held, capital gains or proceeds of capital sales”.
So a club’s turnover includes membership fees, event income and any other income, not only subscriptions. A club that owns valuable assets, such as a clubroom or a collection, does not count those assets as turnover.
Exceptions that bring smaller clubs under the Act
Being under $3 million does not settle it. The OAIC says a not-for-profit must also comply with the Act if it is:
- a contracted service provider for an Australian Government contract
- an organisation providing health services
- a business that sells or purchases personal information or trades it for a benefit
- related to a larger body corporate that is subject to the Act
The OAIC’s guidance for sporting clubs makes a similar point: many smaller clubs may be covered “because they are related to a larger organisation or because they provide a health service and hold health information”. The OAIC’s small business page lists further circumstances that apply to some businesses.
Most motor vehicle clubs will not provide health services or trade in members’ information. But a club that is part of a larger body, or that does something unusual, should check carefully.
Opting in
A club that is not covered can choose to be. The OAIC says small businesses and not-for-profits with an annual turnover of $3 million or less can opt in, provided they are not health service providers and do not trade in personal information.
According to the OAIC:
- the club completes the OAIC’s opt-in application form
- it must provide its privacy policy (applications without one are declined)
- there is no fee for opting in or opting out
- once approved, the club’s trading name and ABN go on a public opt-in register
- the club then becomes subject to the APPs and is treated as covered for complaints and enforcement
- it can opt out later by notifying the OAIC in writing
The OAIC describes opting in as a public commitment to good privacy practice. It is a decision for the committee, and possibly for a general meeting, rather than something to do in passing.
Data breaches
A data breach is when personal information is lost, or someone accesses or discloses it without authority. The OAIC gives examples such as lost or stolen devices, hacked databases, and personal information sent to the wrong person by mistake.
For clubs covered by the Act, the Notifiable Data Breaches scheme applies. The OAIC says any organisation or agency the Privacy Act covers must notify affected individuals and the OAIC when a data breach is likely to result in serious harm.
The OAIC says a breach is an eligible data breach when:
- there is unauthorised access to or disclosure of personal information, or a loss of personal information, that the organisation holds
- this is likely to result in serious harm to one or more individuals
- the organisation has not been able to prevent the likely risk of serious harm with remedial action
If quick action (such as remotely wiping a lost device) means serious harm is no longer likely, the OAIC says the breach is not an eligible data breach. Where an organisation suspects an eligible breach, the OAIC says it must take all reasonable steps to complete its assessment within 30 calendar days.
A notification to members must include the organisation’s name and contact details, the kinds of personal information involved, a description of the breach, and recommendations for the steps people can take.
Clubs not covered by the Act are not bound by the scheme. Telling members promptly and honestly when their details have gone astray is still the right thing to do.
Good practice for every club
These habits are good practice, whether or not the Privacy Act applies to your club. They are not a statement of what the law requires.
Collect only what you need
Ask for information the club will actually use. If you never post anything, you may not need a home address for every member. If you do not need a date of birth, do not ask for one. Every field you collect is a field you must protect.
Tell members why
On the membership form, say what you collect, why, and who will see it. A short paragraph is enough. Members are more relaxed about sharing when they understand the reason.
Limit access by role
Each volunteer should see what their job needs. The treasurer needs payment records; the events helper usually does not. The registrar needs vehicles and log books; the newsletter editor may need only names and postal addresses. Fewer people with access means fewer chances for a mistake. Our page on roles and the activity log shows how MemberCrew handles this.
Keep it secure
Avoid emailing whole member lists as attachments. Avoid keeping the register on one volunteer’s personal laptop or a USB stick. Use strong passwords, and change access when committee members change. Our committee handover checklist includes passwords and access.
Keep it accurate
Wrong details cause real problems: renewal notices to old addresses, log books recorded against the wrong vehicle. Give members an easy way to update their details, and correct errors when you find them.
Delete what you no longer need
Do not keep personal information forever just in case. The OAIC says indefinite retention is unlikely to comply with the APPs. Set a review each year, perhaps after the AGM, and securely delete records the club no longer needs.
Plan for a breach
Decide now who does what if something goes wrong: who contains it, who assesses it, who speaks to members. A one-page plan agreed by the committee is far better than working it out in a hurry.
Scheme records and the five-year rule
Clubs on the Conditional Registration Scheme must keep some records for five years, which sits alongside the good practice of deleting what you no longer need. The Code requires recognised clubs to keep records of MR334 vehicles, duplicate MR334 forms, log books issued to financial members, and other Scheme administration documents, including membership records and minutes, for five years from the date of the document (the Code, clause 2.39). The Department may audit those records (the Code, clause 2.40).
In practice, that means:
- keep the records the Code lists for the full five years, even for members who have left
- after five years, review them and securely delete what the club no longer needs
- keep records that are not Scheme related only as long as the club needs them
For clubs covered by the Act, the OAIC’s APP 11 guidelines say the duty to destroy or de-identify information no longer needed does not apply where the organisation is required by or under an Australian law, or a court or tribunal order, to keep it. Whether that exception applies to the Code’s record-keeping rule is a question for your own advice. Our Scheme guide explains the wider record-keeping duties.
How MemberCrew helps
MemberCrew is built to make these habits easier. Club data is stored in Australia (Sydney). Each committee member only sees what their role allows: an events editor, for example, sees no money or contact details. Every change is recorded in an activity log showing who did what and when.
The club owns its data. Committees can download a full export of all their records at any time, from reports and exports. If a club leaves, it gets a complete export, and its data is deleted on request once the club confirms it has the export.
See security and privacy for the detail, and our privacy policy for how MemberCrew handles information.