Wizz Cabs should have a professional privacy policy that explains how the company collects, uses, stores, protects and shares information relating to passengers, drivers, vehicles and bookings.
The policy should cover passenger names, telephone numbers, booking details, pickup and destination information, payment information, GPS/location data, driver information and information collected through the Wizz Cabs booking and dispatch systems.
Because Wizz Cabs operates taxis in Western Australia, the policy should also specifically address Camera Surveillance Units (CSUs). Where a CSU is required, Wizz Cabs must follow the applicable WA Department of Transport requirements concerning recording, signage, authorised access, storage, downloading, disclosure and disposal of recordings. CSU footage should only be accessed by authorised people for legitimate purposes such as passenger safety, driver safety, complaints, accidents, Police investigations, DTMI/DoT requirements, insurance or legal matters.
Drivers must keep passenger information confidential. They must not save passenger phone numbers for personal use, contact passengers privately, share passenger information, disclose destinations, take screenshots, publish information on social media or copy or distribute camera footage without proper authority.
Wizz Cabs should only collect information that is reasonably necessary for providing taxi services, managing bookings, processing payments, maintaining safety, managing drivers and vehicles, dealing with complaints, meeting regulatory requirements and protecting the company and passengers.
The company should also explain when information may legally be provided to WA Police, Department of Transport/DTMI, courts, insurers, government authorities, lawyers, payment providers, booking providers and other authorised service providers.
The policy should include strong security requirements covering passwords, system access, staff permissions, cloud systems, mobile devices, GPS systems, booking systems and camera recordings.
Wizz Cabs should also have a clear procedure for a data breach. If passenger, driver, payment, booking or camera information is lost, stolen, hacked or accidentally disclosed, management should investigate, contain the incident, preserve evidence and make any notification required by applicable Australian privacy law.
Passengers should have a clear way to request access to or correction of their personal information and to make a privacy complaint. The policy should provide the Privacy Officer's contact details and explain the complaint process.
The policy should also explain how long different types of information are kept and when information is securely destroyed. Camera footage that relates to an accident, complaint, Police investigation, regulatory investigation, insurance matter or possible legal claim should be preserved rather than automatically deleted.
Wizz Cabs should also identify whether any booking, payment, cloud, software or technology providers store information outside Australia. If overseas disclosure is possible, the privacy policy should explain this in accordance with applicable privacy requirements.
Most importantly, the privacy policy should not say that Wizz Cabs is automatically protected from all legal liability. Instead, it should state that Wizz Cabs will maintain procedures designed to comply with applicable Australian privacy law and WA passenger transport requirements, and that mandatory legislation always takes priority.
For Wizz Cabs, the strongest overall privacy system would therefore consist of a public Privacy Policy, supported internally by a CSU Camera Policy, Driver Confidentiality Policy, Data Breach Procedure, Data Retention Procedure and Government/Police Information Request Procedure. This gives the company a much stronger compliance framework than having only a privacy-policy page on the website.