12.5 Customer Records, Payment Data & Privacy Compliance (FOIP, CASL, DNCL)

Key Takeaways

  • Sub-task B-8.03 requires customer information to be entered and updated in the business data system, payment information to be recorded per company policy, and records to be maintained according to FOIP, CASL and DNCL requirements.
  • The RSOS defines customer information as contact information, equipment make, model and VIN, pricing levels, and customer payment history; customer payment information means credit cards and charge accounts.
  • A complete customer record is an operational asset: VIN and equipment data on file eliminates repeated lookups, prevents wrong-part errors, and enables preventative maintenance and recall tracing.
  • Full credit card numbers are never stored in a dealer management system note field, on a paper file, or in a customer profile — the payment terminal tokenizes card data and the card number stays out of the record.
  • Privacy obligations continue after the sale: records are accessed only for a legitimate business purpose, disclosed only with authority, retained only as long as required, and disposed of securely.
Last updated: September 2026

12.5 Customer Records, Payment Data & Privacy Compliance (FOIP, CASL, DNCL)

Sub-task B-8.03, Records customer information, sits inside Task 8 — the largest task in MWA B at 9 of the 120 exam questions. It is short, with only three performance criteria, but it is the sub-task that connects almost every other one: pricing levels drive quotes, VIN and equipment data drive parts identification, payment history drives credit decisions, and recall tracing is impossible without a customer record.

The three performance criteria are:

  1. B-8.03.01P — customer information is entered and updated in the business data system for internal historical records.
  2. B-8.03.02P — customer payment information is recorded in the business data system according to company policies and procedures.
  3. B-8.03.03P — customer records are maintained according to Freedom of Information and Privacy (FOIP) regulations, Canada's Anti-Spam Legislation (CASL), and the Do Not Call List (DNCL).

What Belongs in a Customer Record

The RSOS is explicit. Customer information includes: contact information, equipment make, model and vehicle identification number (VIN), pricing levels, and customer payment history. Customer payment information includes: credit cards and charge accounts.

Field groupContentsWhy it earns its place
Contact informationName, business name, address, phone, email, contact person by roleDelivery accuracy; recall and backorder notification; CASL-compliant messaging
Equipment profileMake, model, year, VIN or serial, engine and drivetrain codes, fleet unit numberEliminates repeated lookups and is the primary defence against wrong-part errors
Pricing levelMatrix or discount tier, contract terms, tax exemption statusConsistent quoting across every technician on the counter
Payment historyTerms, average days to pay, credit limit, exceptionsFeeds credit decisions and account release authority
Purchase historyParts supplied by date and unitWarranty adjudication, core tracking, and recall tracing

Why the Equipment Profile Matters Most

A parts technician who has to ask a fleet customer for the VIN of unit 47 on every call is repeating work the DMS should have stored the first time. Worse, the VIN keyed by phone under time pressure is the single most common source of a wrong-part error on a split-year application.

A maintained equipment profile delivers four things at once:

  • Speed — the application is already resolved.
  • Accuracy — the VIN was captured once, from the vehicle, and verified.
  • Recall tracing — when a recall lands, sub-task D-12.02 requires identifying units already sold by VIN, invoice and work order. That is only possible if the record was populated at the time of sale.
  • Preventative maintenance — service intervals can be scheduled against real equipment rather than guessed.

Keeping records updated is part of the criterion. Fleets replace units, shops change ownership, contacts leave, and a superintendent's phone number that has been wrong for eight months is the reason a backorder notification never arrived.


Recording Payment Information — and What Not to Record

B-8.03.02P requires payment information to be recorded according to company policies and procedures, and the policies exist because payment data is the most sensitive information a parts counter touches.

Charge accounts. The record holds the account number, credit limit, terms of payment, authorized purchasers and their signing authority, purchase order requirements, and tax exemption certificates. All of this is legitimate to store.

Credit cards. The handling rule is the opposite:

  • The payment terminal processes the card. Card data is tokenized so the department holds a reference, not a card number.
  • Never write a full card number into a DMS note field, a special-order record, a delivery manifest, or a paper file drawer.
  • Never retain the card verification value (CVV, in the RSOS acronym list) after authorization — it may not be stored at all.
  • Where a card is kept on file for a recurring commercial account, it is held through the processor's tokenized card-on-file facility, not by the department.
  • Receipts are truncated so only the last digits appear.

Red Seal Exam Trap: A customer asking the counter to "keep my card on file so I don't have to give it every time" is a reasonable request answered the wrong way by writing the number in the account notes. The correct answer is the processor's card-on-file facility, or an in-house charge account application.


FOIP, CASL and DNCL

The three instruments named in the standard cover different activities.

Freedom of Information and Privacy (FOIP). In practice this is the privacy side of the obligation: personal information is collected for a stated purpose, used only for that purpose, safeguarded, and disclosed only with authority. For a parts counter the operational rules are:

  • Collect what the transaction needs. A cash counter sale of a wiper blade does not require a customer's home address and date of birth.
  • Access only for a legitimate business purpose. Looking up a neighbour's vehicle history in the DMS out of curiosity is a privacy breach even though the technician has system rights to do it.
  • Disclose only with authority. A caller claiming to be a customer's employer, insurer or spouse does not get purchase history, VINs or account balances. Verify identity and authority first.
  • Retain and dispose appropriately. Records are kept for the period the business requires for tax, warranty and audit purposes, then destroyed securely — shredded, not placed in the recycling bin, and copier and scanner storage cleared.

Canada's Anti-Spam Legislation (CASL). Governs commercial electronic messages. The record must show whether consent is express or implied, when it was obtained, and whether it has been withdrawn — because an unsubscribe request is honoured against the record, and a request honoured in one system but not another produces a repeat message the recipient already refused.

Do Not Call List (DNCL). Governs telemarketing calls. Numbers on the national list must not be called for telemarketing purposes, subject to defined exemptions such as an existing business relationship. A customer record flagged as do-not-call must be respected by every technician, not just the one who set the flag.

Red Seal Exam Focus: These are separate obligations. A customer who consented to email marketing has not consented to telemarketing calls, and neither consent authorizes disclosing their purchase history to a third party. Questions in this area test whether the candidate keeps the three straight.


Practical Safeguards at the Counter

Privacy compliance at a parts counter is mostly physical and habitual:

  1. Screen positioning. A counter monitor facing the customer queue displays the previous customer's account details to everyone in line.
  2. Individual logins. Shared operator accounts destroy accountability for both transactions and record access.
  3. Session locking. Sessions are locked whenever the counter is left, as covered in Section 2.4.
  4. Document control. Credit applications, warranty packets and account statements are filed or shredded, not left on the counter overnight.
  5. Verification before disclosure. Ask who is calling and confirm authority before releasing anything from an account record.
  6. Breach reporting. A lost delivery manifest full of customer addresses, or a misdirected email containing account data, is reported through the company's policy channel promptly rather than quietly corrected.

A parts department that treats the customer record as a working asset — accurate, current, and properly protected — gets faster lookups, fewer wrong parts, cleaner recall responses and better credit decisions out of the same file. That is why the standard makes maintaining it a performance criterion of the trade rather than an administrative afterthought.

Loading diagram...
Customer Record Handling and Privacy Decision Path
Test Your Knowledge

A regular wholesale customer asks the parts counter to keep their company credit card on file so their shop foreman does not have to provide it on every order. What is the correct response?

A
B
C
D
Test Your Knowledge

A caller states that they are the spouse of an account holder and asks the parts counter for the purchase history and VIN recorded against that customer’s account. What should the technician do?

A
B
C
D
Test Your Knowledge

A parts department holds a customer record showing express consent to receive email promotions, and the customer’s telephone number is registered on the National Do Not Call List. Which statement is correct?

A
B
C
D
Congratulations!

You've completed this section

Continue exploring other exams