The global average cost of a data breach reached $4.99 million in 2026, according to IBM’s 2026 Cost of a Data Breach Report. For any company that relies on a CRM to manage customer relationships, that figure points to a direct business risk: a breach can expose the same customer information the CRM is meant to protect.
CRM data privacy governs how customer data is collected, used, stored, shared, and deleted in a CRM. It turns privacy and security requirements — including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable laws — into day-to-day workflows that sales, RevOps, legal, security, and compliance teams can execute.
This guide covers the features required in a modern CRM stack, how to run a data subject request (DSR) workflow, how to govern third-party integrations and AI, and a phased implementation plan. This article provides general educational information, not legal advice; consult qualified counsel about the requirements that apply to your organization. For a broader view of the regulatory landscape, see HubSpot’s overview of GDPR compliance software.
Table of Contents
- What is CRM data privacy?
- CRM Data Privacy Features to Require in Your Stack
- CRM Data Privacy DSR Workflow Step-by-Step
- CRM Data Privacy for Integrations and Data Sharing
- CRM Data Privacy Due Diligence Checklist
- CRM Data Privacy Implementation Plan You Can Start Today
- Frequently Asked Questions About CRM Data Privacy
- Making CRM Data Privacy Operational
What is CRM data privacy?
CRM data privacy is how businesses responsibly handle the customer information stored in their CRM — from collection and use to storage and deletion. It covers the policies, security controls, and processes that protect customer data, reduce privacy risk, and build trust.
CRM data privacy and CRM security overlap, but they are not the same. Privacy governs whether, why, and how personal data may be collected and used; security focuses on protecting that data from unauthorized access, alteration, or loss. A CRM can have strong technical security controls and still create privacy risk if a team uses customer data for an unauthorized purpose. Organizations need to govern both together.
Cisco’s 2026 Data and Privacy Benchmark Study found that 46% of respondents identified clear communication about data use as the most effective action for building customer confidence. That makes clear, explainable privacy practices part of the customer-trust conversation, not just a legal requirement.
For sales leaders and RevOps teams, the practical takeaway is that CRM data privacy has moved beyond the legal team. Customer-facing workflows such as cold outreach, list uploads, integration handoffs, and AI-drafted messaging can involve personal data, so revenue teams need clear guardrails alongside legal, security, and compliance partners.
HubSpot's Free CRM Software
Free CRM Software & Tools for Your Whole Team
- Sales
- Marketing
- Operations
- Customer Service
CRM Data Privacy Features to Require in Your Stack
Require CRM privacy features that support both compliance workflows and day-to-day operations. During evaluation, ask what each control does, which users can manage it, what subscription or configuration it requires, and how the vendor documents it.

Consent and Preference Management in CRM
Consent and preference management records why a contact’s data may be processed and, when consent is the legal basis, what the person agreed to and how they can change that choice. A CRM should let teams record the relevant legal basis, communication preferences, and evidence needed for the organization’s privacy process.
HubSpot Smart CRM includes data privacy tools that can track a contact’s legal basis for processing and communication subscriptions. HubSpot forms can capture consent to process personal information and consent to receive marketing email. Because feature behavior and legal requirements vary by channel and use case, teams should configure these tools with legal guidance rather than assume every opt-out applies to every workflow.
Example: If a contact opts in to product emails through a webinar form, capture the consent language, subscription type, source, and date available in the CRM. If the contact later changes a subscription preference, use that updated status to govern future communications for the affected channel.
Pro tip: Connect consent information to source and campaign context when your CRM supports it. That gives sales, marketing, legal, and compliance teams a clearer record of how the contact entered the database and which permissions or legal basis apply.
Roles, Permissions, and Least Privilege
Least-privilege access means users receive only the access they need for their work. In a CRM, that can mean controlling access at the object, record, export, and property level, depending on the product and subscription. The goal is to reduce unnecessary exposure if an account is compromised, a role changes, or an employee leaves.
Role design needs regular upkeep as teams, territories, integrations, and responsibilities change. HubSpot supports CRM record-access controls, export permissions, reusable permission sets, and property-access controls; availability varies by subscription. Reusable permission sets and property-level view/edit restrictions require qualifying Enterprise subscriptions, and Sensitive Data has separate Enterprise requirements.
Example: A sales development representative (SDR) can receive edit access to the contact and company records required for an assigned territory. In contrast, export and Sensitive Data access remain restricted to users who need them. When the SDR changes roles, an admin updates the person’s permissions and record access instead of leaving legacy access in place.
Best for: Sales organizations with multiple roles, territories, or shared account ownership across sales development, account executive, and customer success handoffs.
Audit Logs and Change History
Audit logs and change history help teams answer who changed a record or configuration, when it changed, and what changed. During CRM evaluation, confirm which events the system records, which subscription levels expose them, how long records are retained, who can access them, and whether logs can be searched or exported. Do not assume every audit trail captures record reads or is tamper-evident unless the vendor documents that behavior.
HubSpot provides record property history and export logs, and qualifying paid subscriptions include a centralized account audit log; available audit events vary by subscription. HubSpot also lets admins set a threshold for large-export notifications.
Pro tip: Configure the security and export notifications your CRM supports and route them to a channel the responsible team monitors. Prioritize unusual or large exports and administrative or account-access changes that could expose customer data.
Data Minimization and Retention Policies
Data minimization means collecting only the personal data needed for a defined purpose and retaining it only as long as necessary for that purpose and applicable legal obligations. In practice, that can mean limiting form fields, controlling enrichment, reviewing stale properties, and setting defined retention or review periods. For the operational side of keeping the database lean, see HubSpot’s guides to data hygiene and CRM data maintenance.
Retention automation can reduce reliance on manual cleanup, but it should match a documented policy. HubSpot can automatically delete contacts after a configurable period of inactivity; deleted contacts remain restorable for 90 days before permanent deletion. HubSpot recommends assessing the impact before enabling automatic deletion and consulting legal guidance for the retention rules that apply.
Example: A company might review contacts after 24 months of inactivity, but the actual retention period and action should come from the organization’s documented purposes and legal obligations. If the policy calls for deletion, automate only the records and data that meet those criteria rather than applying a universal schedule.
Best for: SaaS and services companies that need documented, repeatable retention and deletion practices across customer data.
Encryption, SSO, and MFA
Encryption, single sign-on (SSO), and multi-factor authentication (MFA) are baseline controls to evaluate in a CRM. Customer data should be encrypted in transit and at rest using current industry-standard cryptography. SSO centralizes authentication through an identity provider, while MFA adds another verification factor when users sign in.
For HubSpot, data is encrypted in transit with TLS 1.2 or 1.3 and at rest with AES-256. HubSpot supports SAML-based SSO for qualifying Enterprise subscriptions. HubSpot uses two-factor authentication (2FA) terminology for its native second-factor controls: 2FA is available across plans. It is required for Starter, Professional, and Enterprise users who sign in with a username and password.
Pro tip: Treat encryption, SSO, and MFA or 2FA as one access-security program rather than a fixed rollout sequence. Verify the CRM’s encryption defaults, then configure identity and second-factor controls around your organization’s identity provider, risk profile, and account model.
For detailed documentation on encryption, SOC 2 Type II, GDPR, and data residency, visit HubSpot’s Trust Center.
CRM Data Privacy DSR Workflow: Step by Step
A data subject request (DSR) is a request from an individual to exercise applicable rights over personal data, such as access, deletion, correction, or portability. Response deadlines vary by law. Under the GDPR, organizations generally must respond without undue delay and in principle within one month; under the CCPA, covered businesses generally have 45 calendar days to respond to requests to know, delete, or correct, with a possible 45-day extension when notice is provided. A repeatable DSR workflow helps teams track the deadline that applies to each request.
1. Intake and verify identity.
Every DSR begins with intake: Receive the request through a documented channel, log it, acknowledge it according to your process, and verify the requester’s identity when required. Verification should be proportionate to the request and the data involved. Under the GDPR, an organization may request additional information when necessary to confirm identity; the CCPA also requires verification for certain consumer requests.
At intake, classify the request type — such as access, deletion, correction, portability, restriction, or objection — and record the law, jurisdiction, and deadline that apply.
Example: An EU customer submits an access request through the company’s privacy portal. The workflow logs the request, acknowledges receipt, completes proportionate identity verification, classifies it as an access request, and routes it to the privacy operations queue with the applicable one-month GDPR response deadline.
2. Locate, review, and redact data.
Once identity is verified where necessary, locate each system that holds personal data relevant to the request, including the CRM and connected systems that received the data. A documented system map and integration inventory make that search repeatable. HubSpot’s Data Request Manager can export contact data from HubSpot, but teams still need to account for personal data held in connected third-party systems.
Review the located data for applicable exceptions, third-party rights, and retention obligations before disclosure or deletion. Document what you excluded or retained and why; legal counsel should determine which exemptions or obligations apply.
Pro tip: Maintain a system-of-record map that lists each downstream tool receiving CRM data, such as sales engagement, enrichment, analytics, dialer, and contract systems. Update the map whenever an integration is added or removed so DSR searches do not depend on memory.
3. Fulfill, document, and close.
Fulfill the request through a secure channel and according to the right being exercised. For deletion requests, carry out the required deletion in the CRM and connected systems, subject to applicable exceptions. For access requests, provide the required copy and information. Where the GDPR right to data portability applies, provide the data the person supplied in a structured, commonly used, machine-readable format.
Document the request, actions taken, response date, and any exceptions or retention decisions. Keep the record for the period required by your organization’s documented retention policy and applicable law.
Example: For the same EU access request, the privacy operations team delivers the response through a secure portal on day 20, documents any redactions or exclusions, and records the completion date and rationale in the DSR log. The organization retains that log according to its approved retention schedule rather than applying a universal six-year period.
HubSpot's Free CRM Software
Free CRM Software & Tools for Your Whole Team
- Sales
- Marketing
- Operations
- Customer Service
CRM Data Privacy for Integrations and Data Sharing
Third-party integrations can increase CRM privacy risk because each connected app may receive, store, or process customer data. Risk rises when teams do not govern requested permissions, storage locations, retention and deletion practices, and the vendor’s role in processing the data.
Verizon’s 2026 Data Breach Investigations Report found that breaches involving third parties accounted for 48% of breaches, with third-party supply-chain involvement up 60% year over year. For CRM stacks with multiple integrations, that makes vendor and integration governance a material part of privacy and security review.
Vetting third-party integrations should follow a repeatable checklist. HubSpot Marketplace listing submissions are reviewed by HubSpot’s Ecosystem Quality team, and listed apps are required to request only the OAuth scopes they need. App certification is a separate program with additional security, privacy, reliability, performance, usability, accessibility, and value requirements. The core vetting steps:
- Review current security assurance and privacy documentation relevant to the use case, such as SOC 2 Type II reports, ISO/IEC 27001 certification, and applicable privacy terms.
- Review the OAuth scopes the integration requests and grant only the access the app needs.
- Confirm where the vendor stores or processes CRM data and whether the available locations and transfer mechanisms meet your requirements.
- Confirm the vendor’s retention and deletion behavior, including what happens to received data when the integration is disconnected.
- Confirm that appropriate data processing terms are in place when the vendor processes personal data on your company’s behalf.
- Log every integration in a central inventory that includes its owner, purpose, data scope, and review or renewal date.
Example: A sales engagement tool requests broad CRM contact access at install. The integration owner limits the app to the permissions required for the workflow and avoids granting access that the integration does not need. The team logs the integration owner, purpose, hosting region, granted access, and next review date in the integration inventory.
Exports deserve the same discipline. Every CSV pulled from the CRM creates another copy of customer data outside the governed system. Log exports where the CRM supports it, limit export permission to users who need it, and prefer governed integrations or scoped API access when they reduce unnecessary copies. Teams that use a customer data platform to unify data across systems should read HubSpot’s guide to customer data platforms.
Best for: Growth-stage and midmarket sales organizations that add integrations frequently and need a repeatable governance process.
In my advisory work with growth-stage sales organizations, the integration inventory is almost always the first governance gap I see. Teams add tools quickly to help reps meet short-term sales goals, and the resulting sprawl only surfaces during a security review or a customer procurement questionnaire. A monthly integration audit — one hour, one owner — pays for itself within a quarter.
CRM Data Privacy Due Diligence Checklist
When evaluating a CRM for privacy, ask vendors for documented answers to the questions below and compare the evidence rather than relying on marketing claims.
- Does the vendor maintain current security assurance reports or certifications relevant to your use case, such as a SOC 2 Type II report or ISO/IEC 27001 certification, and can your team review the evidence?
- What documentation, data processing terms, and transfer mechanisms does the vendor provide to support your obligations under applicable laws such as GDPR and CCPA?
- What data-hosting regions are available, and can existing accounts migrate between them? Ask specifically about the U.S., EU, U.K., Canada, and Australia if those regions matter to your requirements.
- Is data encrypted in transit with TLS 1.2 or later and at rest with AES-256 or an equivalent current standard?
- Does the CRM support SAML-based SSO and enforceable MFA or 2FA, including phishing-resistant methods when your security policy requires them, and which subscriptions include those controls?
- Are consent and preference tools available, and can the CRM record the legal basis and communication preferences your process requires?
- How granular are record, property, export, and administrative permissions, and which subscription level provides each control?
- Which events do audit logs capture, how long are they retained, and can authorized admins search or export them?
- What retention or deletion automation is available, for which objects or record types, and how is it configured?
- How does the CRM support DSR intake, identity verification, data export or deletion, documentation, and deadline tracking?
- What controls govern AI access to customer data, Sensitive Data, human review, and auditability?
- Does the vendor maintain a current trust or security center with assurance reports, privacy documentation, subprocessors, and relevant incident or disclosure information?
- For third-party apps, can admins review and limit requested OAuth scopes, and what marketplace review or certification processes apply?
Pro tip: Score every candidate CRM against the same checklist during procurement. Treat missing, ambiguous, or undocumented answers as a reason to investigate further before signing.
CRM Data Privacy Implementation Plan You Can Start Today
The three-phase plan below sequences implementation from foundational controls to operational workflows to ongoing governance. Set the timeline for each phase based on your CRM’s complexity, user count, integrations, and regulatory obligations.

Phase 1: Configure the foundations.
Phase 1 covers the baseline controls that make everything else possible:
- Verify encryption settings.
- Configure SSO and MFA or 2FA where available.
- Define role-based access.
- Restrict sensitive data.
- Document the CRM-related security policies your team needs.
Phase 1 also includes a first pass at data cleanup — deduplication, standardization, and archival or deletion under the organization’s retention policy — because privacy controls work better when they apply to accurate, necessary data. HubSpot’s guide to contact management is a useful reference for the data-quality side of this work.
Deliverables from Phase 1: Documented login and access settings, a role matrix, a property-access map for Sensitive Data, and a baseline data-quality report. For HubSpot, SAML-based SSO requires qualifying Professional or Enterprise subscriptions. At the same time, 2FA is available across plans and required for Starter, Professional, and Enterprise users who sign in with a username and password.
Best for: Revenue teams establishing a formal CRM privacy program and prioritizing foundational access and data-quality controls.
Phase 2: Operationalize requests and retention.
Phase 2 turns policies into workflows:
- Stand up a DSR intake channel and document the end-to-end process, including identity verification when required, scope and exception review, the applicable response deadline, and completion tracking.
- Configure retention or deletion automation only where the CRM supports it and your approved policy calls for it.
- Add consent and legal-basis capture to the intake points and communication channels that need it.
- Build a runbook for common incidents — such as unusual exports, credential compromise, or an email sent to the wrong list — so response is coordinated rather than improvised.
Deliverables from Phase 2: A DSR workflow and intake queue, documented retention rules, consent and legal-basis capture at applicable forms or channels, and an incident runbook. HubSpot provides Data Request Manager for contact data exports, separate permanent-delete tools, automatic deletion for inactive contacts, legal-basis tracking, and form-based consent tools; exact behavior varies by feature and subscription.
Pro tip: Track DSR deadlines on a shared dashboard or queue visible to the people responsible for fulfillment. A simple status view can make ownership, next steps, and due dates clear without implying that one workflow fits every law.
Phase 3: Govern integrations and AI.
Phase 3 makes CRM privacy an ongoing operating discipline.
- Maintain the integration inventory described earlier
- Set a risk-based review cadence
- Require appropriate data processing terms and security review for new integrations
Extend governance to AI features with documented purpose limits, controls on access to Sensitive Data, human review where needed, and audit records for material AI-generated actions when the CRM supports them. HubSpot’s guide to AI data protection covers broader AI governance considerations.
Deliverables from Phase 3: An integration inventory with owners, a documented review cadence, AI usage policies, and the audit evidence your CRM can produce for relevant AI activity.
Example: An AI email-drafting tool inside the CRM could be limited to prospecting and follow-up drafts, blocked from Sensitive Data, and configured so a sales rep reviews each draft before sending. If the CRM records AI-driven changes or actions, include those events in the audit process.
Best for: Sales organizations evaluating or already using AI-powered CRM features and building governance around that use.
Revenue leaders evaluating a CRM against these criteria can start with Smart CRM. Smart CRM is an AI-powered system of record that unifies customer data across teams and helps surface relevant context. Select Smart CRM functionality is also available in HubSpot’s free tools.
HubSpot currently hosts product infrastructure in the U.S., Canada, Australia, and the EU (Germany), and migration options are subject to eligibility. For current security, privacy, compliance, and data-hosting documentation, review the HubSpot Trust Center.
Frequently Asked Questions About CRM Data Privacy
Is CRM data privacy the same as CRM security?
No. CRM data privacy and CRM security overlap, but they are not the same. Privacy governs how and why customer data may be collected, used, stored, shared, and deleted. Security covers technical and organizational controls that protect data from unauthorized access, alteration, or loss. A CRM can have strong security controls and still create privacy risk if data is used for a purpose that is not permitted.
In practice, revenue teams need both. Security controls such as encryption, SSO, MFA, and access management protect the data; privacy controls such as consent, retention, DSR handling, and integration governance help determine whether teams handle it appropriately. Modern CRMs should support both sets of controls.
What CRM data should be encrypted?
CRM customer data should be encrypted in transit and at rest using current industry-standard cryptography. During vendor review, verify the protocols and algorithms the CRM documents, whether encryption is enabled by default, and whether additional controls apply to Sensitive Data. For example, HubSpot documents TLS 1.2 or 1.3 for data in transit and AES-256 for data at rest.
For data such as government identifiers, financial information, or health and medical information, use the CRM’s Sensitive Data controls and restrict access to users who need it. Organizations subject to HIPAA, PCI DSS, or other sector-specific requirements should confirm that the CRM, contract terms, and configuration can support their obligations before storing regulated data.
HubSpot’s Sensitive Data capabilities are available with qualifying Enterprise subscriptions; accounts storing HIPAA-covered data must enable the relevant settings and, when applicable, accept HubSpot’s Business Associate Agreement.
How often should we audit CRM data privacy controls?
Set audit frequency according to risk, change volume, regulatory obligations, and the control framework your organization uses. Separate frequent access and configuration checks from broader periodic reviews of DSR performance, retention, integrations, and governance, and document the schedule and owner for each control. Frameworks such as the NIST Privacy Framework and ISO/IEC 27701:2025 can help structure the review scope.
Automated monitoring can reduce the gap between formal reviews. Where the CRM supports it, alert on unusual or large exports and material administrative or account-security changes so the responsible team can investigate promptly.
Where should CRM data be stored for compliance?
CRM data does not automatically have to stay in the same country or region as the customer. Under the GDPR, personal data can be transferred outside the European Economic Area when an applicable transfer mechanism or safeguard is in place, such as an adequacy decision or Standard Contractual Clauses. Choose a hosting region and transfer approach based on the laws, contracts, risk, and business needs that apply to your organization.
HubSpot currently hosts product infrastructure in the U.S. East (Virginia), U.S. West (Oregon), Canada (Montreal), Australia (Sydney), and the EU (Germany). HubSpot also provides account data migration options, but destination availability and eligibility can vary. Review current hosting and migration documentation before selecting or changing a region.
How do we honor deletion while preserving compliance records?
Deletion rights are not absolute. Under GDPR Article 17, exceptions can apply when processing is necessary to comply with a legal obligation, establish or exercise legal claims, or meet other specified grounds. Evaluate each request against the applicable law and document any justified retention; legal counsel should determine which records and retention periods are required.
Where lawful retention is necessary, keep only the personal data needed for that purpose and apply appropriate safeguards. If data can be properly anonymized so the individual is no longer identifiable, it may fall outside the GDPR’s personal-data rules; do not assume that simply removing obvious identifiers makes a record anonymous.
Making CRM Data Privacy Operational
CRM data privacy is an operating discipline, not a one-time compliance task. Clear controls for access, consent, retention, DSRs, integrations, and AI help customer-facing teams handle personal data consistently while giving legal, security, and compliance partners better evidence of how the CRM is governed.
For revenue leaders ready to build on an AI-powered system of record, Smart CRM connects customer data across HubSpot’s products, with select Smart CRM functionality available in HubSpot’s free tools. HubSpot publishes current security, privacy, compliance, and data-hosting documentation in the HubSpot Trust Center.
In my own advisory work with sales and RevOps leaders, I have consistently seen that the teams that win the trust of enterprise buyers are the ones that can answer privacy questions in a procurement cycle without stalling. That fluency does not come from a policy document — it comes from processes teams build and practice over time. The frameworks in this guide are the fastest starting point I know of to build that capability without over-engineering the work.
HubSpot's Free CRM Software
Free CRM Software & Tools for Your Whole Team
- Sales
- Marketing
- Operations
- Customer Service
CRM
