Created with AI.
What does the GDPR require of a CRM system?
GDPR often feels like something legal and remote, but in a CRM it boils down to four specific things you need to be able to do.
Each category of personal data requires a lawful basis for processing. For customer relationships, a contract or legitimate interest is common; marketing to consumers generally requires consent. Document it for each category — that is the work that is actually required.
When responding to a data access request, you must be able to retrieve all the information you hold about the person concerned. If the information is scattered across note fields and attachments, this becomes cumbersome. This is an argument for recording information in a structured format rather than as free text.
Some data must be deleted upon request, while other data must be retained for accounting purposes. This distinction must be clarified before anyone asks, not while they are waiting for an answer.
You probably have no grounds for retaining sales leads from 2015 that never went anywhere. A simple rule for how long different types of data are kept ensures both compliance and clean-up in one go.
Ask a question or share what helped you.
Share a question or reflection.
Be the first to contribute.