Expert knowledge for digital decisions
How to Legally Protect Customer Data in a CRM?
Short answer
The Four Obligations
1. Legal Basis
Customer data for contract processing is based on Article 6(1)(b) GDPR. Advertising to existing customers can be based on legitimate interest, while newsletters to interested parties require consent – along with proof of when and how it was granted.
2. Roles and Rights
Not everyone needs access to every dataset. A CRM where everyone can see everything is convenient but not defensible in serious cases.
3. Deletion Periods
Data may only be stored as long as necessary for the purpose. Commercial and tax retention obligations take precedence – they are a reason for retention, not for further processing. Those who must retain data for tax reasons may not use it for further marketing.
4. Data Processing
Every service provider with access – host, support, agency – needs a contract according to Article 28 GDPR.
What is Most Often Missing in Practice
- Proof of Consent. Without it, consent is worthless in case of dispute.
- Implemented Deletion Periods. A concept in a folder is not enough; the system must actually delete.
- Ability to Provide Information. In response to a request under Article 15 GDPR, you generally have one month. Those who have to manually compile the data from five systems cannot do so reliably.
For Custom Solutions
The advantage: Deletion periods, logging, and the ability to provide information can be built in from the start, rather than retrofitted later.
Key facts
- Legal Basis Contract
- Article 6(1)(b) GDPR
- Service Providers with Access
- Contract according to Article 28 GDPR
- Information Period
- generally one month (Article 12(3) GDPR)
Sources
All external claims are backed by traceable sources.-
01
Verordnung (EU) 2016/679 (DSGVO) EUR-Lex