Question Clearly sourced

Expert knowledge for digital decisions

How to Legally Protect Customer Data in a CRM?

Short answer

Four things are mandatory: a legal basis for each processing, a roles and rights concept instead of full access for everyone, documented deletion periods, and a data processing agreement with every service provider that has access. Additionally, there is the obligation to provide information: You must be able to state, upon request, which data is stored about a person.

The Four Obligations

1. Legal Basis

Customer data for contract processing is based on Article 6(1)(b) GDPR. Advertising to existing customers can be based on legitimate interest, while newsletters to interested parties require consent – along with proof of when and how it was granted.

2. Roles and Rights

Not everyone needs access to every dataset. A CRM where everyone can see everything is convenient but not defensible in serious cases.

3. Deletion Periods

Data may only be stored as long as necessary for the purpose. Commercial and tax retention obligations take precedence – they are a reason for retention, not for further processing. Those who must retain data for tax reasons may not use it for further marketing.

4. Data Processing

Every service provider with access – host, support, agency – needs a contract according to Article 28 GDPR.

What is Most Often Missing in Practice

  • Proof of Consent. Without it, consent is worthless in case of dispute.
  • Implemented Deletion Periods. A concept in a folder is not enough; the system must actually delete.
  • Ability to Provide Information. In response to a request under Article 15 GDPR, you generally have one month. Those who have to manually compile the data from five systems cannot do so reliably.

For Custom Solutions

The advantage: Deletion periods, logging, and the ability to provide information can be built in from the start, rather than retrofitted later.

Key facts

Legal Basis Contract
Article 6(1)(b) GDPR
Service Providers with Access
Contract according to Article 28 GDPR
Information Period
generally one month (Article 12(3) GDPR)

Sources

All external claims are backed by traceable sources.
  1. 01

Ready for your next project?

Free initial consultation - no sales pressure, just clear answers.

Request consultation