GDPR in Your CRM: Retention, Consent and Deletion
By CodexierPublished 5 min read
A CRM is designed to remember. Every form, email and meeting adds contacts, and nothing leaves unless someone decides it should. Under GDPR, that is a problem: you may only keep personal data as long as you have a purpose and a legal basis for it. This guide shows how to set a legal basis per contact type, define retention rules, record marketing consent, handle requests from individuals and automate the clean-up.
Legal basis per contact type
GDPR does not require one legal basis for the whole CRM; it requires a basis for each purpose. In practice, most B2B and B2C contacts fall into a few groups with different bases. Writing them down is the foundation for everything else, because retention and deletion follow from the purpose.
| Contact type | Typical legal basis | Typical purpose |
|---|---|---|
| Active customer | Contract | Delivering, invoicing, support |
| Lead who asked for contact | Legitimate interest or steps before a contract | Answering and following up the enquiry |
| Newsletter subscriber | Consent | Sending marketing email |
| Contact person at a customer or supplier company | Legitimate interest | Running the business relationship |
| Former customer | Legitimate interest, limited time | Follow-up, similar offers where marketing law allows |
Accounting records are a separate matter: the Swedish Bookkeeping Act requires invoices and vouchers to be kept for seven years, but that obligation applies to the accounting data, not to every contact in the CRM.
Retention periods and rules
A retention rule has two parts: a period and a trigger. 'Delete leads 24 months after last activity' is a rule; 'delete old data regularly' is not. The period should match how long the purpose really lasts. A lead that has not responded in two years is not a sales opportunity. A former customer who bought something with a long warranty may justify a longer period.
- Define 'activity' precisely: an email opened, a reply, a meeting, a purchase.
- Base the rule on a date field that is updated automatically, not by hand.
- Decide whether to delete or anonymise; anonymised records can keep statistics without identifying anyone.
- Document the rules in your record of processing, so they can be shown to the Swedish Authority for Privacy Protection (IMY) if asked.
Consent records for marketing
If marketing email relies on consent, you must be able to show that consent was given: when, where, for what, and with what wording. A 'marketing: yes' field imported from a spreadsheet three years ago does not show that. Most modern CRMs, including HubSpot, have subscription types with history per contact; use them rather than custom yes/no fields.
- Store the date, source form and consent text for each consent.
- Keep separate subscription types, such as newsletter and product news, so people can choose.
- Process unsubscribes immediately and never re-subscribe someone by import.
- Keep a record of the unsubscribe itself, so the address is not added again by mistake.
Leads arriving from website forms should carry their consent into the CRM automatically; see website leads into your CRM.
Handling deletion and access requests
Individuals can ask what data you hold about them and ask you to delete it. You must answer within one month. The CRM is usually the main source, but copies often live in email, spreadsheets, the newsletter tool, the accounting system and the support desk.
- Keep a simple routine: who receives requests, how identity is checked, and who answers.
- List every system where the person's data might exist, and search them all.
- For access requests, export the data in a readable form, including where it came from.
- For deletion, delete everywhere except where another law requires keeping it, such as accounting records, and tell the person what was kept and why.
- Log the request and the answer date.
Automating the clean-up
Manual clean-ups happen once and then never again. Build the rules into the CRM: a scheduled workflow that finds contacts matching a retention rule, flags them for review for a short period, then deletes or anonymises them. Start with a report of what would be removed and check it before switching on deletion. The same logic keeps the CRM useful, because sales teams work faster with fewer dead records. Our CRM health checklist covers the data-quality side.
When not to buy help: if your CRM has a few hundred contacts and one user, you can set these rules up yourself in an afternoon. When the CRM is shared, fed by several sources or has years of unmanaged history, a CRM setup and audit maps legal bases, fields and automations in one go. Book a short call to see what it would involve.
Frequently asked questions
How long may we keep leads in the CRM?
GDPR sets no fixed period; it must match the purpose. Many companies choose one to two years after last activity for leads who never became customers, and document the reasoning.
Do we need consent to store B2B contacts?
Usually not for the business relationship itself; legitimate interest normally covers it. Marketing email is a separate question with its own rules in the Marketing Act.
Is anonymising the same as deleting?
Only if the result truly cannot be linked back to a person. Removing the name but keeping the email address is not anonymisation.
What if a deleted contact is imported again?
That is a common failure. Keep a suppression list of removed and unsubscribed addresses that imports are checked against, storing only what is needed to block them.
Is your CRM holding data you cannot justify?
Tell us which CRM you use and where contacts come from. On a short call we will outline the retention rules and automations you need and what an audit would cover.
Book a free 15-minute call