
GDPR and CRM: Data Retention, Consent and Deletion Processes
How to build GDPR compliance into your CRM: a data inventory, the consent fields to keep, retention periods, handling deletion requests, and anonymisation.
Your CRM holds the names, phone numbers and email addresses of thousands of people. There is usually no record showing when that data was collected or under what permission. One day a customer asks for their data to be deleted, and nobody knows what to do. GDPR compliance is not only a legal document exercise — it is a handful of fields and processes built into your CRM.
This article is general information and does not replace legal advice. Consult a qualified lawyer for your own situation.
Start with an inventory: what do you actually hold?
The first step is writing down which personal data you hold and why. For every field in the CRM, answer three questions: why is this collected, what lawful basis does it rest on, and how long will it be kept?
This exercise produces surprises on most teams. Fields created years ago, used by nobody, still carrying personal data. Unused personal data is the highest risk you can hold: no benefit, all liability.
Keep the consent record in the CRM
Saying consent was obtained is not enough; when, how and for what must be provable. At minimum you need these fields:
- Consent date and time
- The channel it came through: web form, contract, event registration
- Scope of consent: marketing email, calls and SMS recorded separately
- Which version of the privacy notice was shown
- Withdrawal date, if consent was withdrawn
Channel and notice version are the two most often skipped. When the notice is updated, if you cannot tell which version older consents rest on, the whole consent pool becomes contestable.
Not every processing activity needs consent
A common misconception is that explicit consent is required for everything. Processing needed to perform a contract with an existing customer does not rest on separate consent.
The practical consequence: when a customer withdraws marketing consent, invoice and transaction data held under the contract is not deleted. If it is not written down which data rests on which basis, these two cases get confused and the team either deletes too much or deletes nothing.
Retention periods and automatic cleanup
Personal data cannot be kept indefinitely. Set a retention period for each data type and write down what happens when it expires.
The practical approach is a simple rule in the CRM: flag records that have had no interaction for a defined period and never became customers, then anonymise or delete them. A retention policy run by hand becomes an unapplied document within months.
What happens when a deletion request arrives?
Write the process down in advance so there is no scramble when a request lands:
- Who receives the request and where is it logged?
- How is the person's identity verified?
- Which systems hold the data? CRM, email tool, support desk, backups.
- Which data cannot be deleted, and why? Anything under a statutory retention obligation.
- Within what period do you respond to the requester?
The third item is the hardest. A record deleted from the CRM but still alive in your marketing tool means the request has not been fulfilled.
Anonymise rather than delete
Deleting a record outright breaks your reports: last quarter's sales figures change. In most cases anonymisation is the better answer.
Identifying fields are cleared while deal value and date remain. The request is satisfied and your financial history stays consistent. The anonymisation must be genuine — reversible masking does not count as deletion.
Access rights are part of compliance
Everyone being able to see every record is common and an unnecessary risk. Narrow permissions by role: a rep sees their own book, and export rights are restricted.
Bulk export is the single largest leak vector. If there is no log of who exported what and when, determining the scope of an incident becomes impossible.
Where to start
This week's job: list the fields in your CRM that carry personal data and write next to each one why it is held. The fields where you cannot write a reason are item one on your compliance plan.
Closync keeps consent records and retention periods inside the customer record, making compliance part of the daily workflow.

