Home › Guides › GDPR and CRM

GDPR and CRM: what cleaning your HubSpot base must respect

By Anthony Abreu · Founder of Inspectable · HubSpot Revenue Operations & Sales Hub certified
Updated

CRM base cleaning is often presented as a sales performance topic. It is also, and sometimes first, a compliance topic: the GDPR imposes precise obligations on the data you keep, for how long, and with whom you share it. A base that was never cleaned accumulates gaps without anyone noticing.

This article is a plain language overview of general principles, not legal advice: for your specific situation, consult a professional or your data protection authority's documentation.

What the GDPR expects of your prospect base

  • Minimisation: collect and keep only the data necessary for your purpose. Records piled up "just in case" for years go against this principle.
  • Limited retention period: prospect data is not kept indefinitely. Data protection authorities commonly cite three years after the last contact coming from the prospect as a reference for sales prospecting. Your records with no activity for four years therefore raise a real question.
  • Accuracy: data must be accurate and kept up to date. A base riddled with contradictory duplicates and invalid contact details moves away from that.
  • Rights of individuals: access, rectification, erasure, objection. To honour them, you first need to find all of a person's records, an impossible mission when they exist in three copies under different spellings.
A clean base is not only more profitable: it is more defensible. In the event of an audit or an erasure request, a deduplicated base with retention periods applied demonstrates serious management.

Where to read all this in your portal

None of this needs a tool: it sits in your records, under property names you can filter, export and check yourself.

What you are looking forThe property that carries it
An explicit objection to outreachOpted out of email: Marketing Information
An unsubscribe from every sendUnsubscribed from all email
An address HubSpot has set asideEmail Address Quarantined
An address that bounced for goodEmail Hard Bounce Reason
The legal basis declared for this contactLegal basis for processing contact's data
The last signal that came from the prospectLast Engagement Date

To see them all on one record: open a contact, then View all properties. To count how many records are affected, build a segment, called a list before HubSpot renamed them, filtered on those same properties (Contacts › Lists › Create list, depending on your version). The count at the top of the list is your figure.

The trap that skews everything: Last Contacted and Last Engagement Date do not mean the same thing. The first records the day you wrote; the second, the day the prospect did something. A retention period counts from the second. Filtering on the first gives you records that look "active" although nobody has touched them for years: one mass send is enough to rejuvenate the whole base without a single prospect moving.

One last thing to check before relying on Legal basis for processing contact's data: this property is only filled if GDPR features are switched on in the portal and if someone has entered it. An empty column does not mean "no legal basis", it means "not declared", and that is a different piece of information.

The cleaning itself is a data processing activity

Often overlooked point: handing your base to a cleaning provider is a processing of personal data, with the obligations that come with it. Three questions to ask any provider before sending them a customer file:

The first page of the report: the compliance banner comes before the commercial figures, because no campaign starts without it.
The first page of the report: the compliance banner comes before the commercial figures, because no campaign starts without it.
  1. Where does the data go? A SaaS tool sends it to its servers, in which country? A transfer outside the EU triggers additional requirements. Ask where it is hosted, and how many providers see the file.
  2. Is a data processing agreement (DPA) signed? It is a requirement of GDPR article 28 as soon as a subcontractor handles your data.
  3. What happens to the data after the service? Guaranteed deletion confirmed in writing, or retention in the provider's backups?

Cleaning in compliance: the method

In practice, a GDPR compatible cleanup follows the same method as a quality cleanup, with three extra reflexes: document the rules applied (which records deleted, on what retention criterion); handle objection requests before any reimport (an unsubscribed person must never reappear in a marketing list, a classic pitfall of poorly controlled imports); and keep a trace of the decisions, record by record, so you can account for them.

That is exactly the Inspectable philosophy: no access to your portal, a drop server hosted in France from which the file is removed on receipt, an offline analysis, and a DPA signed before any transfer, every cleaning decision traced in a file you validate, and deletion confirmed in writing after delivery.

Sources

Every page below has been opened and read. These are primary sources: the authority that sets the rule, or the software vendor.

An audit built for GDPR, as a subcontractor

Inspectable analyses your export offline, without ever connecting to your portal. The file passes through a single drop server hosted in France, the three subprocessors are named in the legal notice, and the file is deleted no later than 30 days after your sign-off. The free mini-audit gives you the state of your base within 24h.

Get my free mini-audit