CRM base cleaning is often presented as a sales performance topic. It is also, and sometimes first, a compliance topic: the GDPR imposes precise obligations on the data you keep, for how long, and with whom you share it. A base that was never cleaned accumulates gaps without anyone noticing.
This article is a plain language overview of general principles, not legal advice: for your specific situation, consult a professional or your data protection authority's documentation.
What the GDPR expects of your prospect base
- Minimisation: collect and keep only the data necessary for your purpose. Records piled up "just in case" for years go against this principle.
- Limited retention period: prospect data is not kept indefinitely. Data protection authorities commonly cite three years after the last contact coming from the prospect as a reference for sales prospecting. Your records with no activity for four years therefore raise a real question.
- Accuracy: data must be accurate and kept up to date. A base riddled with contradictory duplicates and invalid contact details moves away from that.
- Rights of individuals: access, rectification, erasure, objection. To honour them, you first need to find all of a person's records, an impossible mission when they exist in three copies under different spellings.
Where to read all this in your portal
None of this needs a tool: it sits in your records, under property names you can filter, export and check yourself.
| What you are looking for | The property that carries it |
|---|---|
| An explicit objection to outreach | Opted out of email: Marketing Information |
| An unsubscribe from every send | Unsubscribed from all email |
| An address HubSpot has set aside | Email Address Quarantined |
| An address that bounced for good | Email Hard Bounce Reason |
| The legal basis declared for this contact | Legal basis for processing contact's data |
| The last signal that came from the prospect | Last Engagement Date |
To see them all on one record: open a contact, then View all properties. To count how many records are affected, build a segment, called a list before HubSpot renamed them, filtered on those same properties (Contacts › Lists › Create list, depending on your version). The count at the top of the list is your figure.
Last Contacted
and Last Engagement Date do not mean the same thing. The first records the day
you wrote; the second, the day the prospect did something. A retention period counts
from the second. Filtering on the first gives you records that look "active" although nobody
has touched them for years: one mass send is enough to rejuvenate the whole base without a
single prospect moving.One last thing to check before relying on Legal basis for processing contact's
data: this property is only filled if GDPR features are switched on in the portal and
if someone has entered it. An empty column does not mean "no legal basis", it means "not
declared", and that is a different piece of information.
The cleaning itself is a data processing activity
Often overlooked point: handing your base to a cleaning provider is a processing of personal data, with the obligations that come with it. Three questions to ask any provider before sending them a customer file:
- Where does the data go? A SaaS tool sends it to its servers, in which country? A transfer outside the EU triggers additional requirements. Ask where it is hosted, and how many providers see the file.
- Is a data processing agreement (DPA) signed? It is a requirement of GDPR article 28 as soon as a subcontractor handles your data.
- What happens to the data after the service? Guaranteed deletion confirmed in writing, or retention in the provider's backups?
Cleaning in compliance: the method
In practice, a GDPR compatible cleanup follows the same method as a quality cleanup, with three extra reflexes: document the rules applied (which records deleted, on what retention criterion); handle objection requests before any reimport (an unsubscribed person must never reappear in a marketing list, a classic pitfall of poorly controlled imports); and keep a trace of the decisions, record by record, so you can account for them.
That is exactly the Inspectable philosophy: no access to your portal, a drop server hosted in France from which the file is removed on receipt, an offline analysis, and a DPA signed before any transfer, every cleaning decision traced in a file you validate, and deletion confirmed in writing after delivery.
Sources
Every page below has been opened and read. These are primary sources: the authority that sets the rule, or the software vendor.
- Regulation (EU) 2016/679 (GDPR), consolidated textEUR-Lex, Official Journal of the European Union. The primary text, including the storage limitation principle.
- La prospection commerciale par courrier électronique, SMS-MMS et automate d’appelCNIL, the French regulator. In French. Consent in B to C, right to object in B to B.
- Create and edit propertiesHubSpot Knowledge Base. How to create and edit the properties named in this guide.
An audit built for GDPR, as a subcontractor
Inspectable analyses your export offline, without ever connecting to your portal. The file passes through a single drop server hosted in France, the three subprocessors are named in the legal notice, and the file is deleted no later than 30 days after your sign-off. The free mini-audit gives you the state of your base within 24h.
Get my free mini-audit