CRM base cleaning is often presented as a sales performance topic. It is also, and sometimes first, a compliance topic: the GDPR imposes precise obligations on the data you keep, for how long, and with whom you share it. A base that was never cleaned accumulates gaps without anyone noticing.
This article is a plain language overview of general principles, not legal advice: for your specific situation, consult a professional or your data protection authority's documentation.
What the GDPR expects of your prospect base
- Minimisation: collect and keep only the data necessary for your purpose. Records piled up "just in case" for years go against this principle.
- Limited retention period: prospect data is not kept indefinitely. Data protection authorities commonly cite three years after the last contact coming from the prospect as a reference for sales prospecting. Your records with no activity for four years therefore raise a real question.
- Accuracy: data must be accurate and kept up to date. A base riddled with contradictory duplicates and invalid contact details moves away from that.
- Rights of individuals: access, rectification, erasure, objection. To honour them, you first need to find all of a person's records, an impossible mission when they exist in three copies under different spellings.
The cleaning itself is a data processing activity
Often overlooked point: handing your base to a cleaning provider is a processing of personal data, with the obligations that come with it. Three questions to ask any provider before sending them a customer file:
- Where does the data go? A SaaS tool sends it to its servers, in which country? A transfer outside the EU triggers additional requirements. Local processing exposes nothing.
- Is a data processing agreement (DPA) signed? It is a requirement of GDPR article 28 as soon as a subcontractor handles your data.
- What happens to the data after the service? Guaranteed deletion confirmed in writing, or retention in the provider's backups?
Cleaning in compliance: the method
In practice, a GDPR compatible cleanup follows the same method as a quality cleanup, with three extra reflexes: document the rules applied (which records deleted, on what retention criterion); handle objection requests before any reimport (an unsubscribed person must never reappear in a marketing list, a classic pitfall of poorly controlled imports); and keep a trace of the decisions, record by record, so you can account for them.
That is exactly the Inspectable philosophy: 100% local processing, your data goes to no cloud, a DPA signed before any transfer, every cleaning decision traced in a file you validate, and deletion confirmed in writing after delivery.
An audit built for GDPR, as a subcontractor
Inspectable processes your export 100% locally: no send to a cloud server, no hidden subcontractor, guaranteed deletion after delivery. The free mini-audit gives you the state of your base within 24h.
Get my free mini-audit