Skip to content
Back to Blog

CRM and GDPR in a small business: what you actually need to handle

You send a mailing to your CRM contact base and get a reply: "Please delete my data, legal basis GDPR." First thought: fine, deleting it. Second thought: where did I actually get this contact, and on what basis am I holding onto it? If you don't know, you're not alone. I see this in almost every CRM rollout I handle for clients.

Picking a CRM and getting your team to use it is one thing. GDPR in your CRM is a completely different thing that almost nobody thinks about until the first email like that shows up, or worse, a letter from a regulator.

Does a small business need to handle GDPR in its CRM?

Yes, no exceptions: if you keep data about individuals in your CRM, such as name, phone number, email, or address, you're processing personal data, and GDPR applies to you regardless of company size. GDPR is the EU regulation on personal data protection that defines on what basis, for how long, and in what way you're allowed to store and use people's data.

I'm not a lawyer and this isn't legal advice. But I run a company that implements CRMs for clients, so this topic has come up dozens of times. I've worked out a practical approach, and I'm sharing it here.

What customer data are you actually allowed to keep in a CRM?

You're allowed to keep the data you genuinely need for contact and customer service, and only for as long as you have a basis for it: consent, a contract, or a so-called legitimate interest. This is the data minimization principle: you collect only what you need, not more "just in case."

In practice, the most common mistake in small businesses is the opposite of this principle. The CRM has a "notes" field and people write everything in it. The client's marital status, their mood during a meeting, something a friend mentioned about their business. That's not data you need for a sale. It's data that turns a simple situation into a big problem in the event of an audit or a leak.

Is consent for a sales contact the same as consent for a newsletter?

No, and that's one of the more common mistakes in small businesses. Sales consent, meaning contact about a quote the client themselves asked for, is different from marketing consent for a regular newsletter and mailings to your whole base. In your CRM, it's worth splitting these into separate fields or tags rather than one shared "consent: yes."

If someone asked you for a quote, you can contact them about that specific matter. That doesn't mean you can add them to your weekly newsletter. This is exactly where companies trip up most often. They mix a working contact with the marketing list.

The most common mistakes I see with CRMs and customer data

  • A contact database with no record of where a contact came from or whether there's consent for it, and after six months nobody remembers anymore
  • A salesperson saves a client's private phone number "just in case," obtained outside of any consent form
  • Old contacts sit around for years because "they might come in handy," even though nobody has reached out to them in two years
  • Everyone in the company has access to the entire database, including interns who don't need it for their work
  • The database gets exported to a spreadsheet "for analysis" and the file sits on someone's desktop for months afterward

None of these mistakes come from bad intentions. They come from nobody in the company being responsible for keeping an eye on it, until a customer asks, or worse, a regulator does.

What you actually need to handle: a checklist

You don't need a legal department. You need a handful of things done once, properly:

  • A legal basis for every contact. You know where a given number or email came from and whether the client agreed to it: by buying a service, filling out a form, or signing up for a newsletter
  • One person responsible for data in the CRM. Same as with rolling out the system itself: without an owner, nobody keeps an eye on it
  • Limited access. A salesperson sees their own clients, not the whole company database. Fewer people with access means less risk
  • An actual data deletion process. Someone asks for deletion, you have a ready procedure instead of figuring out from scratch how to do it in your specific system
  • A data processing agreement with your CRM provider. If you use an external tool, and almost every small business does, the provider processes data on your behalf and there should be a signed agreement for that. Reasonable providers have it ready to download from their dashboard
  • A retention policy. Decide after how long a period of inactivity a contact gets deleted or anonymized, instead of keeping everything "forever"

This is an afternoon's worth of work, if you do it once and properly. The problem is that almost nobody finds that afternoon until they have to.

When a CRM becomes a problem instead of a solution

A CRM was supposed to make working with clients easier, but instead it becomes a source of risk once it accumulates more data than anyone actually controls. The bigger the database and the longer it's kept without any order, the more you stand to lose from a single incident: a lost laptop, the wrong permission, an accidentally shared export.

Paradoxically, a smaller but well-organized database is safer and often just as effective for sales as a huge database full of contacts that have been dead for years. Regularly cleaning up your CRM isn't just a GDPR topic. It's also sales hygiene. It's easier to work with 500 current contacts than to click through 5,000 of which most won't respond anyway.

Frequently asked questions

Does a sole proprietorship also have to comply with GDPR in its CRM?
Yes. GDPR doesn't have a company-size threshold. If you're processing data about individuals, including sole traders treated as individuals in a B2B relationship, the rules apply to you.

Can I keep old contacts in my CRM "just in case"?
Not without a legal basis and without a time limit. A contact you have no relationship with, and no consent to keep contacting, should be deleted or anonymized after a set period.

Is a free CRM worse for GDPR compliance than a paid one?
Not necessarily. What matters is whether the provider offers a data processing agreement and where its servers are physically located. The price of the tool by itself says nothing about compliance.

Who in a small company should be responsible for CRM data?
Usually the owner or one designated person. Shared responsibility, in practice, means no responsibility.

GDPR in your CRM isn't a job for an expensive law firm. It's a handful of habits handled once, properly, and kept up over time. Less data, more order, less stress the first time a client sends you a difficult email.

Related articles

CRM Systems

How much does a CRM cost for a small business, and where can you actually save

A CRM costs more than its subscription. Learn how to budget for licenses, implementation, and team time—and where to save without making sales harder.

Read more
CRM Systems

Does a small business need a CRM, or is a spreadsheet enough?

Every now and then someone asks me whether they should finally get a CRM. The answer almost never depends on how modern that sounds, but on how many contacts you have and who's handling them.

Read more
CRM Systems

CRM implementation: why your team goes back to spreadsheets after a week

You buy a CRM, run a training session, and two weeks later people are still typing data into a spreadsheet. That's not a technology problem. It's an implementation problem.

Read more