GDPR-Compliant CRM: What You Need Beyond Basic Privacy
You sell into the EU or UK. Your website has a privacy policy. Your CRM still cannot prove Art. 7 consent, fulfil an Art. 15 access request in 30 days, or produce Art. 30 processing records when a supervisory authority or a buyer asks.
We turn that exposure into consent management, DSAR workflows, and evidence packs your Information Officer can defend.

Sound Familiar?
These are the exact issues our clients faced before their CRM could prove GDPR data protection compliance:
- A privacy policy sits on the website while the CRM has no Art. 7 consent proof (purpose, timestamp, channel, or version)
- Art. 15 access requests take weeks of hunting across CRM, email tools, and spreadsheets against a hard 30-day window
- Nobody can produce Art. 30 records of processing when a supervisory authority or EU buyer asks
- Art. 17 erasure and Art. 20 portability requests stall because staff cannot locate or export a complete contact pack
- EU and UK prospects refuse to buy until you prove the CRM can evidence consent, DSARs, and cross-border transfer records
EU enforcement is not slowing down. Authorities issued EUR 1.2 billion in GDPR fines in 2024 (about R22.9 billion). LinkedIn alone was fined EUR 310 million (about R5.9 billion) over advertising consent. Insufficient legal basis remains the most common fine category. Schrems transfer scrutiny and buyer due diligence mean a privacy policy PDF no longer closes the deal.
What GDPR Consent Management Looks Like in the CRM
Consent captured → DSAR fulfilled → erasure proven. Your Information Officer stops rebuilding the trail by hand.
Consent Captured
Lead form or deal stage records Art. 7 purpose, channel, timestamp, and policy version
DSAR Queued
Art. 15 access request opens a tracked job with a 30-day SLA clock and identity check
Erasure or Portability
Art. 17 deletion or Art. 20 export runs across CRM and connected systems with a full log
Evidence Pack Ready
DPO exports Art. 30 records and the request trail when a supervisory authority or buyer asks
CRM Compliance Features That Survive EU Scrutiny
Art. 7 Consent Ledger
Every opt-in stores purpose, channel, timestamp, and policy version. Withdrawal is one-click and propagates, so consent is evidence, not a silent checkbox.
DSAR Workflow (Arts. 15–22)
Access, rectification, restriction, and objection requests open a tracked queue with identity checks, SLA clocks against the 30-day window, and an immutable outcome log.
Art. 17 Erasure Automation
A deletion request locates related records, applies delete or anonymise rules (respecting legal holds), cascades to connected systems, and writes a proof trail.
Art. 20 Portability Export
One action packages the subject's CRM data in a structured, machine-readable file so ops can fulfil portability without rebuilding the record by hand.
Art. 30 Processing Records
Purpose, categories of data subjects, recipients, retention, and transfer bases live as live CRM records, not a stale Word document on a shared drive.
DPO and Transfer Tooling
Open DSAR queues, overdue alerts, evidence packs for supervisory authorities, and cross-border transfer logs your DPO or Information Officer can defend.
CRMs We've Hardened for GDPR
From 22 Hours per DSAR to 2
How a 35-person Cape Town SaaS exporter turned GDPR from a sales blocker into a trust signal for EU buyers.
The Manual Process
- Consent was a website checkbox with no Art. 7 purpose or timestamp in HubSpot
- Ops spent 18–25 hours locating records for each Art. 15 access request
- Art. 30 records of processing lived in a stale policy PDF nobody updated
- Average 16–22 days to close a DSAR against the one-month window
- Two EU enterprise deals stalled when buyers asked for consent and erasure proof
The GDPR-Ready Process
- Consent ledger records purpose, channel, timestamp, and policy version
- DSAR workflow verifies identity, packages Art. 15 responses, and logs the outcome
- Art. 17 erasure and Art. 20 portability run as tracked jobs with cascade to email tools
- Most access requests close inside 2–3 business days with a full audit trail
- DPO exports evidence packs in minutes when a supervisory authority or buyer asks
Before vs After a GDPR-Ready CRM
How It Works
From first conversation to a defensible GDPR CRM in 3 to 6 weeks.
Map Your GDPR Gaps
Where EU contact data lives, how consent is captured today, and how DSARs, erasure, and portability currently move (or stall).
Free Scoping Call
30-minute call with your CEO, Information Officer, or ops lead to prioritise consent ledger, DSAR queue, and Art. 30 records.
Build and Test
We wire the fields, workflows, and evidence packs into your CRM, then run sample Art. 15, 17, and 20 drills with your team.
Go Live and Monitor
Staff keep the same CRM. Your DPO gets the queue, 30-day SLA alerts, and one-click proof packs. Manual hunts stop.
Frequently Asked Questions
Does GDPR apply if we are a South African company?
Yes, when you offer goods or services to people in the EU or UK, or monitor their behaviour. Many Cape Town and Johannesburg exporters already process EU customer and prospect data in the CRM. A website privacy policy does not satisfy Arts. 7, 15–22, or 30. The systems that hold the data must enforce and evidence those obligations.
What does a GDPR-compliant CRM actually include?
At minimum: an Art. 7 consent ledger, a DSAR queue covering Arts. 15–22 with a 30-day SLA clock, Art. 17 erasure workflows with an audit log, Art. 20 portability exports, Art. 30 records of processing, and DPO tooling for evidence packs and transfer logs. Legal still owns the policy; we make the CRM prove it.
Can we keep HubSpot, Pipedrive, or Salesforce?
Yes. Most South African teams keep their existing CRM and add GDPR fields, workflows, and reporting. A full rebuild only makes sense when the platform cannot store consent history, run erasure with an auditable trail, or export a portability pack.
How does this help with an Art. 15 access request?
When an EU data subject asks for their data, the CRM opens a tracked DSAR, helps staff locate every related record, packages the response, and logs the outcome against the one-month window. Manual hunting across inboxes and spreadsheets stops being the process.
Is this a legal opinion or a systems build?
It is a systems build. Your attorney or compliance advisor sets lawful bases, retention periods, transfer mechanisms, and exception rules. We configure the CRM so operations can follow those rules and prove they did. We do not replace legal advice.
How much does a GDPR-ready CRM build cost?
Focused consent, DSAR, erasure, and portability work on an existing CRM usually starts around R40,000. Full DPO tooling with Art. 30 records and connected-system cascades typically lands between R60,000 and R110,000. Against roughly R25,000 of labour per manual DSAR and average GDPR fines near R45 million, most mid-market exporters see payback inside a few months.
Stop Treating a Privacy Policy as Compliance
If your CRM cannot evidence consent, fulfil an Art. 15 request inside 30 days, or produce Art. 30 records, you are asking EU buyers and supervisory authorities to take your word for it.
Tell us which CRM you use, where EU contact data lives, and how DSARs move today. We will show you exactly how consent management, erasure, and portability would work in your stack.