CRM Migration Compliance: POPIA, GDPR & Data Transfer Rules | WebFootprint
CRM Integrations CRM Migration Compliance

CRM Migration Compliance: POPIA, GDPR and Data Transfer Rules

Moving customer data between CRMs is a personal-information processing event under POPIA, and under GDPR if you have EU contacts. Skip the operator agreement, dump records into a US-hosted CRM without a transfer mechanism, or lose consent records mid-migration, and you create fine risk plus a go-live blocker your board will notice.

We build the compliance checklist into every migration so cutover is insured, not delayed.

A glass CRM panel and a gold POPIA compliance seal linked by an S-curved ribbon of consent forms and DPA documents in a midnight navy scene
R10 million
maximum POPIA administrative fine the Information Regulator can issue
R100,000
Lancet Laboratories fine paid after failing POPIA breach notification duties
~R46 million
average GDPR fine (€2.3m) at ~R20/EUR across CMS Enforcement Tracker data
R24 billion
Meta’s €1.2bn GDPR fine for unlawful EU-US transfers (Schrems II era)
The Problem

Sound Familiar?

These are the compliance gaps that stall CRM migrations we inherit:

  • The new CRM is US-hosted and nobody has checked section 72 cross-border transfer rules
  • Vendor DPA is unsigned, or it is a GDPR template with no POPIA operator language
  • Consent and purpose fields from the old CRM are being dropped in the field map
  • Legal and ops discover the gap two weeks before cutover, freezing go-live
  • A key customer audit asks for transfer assessments and operator agreements you cannot produce

The Information Regulator is issuing infringement notices and collecting fines (Lancet R100,000 paid; Blouberg R500,000 issued). Enterprise customers are auditing vendor DPAs and transfer mechanisms. Compliance gaps now delay go-live and create fine risk, not just paperwork debt.

How It Works

What Migration Compliance Actually Covers

Gap scan → paperwork closed → data moves under instruction → audit pack ready for go-live.

1

Map the Exposure

Hosting region, existing DPAs, consent fields, and EU contact volume assessed against POPIA and GDPR

2

Close Operator Terms

Section 21 operator agreement or vendor DPA signed; SCCs or DPF checked for foreign hosts

3

Preserve Lawful Basis

Consent, purpose, and processing-condition fields migrate with every contact record

4

Ship the Evidence

Information Officer gets the pack; cutover proceeds without a last-week legal freeze

What We Build

The Compliance Checklist Inside Every Migration

Operator Agreements & DPAs

We confirm a written POPIA section 21 operator agreement (or equivalent DPA) is signed with HubSpot, Salesforce, Dynamics, or your destination CRM before any personal information moves.

Lawful Basis Mapping

Every contact, lead, and marketing field is mapped to its POPIA processing condition and, where you have EU contacts, its GDPR lawful basis, so purpose records survive cutover.

Cross-Border Transfer Assessment

Hosting region, SCCs, and EU-US Data Privacy Framework status are checked against POPIA section 72 and GDPR Chapter V before data lands in a foreign data centre.

Consent & Purpose Preservation

Opt-in flags, marketing preferences, and purpose tags migrate with the record. We do not re-verify blindly; we preserve what you already hold and flag gaps that need a lawful refresh.

Retention Without Unlawful Holding

Source CRM retention for rollback is scoped and time-boxed so dual-run backups do not become indefinite, unlawful retention of personal information.

Audit Evidence Pack

Cutover pack includes signed operator terms, transfer notes, field-level lawful-basis map, retention schedule, and a go/no-go checklist your Information Officer can hand to auditors.

CRM Platforms We've Migrated Under POPIA / GDPR Rules

HubSpotSalesforceMicrosoft DynamicsPipedriveZoho CRMMonday.comCustom CRMs
Client Story

From a 5-Week Legal Freeze to Cutover on Schedule

How a 45-person Cape Town professional services firm unblocked a HubSpot migration after a customer POPIA questionnaire stalled go-live.

Before

Compliance Afterthought

  • HubSpot DPA unsigned; no POPIA section 21 operator language on file
  • US data centre selected with no section 72 transfer note
  • Marketing consent flags omitted from the field map
  • Enterprise client questionnaire returned unanswered, freezing dual-licence cutover
  • Legal and ops discovered the gap 12 days before go-live
5 weeks projected delay and dual-licence burn
After

Compliance as Go-Live Insurance

  • Signed HubSpot DPA with POPIA operator addendum on file
  • Transfer assessment documented (DPF / SCC path confirmed)
  • Consent and purpose fields remapped; gaps flagged for lawful refresh only
  • Audit pack answered the customer questionnaire in one sitting
  • Cutover held the original date; dual-licence window not extended
0 weeks added delay after the compliance pack
5 weeks of dual-licence burn avoided
R82K saved vs projected delay cost
100% customer POPIA questionnaire cleared
3 weeks compliance pack to signed cutover
The Difference

Before vs After Migration Compliance

Before
After
Operator / DPA status
Unsigned or GDPR-only
POPIA s21 terms on file
Cross-border transfers
Hosting region unknown
s72 / SCC / DPF assessed
Consent & purpose records
Dropped in field map
Preserved with gap flags
Source retention for rollback
Indefinite dual-run copy
Time-boxed, purpose-limited
Customer / regulator audit
Questionnaire stalls go-live
Evidence pack ready
Fine and delay exposure
Up to R10m + dual licences
Documented go-live insurance
Getting Started

How It Works

From first conversation to a cutover pack your Information Officer can defend, in 2–4 weeks alongside the technical migration.

01

Compliance Gap Scan

Hosting region, existing DPAs, consent fields, and retention rules reviewed against POPIA and any GDPR exposure.

02

Close the Paperwork

Operator agreements signed, transfer mechanism confirmed, lawful basis and consent fields locked into the migration map.

03

Migrate with Evidence

Personal information moves under documented instructions. Dual-run retention is time-boxed. Audit trail is written as we go.

04

Go-Live Pack

Information Officer receives the evidence pack. Cutover proceeds without a last-minute legal freeze.

Questions

Frequently Asked Questions

Is a CRM migration a POPIA processing event?

Yes. Moving customer and contact records between systems is processing of personal information under POPIA. You remain the responsible party. The new CRM vendor is typically an operator under section 21, which means a written operator agreement is mandatory before the transfer, not after go-live.

What if our new CRM hosts data in the US or EU?

Cross-border transfers trigger POPIA section 72. For EU contacts, GDPR Chapter V also applies. We check whether the vendor offers EU residency, is certified under the EU-US Data Privacy Framework, or provides Standard Contractual Clauses, then document a transfer assessment so you are not dumping SA personal information into a foreign host with no transfer mechanism.

Do we need to re-collect consent from every contact?

Not automatically. If you already hold a valid processing condition or consent for the purpose, the migration should preserve those records. Blind re-verification is expensive and often unnecessary. We map what you hold, flag genuine gaps (especially marketing consent), and only recommend a refresh where the legal basis is missing or purpose has changed.

How does GDPR fit if we are a South African company?

If you process personal data of people in the EU or offer goods and services there, GDPR can apply alongside POPIA. Unlawful international transfers have drawn the largest GDPR penalties (Meta €1.2 billion for EU-US transfers, about R24 billion at R20/EUR). We treat GDPR as the parallel framework for EU contacts, not as a substitute for POPIA.

How long does migration compliance work take?

For a mid-market CRM move, the compliance workstream typically runs 2–4 weeks alongside technical scoping: one week to gap-scan contracts and field maps, one to two weeks to close DPAs and transfer notes, then evidence packaging through cutover. Starting it in week one of the project is what keeps go-live on the calendar.

How much does CRM migration compliance cost?

Compliance scoping and evidence packaging as part of a migration typically sits at R35,000–R95,000 depending on vendor stack, EU exposure, and how incomplete the existing paperwork is. Against a R10 million POPIA administrative fine ceiling, and go-live delays that burn dual-licence fees, most clients treat it as go-live insurance rather than optional red tape.

Ready to insure go-live?

Stop Treating Migration Compliance as Red Tape

If your CRM move has no signed operator agreement, no transfer assessment, and no plan for consent fields, you are not ready for cutover. Compliance gaps delay go-live and create fine risk.

Tell us which CRM you are leaving, where the new one hosts data, and whether you have EU contacts. We will show you the POPIA-first checklist that keeps migration compliance and go-live on the same calendar.

Chat with us