CRM Migration Compliance: POPIA, GDPR and Data Transfer Rules
Moving customer data between CRMs is a personal-information processing event under POPIA, and under GDPR if you have EU contacts. Skip the operator agreement, dump records into a US-hosted CRM without a transfer mechanism, or lose consent records mid-migration, and you create fine risk plus a go-live blocker your board will notice.
We build the compliance checklist into every migration so cutover is insured, not delayed.

Sound Familiar?
These are the compliance gaps that stall CRM migrations we inherit:
- The new CRM is US-hosted and nobody has checked section 72 cross-border transfer rules
- Vendor DPA is unsigned, or it is a GDPR template with no POPIA operator language
- Consent and purpose fields from the old CRM are being dropped in the field map
- Legal and ops discover the gap two weeks before cutover, freezing go-live
- A key customer audit asks for transfer assessments and operator agreements you cannot produce
The Information Regulator is issuing infringement notices and collecting fines (Lancet R100,000 paid; Blouberg R500,000 issued). Enterprise customers are auditing vendor DPAs and transfer mechanisms. Compliance gaps now delay go-live and create fine risk, not just paperwork debt.
What Migration Compliance Actually Covers
Gap scan → paperwork closed → data moves under instruction → audit pack ready for go-live.
Map the Exposure
Hosting region, existing DPAs, consent fields, and EU contact volume assessed against POPIA and GDPR
Close Operator Terms
Section 21 operator agreement or vendor DPA signed; SCCs or DPF checked for foreign hosts
Preserve Lawful Basis
Consent, purpose, and processing-condition fields migrate with every contact record
Ship the Evidence
Information Officer gets the pack; cutover proceeds without a last-week legal freeze
The Compliance Checklist Inside Every Migration
Operator Agreements & DPAs
We confirm a written POPIA section 21 operator agreement (or equivalent DPA) is signed with HubSpot, Salesforce, Dynamics, or your destination CRM before any personal information moves.
Lawful Basis Mapping
Every contact, lead, and marketing field is mapped to its POPIA processing condition and, where you have EU contacts, its GDPR lawful basis, so purpose records survive cutover.
Cross-Border Transfer Assessment
Hosting region, SCCs, and EU-US Data Privacy Framework status are checked against POPIA section 72 and GDPR Chapter V before data lands in a foreign data centre.
Consent & Purpose Preservation
Opt-in flags, marketing preferences, and purpose tags migrate with the record. We do not re-verify blindly; we preserve what you already hold and flag gaps that need a lawful refresh.
Retention Without Unlawful Holding
Source CRM retention for rollback is scoped and time-boxed so dual-run backups do not become indefinite, unlawful retention of personal information.
Audit Evidence Pack
Cutover pack includes signed operator terms, transfer notes, field-level lawful-basis map, retention schedule, and a go/no-go checklist your Information Officer can hand to auditors.
CRM Platforms We've Migrated Under POPIA / GDPR Rules
From a 5-Week Legal Freeze to Cutover on Schedule
How a 45-person Cape Town professional services firm unblocked a HubSpot migration after a customer POPIA questionnaire stalled go-live.
Compliance Afterthought
- HubSpot DPA unsigned; no POPIA section 21 operator language on file
- US data centre selected with no section 72 transfer note
- Marketing consent flags omitted from the field map
- Enterprise client questionnaire returned unanswered, freezing dual-licence cutover
- Legal and ops discovered the gap 12 days before go-live
Compliance as Go-Live Insurance
- Signed HubSpot DPA with POPIA operator addendum on file
- Transfer assessment documented (DPF / SCC path confirmed)
- Consent and purpose fields remapped; gaps flagged for lawful refresh only
- Audit pack answered the customer questionnaire in one sitting
- Cutover held the original date; dual-licence window not extended
Before vs After Migration Compliance
How It Works
From first conversation to a cutover pack your Information Officer can defend, in 2–4 weeks alongside the technical migration.
Compliance Gap Scan
Hosting region, existing DPAs, consent fields, and retention rules reviewed against POPIA and any GDPR exposure.
Close the Paperwork
Operator agreements signed, transfer mechanism confirmed, lawful basis and consent fields locked into the migration map.
Migrate with Evidence
Personal information moves under documented instructions. Dual-run retention is time-boxed. Audit trail is written as we go.
Go-Live Pack
Information Officer receives the evidence pack. Cutover proceeds without a last-minute legal freeze.
Frequently Asked Questions
Is a CRM migration a POPIA processing event?
Yes. Moving customer and contact records between systems is processing of personal information under POPIA. You remain the responsible party. The new CRM vendor is typically an operator under section 21, which means a written operator agreement is mandatory before the transfer, not after go-live.
What if our new CRM hosts data in the US or EU?
Cross-border transfers trigger POPIA section 72. For EU contacts, GDPR Chapter V also applies. We check whether the vendor offers EU residency, is certified under the EU-US Data Privacy Framework, or provides Standard Contractual Clauses, then document a transfer assessment so you are not dumping SA personal information into a foreign host with no transfer mechanism.
Do we need to re-collect consent from every contact?
Not automatically. If you already hold a valid processing condition or consent for the purpose, the migration should preserve those records. Blind re-verification is expensive and often unnecessary. We map what you hold, flag genuine gaps (especially marketing consent), and only recommend a refresh where the legal basis is missing or purpose has changed.
How does GDPR fit if we are a South African company?
If you process personal data of people in the EU or offer goods and services there, GDPR can apply alongside POPIA. Unlawful international transfers have drawn the largest GDPR penalties (Meta €1.2 billion for EU-US transfers, about R24 billion at R20/EUR). We treat GDPR as the parallel framework for EU contacts, not as a substitute for POPIA.
How long does migration compliance work take?
For a mid-market CRM move, the compliance workstream typically runs 2–4 weeks alongside technical scoping: one week to gap-scan contracts and field maps, one to two weeks to close DPAs and transfer notes, then evidence packaging through cutover. Starting it in week one of the project is what keeps go-live on the calendar.
How much does CRM migration compliance cost?
Compliance scoping and evidence packaging as part of a migration typically sits at R35,000–R95,000 depending on vendor stack, EU exposure, and how incomplete the existing paperwork is. Against a R10 million POPIA administrative fine ceiling, and go-live delays that burn dual-licence fees, most clients treat it as go-live insurance rather than optional red tape.
Stop Treating Migration Compliance as Red Tape
If your CRM move has no signed operator agreement, no transfer assessment, and no plan for consent fields, you are not ready for cutover. Compliance gaps delay go-live and create fine risk.
Tell us which CRM you are leaving, where the new one hosts data, and whether you have EU contacts. We will show you the POPIA-first checklist that keeps migration compliance and go-live on the same calendar.