POPIA Compliance for CRM and Customer Data: Controls Before the Fine
Your CRM holds names, numbers, emails, and purchase history. Without lawful basis, retention, and DSAR workflows wired in, every Information Regulator enquiry becomes weeks of panic, and POPIA fines climb to R10 million.
We build the operational POPIA programme into your CRM so consent, retention, and access requests are enforced, not hoped for.

Sound Familiar?
These are the exact gaps South African teams discover when POPIA CRM compliance suddenly matters:
- Customer PII sits in the CRM with no documented lawful basis per purpose
- Operator agreements with HubSpot, Salesforce, or email vendors are missing or unsigned
- Retention is a policy PDF while expired contacts and notes never leave the database
- A data subject access request triggers a two-week scramble across CRM, email, and shared drives
- The Information Officer has no queue, no SLA clock, and no evidence pack when the Regulator asks
The Information Regulator is enforcing. R5 million infringement notices have already been issued. A responsible party that ignores an enforcement notice faces administrative fines up to R10 million, plus criminal exposure for responsible officials. Waiting for a complaint is not a strategy.
What a POPIA CRM Programme Actually Does
Lawful basis recorded → retention enforced → DSAR answered → Regulator-ready evidence. No Friday-afternoon scramble.
Map Every Purpose
Contacts and marketing purposes get a lawful basis and purpose tag in the CRM
Wire Controls In
Retention clocks, operator agreement status, and section 19 safeguards land on the record
Run DSARs from the CRM
Access and erasure requests open a tracked queue with SLA clocks against 30 days
Prove It on Demand
The Information Officer exports evidence packs instead of reconstructing history from inboxes
Everything You Need for Defensible POPIA CRM Controls
Lawful Basis Register
Every CRM contact and marketing purpose maps to a POPIA processing condition. Staff see why you hold the record, not just that it exists.
Operator Agreements
Section 21 operator terms with CRM, ESP, and cloud vendors are tracked against live integrations so processors stay documented, not assumed.
Retention Automation
Record types get retention windows that match your policy. Expired contacts flag for review or deletion instead of sitting in the CRM forever.
DSAR Response Workflows
Access, correction, and erasure requests open a tracked queue with identity checks, record discovery, and an immutable outcome log against the 30-day window.
Section 19 Safeguards
Access controls, encryption flags, breach-notification triggers, and audit logs sit where your CRM actually holds personal information.
Information Officer Console
Open requests, overdue SLAs, consent gaps, and evidence packs in one view so the IO is ready for Regulator scrutiny without rebuilding the story from emails.
CRMs We've Hardened for POPIA
From 22 Hours per DSAR to Under 2
How a mid-market Gauteng services firm stopped treating POPIA as a policy PDF and made their CRM the control plane.
The Manual Scramble
- No lawful basis register; purposes lived in a shared Google Doc
- HubSpot and Mailchimp operator agreements were unsigned drafts
- Retention policy existed; expired contacts never left the CRM
- Each access request took about 22 hours across ops, IT, and legal
- Information Officer rebuilt evidence from email threads when asked
The Operational Programme
- Every contact purpose carries a lawful basis and retention clock
- Operator agreement status tracked against live integrations
- Expired records flag for review; deletions leave an audit trail
- DSARs open in the CRM with SLA clocks against the 30-day window
- Information Officer exports evidence packs in minutes, not weeks
Before vs After POPIA CRM Controls
How It Works
From first conversation to a live POPIA programme in 4 to 8 weeks.
Audit Your CRM Exposure
Where personal information lives, which purposes lack a lawful basis, and how DSARs and retention are handled today.
Free Scoping Call
30-minute call with your CEO or Information Officer to prioritise lawful basis, operator terms, DSAR workflows, and safeguards.
Build the Programme
We wire registers, retention rules, DSAR queues, and IO tooling into your CRM, then run sample access and erasure drills.
Go Live and Prove It
Staff keep using the same CRM. The Information Officer gets queues, SLA alerts, and evidence packs. Audit panic stops.
Frequently Asked Questions
What does a POPIA programme for CRM data actually cover?
It is the operational layer around customer personal information in your CRM: a lawful basis register per purpose, section 21 operator agreements with processors, retention schedules that actually delete or anonymise, DSAR workflows for access and erasure within 30 days, section 19 security safeguards, and Information Officer tooling to prove all of it. Legal still owns the policy; we make the CRM enforce and evidence it.
How is this different from buying POPIA CRM features or a consent platform?
Feature packs wire consent, retention, and erasure fields into the CRM. A consent management platform tracks marketing permissions across channels. This programme ties those pieces into one operational posture: lawful basis, operator agreements, DSAR readiness, security safeguards, and IO evidence. Most mid-market teams need the programme, not another checkbox.
What are the real POPIA fines and enforcement risks?
POPIA section 109 allows administrative fines up to R10 million. The Information Regulator has already issued R5 million infringement notices (Department of Justice in 2023; Department of Basic Education in late 2024). Separately, IBM's 2025 Cost of a Data Breach Report puts the average South African breach at R44.1 million. Fine risk and breach cost are not theoretical.
How fast must we respond to a data subject access request?
POPIA access requests follow PAIA procedures: respond within 30 calendar days, with one possible 30-day extension for complex searches. Manual fulfilment commonly takes 18 to 27 hours of staff time. Gartner has estimated roughly US$1,400 to US$1,524 per request (about R23,000 to R25,000 at current rates). Automation is how you hit the deadline without burning a week of ops time.
Can we keep HubSpot, Pipedrive, or Salesforce?
Yes. We configure registers, workflows, and reporting on your existing CRM in most cases. A platform change only makes sense when the CRM cannot store lawful-basis history, run DSAR queues, or produce an auditable trail.
How much does a POPIA CRM compliance programme cost?
Focused lawful-basis, retention, and DSAR work on an existing CRM typically starts around R45,000. Full Information Officer tooling with operator-agreement tracking, connected-system cascades, and section 19 safeguard wiring usually lands between R65,000 and R110,000. Against R10 million fine exposure and R23,000-plus per manual DSAR, most mid-market teams see payback inside a few requests or one avoided Regulator scare.
Stop Hoping Your CRM Is POPIA-Ready
If customer personal information sits in your CRM without lawful basis, retention, and DSAR workflows, you are one Regulator enquiry away from weeks of panic and R10 million fine exposure.
Tell us which CRM you use, who acts as Information Officer, and where access requests currently stall. We will show you exactly how an operational POPIA programme would land in your stack.