Any CRM, however small the business using it, stores personal data: names, emails, phone numbers, purchase history, sometimes even preferences or personal notes jotted down by the sales team. That automatically makes the business a data controller under data protection law (such as GDPR in the EU, or equivalent regulations elsewhere), with obligations that don't depend on company size or on whether it sees itself as "too small a business to handle sensitive data".
The legal basis: why you have that data
Every piece of data stored in the CRM needs a legal basis justifying its processing: it can be the customer's explicit consent, the performance of a contract (you need their address to deliver what they bought), or a well-argued legitimate interest. Storing data "just in case, for the future", with no clear, documented legal basis, is one of the most common and riskiest practices among small businesses managing their CRM without specific legal advice.
The right to erasure and access to data
Anyone can request their data be deleted from the CRM (right to erasure) or that they be given a copy of all the information you hold on them (right of access), and the business has a limited legal window to respond to that request. Having a clear internal process (who handles these requests, how information gets located and deleted or exported) prevents a legitimate request going unanswered simply due to disorganisation, which can lead to penalties.
Who on the team has access to the data
Not everyone on the team needs to see every customer's full information. Setting up access permissions within the CRM by role (a sales rep doesn't need to see the full billing details of a customer they don't manage) reduces the risk of misuse and is also a requirement of the data-minimisation principle set out in the regulation.
External providers: your CRM is still your responsibility even when it's a third party's
If you use a cloud CRM from an external provider, you remain responsible for processing that data, even though the provider technically stores it. You need a signed data-processing agreement with that provider, and you should check where the data is physically stored (within or outside your regulatory region), because that also carries specific legal implications.
Frequently asked questions
Do I need explicit consent from every customer to have them in the CRM?
Not always: if the data is necessary to perform a contract with that customer (for example, managing their order), the legal basis can be the contractual relationship itself, with no need for additional specific consent for that.
What happens if a customer asks to delete their data but I have a legal duty to keep the invoice?
Regulations account for these exceptions: you can retain the data strictly necessary to comply with legal obligations (such as tax ones), even if the customer requested their general deletion from the rest of the CRM.
Do I need a CRM specifically certified for data protection compliance?
There's no single official "compliance certification", but it's worth choosing providers who explicitly state their regulatory compliance and offer the necessary contractual guarantees (data-processing agreement, clear server location).