TR Start free
HomeBlog › Guide

GDPR-compliant CRM: five common myths about customer data, and what is true

O Ohana360 Team • September 18, 2026 • 12 min read
Illustration of a person's data moving through collection, consent evidence, use, access and disposal inside a CRM

Anyone searching for a GDPR-compliant CRM is usually asking a simpler question: "If we buy this, is the GDPR sorted?" The short answer is no. A CRM can give you tools that make it much easier to keep customer data in line with the GDPR: consent records, retention periods, request tracking, anonymisation, an access trail. Which rules those tools run on is still your decision, because in law you are the controller.

Important: This article is not legal advice. Confirm your decisions on the GDPR, lawful bases and international transfers with qualified counsel. The Ohana360 features described below are tools that make compliance easier; they do not make every company using Ohana360 compliant by default.

Our example is Aksoy Furniture, a furniture retailer with three showrooms and thirty-eight staff. Their CRM holds 6,400 customer contacts, 1,900 leads from the website form and 3,100 newsletter subscribers. They keep addresses for delivery, phone numbers for instalment plans and email for campaigns. Last year they received 14 data subject requests: 9 for erasure, 3 for access and 2 objecting to marketing. Every one was handled from a single employee's inbox, and nobody can say how long each took. (Fictional example.)

This guide takes five things Aksoy Furniture believed about data protection, sets each against what is actually true, and shows how the work gets recorded in a CRM. First the big picture: a person's data passes five stops in your CRM, and at each one some work falls to the tool and a decision falls to you.

A person's data passes five stops in your CRM Aksoy Furniture setup, fictional example: 6,400 contacts, 1,900 leads, 3,100 subscribers WHAT OHANA360 DOES WHAT YOU DECIDE (THE CONTROLLER) 1 Collect web form, consent box Box ticked: email and message consent set to Approved Which fields do you really need, and why? 2 Evidence consent card Time, source, IP, who entered it and the text version Have counsel check the privacy notice before publishing 3 Use send gates Email consent Refused: the server blocks the send Which lawful basis covers each kind of message 4 Access profiles, 2FA, trail Who opened which record; the trail is kept 2 years Who sees what: profiles and the sharing default 5 Dispose nightly at 03:00 Expired records are anonymised or deleted for good A period per object; statutory periods for invoices The tool keeps the record and applies the rule; the controller sets the rule and answers for it.

Myth 1: "Buy a GDPR-compliant CRM and compliance is done"

What is true: compliance is a way of operating, not a product feature. Which data you collect and why, what your privacy notice says, how long you keep records and how you answer requests are your decisions. Ohana360's terms spell the roles out: for the personal data you enter, you are the controller, and Ohana360 is a processor acting on your behalf under a data processing agreement, as Article 28 expects.

What the tool adds is a way to put those decisions on the record and repeat them. In Ohana360 that happens under Setup > Compliance, which has three tabs:

The screen itself states the limit: the generated text is a draft and should be confirmed with counsel before you publish it. The draft is written around Turkey's KVKK, which follows the GDPR closely but not word for word, so an EU business should treat it as a starting point for its own privacy notice.

Myth 2: "A ticked box on the form is our consent record"

What is true: the box is the start, not the record. Where you rely on consent, the GDPR expects you to be able to demonstrate it. If someone asks why a campaign email reached them, the answer is not that a box was ticked; it is who consented, when, through which channel and having read which version of your notice. It also helps to remember that consent is only one lawful basis, and much CRM processing rests on contract or legitimate interests instead. Which basis covers which processing is a question for counsel.

In Ohana360, marketing consents live on a card on contact and lead records, provided by a system add-on enabled from the Marketplace. The card manages three channels separately.

ChannelWhere consent comes fromWhat happens on send
EmailThe consent box in the web form, the Newsletter360 subscription form, manual entryMarketing360 bulk email goes only to Approved; record emails and newsletters to a Refused address are blocked on the server
Message / WhatsAppThe web form consent box, manual entryRefused: the WhatsApp button will not send; Unknown: a warning
CallManual entry, with sources such as signed form, call centre or eventThe status shows on the card for building call lists

For every channel the card stores the status (Approved, Refused or Unknown), the moment of consent including the hour, the source, the user who entered it, the IP and the text version. The unsubscribe link in a newsletter sets email consent to Refused by itself. One note for teams that also market to recipients in Turkey: the same card exports the file format for Turkey's national consent registry, IYS. If you do not send to Turkey, you can ignore that part entirely.

Myth 3: "Keeping data is harmless; we might need it one day"

What is true: storage limitation is one of the GDPR's core principles. Data kept past its purpose is data you can lose in a breach, and every old lead kept "just in case" is part of that. A retention period should be a written policy that applies itself, because a manual clean-up is the first thing dropped in a busy month.

In Ohana360 this lives in Object Manager > object > Retention. For each object you pick a period (3 or 6 months, or 1, 2, 3, 5 or 10 years) and what happens when it runs out: anonymise (personal fields cleared, record kept) or delete permanently. The job runs nightly at 03:00 on the server and writes an entry to the audit log as kvkk_saklama, with how many records were handled in each object. The periods you choose also flow into the retention section of the draft privacy notice.

ObjectPeriodAt the endWhy
Lead1 yearAnonymiseA form that has not become a customer in a year has no sales value; the count stays in reports
Contact5 yearsAnonymiseWarranty and service continue; the clock runs from the last edit, so active customers are untouched
Case3 yearsAnonymiseService statistics stay, personal details in complaint text go
InvoiceYour statutory periodAnonymiseTax law sets a minimum; agree it with your accountant
Careful: a retention policy cannot be undone. The first run applies that night to every record already past its date. The clock runs from the record's last modification, so update an old but still important record first. Export and review your data once before you save, as the guide to moving off spreadsheets describes.

Myth 4: "On an erasure request, deleting the record is enough"

What is true: a request is a process: it is logged, answered without undue delay and within one month, and the work done is provable. Deletion is not always the best answer either; deleting a record breaks the sales and service history attached to it, and anonymising often reaches the same end without damaging business records. For an access request you have to gather and hand over the person's data, which in an untidy CRM takes days.

A data subject request: 30 days, the right action, a trail Aksoy Furniture, last year 14 requests: 9 erasure, 3 access, 2 objection (fictional) REQUEST RECORD AND COUNTER DAY 0 Request logged type, channel, date DAY 3 Verify identity your own process DAY 10 Data package one JSON file DAY 23 Attention list at 7 days left DAY 30 Deadline outcome recorded REQUEST TYPE AND THE CRM ACTION Access, portability Download the data package Erasure Anonymize (cannot be undone) Rectification Edit the record, log the outcome Objection to marketing Set that channel to Refused ANONYMISATION Cleared Name: "Anonim" plus 4 characters Email and phone Notes and description Consent statuses Kept Linked tasks, cases, deals Amounts and dates Sales and service history Clear your own custom fields by hand.

In Ohana360, Set up the request object under Compliance Tools creates a requests tab and record form in one click. The fields: requester name, email and phone; request type (access, rectification, erasure, portability, objection, transfer information); status (received, in review, completed, rejected); date received; channel (email, letter, registered electronic mail, notary, in person); the related contact record; and the outcome. Each open request runs a 30-day counter, and requests within seven days of the deadline or overdue appear in the Attention list on the Platform home page.

The work itself happens in Per-person Data Operations on the same tab. Type a contact's or lead's name or email and two buttons appear on the row:

Both actions are written to the audit log, so six months later the answer to "who handled this request, and when" is on the record. Verifying the requester's identity is your own process; the CRM does not do it. Under this setup Aksoy Furniture's nine erasure requests would have been nine anonymisations, and sales reports across 6,400 contacts would have stayed intact.

Myth 5: "Our team is trustworthy, so everyone can see every record"

What is true: trust is not an access policy. A showroom salesperson has no need to read finance's collection notes, and an intern has no need to see the whole customer list. The GDPR asks for appropriate technical and organisational measures, and the most basic one is that people see what their job needs and that you can tell who looked at what.

Aksoy Furniture set up three profiles: showroom (contacts and opportunities), service (cases) and management. They set the contact sharing default to owner only, and showroom managers see their own team's customers through the role hierarchy.

Where is the data, and does it leave the EU?

Ohana360 keeps your organisation's data on servers in Frankfurt, Germany. Traffic is encrypted with HTTPS and HSTS, the database is backed up nightly and an off-site copy is kept. For an EU business that means the primary hosting sits inside the EU. The other thing to map is the AI assistant: when it is used, the relevant record's content can be sent to a third-party AI provider. If you do not want that, switch on Disable the AI assistant in this org; the AI card disappears from record pages, the server refuses AI requests and the AI sentence drops out of the draft privacy notice. For your records of processing, ask for the current sub-processor list and check where each one processes data.

Where all of this lives in Ohana360

None of this is sold as a separate compliance module; it is part of the platform, with the consent card as a system add-on enabled from the Marketplace. Current plans are on the pricing page.

What it does not do

A plan for the first week

DayWhat to doTime
1List which personal data the CRM holds and why; check the inventory summary and flag fields you do not need45 minutes
2Enter controller details under Compliance, send the draft notice to counsel and save the approved version (a version number is created)30 minutes
3Review profiles and sharing defaults, turn on mandatory 2FA, deactivate accounts of people who have left60 minutes
4Enable the consent add-on, import existing consents with their source, update the web form snippet with the consent box90 minutes
5Set up the request object and make it a rule that every request arriving by email is logged there20 minutes
6After exporting and reviewing your data, save the first retention policies and check the audit log the next morning45 minutes

If CRM vocabulary is new, what is CRM covers the basics, and the Marketing360 page shows how consent feeds into campaigns and segments.

Frequently asked questions

Is there such a thing as a GDPR-compliant CRM?
Software on its own is neither compliant nor non-compliant; compliance is about how data is collected, how long it is kept, who can see it and how you answer requests. What you should expect from a CRM is tooling that lets you do those things on the record and the same way every time: evidenced consent, a retention period per object, a 30-day request tracker, a data package, anonymisation and an access trail. In Ohana360 these live under Setup > Compliance. You, as the controller, still set the rules and answer for them. This answer is not legal advice.
Does storing consent in the CRM prove consent?
It helps you demonstrate it, which is what the GDPR asks of a controller who relies on consent. In Ohana360 each consent entry on a contact or lead stores the status per channel (Approved, Refused or Unknown), the time including the hour, the source, the user who entered it, the IP and the version of your privacy text in force at that moment. Whether consent is the right lawful basis for a given message is a separate question, and one for your counsel.
Should I delete or anonymise a record on an erasure request?
That is your call with your counsel, but the practical difference is this: deleting a record breaks the sales and service history attached to it, while anonymising makes the person unidentifiable and keeps the business records. The Anonymize button under Compliance Tools replaces the name with "Anonim" plus the last four characters of the record ID, clears email, phone, notes, description and consent statuses, and leaves linked tasks, cases and opportunities in place. It cannot be undone and it is written to the audit log. Custom fields you added yourself are not cleared automatically.
Where is Ohana360 data hosted?
Your organisation's data sits on servers in Frankfurt, Germany, served over HTTPS with HSTS, with a nightly backup and an off-site copy. The AI assistant is the other point to know about: when it is used, the record's content can go to a third-party AI provider. If you do not want that, switch the AI assistant off for the whole org under Setup > Compliance, and no record data reaches any AI provider. Ask for the current sub-processor list when you write your records of processing.
What happens when a retention period runs out?
In Object Manager, on an object's Retention tab, you choose a period (three months to ten years) and what happens at the end (anonymise or delete permanently). The clock runs from the record's last modification. The job runs nightly at 03:00 on the server and is written to the audit log as kvkk_saklama. The policy cannot be undone and the first run applies to every record already past its date, so for invoices and other records with a statutory period, set the period with your accountant.
Can I see which customer records an employee opened?
Yes. The Record Access Trail under Compliance Tools shows who opened which record, when and from which IP. One row is written per user and record every ten minutes, the trail is kept for two years and survives the record being deleted. File access is tracked separately under Files, and successful and failed sign-ins are in the Login History tab of the audit log.

Keep customer data on the record

Consent evidence, retention periods, a request counter and an access trail on one screen. You set the rules; the tool applies them.

Read next