GDPR Data Erasure
The One CRM provides a structured workflow for handling GDPR right-to-erasure requests and right-of-access data exports.
Right to Erasure Request Workflow
When an individual requests deletion of their personal data:
- Receive the request — Typically via email or your privacy contact
- Locate the contact in CRM by searching for their name or email
- Open the contact record and click Actions > GDPR Erasure
- CRM shows a preview of all data that will be deleted and data that will be retained
- Confirm the erasure — This action is irreversible
- CRM processes the erasure and generates a certificate
What Data Is Deleted
When erasure is executed, CRM removes:
| Data Type | Action |
|---|---|
| Contact record | Name, email, phone, address, job title — all personal fields deleted |
| Activity log | Emails, calls, meetings, notes associated with the contact |
| Email history | All sent/received emails linked to this contact |
| Sequence enrollments | Active sequences are terminated, enrollment history removed |
| Form submissions | Lead capture form data submitted by this contact |
| Notes | All notes on the contact record |
| Custom field data | Any custom field values |
What Data Is Retained
Certain data is retained for legal and financial compliance:
| Data Type | Reason |
|---|---|
| Invoices in Books | Financial records required for tax and audit compliance |
| Audit log entries | Compliance requirement — entries are anonymized (personal details removed, action logged) |
| Won/lost deal records | Financial reporting — contact reference is removed but deal value and outcome remain |
| Suppression list entry | The email address is retained on the suppression list to prevent future contact (GDPR permits this) |
⚠️Erasure is permanent and cannot be undone. Review the preview carefully before confirming. If the contact has linked invoices in Books, the erasure will proceed but those financial records are preserved as required by law.
Erasure Certificate
After erasure completes, CRM generates a certificate that includes:
- Date and time of erasure
- Categories of data deleted
- Categories of data retained and the legal basis
- The user who performed the erasure
- A unique reference number
Download the certificate from the audit log. Provide it to the requesting individual as proof of compliance.
GDPR Data Export (Right of Access)
To fulfill a right-of-access request:
- Open the contact record
- Click Actions > Export Data
- CRM generates a JSON file containing:
- All personal data fields
- Activity timeline
- Email history
- Sequence enrollment history
- Associated company and deal references
- Consent records
- Download and provide to the individual within the 30-day GDPR timeframe
Consent Management
CRM tracks consent at the contact level with four fields:
| Field | Values |
|---|---|
| Consent Status | Opted In, Opted Out, Pending, Unknown |
| Consent Type | Explicit (actively opted in), Implied (existing business relationship), Imported |
| GDPR Basis | Consent, Legitimate Interest, Contract |
| Consent Source | Web form, trade show, imported, API, manual |
Updating Consent
- Contact opts in: Update consent status via form submission, preference center, or manually
- Contact opts out: Click the unsubscribe link in any email, or update manually
- Preference center: Contacts can manage their own consent at a public URL (no login required)
ℹ️Consent status changes are logged in the audit trail with timestamps. This creates a defensible record of when and how consent was given or withdrawn.
Best Practices
- Process requests promptly — GDPR requires response within 30 days
- Verify identity — Before erasing, confirm the requester is who they claim to be
- Check all systems — CRM erasure only covers CRM data. If the contact exists in PSA, Books, or other systems, coordinate erasure across all products
- Keep the certificate — Store erasure certificates for your compliance records
- Train your team — Ensure everyone who handles contact data knows the erasure workflow
Next Steps
- Email Compliance — CASL consent tracking and suppression management
- Contact Management — Contact consent fields and data export
- Integrations — Cross-product data flow considerations for GDPR