Guide
GDPR-Compliant CRM Software: What Companies Need to Check
·6 min read·digitalWAS solutions

Whether a CRM is GDPR compliant comes down to five checkable points, not a badge: a data processing agreement under Art. 28 GDPR, a clear server location without uncontrolled third-country transfers, a role and permission model, a deletion policy with retention periods, and an audit log showing who changed what and when. Add support for data subject rights such as access and erasure. This article explains each point, provides a vendor checklist and clears up common misconceptions.
What compliance means for a software product
The GDPR addresses you as the controller, not the tool. Software cannot make you compliant, but it can make compliance possible or impossible. Everyday sales work usually rests on contract performance or legitimate interest under Art. 6(1). Consent is mainly needed for marketing emails, and the software has to record who agreed and who objected.
The data processing agreement under Art. 28
A vendor that stores your customer data is a processor, and you need a written agreement. Art. 28(3) sets the minimum content: subject matter, duration, nature and purpose of processing, documented instructions only, confidentiality of staff, security measures under Art. 32, rules for sub-processors, support with data subject requests and breaches, deletion or return of data after the contract, and audit rights. A serious vendor provides the agreement and a current list of sub-processors with their locations without being asked.
Server location and third-country transfers
The GDPR does not prohibit transfers outside the EU and EEA but attaches conditions (Art. 44 et seq.): an adequacy decision, standard contractual clauses with an assessment of the destination country, or a narrow exception. The adequacy decision for the United States in force since 2023 covers only certified companies, and its two predecessors were struck down by the Court of Justice of the EU. Every transfer means assessment work that you carry, not the vendor. Hosting in Germany or the EU removes that work. It does not make the software compliant by itself, but it takes one of the hardest questions off your records of processing activities. digital scaleUp solutions is developed in Berlin and hosted in Germany, a solid foundation that still needs your own documentation.
Roles, permissions and deletion
Art. 32 requires measures appropriate to the risk, with access control at the top. A usable permission model separates module access, data access (own, team or all customers) and action rights (read, edit, export, delete). In digital scaleUp solutions, document storage has permissions per team and call notes stay in the customer file, see customer management with a digital customer file.
Storage limitation under Art. 5(1)(e) is the most ignored principle. A deletion policy states per category why you keep the data, for how long, and what happens afterwards: leads without a deal a few months after the last contact, customer data at the end of the contract plus statutory retention periods for accounting records. These are orientation values, not legal advice, and the software must surface old records through follow-ups, flags or rules.
Audit log and data subject rights
Accountability under Art. 5(2) means proving compliance, so the software needs a change log recording who created, changed, exported or deleted which record and when, protected from erasure by normal users. Customers may request access, rectification, erasure, restriction and portability (Art. 15 to 20) and may object (Art. 21), usually within one month. Test it: can you compile all data about one person in a few clicks and delete a record including attachments? One customer file instead of five silos makes this far easier, see all-in-one software for SMEs.
Vendor checklist
| Check | Question for the vendor | GDPR reference |
|---|---|---|
| Processing agreement | Agreement with the minimum content in place? | Art. 28(3) |
| Sub-processors | Current list with location and purpose? | Art. 28(2) and (4) |
| Server location | Production data and backups in Germany or the EU? | Art. 44 et seq. |
| Roles and permissions | Module, data and action rights separable, exports included? | Art. 32, Art. 25 |
| Deletion policy | Retention periods per category definable and enforceable? | Art. 5(1)(e), Art. 17 |
| Audit log | Change log that normal users cannot erase? | Art. 5(2) |
| Breach notification | Notification without delay so you can meet the 72-hour deadline? | Art. 33 |
| End of contract | Data exported and then deleted after termination? | Art. 28(3)(g) |
More than two answers of No means you should ask further questions or keep looking.
Common misconceptions
Servers in Germany do not equal compliance; location settles the transfer question and nothing else. The vendor is not responsible; it is the processor, you remain the controller. Not everything needs consent; customer management within a business relationship usually rests on contract or legitimate interest. A spreadsheet is not safer; it has no roles, no log and no deletion periods, and the CRM implementation checklist shows the way out.
Frequently asked questions
Do I need a processing agreement for a trial?
Yes, as soon as you enter real customer data. A trial with fictitious data does not need one, but read the agreement beforehand so you can go live without delay.
Is EU hosting enough, or does it have to be Germany?
Under the GDPR the EU and EEA are equivalent. Germany adds German contract law, German-speaking support and short paths to the supervisory authority: a practical advantage, not a legal requirement.
Does WhatsApp Business need a separate assessment?
Yes. Messaging is a separate processing activity with its own provider and transfer routes. Assess the provider, inform customers and document the channel in your records of processing activities.
Check instead of guessing
The best vendor assessment is your own trial with the checklist in hand. Try digital scaleUp solutions free for 30 days, no credit card required, or book a consultation to go through agreement, hosting and permissions for your company. More in the FAQ, CRM for small businesses and CRM software costs.