Skip to content
Legal·7 min read

CRM data retention: what GDPR requires

Sales teams keep looking for one number: how long a prospect who never replied may sit in the CRM. That number does not exist. GDPR sets no time limit for prospect data, Sweden's regulator IMY sets none either, and the Bookkeeping Act's seven years applies to invoices, not contact lists. What the law does require is that you decide a period for each purpose yourselves, write it down, disclose it and stick to it. What follows is why the usual shortcuts fail, and a routine that holds up without wiping deal history you are entitled to keep.

SP

Salesprep editorial team

Sales and sales training editorial team

Definition

Prospect data retention in a CRM : Prospect data retention in a CRM is the application of storage limitation, GDPR Article 5(1)(e): a contact's personal data may be kept in identifiable form only as long as needed for the documented purpose. The company sets, justifies and documents the period itself. There is no statutory limit for prospects, and the Bookkeeping Act's seven years covers accounting records.

This is an overview, not legal advice. It draws on GDPR Articles 5, 13, 14, 17, 19 and 30, IMY's guidance on basic principles and records of processing, and the Swedish Bookkeeping Act. How contacts get into the CRM in the first place, the legal basis for prospecting, is covered in a separate article. This one is about what should happen to them afterwards.

The problem: three shortcuts that do not hold up

The first shortcut is an invented number. 'GDPR says prospects must be deleted after 24 months' appears in plenty of CRM policies, but no such figure exists in the regulation or in IMY's guidance. IMY's own wording is that you may keep personal data as long as it is needed for the purpose of the processing, and it leaves you to decide what that means in practice. Your figure may well end up at 24 months, but then it is your policy, justified by your sales cycle, not the law.

The second shortcut is seven years. Chapter 7 Section 2 of the Bookkeeping Act (1999:1078) requires accounting records to be kept until the end of the seventh year after the end of the calendar year in which the financial year closed. That covers invoices, contracts and the material behind the bookkeeping, which means customers who actually bought something. A note that the head of procurement at a company that never became a customer 'seemed interested in March' is not an accounting record. IMY does point out that documents containing personal data sometimes have to be kept after you have stopped using them, while recommending that such data is kept apart from whatever is in active use.

The third shortcut is deleting the whole account. Recital 14 of GDPR says the regulation does not cover data about legal persons, so company name, registration number, address, switchboard number and company-level deal history all fall outside it. What it does cover is the person: name, direct line, work email, notes about that person, recordings. Wiping a company card with three years of deal history because one contact changed jobs destroys information you were allowed to keep.

What the law actually requires

Article 5(1)(e): data may not be kept in identifiable form longer than necessary for the purpose. Article 5(2): you must be able to demonstrate compliance, or in IMY's words, you are responsible for the principles and must be able to show that you follow them. Article 30(1)(f): the record of processing must, where possible, state the envisaged time limits for erasure per category of data. Articles 13(2)(a) and 14(2)(a): your privacy notice must state the storage period or, if that is not possible, the criteria used to determine it. Four provisions that add up to one instruction: set a period, write it into the record and the notice, and follow it.

On top of that come the individual's rights. Article 17 gives a right to erasure without undue delay when the data is no longer needed for its purpose, when the person has objected to direct marketing under Article 21(2), or when a legal obligation requires erasure, with an exception for data you are required by law to keep. Then there is Article 19, which IMY highlights: if data is erased at the data subject's request, you must also tell anyone you have passed the data on to. A list shared with a partner or copied into another system has to be erased there too.

The solution: a deletion routine in five steps

The routine below follows IMY's recommendation of periodic reviews or time-based purges, and of keeping data held under a legal obligation apart from data in active use. Every period given is an example of a policy you set yourselves, not a legal rule.

  1. Split the CRM into three categories: customers (contracts, invoices, accounting records governed by the Bookkeeping Act), active prospects (an ongoing dialogue with a documented purpose) and dormant prospects (no contact for a long time, no explicit no).
  2. Set a period per category and tie it to a reason: for example, a dormant prospect is anonymised at person level after the equivalent of two sales cycles, or straight away once the person has left the company or said no. Write the period and the reason into the Article 30 record and the privacy notice.
  3. Anonymise the person, keep the company: remove name, direct line, work email and notes about the person, but leave the company card and the company-level deal history, since data about legal persons falls outside GDPR.
  4. Build the suppression list: after an objection under Article 21(2) you need to keep a minimum of data so the person is not re-added from the next list. Which data that may be, and on what basis, is a question for your lawyer or data protection officer, since IMY has not ruled on it.
  5. Run the purge on a schedule and log it: a monthly automated run or a quarterly review, with a log showing what was anonymised and when, so you can meet Article 5(2) when IMY or the data subject asks.

What gets better when the list shrinks

A list of 4,000 contacts where 2,500 have not replied in two years is not an asset. It is exposure in a data breach, a cost at every access request and a reason to keep calling the wrong people. The contacts that survive the purge are the ones worth calling again, and that call, to someone who got an email nine months ago and never answered, is a skill in itself. Salesprep's Follow-up module is built for exactly that: opening with an AI buyer who barely remembers you, without sounding like a reminder. Every call is scored on seven metrics with a written comment per score. Follow-up is available on Pro and up, with three free calls in the Cold call module when you create the account, no card required.

Common questions about this topic

How long can you keep prospects in a CRM under GDPR?

As long as the data is needed for the documented purpose, under Article 5(1)(e), and no longer. GDPR sets no time limit in months or years for prospects, and neither does IMY: IMY writes that you may keep personal data as long as it is needed for the purpose of the processing. So you set the period yourselves, for example based on your sales cycle, write it into the Article 30 record and the privacy notice under Articles 13 and 14, and can show that you follow it. An invented 'GDPR limit' of 24 months is your policy, not law.

Do we have to keep customer data for seven years because of the Bookkeeping Act?

Only accounting records. Chapter 7 Section 2 of the Swedish Bookkeeping Act requires accounting records, such as invoices, contracts and accounting material, to be kept until the end of the seventh year after the end of the calendar year in which the financial year closed. Contact details, call notes and recordings about a prospect who never became a customer are not accounting records and should be purged according to the period you set yourselves. IMY recommends keeping data held under a legal obligation separate from the data in active use.

Try it yourself.

Three free calls are included when you create an account. No credit card needed and the first call fits in before your coffee cools.

Create a free account