The DPDP Act frames obligations around lawful processing, notice, consent where required, the rights of data principals, security safeguards, and breach reporting for digital personal data in India. Your CRM holds names, phone numbers, email addresses, and increasingly WhatsApp conversation history—so it is in scope for your governance programme regardless of who hosts the application.
This page is orientation, not legal advice. It describes how CRM operations intersect with a privacy programme. Interpretation for your business belongs with your counsel.
The data lifecycle you need to be able to describe
What to document, per data element
- Lawful basis for each element you collect—not for “CRM data” as a blanket category
- Purpose, stated at collection in language a person understands
- Retention schedule, which will differ between an active client and a lead that went nowhere three years ago
- Subprocessors—hosting, email delivery, analytics, messaging—with agreements in place
- Access scope: who inside your organisation can see it, and the break-glass process for administrators
- Runbooks for export and erasure when a data principal exercises a right
Handling a data principal request
Where CRM operations meet the programme
| Programme requirement | What it looks like in daily CRM work |
|---|---|
| Purpose limitation | Not repurposing a support contact list for cold marketing |
| Data minimisation | Removing fields nobody reports on; not collecting what you cannot justify |
| Accuracy | Deduplication and correction processes that actually run |
| Storage limitation | A retention schedule applied to dormant leads, not only to closed accounts |
| Security safeguards | RBAC, MFA for admins, TLS, export monitoring |
| Breach readiness | An audit trail you can query, and a decision-maker named in advance |
Where Vertex CRM fits architecturally
Vertex CRM provides access control, authenticated APIs, administrative visibility, and operational surfaces your administrators govern. Compliance is never “checkbox complete”, because your policies, contracts, and incident response determine the outcome. Pair this overview with counsel and read our privacy policy for product-level statements.
Related: CRM security overview, audit trail, and WhatsApp and consent.
Frequently asked questions
- Does using Vertex CRM make us compliant?
- No software alone guarantees compliance; you need policies, contracts, and operational controls.
- What should legal review in a CRM?
- Subprocessors, data residency statements, access logs, retention, and breach notification workflows.