You have a CRM with thousands of customer records, an ERP with order histories going back ten years, and invoicing software accumulating data since you founded the company. All of that falls under GDPR, and in many cases businesses don't know exactly what to keep, for how long, or under what conditions.
This article is not a comprehensive legal analysis. It is a practical guide so that any SME manager knows what questions to ask about their systems and what points to review before an inspection or complaint arrives.
Important: GDPR non-compliance fines can reach €20 million or 4% of annual global turnover, whichever is higher. SMEs are not exempt, and sanctions against small businesses have increased significantly since 2024.
What GDPR says about data retention
The principle of storage limitation requires that personal data not be kept longer than necessary for the purpose for which it was collected. This translates into a concrete question: why do you still have data in your CRM for a customer who hasn't bought anything in seven years?
The problem is that "necessary" doesn't have a single numeric value. It depends on the type of data and the purpose, and in many cases conflicts with other legal obligations such as tax or commercial ones, which do require retaining certain information for specific periods.
Key legal retention periods in the EU
| Data type | Minimum retention period | Legal basis |
|---|---|---|
| Invoices and accounting documentation | 6 years (Spain) / varies by country | Commercial Code / local tax law |
| Tax records (VAT, income tax) | 4–5 years depending on jurisdiction | General Tax Law |
| Employment contracts and payslips | 4–5 years | Labour law / Social Security |
| System access logs | Minimum 2 years | LOPDGDD / national data protection laws |
| Customer data with no active relationship | Delete or anonymise when purpose ends | GDPR Art. 5.1.e |
| Recruitment candidates | 1 year after process ends | Data protection authority guidance |
| Purchase history (e-commerce) | Up to 3 years for consumer claims | Consumer protection law |
The real problem in ERPs and CRMs is that these periods overlap: the same customer record may contain tax data (to be kept 6 years), commercial data (which should be deleted when the relationship ends) and marketing communications data (which requires valid consent). Separating all of that within a system is not always straightforward.
Real fine cases in Europe (2024–2026)
Sanctions are no longer reserved for large corporations. These representative cases illustrate the most common data management errors:
Retained potential customer data in its CRM without a legitimate basis and without a deletion policy. Records had been inactive for more than 5 years and there was no evidence of initial consent.
The ERP provider had access to client data without a data processing agreement. A common failure when migrating to SaaS software without reviewing service terms.
Used CRM data for email campaigns without updated consent. The problem: contacts had been imported from third-party platforms without verifying the legal basis of the original collection.
The pattern is always similar: data accumulated without criteria, without documented legal basis, and without a periodic review process.
The 5 most common errors in ERPs and CRMs
1. Inactive customer records are never deleted
Most systems allow records to accumulate indefinitely. If your CRM has contacts that haven't interacted in years and have no legal retention obligation, you are already violating the storage limitation principle.
2. The SaaS provider is not signed as a data processor
If you use a cloud CRM or ERP (Salesforce, Zoho, HubSpot, SAP Business One, Holded…), the provider accesses personal data of your clients. GDPR requires a specific data processing agreement. Without it, liability falls entirely on you.
3. Consent fields are not recorded
It's not enough to have consent: you must be able to prove when it was obtained, for what purpose and how. If your CRM doesn't record the date and type of consent for each contact, you won't be able to prove it to the data protection authority.
4. Access logs are not kept correctly
Who accessed what data and when? Systems must generate and retain audit records. Many companies disable this feature for performance or storage reasons, not knowing it is a legal requirement.
5. No formal process exists to handle the right to erasure
When a customer asks you to delete their data, you have a maximum of one month to do so. If their data is spread across the ERP, CRM, email marketing platform and backups, do you know how to execute that complete deletion?
Compliance checklist to review right now
Data inventory
- You have mapped what personal data your ERP and CRM contain
- You know which data categories are specially protected (health, ethnic origin, sensitive financial data)
- You have identified the legal basis for each type of data (contract, consent, legitimate interest, legal obligation)
Contracts with providers
- All SaaS providers accessing personal data have a signed data processing agreement
- You have checked where your providers store data (if outside the EU, you need additional safeguards)
- Contract clauses cover the obligation to notify security breaches within 72 hours
Retention and deletion
- You have a defined retention policy with concrete timelines for each data type
- There is an automated or periodic process to review and delete expired records
- Backups also follow the retention policy (deleting data from the CRM doesn't help if it remains in the backup)
- You can execute the right to erasure in a traceable and documented way
Consents and rights
- Marketing consents are recorded with exact date, channel and purpose
- You have a clear process for handling access, rectification and erasure requests
- Capture forms include information about retention periods and data subject rights
Technical security
- Access to the ERP and CRM is controlled by user and permission profile
- An access audit log is active and retained for at least 2 years
- Passwords and admin credentials are managed securely (not shared, periodic rotation)
- You have a documented protocol to notify security breaches to the data protection authority within 72 hours
What if your ERP or CRM can't meet these requirements?
Some older or low-cost systems don't offer basic compliance features: they don't record consents, don't allow exporting a specific user's data in response to an access request, or don't generate configurable audit logs.
In that case, you have two options: add external layers that complement the system (consent management tools, independent logging systems) or consider migrating to a system that integrates these features natively.
Evaluating whether your current system is sufficient or needs to be complemented or replaced is part of a basic IT audit. It's not a decision you should make based solely on the vendor's documentation.
Where to start
If you have never reviewed GDPR compliance for your systems, the first step is the inventory: knowing exactly what data you have, where it is and what it's used for. Without that map, any other action is partial.
The second step is reviewing contracts with your software providers. It's the point most easily fixed and most frequently missing.
The third: define retention periods and configure periodic review processes in the system. Without automation, these tasks tend not to get done.
At EstructuraBit we help companies audit their IT systems from a technical and compliance perspective: we identify missing configurations, contracts to update and how to integrate the necessary tools so that compliance doesn't depend on manual processes. If you'd like us to review your situation, contact us with no obligation.
Back to blog