HubSpot & GDPR: Is this CRM compliant?

- HubSpot processes personal data such as names, addresses, and IP addresses.
- Storing personal data on US servers is not GDPR-compliant.
- A data processing agreement with HubSpot and appropriate safeguards are required for GDPR compliance.
- Companies must include HubSpot in their privacy policy.
- HubSpot has been offering EU servers for data migration since 2022.
Is HubSpot GDPR-compliant? In short: Only if specific legal frameworks are met. Whether these are fulfilled depends not only on formal compliance with legal regulations, but also on the location of data storage. So, how can the use of HubSpot and data protection be reconciled? It comes down to a few key aspects, which the following article examines in more detail.
CRM Data Protection: What data is processed with HubSpot?
HubSpot is a marketing and sales platform that helps companies attract more visitors to their website and convert them into leads. Data protection in sales and marketing naturally plays an important role when using CRM systems. To address potential customers individually, a great deal of personal data is required. Like other CRM systems, HubSpot stores various user data, such as:
- Name
- Address
- Email address
- IP address
Personal data refers to specific individuals and makes them identifiable. Handling this data is therefore particularly sensitive and is subject to the regulations of the European General Data Protection Regulation (GDPR), as well as other applicable national data protection laws. As a European Union regulation, the GDPR standardizes data protection in Europe and creates uniform data protection standards and transparency for all member states. Therefore, when using HubSpot, the GDPR applies, which mandates the protection of personal data.
HubSpot & Data Protection: Legal Basis
Since July 2021, HubSpot users have been able to choose whether processed data is stored on servers in Europe or in the USA, where data protection regulations are less stringent than in the EU. Older contracts are excluded from this option. The EU-US Privacy Shield, which contained agreements between the EU and the USA regarding data protection law, was declared invalid by the European Court of Justice (ECJ). Since then, companies may no longer use the Privacy Shield as a legal basis for data processing, data transfer to a third country, or further data processing there. However, the GDPR prohibits companies from transferring personal data to third countries that do not have an adequate level of data protection. Consequently, storing HubSpot data on US servers is currently not compatible with the GDPR. This also applies to data on EU servers that the US company has access to.
How to use HubSpot in compliance with the GDPR
To use HubSpot in a GDPR-compliant manner, a data processing agreement (DPA) between your company and HubSpot is required. Since HubSpot is a US-based provider, an adequate level of data protection as required by the GDPR must also be ensured through so-called appropriate safeguards. This is the only way to ensure that the CRM system's data storage is in line with the data protection provisions of the GDPR. The DPA should contain information about what user data HubSpot stores and for how long, and in particular, ensure that data processing may only take place according to the instructions of the controller. The reason for data storage and processing must be presented as transparently as the rights and obligations of the controllers.
Furthermore, HubSpot should be included in your company's privacy policy, including the following explanations in the text:
- Reference to the existing legal basis under the GDPR and the data processing agreement concluded between your company and HubSpot
- Explanation of why and for how long personal data is collected and stored
- Reference to the right to object to data storage
Data Processing Agreements
To use HubSpot in compliance with the GDPR, a data processing agreement between your company and HubSpot is required. We offer professional support in concluding GDPR-compliant data processing agreements.
Taking the above points into account, the GDPR and CRM systems are certainly compatible in terms of data protection. Nevertheless, the invalidation of the Privacy Shield as a legal basis for data storage poses risks when using CRM systems. According to the ECJ, there is currently no adequate level of data protection in the USA based on an adequacy decision comparable to the Privacy Shield, which guaranteed the secure transfer and processing of data. HubSpot responded to this situation by establishing a data center in Europe and introducing standard contractual clauses to ensure a secure level of data protection.
[Update 10/28/2022] Effective immediately, both new and existing HubSpot customers can migrate their data to the new EU data center.
Do you have further questions on this topic? Our experts will be happy to advise you free of charge.













