CRM security and data governance: what ISO 27001 practice looks like in HubSpot
Permissions, data retention, audit trails and vendor risk: how to run a CRM that survives a security review.
CRM security and data governance: what ISO 27001 practice looks like in HubSpot
A CRM holds the most commercially sensitive dataset most companies own, yet permissions are often set once and never reviewed. When an enterprise client, a bank or a public tender asks how you protect their data, the answer has to be specific: who can export, what is logged, how long data is kept and how access is removed when someone leaves.
Who asks this question
- Companies selling to enterprises that send security questionnaires.
- Regulated sectors in Europe and the Gulf with audit obligations.
- Teams preparing for ISO 27001 certification or a client audit.
How to implement it
- Define roles and permission sets by job function, with export rights restricted and reviewed quarterly.
- Turn on and monitor audit logging for data exports, integration changes and permission changes.
- Document data retention: what is deleted, when, and how deletion requests are executed across integrated systems.
- Control the integration surface: inventory every connected app, its scope, and its business owner.
- Run offboarding as a checklist: seat removal, token revocation, ownership reassignment, all within one working day.
What to measure
- Number of users with export or admin rights, tracked over time.
- Time to revoke access after offboarding.
- Percentage of connected apps with a named owner and documented scope.
- Open findings from the last internal access review.
Common mistakes
- Giving super admin rights for convenience during implementation and never removing them.
- No inventory of connected apps, so nobody knows what has API access.
- Retention policies written but never enforced technically.
- Treating security review as a document exercise instead of a configuration one.
Frequently asked questions
Is HubSpot compliant with GDPR?
HubSpot provides the tooling and contractual framework; compliance depends on your configuration, consent handling and retention practice.
Does ISO 27001 require specific CRM settings?
It requires demonstrable control: documented access management, logging, retention and supplier review. The settings follow from those controls.
What is the fastest improvement?
An access review. Most portals have several users with rights they no longer need, and reducing that surface takes hours, not weeks.
Piceci Services is a HubSpot Solutions Partner and ISO 27001 certified consultancy operating from Milan and Dubai. If you want this reviewed against your current setup, book a call and we will walk through it with your data.
Want a second pair of eyes on your CRM?
We run free 15-minute reviews โ no slides, no pitch, just a look at your setup.
Book a review โ