Skip to content
All articles
Security & governance

Data subject rights · exporting and anonymizing personal data

When someone asks for access to their own data or asks for it to be erased, you fulfill the request with the Export subject data and Anonymize buttons on the Contact or Lead record. The export downloads a file; the anonymization replaces personal data with a marker and is irreversible.

Data protection laws such as GDPR, LGPD and CCPA give a person two rights that a CRM has to be able to honor: asking for a copy of what you keep about them, and asking for that to be erased. SellioCRM handles both on the subject's own record, and writes both actions to the audit trail so you can later prove what was done and when.

Exporting a data subject's data

  1. Open the Contact or Lead record.
  2. In the more actions menu at the top of the record, click Export subject data.
  3. The file downloads in JSON format.

The file gathers the record's filled-in fields with their readable labels, the activities linked to it, the messages from that person's tickets including internal notes and side conversations, satisfaction survey responses, and mentions of their email in items and comments on Projects boards.

Anonymizing

  1. Open the Contact or Lead record.
  2. In the more actions menu, click Anonymize.
  3. Write the Reason, which is stored in the audit trail, for example subject request.
  4. Type the word ANONYMIZE in the confirmation field.
  5. Click Anonymize permanently.

Anonymization replaces the record's personal data fields with a marker, meaning fields of the email and phone types plus fields whose name points to a name, last name, government ID, address or contact detail. It also clears the body and the author of that person's ticket messages, their satisfaction comments and mentions of their email on Projects boards. It goes further: it removes the person's name, email and phone from the text of the record's activities, notes and comments, deletes the record's attachments including the file itself, and sweeps records of other objects that mention their email. The rest of the record keeps existing, so that totals, deal history and reports do not end up with holes. On a very large base a single pass may not reach everything: when that happens the screen says so, and running it again carries on.

Example: An agency receives an erasure request by email for a contact named Helen Prado. The person in charge opens the record, first exports the JSON to attach to the formal reply, then anonymizes it with the reason stated. The contact now shows an anonymized marker in the name, the email and the phone; the two opportunities he won still count toward the quarter's revenue.

What anonymization does NOT reach

  • The audit trail: it is immutable by design, and it records that the anonymization happened.
  • Whatever already left the CRM: files exported earlier and emails already sent.
  • Mailboxes synced from outside (Gmail, Outlook, IMAP): the message lives on the mail server, and it has to be deleted there.

Before you consider an erasure request closed, run a search for the person's name and email and handle by hand whatever turns up outside the list above.

Automatic retention

Under Settings, Privacy & compliance, the Retention policy table sets, per object, how many days records are kept before they go automatically to the trash, which is a reversible deletion. The sweep runs daily. Zero keeps them forever, and the maximum is 3650 days.

  • Marketing communications only go out to subjects who have consented, and anyone who opted out never receives them. Every email carries an unsubscribe link, and the subject manages their own preferences through the Preference center, with no login needed.
  • The Privacy contact email field stores the address of your data protection officer, for you to use in your policies and communications. It is optional.
  • Behavioral web tracking starts off and is opt-in. Email opens and clicks and form submissions are recorded either way; this switch governs only the tracking of visited pages.

Who can do this

  • Exporting a subject's data: anyone who can open that record.
  • Anonymizing: only people with permission to manage settings.
  • Changing retention, the privacy contact and tracking: only people who administer the settings.
💡 The buttons appear only on the Contact and Lead objects. For other objects that hold personal data, exporting and anonymizing have to be done another way, such as exporting the list view and editing the fields by hand.

Open this article inside the system

Read it and want to see it working?

The account is free and the whole manual is available inside the system, with an assistant that answers from this very content.

Create free account
Data subject rights · exporting and anonymizing personal data · Sellio