Short answer
Sort every kind of data into three tiers: data the CRM may hold, data the CRM may only reference by title, status and link, and data that never enters the CRM. When unsure, drop a tier. Enforce it with picklists instead of free text, no file uploads on sensitive records, field permissions and AI features off until reviewed.
The three tiers
| Tier | Rule | Examples |
|---|---|---|
| 1. Held in the CRM | Stored as fields and activities | Contact details, relationship history, pipeline, service cases |
| 2. Referenced only | Title, status, date and a link to the system that holds it | Account statements, tax documents, signed agreements, health information in a separate system |
| 3. Never in the CRM | Not stored, not attached, not pasted into notes | Full tax IDs, account passwords, export-controlled data, data your contracts forbid |
The tier list depends on your regulations and contracts (for example SEC and FINRA rules, Regulation S-P, HIPAA or state privacy laws). Compliance owns it.
Controls
- Picklists instead of free text for anything sensitive, so people can't type more than they should.
- No file uploads on sensitive records; store a link to the document system instead.
- Field-level permissions on tier 1 fields that still need limited access.
- Email logging opt-in, without attachments, for teams that handle tier 2 and 3 data.
- Meeting tools sync summaries and action items, not raw transcripts.
- CRM AI features off for sensitive objects until compliance reviews them.
- Integration mappings reviewed against the tier list before any new sync goes live.
Roll it out
- Write the tier list with compliance and get it signed off.
- Scan the CRM for tier 3 data already there (notes, attachments, free-text fields) and remove it.
- Give users a one-page guide with examples.
- Spot-check a sample of records every quarter.
Official documentation
Frequently asked questions
What data should never be stored in a CRM?
Anything your regulations or contracts forbid there, such as full tax IDs, passwords and export-controlled data. Compliance should write the list, and the CRM should be set up so users can't easily enter it.
How do you reference sensitive documents without storing them in the CRM?
Store the document's title, status, date and a link to the system that holds it. Users open the file from that system, which keeps its own access controls and retention.
Salesforce, HubSpot, Anthropic and OpenAI change their products often. Check the official documentation before you rely on a specific setting, limit or price.
