Skip to content

Docs · Delivery & compliance · Standard

Keeping regulated data out of the CRM: a three-tier boundary

For compliance officers, crm admins, it and security.

Short answer

Sort every kind of data into three tiers: data the CRM may hold, data the CRM may only reference by title, status and link, and data that never enters the CRM. When unsure, drop a tier. Enforce it with picklists instead of free text, no file uploads on sensitive records, field permissions and AI features off until reviewed.

The three tiers

TierRuleExamples
1. Held in the CRMStored as fields and activitiesContact details, relationship history, pipeline, service cases
2. Referenced onlyTitle, status, date and a link to the system that holds itAccount statements, tax documents, signed agreements, health information in a separate system
3. Never in the CRMNot stored, not attached, not pasted into notesFull tax IDs, account passwords, export-controlled data, data your contracts forbid

The tier list depends on your regulations and contracts (for example SEC and FINRA rules, Regulation S-P, HIPAA or state privacy laws). Compliance owns it.

Controls

  • Picklists instead of free text for anything sensitive, so people can't type more than they should.
  • No file uploads on sensitive records; store a link to the document system instead.
  • Field-level permissions on tier 1 fields that still need limited access.
  • Email logging opt-in, without attachments, for teams that handle tier 2 and 3 data.
  • Meeting tools sync summaries and action items, not raw transcripts.
  • CRM AI features off for sensitive objects until compliance reviews them.
  • Integration mappings reviewed against the tier list before any new sync goes live.

Roll it out

  1. Write the tier list with compliance and get it signed off.
  2. Scan the CRM for tier 3 data already there (notes, attachments, free-text fields) and remove it.
  3. Give users a one-page guide with examples.
  4. Spot-check a sample of records every quarter.

Official documentation

Frequently asked questions

What data should never be stored in a CRM?

Anything your regulations or contracts forbid there, such as full tax IDs, passwords and export-controlled data. Compliance should write the list, and the CRM should be set up so users can't easily enter it.

How do you reference sensitive documents without storing them in the CRM?

Store the document's title, status, date and a link to the system that holds it. Users open the file from that system, which keeps its own access controls and retention.

Salesforce, HubSpot, Anthropic and OpenAI change their products often. Check the official documentation before you rely on a specific setting, limit or price.

Last reviewed October 9, 2026 by the Vantage Point team. Browse all docs