The GDPR is the EU's data-protection law, and for marketers it comes down to one idea. You may only collect and use personal data when you have a lawful reason to, you've told people what you're doing, and you can honor their right to see, correct, or delete it. It applies to any business that handles the personal data of people in the EU — wherever that business sits. Here's the practitioner's read: what the law actually requires of a marketing team, and how to make your CRM do the heavy lifting.
A lawful basis for processing, clear notice to the person, and a way to act on their data rights — those three things cover most of what marketing touches. "Personal data" is anything that identifies someone: name, email, IP address, even a cookie ID. Before you collect it, you need a lawful basis — usually consent (they said yes) or legitimate interest (a justifiable business reason you've documented). You also have to tell people what you collect and why, in plain language, and give them a way to opt out. Worked example: an email signup form needs an unticked consent checkbox, a link to your privacy policy, and a record of when and how that consent was given — not a pre-checked box buried in fine print.
Consent must be a clear, freely given, specific opt-in — and you have to be able to prove it. Silence, pre-ticked boxes, and "by using this site you agree" don't count. For marketing emails to EU contacts, consent is the cleanest basis: the person actively asked to hear from you, for a purpose you named. You should log the source, the timestamp, and the exact wording they agreed to, because if a regulator or the person asks, "they signed up somehow" is not an answer. Legitimate interest can cover some B2B outreach, but it's a documented judgment call, not a loophole — and the person can still object.
People can ask to see their data, correct it, delete it, or stop you from using it — and you generally have one month to respond. The main ones marketers meet are access (a copy of what you hold), erasure ("delete me"), and objection ("stop marketing to me"). The unsubscribe link handles the everyday case, but a formal erasure request means actually removing the person from your systems, not just suppressing them. Worked example: someone replies to a campaign asking you to delete their data — you need a process to find every place that record lives (CRM, email tool, ad audiences, spreadsheets) and remove or anonymize it, then confirm back to them.
Turn on HubSpot's privacy and consent tools so lawful basis, consent records, and unsubscribe handling are tracked automatically on every contact. HubSpot can record a legal basis on each contact, store subscription preferences per communication type, show a cookie consent banner, and honor unsubscribes across email. Set those up once and the system keeps the evidence for you — the timestamp, the source, the basis — instead of you reconstructing it later. This is exactly the order we follow with clients: decide the lawful basis for each form and list, configure HubSpot to capture and store consent, then make sure deletion and data-access requests have an owner and a process. Compliance that lives in the platform survives staff turnover; compliance that lives in someone's head does not.
GDPR is less scary than it looks once you stop treating it as a legal hurdle and start treating it as data hygiene with a paper trail. The teams that struggle are the ones who collected first and asked questions later; the teams that don't are the ones whose CRM records why every contact is in the database and what they agreed to. Get the lawful basis and the consent records right at the point of capture, and the rest — rights requests, audits, deletions — becomes routine instead of a fire drill. Note that this is practical guidance, not legal advice; for edge cases, talk to a data-protection professional.
Not sure your HubSpot setup would survive a data-rights request? Book a 30-minute portal audit — we'll check how consent and lawful basis are tracked in your portal and where the gaps are. See how we approach HubSpot implementation and optimization.
Does the GDPR apply to my business if I'm not in the EU?
Yes, if you handle the personal data of people in the EU — for example, marketing to EU contacts or tracking EU website visitors. The law follows the data subject, not your office location.
Do I need consent for every marketing email?
For EU contacts, consent is the safest basis and you must be able to prove it. Some B2B outreach can rely on documented legitimate interest, but the person can always object, so most teams default to clear opt-in.
What happens if someone asks me to delete their data?
You generally have one month to remove or anonymize their personal data across every system that holds it and confirm you've done so. A suppression flag alone isn't the same as erasure.
Can HubSpot make me GDPR compliant on its own?
No tool makes you compliant by itself, but HubSpot's privacy tools record lawful basis, consent, and preferences so the evidence is captured automatically. The policies and processes around it are still yours to set.