CRM helps businesses centralize customer data, track interaction history, and automate various Sales, Marketing, and Customer Service activities. However, when customer information is consolidated into one system, businesses also need to carefully control how personal data is collected, used, stored, and shared.
In Vietnam, Decree No. 13/2023/ND-CP was an important legal framework for personal data protection and took effect on July 1, 2023. From January 1, 2026, the Law on Personal Data Protection No. 91/2025/QH15 and Decree No. 356/2025/ND-CP came into effect, establishing a new legal framework for personal data processing.
Therefore, when implementing CRM, businesses should treat personal data protection as part of the system and operational design rather than something to address only after the CRM has been deployed.
What Types of Personal Data Can a CRM Contain?
CRM systems typically store various types of information that can identify an individual, such as full name, phone number, email address, address, account information, or interaction history. Decree No. 13/2023/ND-CP previously classified personal data into basic personal data and sensitive personal data, with basic data covering many types of information commonly stored in CRM systems.
In addition to identification information, CRM systems may also store purchase history, communication records, support requests, or customer interaction behavior. Therefore, the scope of data that needs to be managed should be identified from the system design stage.
1. Identify What Data Needs to Be Collected
Businesses should not transfer every piece of existing information into the CRM simply because the system allows them to store it. Instead, they should first identify which data fields are actually needed for Sales, Marketing, or Customer Service activities and define the purpose of using each category of data.
This approach helps businesses minimize unnecessary data while making access rights and data retention periods easier to manage.
2. Be Transparent About the Purpose and Mechanisms of Data Processing
When collecting customer data, businesses need to clearly determine the purposes for which the data will be used and establish appropriate notification, consent, or other lawful processing mechanisms in accordance with applicable regulations.
For Marketing activities in particular, businesses should distinguish between data used to support transactions and customer service and data used for other marketing or analytical purposes. Storing data in a CRM does not automatically mean that the data can be used for every possible purpose.
3. Control Access Permissions Within the CRM
Not every employee needs access to all customer information. Businesses should design access permissions based on roles and job requirements. For example, Sales representatives may only need access to the customers they are responsible for, while Customer Service teams may need to view transaction and support history.
In addition to access control, businesses should also monitor data exports, data sharing, and high-risk access activities. These controls become particularly important when the CRM serves as the company's centralized customer data repository.
4. Manage Third Parties and Data Transfers
CRM systems rarely operate independently. They are often integrated with other platforms such as Marketing Automation, contact centers, email, websites, or analytics applications. Each integration can create an additional data flow that needs to be controlled.
Businesses should identify which parties are involved in processing the data, what information is being shared, and the purpose of the data sharing. If the processing involves transferring personal data overseas, businesses should also assess the corresponding legal requirements. Under the regulations applicable when Decree No. 13 was in effect, the Ministry of Justice highlighted the requirement to prepare an impact assessment dossier when personal data was transferred overseas.
5. Prepare Incident Response and Data Governance Processes
Data protection is not only a technology issue. Businesses need internal procedures for responding to situations where data is accessed without authorization, shared with the wrong party, or exposed through a security incident.
Employees who use the CRM should also receive guidance on access rights, data handling practices, and prohibited activities. Internal policies, confidentiality agreements, and data usage rules should be developed according to the responsibilities of each employee group.
CRM Should Be Implemented Alongside Data Governance
An effective CRM project should not be measured only by the number of users or the level of process automation. Businesses also need to consider what data is entered into the system, who is authorized to use it, for what purposes it can be used, and how it is protected.
For Vietnamese businesses, a practical approach is to incorporate personal data protection requirements from the CRM design stage, covering the data model, collection forms, consent mechanisms, access controls, and integrations with external systems. When security and compliance are built into the CRM from the beginning, businesses can make better use of customer data while reducing operational risks.
Conclusion
The more data a CRM system centralizes, the more important effective data governance becomes. Compliance with personal data protection regulations should therefore not be treated as a final checklist, but as an integral part of the entire CRM implementation and usage lifecycle.
For businesses implementing or upgrading their CRM, reviewing the current legal framework, defining data processing purposes, controlling access rights, and managing third parties are fundamental steps toward building a secure and sustainable CRM environment.