Zoho CRM

Recording privacy notices and explicit consent in CRM

· 6 min read ·Türkçe
Recording privacy notices and explicit consent in CRM

Combining a privacy notice and explicit consent in one checkbox obscures records. The notice documents the information presented. Explicit consent is a statement concerning a specific subject, based on prior information, and expressed through free will. A sound record therefore distinguishes the text shown to the person, the scope involved, and the statement that followed.

Not every processing activity relies on explicit consent. The system's role is not to request consent or make an assessment, but to record the process defined by the institution. Zoho CRM provides built-in consent management, yet that structure does not establish legal compliance. An implementation identifies where the standard structure ends before adding institutional records.

Privacy notices and explicit consent are separate records

A notice record shows that information was presented. A consent record represents the separate statement. The requirement for consent to rest on prior notice does not make them identical. With one checkbox, the distinctions among text, statement, and scope can disappear, making the recorded event difficult to explain.

The institution first determines which processing relies on consent and which requires another assessment. CRM carries the record; it does not replace the decision's legal basis. This distinction prevents operations teams from sending the request to everyone and stops fields from being presented as legal conclusions.

The presentation of a notice and the person's statement need to remain distinct events. The presence of one does not prove the other. The essential connection is the information on which the statement relied. Teams can then examine the relationship among text, time, and scope.

Zoho CRM includes built-in consent management

In Zoho CRM, the path is Setup > Security Control > Compliance Settings > GDPR Compliance. Enabling the feature adds a Data Privacy section in modules. It supports a processing basis, a consent form, and insertion of the form link into an email template or an email.

Consent can be entered manually in Data Privacy, while Overview displays consent statuses. The waiting period is set in days or months. During it, processing may continue, stop, or restrict email, calls, and editing. If a person selects only phone, email sending is restricted automatically.

Consent remains absent from the system if nobody owns the follow-up. When the advisor does not enter it in Data Privacy, the record stays Pending; Overview places the person among requests not sent. Setup covers Contacts, Leads, Vendors, and custom modules. Deals and Accounts are not listed. Additional records sit above this built-in structure.

Consent has four statuses, and withdrawn is not one

Four consent stages are defined. Pending means the request has not been sent. Waiting means the form was sent. Obtained means consent was received. Not Responded means no response arrived within the waiting period, and the record locks automatically. Because every effect of that lock is unverified, no broader behavior should be inferred.

Withdrawn is not one of these statuses. The mechanism is the Data Subject Rights flow. A stop-processing request locks, while an erasure request blacklists it. Requests received by email, phone, or in person can be entered in Data Privacy. A response to a data-request link can be captured.

A patient asks to stop campaign messages. The team looks for a withdrawn status, the list ends with Obtained and Not Responded. If no field records the statement, the information remains in one note. When such a field is added, it must be clear that the withdrawal date is absent from the built-in status list.

Keep scope and text version in separate fields

Versioning the text in a document repository and carrying its version identifier in CRM preserves the connection. Text type, effective start, and scope code should remain distinct. The scope code follows the purpose vocabulary; an unrestricted phrase such as every operation for everyone does not create a meaningful evidence chain.

The text and the version identifier written to CRM need to come from the same release package. Otherwise, the person may see one text while the record points to another. The objective is not to copy the document, but to retain an immutable identity and relevant scope that can be compared.

The product recommends separating consent from other terms, avoiding preselected boxes, and refreshing consent. These are product recommendations, not classifications. A permission field in CRM records permission; it is not the legal basis itself.

Apply withdrawal records only to their relevant scope

A person withdrawing consent for a specific purpose does not mean the contact record closes. The institution evaluates which statement and scope are affected. If retention or processing continues for a purpose, its basis receives a separate assessment. The CRM record should expose those distinctions instead of merging different processes under one mark.

A task approval and the person's permission are different records. The first concerns who performs the work; the second concerns the person's statement. Treating one as the other obscures which scope it affects. The product's flows for stopping processing and erasure do not automatically resolve this distinction.

Fields carrying health information can be marked Sensitive under personal-field classification; the other level is Normal. The documented effect is limited to export, API access, transfer to Zoho applications, and third-party transfer. Auto Number, Formula, User, Lookup, First Name, and Last Name cannot be marked, so privacy cannot be designed around name fields.

An audit log does not replace an evidence archive

The Zoho CRM audit log records actions adding, updating, deleting, operations, importing, exporting, converting, restoring, and merging duplicates. It tracks changes to setup items templates, workflows, webhooks, web forms, roles, profiles, and reports. It does not record who viewed, so it cannot serve as evidence or a complete archive.

The Audit log can be exported as CSV. Unfiltered export is limited to the last three years or one million entries; with an entity, user, or action filter, the time range cannot exceed 180 days. No retention figure should be stated. If a form submission is recorded in another product, that product's own help documentation governs; the CRM audit log shows only actions performed inside CRM.

Deleting a CRM record does not destroy it. The record remains in the recycle bin for 60 days, and visibility there follows role hierarchy and the permission to view those records. Deletion also affects child records, notes, and activities. There is no record-level automatic retention setting. Audit, document storage, and deletion procedures address different needs.

Build acceptance tests around version and identity errors

Change the text version, submit a statement through an old link, and let the waiting period expire. Confirm that Not Responded locks the record. Then process a withdrawal request and, if an added date record is used, verify that it remains separate from built-in statuses. Do not treat the form's success message as acceptance.

Two people sharing the same email address, record merging, an offline signed document, a representative's statement, and an event time from another time zone require expert assessment. Testing must not assume that these cases resolve. For each event, examine identity, text version, scope, and time to reveal whether a statement was attached to the record.

Additional fields require at least Standard because Free has no custom fields or custom modules. Self-service consent updates and data-subject requests require Enterprise. Manage Compliance Settings profile permission is required. The GDPR tab threshold under Compliance Settings varies by edition and must be verified in Setup before a proposal. Acceptance is complete only when identity, version, and scope agree.

Zoho CRM

Planning a Zoho or automation project?

As a Zoho Authorized Partner, we design and implement these systems end to end. Start with a free 30-minute discovery call.

Schedule a free call →
← All articles