01
Accountability
Role map
Roles depend on who decides purpose and means, who acts on instructions, and what each party actually does. Record the conclusion and its evidence; do not infer it from the vendor label.
- Name owners for CRM properties, forms, subscriptions, campaigns and service records.
- Separate super admins, ordinary users, private-app owners and integration identities.
- Assess HubSpot and connected apps from current agreements and actual use.
02
Collection surfaces
Collection and notice touchpoints
Walk each entry path as a real user. Save the notice, fields, choices, time and destination rather than relying on a policy page alone.
- Forms, meetings, chat, imports, tracking code and manual CRM entry.
- Email engagement, subscriptions, tickets, notes, calls and files.
- Private apps, marketplace apps, ad platforms and enrichment.
03
Purpose discipline
Purpose and data minimisation checks
Every field and copy should have a named operating reason, accountable owner and review event.
- Map every contact property to purpose and owner.
- Review hidden fields, tracking, enrichment and calculated properties.
- Retire unused lists, forms, exports and integrations.
04
Choice evidence
Consent and preference evidence
When consent is relied on, preserve the affirmative action and withdrawal path. Where another legal route is assessed, record that analysis instead of manufacturing a consent record.
- Preserve notice and form version with source and time.
- Test subscription and withdrawal effects across lists, workflows and senders.
- Separate cookie, marketing and other processing choices.
05
Least privilege
Access control and privileged roles
Test ordinary view, sensitive fields, bulk action, export, configuration and integration access separately.
- Review super admins, permissions, teams, private apps and exports.
- Restrict sensitive-property view and export where available.
- Exercise user removal and token rotation.
06
Lifecycle
Retention, deletion, backup and export behaviour
A delete button is not a lifecycle rule. Record the start event, end event, exception, system action, residual copy and accountable approver.
- Define events for prospects, customers, tickets, files and activity history.
- Test recycle or restore windows, permanent deletion and connected copies.
- Record what exports include and how delivery links are controlled.
07
Service chain
Processor, sub-processor and contract checks
Use the current contract and actual architecture. A product page cannot establish the complete role allocation for your organisation.
- Retrieve current terms, DPA and sub-processor information.
- List marketplace apps, private apps, ads, enrichment and syncs.
- Record assistance, deletion, exit and incident commitments.
08
Detection + response
Logs, monitoring and breach evidence
Coverage, event types, retention and exportability vary. Preserve an evidence timeline without claiming that one log proves the complete event.
- Confirm audit categories, retention and export availability for the subscription.
- Sample login, security, export and configuration events.
- Record important gaps, such as system-generated actions not appearing in a user-action log.
09
Request workflow
Rights-request search, export, correction and erasure workflow
- 01
Search CRM objects, tickets, activities, files and connected systems.
- 02
Review merges and duplicate contacts before action.
- 03
Apply exceptions and perform authorised correction or deletion.
- 04
Re-run workflows and list membership checks after action.
10
Bounded configuration
Configuration checklist
The team knows which user actions are recorded and for how long.
- Admin path
- Verify in the current admin console
- Evidence to save
- Filtered export, subscription note and known gaps.
Preference changes propagate to the intended workflows and sends.
- Admin path
- Verify in the current admin console
- Evidence to save
- End-to-end test with timestamps and results.
Export and private-app access are owned and reviewed.
- Admin path
- Verify in the current admin console
- Evidence to save
- Export log and connected-app inventory.
No menu-path fiction: open the current vendor documentation and your live console together. Feature names, paths and entitlements can change.
11
Retrievable proof
Evidence to save
Property and purpose inventory
Form-to-notice trace
Subscription withdrawal test
Admin and private-app review
Audit and export samples
Rights-request exercise
Save redacted configuration evidence in an approved internal location. This private preview does not accept uploads or store these records.
12
Do not overclaim
Known limitations and questions for the vendor
Known limitations
- Audit categories and history vary by subscription.
- User-action logs may exclude system-generated changes.
- Connected marketing and advertising tools require separate evidence.
Questions to resolve
- Which hubs and subscription tier are active?
- Which private apps have broad scopes?
- Can a withdrawal stop every relevant workflow?
- Which exports have been downloaded and disposed of?
13
Traceable record
Official vendor sources, DPDP sources and corrections
Vendor documentation supports configuration questions only. DPDP statements are mapped separately to official Indian sources and phased commencement records.
Official vendor documentation
Official DPDP record
- Act No. 22 of 2023Ministry of Law and Justice, Government of India · checked 2026-09-27 ↗
- G.S.R. 843(E)Ministry of Electronics and Information Technology, Government of India · checked 2026-09-27 ↗
- G.S.R. 846(E)Ministry of Electronics and Information Technology, Government of India · checked 2026-09-27 ↗
- G.S.R. 892(E)Ministry of Electronics and Information Technology, Government of India · checked 2026-09-27 ↗
Reviewed · not counsel-reviewed · educational implementation guidance, not legal advice, certification or a legal conclusion.
Report or inspect a correctionHubSpot is a trademark of HubSpot, Inc. It is referenced nominatively; no affiliation or endorsement is implied.