Independent DPDP educationBrowser-only workspace · no accounts, analytics or submissions

CRM + serviceSystem guide · implementation aid

Zoho CRM: follow the evidence.

Trace a lead from collection to module fields, automations, exports and eventual deletion.

00 What usually flows through Zoho CRM

A working data journey, not a legal conclusion.

Leads, contacts, deals, campaigns, tickets, notes, attachments and workflow history. Replace this editorial model with the systems, data and roles your organisation can actually evidence.

Typical Zoho CRM data journeySix stages show information moving from collection through operational systems, evidence and an end-of-lifecycle decision.010203040506
  1. 01Collectform · import · manual
  2. 02CRM recordfields · notes · files
  3. 03Automatescore · route · notify
  4. 04Connectmail · support · API
  5. 05Evidenceaudit · export · version
  6. 06Endclose · delete · residual
Illustrative operating model. Verify actual fields, destinations, contracts, regions, retention and access.

01

Accountability

Role map

Roles depend on who decides purpose and means, who acts on instructions, and what each party actually does. Record the conclusion and its evidence; do not infer it from the vendor label.

  • Name the business team that decides why each CRM module and field is used.
  • Record Zoho’s role for hosted CRM processing from the current contract, service terms and configuration.
  • List connected form, email, telephony, support, enrichment and analytics services as separate parties.

02

Collection surfaces

Collection and notice touchpoints

Walk each entry path as a real user. Save the notice, fields, choices, time and destination rather than relying on a policy page alone.

  • Website and campaign forms that create leads or contacts, including hidden and derived fields.
  • Manual entry, spreadsheet imports, email capture, business-card capture and API-created records.
  • Call notes, deal activity, support history and attachments added after initial collection.

03

Purpose discipline

Purpose and data minimisation checks

Every field and copy should have a named operating reason, accountable owner and review event.

  • For every standard and custom field, record purpose, owner, required/optional status and downstream use.
  • Find duplicate personal data in notes, attachments, tags and free-text fields that structured fields already cover.
  • Challenge enrichment, scoring and automation inputs that are collected “just in case”.

04

Choice evidence

Consent and preference evidence

When consent is relied on, preserve the affirmative action and withdrawal path. Where another legal route is assessed, record that analysis instead of manufacturing a consent record.

  • Link the exact notice version and collection event to the resulting CRM record or campaign source.
  • Test whether a preference change stops every relevant workflow, list, campaign and connected sender.
  • Keep the lawful-basis or permitted-use assessment separate from a marketing subscription flag.

05

Least privilege

Access control and privileged roles

Test ordinary view, sensitive fields, bulk action, export, configuration and integration access separately.

  • Review profiles, roles, territories, sharing rules, API users and temporary support access.
  • Test whether export, mass-delete, field visibility and attachment access are more restricted than ordinary viewing.
  • Remove a departing user in a controlled exercise and confirm ownership, tokens and scheduled actions are handled.

06

Lifecycle

Retention, deletion, backup and export behaviour

A delete button is not a lifecycle rule. Record the start event, end event, exception, system action, residual copy and accountable approver.

  • Define retention events separately for unqualified leads, active customers, lost deals, complaints and legal holds.
  • Test deletion against related records, attachments, recycle behaviour, exports, connected apps and backups.
  • Record what the available export includes and excludes before relying on it for portability or exit.

07

Service chain

Processor, sub-processor and contract checks

Use the current contract and actual architecture. A product page cannot establish the complete role allocation for your organisation.

  • Retrieve the current agreement, data-processing terms, service locations and sub-processor information.
  • List marketplace extensions and custom functions because they can create separate data disclosures.
  • Document assistance, deletion, return, security and incident-notification commitments without assuming an outcome.
Open the processor-register guide

08

Detection + response

Logs, monitoring and breach evidence

Coverage, event types, retention and exportability vary. Preserve an evidence timeline without claiming that one log proves the complete event.

  • Sample audit entries for permission, configuration, export and deletion events your organisation needs to investigate.
  • Record audit-log availability and retention for the subscribed edition; features can differ by plan.
  • Connect a CRM incident signal to the internal triage, containment, impact and notification evidence workflow.

09

Request workflow

Rights-request search, export, correction and erasure workflow

  1. 01

    Verify the requester outside the CRM, then search by the identifiers the person is likely to provide.

  2. 02

    Search leads, contacts, deals, notes, attachments, activities, emails, tickets, custom modules and connected services.

  3. 03

    Review legal and operational exceptions before correction or erasure, and retain a bounded action record.

  4. 04

    Re-run the search after action and record residual copies, backup treatment and downstream confirmations.

10

Bounded configuration

Configuration checklist

Access model

Profiles, roles, sharing rules, privileged capabilities and API identities are owned and reviewed.

Admin path
Verify in the current admin console
Evidence to save
Dated role/profile export or screenshots, reviewer, exceptions and next review.
Audit evidence

The team can retrieve events needed to investigate configuration and user activity.

Admin path
Verify in the current admin console
Evidence to save
Dated audit sample, available event types, retention window and edition limitation.
Export and exit

The team understands export scope, delivery, access, protection and secure disposal.

Admin path
Verify in the current admin console
Evidence to save
Test export inventory, recipient, storage location, deletion record and missing items.
Data sharing

Default and exception sharing match job need and connected-app purpose.

Admin path
Verify in the current admin console
Evidence to save
Sharing-rule review, integration list, exception owner and remediation decision.

No menu-path fiction: open the current vendor documentation and your live console together. Feature names, paths and entitlements can change.

11

Retrievable proof

Evidence to save

Module and field inventory with purpose owner

Notice and source-to-record trace

Role, profile and sharing review

Connected-app and automation register

Audit-log and export samples

Retention and rights-request exercise

Save redacted configuration evidence in an approved internal location. This private preview does not accept uploads or store these records.

12

Do not overclaim

Known limitations and questions for the vendor

Known limitations

  • Zoho editions can expose different audit, export and security features.
  • Custom functions, extensions and APIs may create flows the base product documentation cannot show.
  • A CRM deletion outcome does not prove deletion in mailboxes, spreadsheets, connected apps or backups.

Questions to resolve

  1. Which edition and data centre does the organisation use?
  2. Which user or integration can export the broadest dataset?
  3. Can a withdrawn preference be traced through every campaign and workflow?
  4. What remains after the tested deletion and for how long?

13

Traceable record

Official vendor sources, DPDP sources and corrections

Vendor documentation supports configuration questions only. DPDP statements are mapped separately to official Indian sources and phased commencement records.

Editorial status

Reviewed · not counsel-reviewed · educational implementation guidance, not legal advice, certification or a legal conclusion.

Report or inspect a correction

Zoho and Zoho CRM are trademarks of Zoho Corporation. They are referenced only to identify the system; no affiliation or endorsement is implied.

14 Continue the workspace

Turn this system review into owned gaps.

The browser-only readiness map can capture what is evidenced, partial, unknown or missing. It does not produce a pass, certificate or legal conclusion.

Answer the linked readiness itemTrace MAP-01 to evidence Read: Processor contracts in operation
Related system guides

SalesforceCRM + service

Freshworks / FreshsalesCRM + service

All system guidesSearch the complete stack