01
Accountability
Role map
Roles depend on who decides purpose and means, who acts on instructions, and what each party actually does. Record the conclusion and its evidence; do not infer it from the vendor label.
- Name the business team that decides why each CRM module and field is used.
- Record Zoho’s role for hosted CRM processing from the current contract, service terms and configuration.
- List connected form, email, telephony, support, enrichment and analytics services as separate parties.
02
Collection surfaces
Collection and notice touchpoints
Walk each entry path as a real user. Save the notice, fields, choices, time and destination rather than relying on a policy page alone.
- Website and campaign forms that create leads or contacts, including hidden and derived fields.
- Manual entry, spreadsheet imports, email capture, business-card capture and API-created records.
- Call notes, deal activity, support history and attachments added after initial collection.
03
Purpose discipline
Purpose and data minimisation checks
Every field and copy should have a named operating reason, accountable owner and review event.
- For every standard and custom field, record purpose, owner, required/optional status and downstream use.
- Find duplicate personal data in notes, attachments, tags and free-text fields that structured fields already cover.
- Challenge enrichment, scoring and automation inputs that are collected “just in case”.
04
Choice evidence
Consent and preference evidence
When consent is relied on, preserve the affirmative action and withdrawal path. Where another legal route is assessed, record that analysis instead of manufacturing a consent record.
- Link the exact notice version and collection event to the resulting CRM record or campaign source.
- Test whether a preference change stops every relevant workflow, list, campaign and connected sender.
- Keep the lawful-basis or permitted-use assessment separate from a marketing subscription flag.
05
Least privilege
Access control and privileged roles
Test ordinary view, sensitive fields, bulk action, export, configuration and integration access separately.
- Review profiles, roles, territories, sharing rules, API users and temporary support access.
- Test whether export, mass-delete, field visibility and attachment access are more restricted than ordinary viewing.
- Remove a departing user in a controlled exercise and confirm ownership, tokens and scheduled actions are handled.
06
Lifecycle
Retention, deletion, backup and export behaviour
A delete button is not a lifecycle rule. Record the start event, end event, exception, system action, residual copy and accountable approver.
- Define retention events separately for unqualified leads, active customers, lost deals, complaints and legal holds.
- Test deletion against related records, attachments, recycle behaviour, exports, connected apps and backups.
- Record what the available export includes and excludes before relying on it for portability or exit.
07
Service chain
Processor, sub-processor and contract checks
Use the current contract and actual architecture. A product page cannot establish the complete role allocation for your organisation.
- Retrieve the current agreement, data-processing terms, service locations and sub-processor information.
- List marketplace extensions and custom functions because they can create separate data disclosures.
- Document assistance, deletion, return, security and incident-notification commitments without assuming an outcome.
08
Detection + response
Logs, monitoring and breach evidence
Coverage, event types, retention and exportability vary. Preserve an evidence timeline without claiming that one log proves the complete event.
- Sample audit entries for permission, configuration, export and deletion events your organisation needs to investigate.
- Record audit-log availability and retention for the subscribed edition; features can differ by plan.
- Connect a CRM incident signal to the internal triage, containment, impact and notification evidence workflow.
09
Request workflow
Rights-request search, export, correction and erasure workflow
- 01
Verify the requester outside the CRM, then search by the identifiers the person is likely to provide.
- 02
Search leads, contacts, deals, notes, attachments, activities, emails, tickets, custom modules and connected services.
- 03
Review legal and operational exceptions before correction or erasure, and retain a bounded action record.
- 04
Re-run the search after action and record residual copies, backup treatment and downstream confirmations.
10
Bounded configuration
Configuration checklist
Profiles, roles, sharing rules, privileged capabilities and API identities are owned and reviewed.
- Admin path
- Verify in the current admin console
- Evidence to save
- Dated role/profile export or screenshots, reviewer, exceptions and next review.
The team can retrieve events needed to investigate configuration and user activity.
- Admin path
- Verify in the current admin console
- Evidence to save
- Dated audit sample, available event types, retention window and edition limitation.
The team understands export scope, delivery, access, protection and secure disposal.
- Admin path
- Verify in the current admin console
- Evidence to save
- Test export inventory, recipient, storage location, deletion record and missing items.
Default and exception sharing match job need and connected-app purpose.
- Admin path
- Verify in the current admin console
- Evidence to save
- Sharing-rule review, integration list, exception owner and remediation decision.
No menu-path fiction: open the current vendor documentation and your live console together. Feature names, paths and entitlements can change.
11
Retrievable proof
Evidence to save
Module and field inventory with purpose owner
Notice and source-to-record trace
Role, profile and sharing review
Connected-app and automation register
Audit-log and export samples
Retention and rights-request exercise
Save redacted configuration evidence in an approved internal location. This private preview does not accept uploads or store these records.
12
Do not overclaim
Known limitations and questions for the vendor
Known limitations
- Zoho editions can expose different audit, export and security features.
- Custom functions, extensions and APIs may create flows the base product documentation cannot show.
- A CRM deletion outcome does not prove deletion in mailboxes, spreadsheets, connected apps or backups.
Questions to resolve
- Which edition and data centre does the organisation use?
- Which user or integration can export the broadest dataset?
- Can a withdrawn preference be traced through every campaign and workflow?
- What remains after the tested deletion and for how long?
13
Traceable record
Official vendor sources, DPDP sources and corrections
Vendor documentation supports configuration questions only. DPDP statements are mapped separately to official Indian sources and phased commencement records.
Official vendor documentation
Official DPDP record
- Act No. 22 of 2023Ministry of Law and Justice, Government of India · checked 2026-09-27 ↗
- G.S.R. 843(E)Ministry of Electronics and Information Technology, Government of India · checked 2026-09-27 ↗
- G.S.R. 846(E)Ministry of Electronics and Information Technology, Government of India · checked 2026-09-27 ↗
- G.S.R. 892(E)Ministry of Electronics and Information Technology, Government of India · checked 2026-09-27 ↗
Reviewed · not counsel-reviewed · educational implementation guidance, not legal advice, certification or a legal conclusion.
Report or inspect a correctionZoho and Zoho CRM are trademarks of Zoho Corporation. They are referenced only to identify the system; no affiliation or endorsement is implied.