{"id":7250,"date":"2026-05-26T17:11:19","date_gmt":"2026-05-26T16:11:19","guid":{"rendered":"https:\/\/liminal.pt\/martech-magazine\/?p=7250"},"modified":"2026-05-26T17:11:28","modified_gmt":"2026-05-26T16:11:28","slug":"10-gdpr-and-security-requirements-for-crm-and-automation-in-2026","status":"publish","type":"post","link":"https:\/\/liminal.pt\/martech-magazine\/en\/10-gdpr-and-security-requirements-for-crm-and-automation-in-2026\/","title":{"rendered":"10 GDPR and security requirements for CRM and automation in 2026"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Compare features, integrations and price. In 2026, the decision must include one central question: does the platform allow personal data to be processed securely, traceably and in compliance with GDPR?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This question is critical because CRM and marketing automation concentrate some of the most sensitive data in the commercial operation: contacts, job titles, emails, phone numbers, interaction history, communication preferences, acquisition sources, commercial interests, lead scoring scores, meeting notes, proposals and, in some cases, contractual or financial data. Even in a B2B context, much of this data remains personal data when it identifies or makes a natural person identifiable.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">GDPR does not prohibit marketing, sales or automation. It also does not prevent companies from using CRM, scoring, segmentation or commercial workflows. What it requires is that the processing of personal data has a legal basis, clear purposes, adequate security, transparency, respect for data subjects\u2019 rights and documented accountability. The regulation itself establishes principles such as lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality and accountability.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In practice, this means that a B2B SME should not choose a CRM only because it is easy to use or because it has good automations. It must assess whether the platform allows consent management, access control, data export, record deletion, processing documentation, response to data breaches and evidence of compliance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At Liminal, we help companies design CRM and automation implementations that combine commercial efficiency, data quality and governance. The goal is not to turn GDPR into an operational blocker. It is to create processes that allow companies to sell, communicate and automate with confidence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This guide presents the 10 essential GDPR and security requirements that should be assessed before implementing or reviewing a CRM and marketing automation platform.<\/p>\n\n\n\n<p class=\"has-text-align-center wp-block-paragraph\"><a href=\"https:\/\/liminal.pt\/rgpd\/checklist\/\" target=\"_blank\" rel=\"noreferrer noopener\">RGPD for Marketeers &#8211; A Checklist Elementar<\/a><\/p>\n\n\n\n<h1 class=\"wp-block-heading\">Quick guide: 10 GDPR and security requirements for B2B CRM<\/h1>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Legal basis and consent management<br>Allows the company to record why it can process data and communicate with each contact.<\/li>\n\n\n\n<li>Data encryption<br>Protects personal data in transit and at rest, reducing risk in the event of unauthorised access.<\/li>\n\n\n\n<li>Access control and permissions<br>Ensures that each user only accesses the data needed for their role.<\/li>\n\n\n\n<li>Data portability<br>Allows the company to respond to data subject requests with structured and readable exports.<\/li>\n\n\n\n<li>Right to erasure and data retention<br>Allows data to be deleted when applicable and retention periods to be defined.<\/li>\n\n\n\n<li>Data Protection Impact Assessment<br>Helps assess risks when there are more intrusive processing activities, such as profiling or scoring.<\/li>\n\n\n\n<li>Records of processing activities<br>Documents what data is processed, for what purpose, by whom and for how long.<\/li>\n\n\n\n<li>Notification and management of data breaches<br>Allows incidents to be detected, response to be documented and legal deadlines to be met.<\/li>\n\n\n\n<li>Data location and international transfers<br>Assesses where data is hosted and what mechanisms exist when data leaves the European Economic Area.<\/li>\n\n\n\n<li>Governance of integrations and processors<br>Ensures that the website, ERP, email tools, analytics, advertising and automation follow the same data protection model.<\/li>\n<\/ol>\n\n\n\n<h1 class=\"wp-block-heading\">How we assessed these requirements<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">These criteria were selected based on three dimensions: GDPR legal obligations, common operational risks in CRM and automation, and real impact on marketing and sales management.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The first dimension is regulatory compliance. GDPR defines data subject rights, obligations for controllers, rules for security of processing, notification of breaches, processing records and impact assessments. These requirements are not secondary. They must be reflected in the way the CRM collects, stores, segments, exports and deletes data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The second dimension is practical applicability. A requirement is only useful if it can be verified during a demo, a trial period or a configuration audit. It is not enough for the vendor to say that it \u201ccomplies with GDPR\u201d. It is necessary to understand how consent is recorded, how a contact is exported, how a record is deleted, how access is limited by profile and how a change is audited.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The third dimension is business impact. A poor GDPR configuration does not only create legal risk. It creates commercial risk. Databases without clear consent cannot be activated with confidence. Poorly recorded contact sources prevent attribution. Duplicates and outdated data reduce campaign effectiveness. Excessively open permissions increase the risk of data leaks. Poorly governed integrations circulate data without control.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For this reason, the following 10 requirements should be seen as a decision checklist for CEOs, CMOs, sales directors and marketing operations leaders.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">1. Legal basis and consent management<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Consent management is one of the most visible aspects of GDPR, but it should not be confused with the entirety of compliance. Not all personal data processing depends on consent. In a B2B context, there may be other legal bases, such as contract performance or legitimate interest, depending on the purpose and context. Even so, when consent is used, it must be specific, informed, freely given and demonstrable.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In a CRM and automation platform, the company must be able to answer simple questions: why is this contact in the database? What communications did they authorise? When did they give authorisation? Through which form? Can they easily withdraw consent? Does the system prevent communications that do not respect the recorded preferences?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Consent management must be granular. Authorising a newsletter is not the same as accepting direct commercial contact. Taking part in a webinar should not mean automatic consent for all future campaigns. The CRM must allow purposes to be separated, such as institutional communications, educational content, event invitations, commercial campaigns, telephone contact or customer related communications.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Features to verify:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Specific fields for legal basis and processing purpose.<\/li>\n\n\n\n<li>Record of the date, time, source and consent version.<\/li>\n\n\n\n<li>Forms with separate options by purpose.<\/li>\n\n\n\n<li>Preference centre for updating choices.<\/li>\n\n\n\n<li>Workflows that prevent communications without an appropriate legal basis.<\/li>\n\n\n\n<li>History of changes to the contact\u2019s preferences.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">This requirement is important because it protects the company in the event of a complaint and improves database quality. Contacts with clear permissions tend to generate more reliable campaigns. Imported contacts without source, without consent or without documented legal basis create risk and reduce operational trust.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The common mistake is to create a generic field called \u201cGDPR accepted\u201d and consider the issue solved. That field is rarely enough. What must be documented is the purpose, legal basis, source, moment and associated proof.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">2. Data encryption<\/h1>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"840\" height=\"559\" src=\"https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/05\/12311.jpg?resize=840%2C559&#038;ssl=1\" alt=\"\" class=\"wp-image-7246\" srcset=\"https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/05\/12311.jpg?resize=1024%2C682&amp;ssl=1 1024w, https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/05\/12311.jpg?resize=300%2C200&amp;ssl=1 300w, https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/05\/12311.jpg?resize=768%2C512&amp;ssl=1 768w, https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/05\/12311.jpg?resize=1536%2C1024&amp;ssl=1 1536w, https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/05\/12311.jpg?resize=420%2C280&amp;ssl=1 420w, https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/05\/12311.jpg?w=2000&amp;ssl=1 2000w, https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/05\/12311.jpg?w=1680&amp;ssl=1 1680w\" sizes=\"auto, (max-width: 840px) 100vw, 840px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Encryption is an essential technical measure to reduce the risk of exposure of personal data. Article 32 of GDPR refers to the need for technical and organisational measures appropriate to the risk, including, where appropriate, pseudonymisation and encryption of personal data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In a CRM context, there are two dimensions to assess: encryption in transit and encryption at rest. The first protects data when it circulates between users, browsers, applications, APIs and servers. The second protects data stored in databases, files, backups and cloud infrastructure.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The company must confirm whether the platform uses HTTPS, updated TLS, encryption of stored data and robust key management practices. It must also understand whether attachments, exports, backups and logs are protected. Many failures happen outside the main CRM database, for example in files exported to spreadsheets, unsecured integrations or poorly configured backups.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Features to verify:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Mandatory HTTPS across the entire application.<\/li>\n\n\n\n<li>Encryption of data at rest.<\/li>\n\n\n\n<li>Encryption of backups.<\/li>\n\n\n\n<li>Secure key management.<\/li>\n\n\n\n<li>Protection of attachments and documents.<\/li>\n\n\n\n<li>APIs with secure authentication.<\/li>\n\n\n\n<li>Credential expiration and rotation policies.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Encryption does not eliminate all risks, but it significantly reduces the impact of unauthorised access. If an incident occurs, encrypted data is harder to exploit. It also demonstrates diligence in applying measures appropriate to the risk.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The common mistake is to assume that \u201cbeing in the cloud\u201d means being secure. Cloud is not an automatic guarantee of protection. Security depends on the vendor\u2019s architecture, the platform configuration, internal access, integrations and the company\u2019s own practices.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">3. Access control and permissions<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Not everyone in the company needs to access all data. The principle of minimisation also applies to internal access. Each user should only have access to the data needed to perform their role.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In a CRM, this is particularly relevant because the platform brings together information from marketing, sales, support and management. A sales representative may need to see their opportunities and contacts, but not necessarily every contact in the organisation. A marketing team may need to segment campaigns, but not access sensitive commercial information. An external user or consultant may need temporary, limited and auditable access.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Access control must be granular. It must allow permissions to be configured by team, role, property, object, pipeline, region, owner or record type. It must also allow restrictions on exports, bulk editing, data deletion and access to sensitive reports.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Features to verify:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>User profiles by role.<\/li>\n\n\n\n<li>Teams and access hierarchies.<\/li>\n\n\n\n<li>Permissions by object, field and pipeline.<\/li>\n\n\n\n<li>Restrictions on data export.<\/li>\n\n\n\n<li>Multifactor authentication.<\/li>\n\n\n\n<li>Access and change logs.<\/li>\n\n\n\n<li>Periodic review of active users.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">This requirement reduces the risk of internal leaks, human error and unauthorised access. It also facilitates audits, because it allows the company to demonstrate that it applies control proportional to the risk.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The common mistake is to give administrator permissions to too many people. This speeds up implementation in the short term, but creates high risk. Another frequent mistake is forgetting old accounts belonging to employees who changed role or left the company.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">4. Data portability<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">The right to portability allows the data subject to receive their personal data in a structured, commonly used and machine readable format, and to transmit it to another controller when applicable. The CNPD describes this right as the possibility of receiving personal data in this type of format and, when technically possible, transmitting it directly between controllers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In a CRM, this means that the company must be able to export the data of a specific person in a complete and understandable way. Exporting only name and email is not enough. Depending on the case, it may be necessary to include contact details, preferences, consents, interaction history, acquisition sources, data provided by the data subject and other relevant fields.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Features to verify:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Export by individual contact.<\/li>\n\n\n\n<li>Export in formats such as CSV, JSON or XML.<\/li>\n\n\n\n<li>Inclusion of relevant metadata, such as creation date and source.<\/li>\n\n\n\n<li>Inclusion of consents and preferences.<\/li>\n\n\n\n<li>Ability to export interaction history.<\/li>\n\n\n\n<li>Documented process for validating the requester\u2019s identity.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Portability is important because it forces the company to know where the data is and how to deliver it. It is also a test of CRM architecture maturity. If data is spread across several platforms without a clear connection, responding to a portability request becomes slow and risky.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The common mistake is to think that exporting a complete contact list solves the request. Portability concerns the data of the data subject who made the request. The export must be precise, limited and secure.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">5. Right to erasure and data retention<\/h1>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"840\" height=\"559\" src=\"https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/05\/91.jpg?resize=840%2C559&#038;ssl=1\" alt=\"\" class=\"wp-image-7247\" srcset=\"https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/05\/91.jpg?resize=1024%2C682&amp;ssl=1 1024w, https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/05\/91.jpg?resize=300%2C200&amp;ssl=1 300w, https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/05\/91.jpg?resize=768%2C512&amp;ssl=1 768w, https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/05\/91.jpg?resize=1536%2C1024&amp;ssl=1 1536w, https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/05\/91.jpg?resize=420%2C280&amp;ssl=1 420w, https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/05\/91.jpg?w=2000&amp;ssl=1 2000w, https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/05\/91.jpg?w=1680&amp;ssl=1 1680w\" sizes=\"auto, (max-width: 840px) 100vw, 840px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">The right to erasure, also known as the right to be forgotten, allows the data subject to request the deletion of their data in certain circumstances. The CNPD explains that this right applies, for example, when the data is no longer necessary for the purpose that justified its collection, when consent has been withdrawn and there is no other legal basis, or when there is an objection to processing without overriding legitimate interests.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In the CRM, this requirement demands more than a delete button. The company must distinguish between deletion, anonymisation, marketing suppression, deactivation and mandatory retention. There are cases where certain data may have to be retained due to legal, tax or contractual obligations. In other cases, it must be deleted or anonymised.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Features to verify:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Permanent deletion of contacts when applicable.<\/li>\n\n\n\n<li>Anonymisation of data when total deletion is not appropriate.<\/li>\n\n\n\n<li>Suppression lists to prevent new communications.<\/li>\n\n\n\n<li>Retention policies by data type.<\/li>\n\n\n\n<li>Workflows for reviewing inactive contacts.<\/li>\n\n\n\n<li>Propagation of requests to integrated systems.<\/li>\n\n\n\n<li>Minimum record of request fulfilment.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">This requirement is essential because old databases, without a current purpose, increase risk and reduce quality. Obsolete data harms segmentation, reporting and automations. In addition, keeping data indefinitely without necessity goes against the principle of storage limitation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The common mistake is to delete only in the main CRM and forget connected tools, such as email marketing, event platforms, spreadsheets, ERP integrations, advertising tools or operational backups.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">6. Data Protection Impact Assessment<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">A Data Protection Impact Assessment, known as DPIA, is required when a type of processing is likely to result in a high risk to the rights and freedoms of individuals. The European Data Protection Board maintains guidelines on DPIA and high risk processing, which are relevant for assessing when an organisation should carry out this analysis.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In CRM and automation, a DPIA may be necessary in scenarios such as intensive profiling, automated scoring, advanced behavioural segmentation, data enrichment from multiple sources, large scale processing or automated decisions with significant impact.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A DPIA should not be seen as a bureaucratic document. It should function as a structured analysis of what will be done, why, with what data, with what risks and with what mitigation measures.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Features to verify:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Inventory of data used in automations and scoring.<\/li>\n\n\n\n<li>Mapping of flows between CRM, website, ERP and external tools.<\/li>\n\n\n\n<li>Identification of processing activities involving profiling.<\/li>\n\n\n\n<li>Documentation of the purposes of each automation.<\/li>\n\n\n\n<li>Record of mitigation measures.<\/li>\n\n\n\n<li>Review before launching new high risk workflows.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">A DPIA helps avoid projects that are only corrected after implementation. In marketing automation, this is particularly relevant because it is easy to create flows that seem efficient, but use excessive data, unclear purposes or opaque decision logic.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The common mistake is to treat lead scoring as a simple commercial feature. In many cases it is only internal prioritisation. But when it involves significant profiling, multiple data sources or relevant effects for data subjects, it must be assessed more carefully.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">7. Records of processing activities<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Article 30 of GDPR requires controllers and processors to maintain records of processing activities under certain conditions. Even when an SME is not automatically required in every scenario, any company that uses CRM and automation on a regular basis should keep organised documentation about the processing activities it carries out.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In practice, records of processing activities answer fundamental questions: what data is processed? For what purpose? With what legal basis? Who has access? For how long is it retained? Which vendors are involved? Are there international transfers? What security measures exist?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Features to verify:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Data inventory by module and purpose.<\/li>\n\n\n\n<li>Documentation of legal bases.<\/li>\n\n\n\n<li>Identification of categories of data subjects and data.<\/li>\n\n\n\n<li>Identification of processors.<\/li>\n\n\n\n<li>Retention periods.<\/li>\n\n\n\n<li>Record of integrations and data flows.<\/li>\n\n\n\n<li>Export for audits.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">This requirement is important because it turns compliance into management. When the company understands its processing activities, it can respond better to requests, audits, incidents and internal changes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The common mistake is to keep this record in a static document, created once and never updated. Whenever there is a new integration, new campaign, new form, new automation or new vendor, the record may need to be reviewed.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">8. Notification and management of data breaches<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">A personal data breach is not only a cyberattack. It may include sending data to the wrong recipient, losing a device, unauthorised access, unauthorised export, an integration error or accidental exposure of information.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The CNPD indicates that when a personal data breach is likely to result in a risk to the rights and freedoms of natural persons, it must be notified within 72 hours after the controller becomes aware of it. The EDPB also reinforces that notification must be made without undue delay and, when required, within that deadline.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Features to verify:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Alerts on suspicious access.<\/li>\n\n\n\n<li>Alerts on mass exports.<\/li>\n\n\n\n<li>Change and access logs.<\/li>\n\n\n\n<li>Chronological incident record.<\/li>\n\n\n\n<li>Internal escalation procedure.<\/li>\n\n\n\n<li>Rapid identification of affected data.<\/li>\n\n\n\n<li>Communication and notification templates.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">This requirement is critical because the 72 hour deadline is short. Without logs, alerts and defined processes, the company loses time trying to understand what happened, who was affected and what measures it took.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The common mistake is having technology, but no procedure. A CRM may have logs, but if no one monitors them, if there is no person responsible for incidents and if there is no response process, the functionality does not resolve the risk.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">9. Data location and international transfers<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Data location remains a relevant topic for CRM and automation, especially because many global platforms use infrastructure, processors and support teams outside the European Union or the European Economic Area.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">European rules apply to the European Economic Area, and when personal data is transferred outside this area, appropriate safeguards must exist to ensure that protection follows the data. The European Commission explains that international transfers require specific mechanisms, such as adequacy decisions or other safeguards provided for in GDPR.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Choosing servers in the European Union may simplify part of the analysis, but it does not solve everything. It is necessary to verify where primary data, backups, logs, support tools, processors, AI services, email platforms and integrations are located.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Features to verify:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Hosting option in the European Union or European Economic Area.<\/li>\n\n\n\n<li>List of processors and their locations.<\/li>\n\n\n\n<li>Information about international transfers.<\/li>\n\n\n\n<li>Standard contractual clauses when applicable.<\/li>\n\n\n\n<li>Backup and disaster recovery policy.<\/li>\n\n\n\n<li>Information about access by support teams outside the EU.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">This requirement is important because many CRM implementations depend on ecosystems. The CRM may be in the EU, but a lead enrichment, analytics or support tool may transfer data to other countries.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The common mistake is to ask only \u201cwhere are the servers?\u201d and ignore processors, integrations, logs and technical support.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">10. Governance of integrations and processors<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">CRM and automation rarely operate in isolation. They usually connect the website, forms, email marketing, ERP, advertising platforms, analytics tools, call centre, chat, webinars, proposals, invoicing, BI and API integrations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Each integration creates data circulation. Each vendor may act as a processor. Each API may expose data if not configured correctly. For this reason, governance of integrations is a central security and GDPR requirement.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Features to verify:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Inventory of all integrations connected to the CRM.<\/li>\n\n\n\n<li>Processing agreements with relevant vendors.<\/li>\n\n\n\n<li>Control of API permissions.<\/li>\n\n\n\n<li>Management of tokens and access keys.<\/li>\n\n\n\n<li>Synchronisation logs.<\/li>\n\n\n\n<li>Data minimisation rules by integration.<\/li>\n\n\n\n<li>Approval process for new tools.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">This requirement is often the most neglected. The company may have a well configured CRM, but lose control when data moves to spreadsheets, external tools or integrations created without governance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The common mistake is to let teams create integrations without prior assessment. This happens with automation tools, no code connectors, manual exports and occasional scripts. The risk is not only in the CRM. It is in the ecosystem around it.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">How to configure these requirements in HubSpot, Salesforce and Zoho<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">HubSpot, Salesforce and Zoho can support security and GDPR requirements, but they require adequate configuration. No platform guarantees compliance simply by being contracted.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">HubSpot<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">HubSpot is strong for teams that need to integrate marketing, sales and service in an accessible platform. It allows companies to work with consent properties, email subscriptions, forms, permissions, teams, workflows and reports. For B2B companies, it is particularly useful when the goal is to connect lead capture, contact management, automation and pipeline.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The critical point is to configure legal bases, subscription types, preferences, retention and permissions correctly. Without this configuration, the platform\u2019s ease of use may lead to excessive data use or communications without adequate segmentation.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Salesforce<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Salesforce is suitable for organisations with greater operational complexity, multiple access profiles, several teams, custom objects, advanced rules and enterprise integrations. It has strong personalisation capabilities, but that flexibility requires stronger governance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The risk lies in creating an architecture that is too complex, with permissions, fields, objects and integrations that are difficult to audit. For companies with mature processes, Salesforce can be very robust. For teams without governance, it can become difficult to control.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Zoho CRM<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Zoho CRM offers a good balance between cost, flexibility and ecosystem. It can be a strong option for SMEs that want CRM, automation, campaigns, support, projects and other applications in an integrated environment.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The critical point is to design the data model, permissions, integrations and flows between Zoho applications and external tools properly. As with HubSpot and Salesforce, compliance depends on configuration, not only on the subscription.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">Comparative table: GDPR and security requirements for CRM<\/h1>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Requirement<\/strong><\/td><td><strong>GDPR obligation or relevance<\/strong><\/td><td><strong>Operational impact<\/strong><\/td><td><strong>Risk if it fails<\/strong><\/td><td><strong>Liminal support<\/strong><\/td><\/tr><tr><td><strong>Legal basis and consent management<\/strong><\/td><td>High<\/td><td>High<\/td><td>Improper communications, complaints and loss of trust<\/td><td>Configuration of fields, forms, preferences and workflows<\/td><\/tr><tr><td><strong>Data encryption<\/strong><\/td><td>High as a security measure appropriate to the risk<\/td><td>Medium<\/td><td>Data exposure in the event of an incident<\/td><td>Assessment of vendors and technical requirements<\/td><\/tr><tr><td><strong>Access control<\/strong><\/td><td>High<\/td><td>High<\/td><td>Unauthorised access and data leakage<\/td><td>Definition of profiles, teams and permissions<\/td><\/tr><tr><td><strong>Data portability<\/strong><\/td><td>High when applicable<\/td><td>Medium<\/td><td>Inability to respond to data subject requests<\/td><td>Export processes and documentation<\/td><\/tr><tr><td><strong>Right to erasure and retention<\/strong><\/td><td>High when applicable<\/td><td>High<\/td><td>Improper data retention<\/td><td>Deletion, anonymisation and retention workflows<\/td><\/tr><tr><td><strong>DPIA<\/strong><\/td><td>Situational, but critical in high risk processing<\/td><td>Medium<\/td><td>Launching automations with high risk without assessment<\/td><td>Data mapping and assessment support<\/td><\/tr><tr><td><strong>Records of processing activities<\/strong><\/td><td>High in many contexts<\/td><td>Medium<\/td><td>Lack of evidence in an audit<\/td><td>Inventory of data, purposes and integrations<\/td><\/tr><tr><td><strong>Notification of breaches<\/strong><\/td><td>High<\/td><td>High<\/td><td>Failure to meet the 72 hour deadline<\/td><td>Procedures, logs and response model<\/td><\/tr><tr><td><strong>Location and international transfers<\/strong><\/td><td>High when there are transfers outside the EEA<\/td><td>Medium<\/td><td>Transfers without appropriate safeguards<\/td><td>Assessment of vendors and processors<\/td><\/tr><tr><td><strong>Governance of integrations<\/strong><\/td><td>High as part of processing accountability<\/td><td>High<\/td><td>Loss of control over data in the ecosystem<\/td><td>Integrated architecture and operational governance<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h1 class=\"wp-block-heading\">How to prepare a DPIA for B2B marketing automation<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">A DPIA, Data Protection Impact Assessment, starts by mapping the processing. Before assessing risks, the company needs to know what data is collected, through which channels it enters, where it is stored, which systems receive it, which automations use it and which decisions are made based on that data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In B2B marketing automation, this analysis should include forms, cookies, campaigns, scoring, segmentation, automated emails, CRM integration, connection to sales, data enrichment and performance reports.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The second step is to assess necessity and proportionality. The question is not only \u201ccan we collect this data?\u201d. The correct question is \u201cdo we really need this data for this purpose?\u201d. If the campaign can work with less data, less data should be collected.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The third step is to identify risks. Common examples include excessive segmentation, lack of transparency, outdated data, opaque scoring, unexpected communications, access by people without operational need or transfer to external tools without safeguards.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The fourth step is to define mitigation measures. These may include clear consents, retention policies, pseudonymisation, access limitation, human review of decisions, simple opt out, activity logs, vendor documentation and testing before activating workflows.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The DPIA should be reviewed whenever the processing changes in a relevant way. A simple nurture automation does not carry the same risk as a scoring model fed by multiple sources and used to prioritise commercial opportunities.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">What are the fines for GDPR non compliance in Portugal?<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">GDPR provides for two main levels of administrative fines. The most serious infringements may reach 20 million euros or 4% of annual worldwide turnover, whichever amount is higher. Other infringements may reach 10 million euros or 2% of annual worldwide turnover. These limits are set out in Article 83 of GDPR.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In practice, risk should not be assessed only by the size of the fine. There is also reputational risk, loss of trust, operational disruption, incident response costs, audits, the need to clean databases and loss of commercial activation capacity.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For SMEs, the best strategy is operational prevention. This means choosing appropriate tools, configuring permissions, documenting processing activities, managing consents, defining retention, controlling integrations and training teams.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">Why a Marketing Ops consultancy improves security and GDPR in CRM<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">A Marketing Ops consultancy adds value because it connects three dimensions that are usually separate: commercial strategy, technology and data governance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The legal team can interpret obligations. The IT team can assess technical security. The marketing team wants to execute campaigns and generate pipeline. The problem is that the CRM lives at the intersection of these areas. Without an operational bridge, the risk is creating policies that no one applies, or efficient automations that no one can audit.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is where Liminal adds value. Liminal helps companies turn GDPR requirements into concrete processes inside CRM and automation platforms. This includes data structure, consent fields, segmentation rules, permissions, workflows, integrations, reporting and team training.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The question is not only whether to choose HubSpot, Salesforce or Zoho. The question is how to design a system in which data, processes and automations support commercial growth without creating unnecessary risk.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">Conclusion<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">GDPR and security should not be treated as a final step in CRM implementation. They should be part of the initial architecture design.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A CRM platform can be powerful, but if it does not have a documented legal basis, clear consents, adequate permissions, data export, retention, erasure, logs, incident management and integration control, the company remains exposed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The 10 requirements presented in this article help assess vendors, review existing configurations and prepare a more secure implementation. They do not replace legal advice or the work of a Data Protection Officer when applicable, but they create a solid operational foundation for CRM and automation decisions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In 2026, B2B companies that treat data rigorously will have a competitive advantage. They will communicate with more confidence, activate databases with lower risk, respond better to audits and build more transparent relationships with clients and prospects.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The right technology matters. But architecture, governance and adoption matter more.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><a href=\"https:\/\/liminal.pt\/livro-hiperpersonalizacao-martech\/\" target=\"_blank\" rel=\" noreferrer noopener\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"840\" height=\"441\" src=\"https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2024\/09\/share-livro.jpg?resize=840%2C441&#038;ssl=1\" alt=\"Livro: Do Zero \u00e0 Hiperpersonaliza\u00e7\u00e3o: Estrat\u00e9gias de Marketing, CRM e Automa\u00e7\u00e3o com Intelig\u00eancia Artificial na Era das MarTech\" class=\"wp-image-5764\" srcset=\"https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2024\/09\/share-livro.jpg?resize=1024%2C538&amp;ssl=1 1024w, https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2024\/09\/share-livro.jpg?resize=300%2C158&amp;ssl=1 300w, https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2024\/09\/share-livro.jpg?resize=768%2C404&amp;ssl=1 768w, https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2024\/09\/share-livro.jpg?w=1200&amp;ssl=1 1200w\" sizes=\"auto, (max-width: 840px) 100vw, 840px\" \/><\/a><\/figure>\n<\/div>\n\n\n<h2 class=\"wp-block-heading\">Count on Liminal\u2019s CRM specialists<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The world of Marketing and Technology is constantly evolving. It is increasingly important to rely on specialists who ensure that innovations are integrated into companies. In addition, for technology to contribute to business success, it is essential to have a strategy that guides the implementation, adoption and evolution of systems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As MarTech specialists, <a href=\"https:\/\/liminal.pt\/\">Liminal<\/a> offers an integrated vision that combines Technology, Marketing and Strategy. We ensure the successful adoption and implementation of marketing technologies, whether through the impartial choice of the right systems to address the challenges of the company, the adaptation of processes and flows in existing systems, or the development of a <a href=\"https:\/\/liminal.pt\/produtos\/crm.html\">CRM<\/a> &amp; <a href=\"https:\/\/liminal.pt\/produtos\/automacao-de-marketing.html\">Automation<\/a> strategy that contributes to business growth.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">FAQs about GDPR and security requirements in CRM<\/h1>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>What is GDPR and how does it affect CRM?<\/strong><\/summary>\n<p class=\"wp-block-paragraph\">GDPR is the General Data Protection Regulation and applies to the processing of personal data of natural persons. In the context of CRM, it affects how the company collects, stores, uses, shares, exports and deletes data from contacts, leads, clients and users.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>Is B2B data also covered by GDPR?<\/strong><\/summary>\n<p class=\"wp-block-paragraph\">Yes, when it identifies or makes a natural person identifiable. A general email such as <a>info@company.pt<\/a> may not directly identify a person, but a professional email with name, job title and company is normally personal data.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>Is marketing automation compatible with GDPR?<\/strong><\/summary>\n<p class=\"wp-block-paragraph\">Yes. GDPR does not prohibit marketing automation. It requires transparency, an appropriate legal basis, security, respect for data subject rights and limitation of the data used for each purpose.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>Is consent always necessary for B2B campaigns?<\/strong><\/summary>\n<p class=\"wp-block-paragraph\">Not necessarily. Consent is one possible legal basis, but it is not the only one. Depending on the case, legitimate interest or another legal basis may exist. The choice must be documented and validated according to the purpose, context and expectation of the data subject.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>How long can data remain in the CRM?<\/strong><\/summary>\n<p class=\"wp-block-paragraph\">There is no single time limit. GDPR requires storage only for as long as necessary for the purpose. The company must define retention policies by data type, purpose and legal obligation.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>What happens if someone asks to have their data erased?<\/strong><\/summary>\n<p class=\"wp-block-paragraph\">The company must assess whether the request applies and whether there are legal obligations that justify partial retention. When applicable, it must delete or anonymise the data and ensure that the request is reflected in integrated systems.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>Should the CRM be hosted in the European Union?<\/strong><\/summary>\n<p class=\"wp-block-paragraph\">It is not always mandatory, but it can simplify compliance. When there are transfers outside the European Economic Area, appropriate mechanisms must exist, such as adequacy decisions or standard contractual clauses.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>What should exist in a data breach process?<\/strong><\/summary>\n<p class=\"wp-block-paragraph\">There should be detection, recording, risk assessment, identification of the affected data, a decision on notification to the CNPD, communication to data subjects when applicable and documentation of the measures taken.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary><strong>Does an SME need records of processing activities?<\/strong><\/summary>\n<p class=\"wp-block-paragraph\">Many SMEs that use CRM and automation regularly should maintain documentation of processing activities, even when the formal obligation depends on the context. In practice, it is an essential good practice for audits, response to data subjects and risk management.<\/p>\n<\/details>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n<div class=\"rtng-rating-total\" data-id=\"7250\"><span class=\"rtng-text rtng-title\">Feedback<\/span><div class=\"rtng-star-rating rtng-no-js \" data-rating=\"0\"><div class=\"rtng-star\" data-rating=\"1\">\n\t\t\t\t\t<span class=\"dashicons dashicons-star-empty\"><\/span>\n\t\t\t\t<\/div><div class=\"rtng-star\" data-rating=\"2\">\n\t\t\t\t\t<span class=\"dashicons dashicons-star-empty\"><\/span>\n\t\t\t\t<\/div><div class=\"rtng-star\" data-rating=\"3\">\n\t\t\t\t\t<span class=\"dashicons dashicons-star-empty\"><\/span>\n\t\t\t\t<\/div><div class=\"rtng-star\" data-rating=\"4\">\n\t\t\t\t\t<span class=\"dashicons dashicons-star-empty\"><\/span>\n\t\t\t\t<\/div><div class=\"rtng-star\" data-rating=\"5\">\n\t\t\t\t\t<span class=\"dashicons dashicons-star-empty\"><\/span>\n\t\t\t\t<\/div><\/div><span class=\"rtng-text rtng-total\">No rating yet<\/span><\/div><form action=\"\" method=\"post\" class=\"rtng-form\" data-id=\"7250\"><input type=\"hidden\" name=\"rtng_show_title\" value=\"1\"><span class=\"rtng-text rtng-vote-title\">O meu feedback:<\/span><div class=\"rtng-star-rating rtng-no-js rtng-active\" data-rating=\"\"><label class=\"rtng-star\" data-rating=\"1\">\n\t\t\t\t\t<input type=\"radio\"  name=\"rtng_rating[0]\" value=\"1\" \/>\n\t\t\t\t\t<span class=\"dashicons dashicons-star-empty\"><\/span>\n\t\t\t\t<\/label><label class=\"rtng-star\" data-rating=\"2\">\n\t\t\t\t\t<input type=\"radio\"  name=\"rtng_rating[0]\" value=\"2\" \/>\n\t\t\t\t\t<span class=\"dashicons dashicons-star-empty\"><\/span>\n\t\t\t\t<\/label><label class=\"rtng-star\" data-rating=\"3\">\n\t\t\t\t\t<input type=\"radio\"  name=\"rtng_rating[0]\" value=\"3\" \/>\n\t\t\t\t\t<span class=\"dashicons dashicons-star-empty\"><\/span>\n\t\t\t\t<\/label><label class=\"rtng-star\" data-rating=\"4\">\n\t\t\t\t\t<input type=\"radio\"  name=\"rtng_rating[0]\" value=\"4\" \/>\n\t\t\t\t\t<span class=\"dashicons dashicons-star-empty\"><\/span>\n\t\t\t\t<\/label><label class=\"rtng-star\" data-rating=\"5\">\n\t\t\t\t\t<input type=\"radio\"  name=\"rtng_rating[0]\" value=\"5\" \/>\n\t\t\t\t\t<span class=\"dashicons dashicons-star-empty\"><\/span>\n\t\t\t\t<\/label><\/div><noscript><input type=\"submit\" name=\"rtng_add_button\" class=\"rtng-add-button\" value=\"Rate\" \/><\/noscript>\n\t\t\t\t<input type=\"hidden\" name=\"rtng_object_type\" value=\"post\">\n\t\t\t\t<input type=\"hidden\" name=\"rtng_object_id\" value=\"0\">\n\t\t\t\t<input type=\"hidden\" name=\"rtng_post_id\" value=\"7250\"><input type=\"hidden\" id=\"rtng_nonce_button\" name=\"rtng_nonce_button\" value=\"644b19a7f0\" \/><input type=\"hidden\" name=\"_wp_http_referer\" value=\"\/martech-magazine\/wp-json\/wp\/v2\/posts\/7250\" \/><\/form>","protected":false},"excerpt":{"rendered":"<p>Compare features, integrations and price. In 2026, the decision must include one central question: does the platform allow personal data to be processed securely, traceably and in compliance with GDPR? &hellip; <\/p>\n","protected":false},"author":14,"featured_media":7240,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[655],"tags":[],"class_list":["post-7250","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-gdpr"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>10 GDPR and security requirements for CRM and automation in 2026 | Martech Magazine<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/liminal.pt\/martech-magazine\/en\/10-gdpr-and-security-requirements-for-crm-and-automation-in-2026\/\" \/>\n<meta property=\"og:locale\" content=\"pt_PT\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"10 GDPR and security requirements for CRM and automation in 2026 | Martech Magazine\" \/>\n<meta property=\"og:description\" content=\"Compare features, integrations and price. In 2026, the decision must include one central question: does the platform allow personal data to be processed securely, traceably and in compliance with GDPR? &hellip;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/liminal.pt\/martech-magazine\/en\/10-gdpr-and-security-requirements-for-crm-and-automation-in-2026\/\" \/>\n<meta property=\"og:site_name\" content=\"Martech Magazine\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Liminal-270123610141550\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-05-26T16:11:19+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-05-26T16:11:28+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/05\/491.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2000\" \/>\n\t<meta property=\"og:image:height\" content=\"1597\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Dara Correia\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Dara Correia\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tempo estimado de leitura\" \/>\n\t<meta name=\"twitter:data2\" content=\"27 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/liminal.pt\\\/martech-magazine\\\/en\\\/10-gdpr-and-security-requirements-for-crm-and-automation-in-2026\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/liminal.pt\\\/martech-magazine\\\/en\\\/10-gdpr-and-security-requirements-for-crm-and-automation-in-2026\\\/\"},\"author\":{\"name\":\"Dara Correia\",\"@id\":\"https:\\\/\\\/liminal.pt\\\/martech-magazine\\\/#\\\/schema\\\/person\\\/870bd144c500aab26df7c6bc61b4bed4\"},\"headline\":\"10 GDPR and security requirements for CRM and automation in 2026\",\"datePublished\":\"2026-05-26T16:11:19+00:00\",\"dateModified\":\"2026-05-26T16:11:28+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/liminal.pt\\\/martech-magazine\\\/en\\\/10-gdpr-and-security-requirements-for-crm-and-automation-in-2026\\\/\"},\"wordCount\":4736,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/liminal.pt\\\/martech-magazine\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/liminal.pt\\\/martech-magazine\\\/en\\\/10-gdpr-and-security-requirements-for-crm-and-automation-in-2026\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/i0.wp.com\\\/liminal.pt\\\/martech-magazine\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/491.jpg?fit=2000%2C1597&ssl=1\",\"articleSection\":[\"GDPR\"],\"inLanguage\":\"pt-PT\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/liminal.pt\\\/martech-magazine\\\/en\\\/10-gdpr-and-security-requirements-for-crm-and-automation-in-2026\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/liminal.pt\\\/martech-magazine\\\/en\\\/10-gdpr-and-security-requirements-for-crm-and-automation-in-2026\\\/\",\"url\":\"https:\\\/\\\/liminal.pt\\\/martech-magazine\\\/en\\\/10-gdpr-and-security-requirements-for-crm-and-automation-in-2026\\\/\",\"name\":\"10 GDPR and security requirements for CRM and automation in 2026 | Martech Magazine\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/liminal.pt\\\/martech-magazine\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/liminal.pt\\\/martech-magazine\\\/en\\\/10-gdpr-and-security-requirements-for-crm-and-automation-in-2026\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/liminal.pt\\\/martech-magazine\\\/en\\\/10-gdpr-and-security-requirements-for-crm-and-automation-in-2026\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/i0.wp.com\\\/liminal.pt\\\/martech-magazine\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/491.jpg?fit=2000%2C1597&ssl=1\",\"datePublished\":\"2026-05-26T16:11:19+00:00\",\"dateModified\":\"2026-05-26T16:11:28+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/liminal.pt\\\/martech-magazine\\\/en\\\/10-gdpr-and-security-requirements-for-crm-and-automation-in-2026\\\/#breadcrumb\"},\"inLanguage\":\"pt-PT\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/liminal.pt\\\/martech-magazine\\\/en\\\/10-gdpr-and-security-requirements-for-crm-and-automation-in-2026\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-PT\",\"@id\":\"https:\\\/\\\/liminal.pt\\\/martech-magazine\\\/en\\\/10-gdpr-and-security-requirements-for-crm-and-automation-in-2026\\\/#primaryimage\",\"url\":\"https:\\\/\\\/i0.wp.com\\\/liminal.pt\\\/martech-magazine\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/491.jpg?fit=2000%2C1597&ssl=1\",\"contentUrl\":\"https:\\\/\\\/i0.wp.com\\\/liminal.pt\\\/martech-magazine\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/491.jpg?fit=2000%2C1597&ssl=1\",\"width\":2000,\"height\":1597},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/liminal.pt\\\/martech-magazine\\\/en\\\/10-gdpr-and-security-requirements-for-crm-and-automation-in-2026\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"In\u00edcio\",\"item\":\"https:\\\/\\\/liminal.pt\\\/martech-magazine\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"10 GDPR and security requirements for CRM and automation in 2026\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/liminal.pt\\\/martech-magazine\\\/#website\",\"url\":\"https:\\\/\\\/liminal.pt\\\/martech-magazine\\\/\",\"name\":\"Martech Magazine\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/liminal.pt\\\/martech-magazine\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/liminal.pt\\\/martech-magazine\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"pt-PT\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/liminal.pt\\\/martech-magazine\\\/#organization\",\"name\":\"Liminal\",\"url\":\"https:\\\/\\\/liminal.pt\\\/martech-magazine\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-PT\",\"@id\":\"https:\\\/\\\/liminal.pt\\\/martech-magazine\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/i0.wp.com\\\/liminal.pt\\\/martech-magazine\\\/wp-content\\\/uploads\\\/2019\\\/01\\\/logotipo-liminal.png?fit=3012%2C3319&ssl=1\",\"contentUrl\":\"https:\\\/\\\/i0.wp.com\\\/liminal.pt\\\/martech-magazine\\\/wp-content\\\/uploads\\\/2019\\\/01\\\/logotipo-liminal.png?fit=3012%2C3319&ssl=1\",\"width\":3012,\"height\":3319,\"caption\":\"Liminal\"},\"image\":{\"@id\":\"https:\\\/\\\/liminal.pt\\\/martech-magazine\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Liminal-270123610141550\\\/\",\"https:\\\/\\\/www.instagram.com\\\/liminalmarketing\\\/\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/liminalmarketing\\\/\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UCmr6iaNEpIKmX2wfSfcgGWg\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/liminal.pt\\\/martech-magazine\\\/#\\\/schema\\\/person\\\/870bd144c500aab26df7c6bc61b4bed4\",\"name\":\"Dara Correia\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-PT\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/6227e3d319896007b27cc8e07bad9f555e484528bfa038607a19bed547660144?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/6227e3d319896007b27cc8e07bad9f555e484528bfa038607a19bed547660144?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/6227e3d319896007b27cc8e07bad9f555e484528bfa038607a19bed547660144?s=96&d=mm&r=g\",\"caption\":\"Dara Correia\"},\"url\":\"https:\\\/\\\/liminal.pt\\\/martech-magazine\\\/author\\\/dara-correia\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"10 GDPR and security requirements for CRM and automation in 2026 | Martech Magazine","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/liminal.pt\/martech-magazine\/en\/10-gdpr-and-security-requirements-for-crm-and-automation-in-2026\/","og_locale":"pt_PT","og_type":"article","og_title":"10 GDPR and security requirements for CRM and automation in 2026 | Martech Magazine","og_description":"Compare features, integrations and price. In 2026, the decision must include one central question: does the platform allow personal data to be processed securely, traceably and in compliance with GDPR? &hellip;","og_url":"https:\/\/liminal.pt\/martech-magazine\/en\/10-gdpr-and-security-requirements-for-crm-and-automation-in-2026\/","og_site_name":"Martech Magazine","article_publisher":"https:\/\/www.facebook.com\/Liminal-270123610141550\/","article_published_time":"2026-05-26T16:11:19+00:00","article_modified_time":"2026-05-26T16:11:28+00:00","og_image":[{"width":2000,"height":1597,"url":"https:\/\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/05\/491.jpg","type":"image\/jpeg"}],"author":"Dara Correia","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Dara Correia","Tempo estimado de leitura":"27 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/liminal.pt\/martech-magazine\/en\/10-gdpr-and-security-requirements-for-crm-and-automation-in-2026\/#article","isPartOf":{"@id":"https:\/\/liminal.pt\/martech-magazine\/en\/10-gdpr-and-security-requirements-for-crm-and-automation-in-2026\/"},"author":{"name":"Dara Correia","@id":"https:\/\/liminal.pt\/martech-magazine\/#\/schema\/person\/870bd144c500aab26df7c6bc61b4bed4"},"headline":"10 GDPR and security requirements for CRM and automation in 2026","datePublished":"2026-05-26T16:11:19+00:00","dateModified":"2026-05-26T16:11:28+00:00","mainEntityOfPage":{"@id":"https:\/\/liminal.pt\/martech-magazine\/en\/10-gdpr-and-security-requirements-for-crm-and-automation-in-2026\/"},"wordCount":4736,"commentCount":0,"publisher":{"@id":"https:\/\/liminal.pt\/martech-magazine\/#organization"},"image":{"@id":"https:\/\/liminal.pt\/martech-magazine\/en\/10-gdpr-and-security-requirements-for-crm-and-automation-in-2026\/#primaryimage"},"thumbnailUrl":"https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/05\/491.jpg?fit=2000%2C1597&ssl=1","articleSection":["GDPR"],"inLanguage":"pt-PT","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/liminal.pt\/martech-magazine\/en\/10-gdpr-and-security-requirements-for-crm-and-automation-in-2026\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/liminal.pt\/martech-magazine\/en\/10-gdpr-and-security-requirements-for-crm-and-automation-in-2026\/","url":"https:\/\/liminal.pt\/martech-magazine\/en\/10-gdpr-and-security-requirements-for-crm-and-automation-in-2026\/","name":"10 GDPR and security requirements for CRM and automation in 2026 | Martech Magazine","isPartOf":{"@id":"https:\/\/liminal.pt\/martech-magazine\/#website"},"primaryImageOfPage":{"@id":"https:\/\/liminal.pt\/martech-magazine\/en\/10-gdpr-and-security-requirements-for-crm-and-automation-in-2026\/#primaryimage"},"image":{"@id":"https:\/\/liminal.pt\/martech-magazine\/en\/10-gdpr-and-security-requirements-for-crm-and-automation-in-2026\/#primaryimage"},"thumbnailUrl":"https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/05\/491.jpg?fit=2000%2C1597&ssl=1","datePublished":"2026-05-26T16:11:19+00:00","dateModified":"2026-05-26T16:11:28+00:00","breadcrumb":{"@id":"https:\/\/liminal.pt\/martech-magazine\/en\/10-gdpr-and-security-requirements-for-crm-and-automation-in-2026\/#breadcrumb"},"inLanguage":"pt-PT","potentialAction":[{"@type":"ReadAction","target":["https:\/\/liminal.pt\/martech-magazine\/en\/10-gdpr-and-security-requirements-for-crm-and-automation-in-2026\/"]}]},{"@type":"ImageObject","inLanguage":"pt-PT","@id":"https:\/\/liminal.pt\/martech-magazine\/en\/10-gdpr-and-security-requirements-for-crm-and-automation-in-2026\/#primaryimage","url":"https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/05\/491.jpg?fit=2000%2C1597&ssl=1","contentUrl":"https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/05\/491.jpg?fit=2000%2C1597&ssl=1","width":2000,"height":1597},{"@type":"BreadcrumbList","@id":"https:\/\/liminal.pt\/martech-magazine\/en\/10-gdpr-and-security-requirements-for-crm-and-automation-in-2026\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"In\u00edcio","item":"https:\/\/liminal.pt\/martech-magazine\/"},{"@type":"ListItem","position":2,"name":"10 GDPR and security requirements for CRM and automation in 2026"}]},{"@type":"WebSite","@id":"https:\/\/liminal.pt\/martech-magazine\/#website","url":"https:\/\/liminal.pt\/martech-magazine\/","name":"Martech Magazine","description":"","publisher":{"@id":"https:\/\/liminal.pt\/martech-magazine\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/liminal.pt\/martech-magazine\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"pt-PT"},{"@type":"Organization","@id":"https:\/\/liminal.pt\/martech-magazine\/#organization","name":"Liminal","url":"https:\/\/liminal.pt\/martech-magazine\/","logo":{"@type":"ImageObject","inLanguage":"pt-PT","@id":"https:\/\/liminal.pt\/martech-magazine\/#\/schema\/logo\/image\/","url":"https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2019\/01\/logotipo-liminal.png?fit=3012%2C3319&ssl=1","contentUrl":"https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2019\/01\/logotipo-liminal.png?fit=3012%2C3319&ssl=1","width":3012,"height":3319,"caption":"Liminal"},"image":{"@id":"https:\/\/liminal.pt\/martech-magazine\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Liminal-270123610141550\/","https:\/\/www.instagram.com\/liminalmarketing\/","https:\/\/www.linkedin.com\/company\/liminalmarketing\/","https:\/\/www.youtube.com\/channel\/UCmr6iaNEpIKmX2wfSfcgGWg"]},{"@type":"Person","@id":"https:\/\/liminal.pt\/martech-magazine\/#\/schema\/person\/870bd144c500aab26df7c6bc61b4bed4","name":"Dara Correia","image":{"@type":"ImageObject","inLanguage":"pt-PT","@id":"https:\/\/secure.gravatar.com\/avatar\/6227e3d319896007b27cc8e07bad9f555e484528bfa038607a19bed547660144?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/6227e3d319896007b27cc8e07bad9f555e484528bfa038607a19bed547660144?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/6227e3d319896007b27cc8e07bad9f555e484528bfa038607a19bed547660144?s=96&d=mm&r=g","caption":"Dara Correia"},"url":"https:\/\/liminal.pt\/martech-magazine\/author\/dara-correia\/"}]}},"jetpack-related-posts":[{"id":7503,"url":"https:\/\/liminal.pt\/martech-magazine\/en\/what-to-ask-before-choosing-ai-marketing-automation\/","url_meta":{"origin":7250,"position":0},"title":"What to Ask Before Choosing AI Marketing Automation","author":"Alexandre Peric\u00e3o","date":"04\/09\/2026","format":false,"excerpt":"Choosing B2B marketing automation services with artificial intelligence is no longer a purely technological decision. For B2B CEOs and CMOs at SMB and mid market companies, the question is no longer simply which tool sends emails, creates workflows or generates content with AI. The right decision depends on whether the\u2026","rel":"","context":"In &quot;Uncategorized&quot;","block_context":{"text":"Uncategorized","link":"https:\/\/liminal.pt\/martech-magazine\/en\/category\/uncategorized-en\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/09\/Adicionar-um-titulo-1.png?fit=1200%2C590&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/09\/Adicionar-um-titulo-1.png?fit=1200%2C590&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/09\/Adicionar-um-titulo-1.png?fit=1200%2C590&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/09\/Adicionar-um-titulo-1.png?fit=1200%2C590&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/09\/Adicionar-um-titulo-1.png?fit=1200%2C590&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":7443,"url":"https:\/\/liminal.pt\/martech-magazine\/en\/10-things-to-know-about-ai-marketing-automation\/","url_meta":{"origin":7250,"position":1},"title":"10 Things to Know About AI Marketing Automation","author":"Alexandre Peric\u00e3o","date":"31\/07\/2026","format":false,"excerpt":"AI marketing automation should no longer be seen as a faster way to send campaigns or generate content. For SMB CEOs and CMOs, it has become a strategic issue: how to use artificial intelligence, data, automation and marketing tools to improve commercial results, increase efficiency and create more relevant experiences\u2026","rel":"","context":"In &quot;Digital Transformation&quot;","block_context":{"text":"Digital Transformation","link":"https:\/\/liminal.pt\/martech-magazine\/en\/category\/digital-transformation\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/07\/10-coisas-a-saber-sobre-AI-marketing-automation.png?fit=1200%2C590&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/07\/10-coisas-a-saber-sobre-AI-marketing-automation.png?fit=1200%2C590&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/07\/10-coisas-a-saber-sobre-AI-marketing-automation.png?fit=1200%2C590&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/07\/10-coisas-a-saber-sobre-AI-marketing-automation.png?fit=1200%2C590&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/07\/10-coisas-a-saber-sobre-AI-marketing-automation.png?fit=1200%2C590&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":7303,"url":"https:\/\/liminal.pt\/martech-magazine\/en\/marketing-and-sales-automation-with-ai-and-crm-how-to-grow-your-pipeline-in-2026\/","url_meta":{"origin":7250,"position":2},"title":"Marketing and Sales Automation with AI and CRM: How to Grow Your Pipeline in 2026","author":"Mafalda Martins","date":"15\/06\/2026","format":false,"excerpt":"Generating pipeline no longer depends only on capturing more leads. In 2026, commercial growth increasingly depends on the ability to connect marketing, sales, CRM, automation, and data into a single system that can identify intent, prioritise opportunities, and accelerate sales follow-up. Many companies have already invested in CRM, digital campaigns,\u2026","rel":"","context":"In &quot;CRM&quot;","block_context":{"text":"CRM","link":"https:\/\/liminal.pt\/martech-magazine\/en\/category\/customer-relationship-management\/"},"img":{"alt_text":"CRM, Automa\u00e7\u00e3o de Marketing, IA, intelig\u00eancia artificial, como aumentar pipeline, pipeline de marketing, pipeline de vendas, leads de marketing, liminal","src":"https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/06\/crm-ia-automacao-de-marketing-como-aumentar-pipeline-2026-liminal.jpg?fit=1200%2C800&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/06\/crm-ia-automacao-de-marketing-como-aumentar-pipeline-2026-liminal.jpg?fit=1200%2C800&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/06\/crm-ia-automacao-de-marketing-como-aumentar-pipeline-2026-liminal.jpg?fit=1200%2C800&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/06\/crm-ia-automacao-de-marketing-como-aumentar-pipeline-2026-liminal.jpg?fit=1200%2C800&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/06\/crm-ia-automacao-de-marketing-como-aumentar-pipeline-2026-liminal.jpg?fit=1200%2C800&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":7181,"url":"https:\/\/liminal.pt\/martech-magazine\/en\/how-to-choose-a-hubspot-partner-in-portugal-to-implement-crm-marketing-automation-and-b2b-sales\/","url_meta":{"origin":7250,"position":3},"title":"How to choose a HubSpot partner in Portugal to implement CRM, marketing automation and B2B sales","author":"Alexandre Peric\u00e3o","date":"08\/05\/2026","format":false,"excerpt":"Choosing a HubSpot partner in Portugal should not be treated as a simple technology supplier decision. For a B2B SME or mid market company, a HubSpot implementation can redefine how marketing, sales, customer service and management teams analyse commercial growth. When the project is well executed, the company gains visibility\u2026","rel":"","context":"In &quot;CRM&quot;","block_context":{"text":"CRM","link":"https:\/\/liminal.pt\/martech-magazine\/en\/category\/customer-relationship-management\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/05\/Como-escolher-um-parceiro-HubSpot-em-Portugal-para-implementar-CRM.jpg?fit=1200%2C590&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/05\/Como-escolher-um-parceiro-HubSpot-em-Portugal-para-implementar-CRM.jpg?fit=1200%2C590&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/05\/Como-escolher-um-parceiro-HubSpot-em-Portugal-para-implementar-CRM.jpg?fit=1200%2C590&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/05\/Como-escolher-um-parceiro-HubSpot-em-Portugal-para-implementar-CRM.jpg?fit=1200%2C590&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/05\/Como-escolher-um-parceiro-HubSpot-em-Portugal-para-implementar-CRM.jpg?fit=1200%2C590&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":7475,"url":"https:\/\/liminal.pt\/martech-magazine\/en\/how-to-use-ai-sales-automation-in-2026\/","url_meta":{"origin":7250,"position":4},"title":"How to Use AI Sales Automation in 2026","author":"Dara Correia","date":"17\/08\/2026","format":false,"excerpt":"AI sales automation is no longer just a way to write emails faster or summarise sales meetings. In 2026, artificial intelligence applied to sales should be seen as an operational layer that helps B2B companies qualify leads better, prioritise opportunities, accelerate follow up, support commercial decisions and improve sales team\u2026","rel":"","context":"In &quot;Sales&quot;","block_context":{"text":"Sales","link":"https:\/\/liminal.pt\/martech-magazine\/en\/category\/sales\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/08\/2150038414.jpg?fit=1200%2C900&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/08\/2150038414.jpg?fit=1200%2C900&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/08\/2150038414.jpg?fit=1200%2C900&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/08\/2150038414.jpg?fit=1200%2C900&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/08\/2150038414.jpg?fit=1200%2C900&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":7468,"url":"https:\/\/liminal.pt\/martech-magazine\/en\/7-parts-of-crm-and-marketing-automation-integration\/","url_meta":{"origin":7250,"position":5},"title":"7 Parts of CRM and Marketing Automation Integration","author":"Dara Correia","date":"10\/08\/2026","format":false,"excerpt":"Integrating CRM and marketing automation is one of the most important decisions for companies that want to connect lead generation, sales follow up and revenue into the same operating model. For CEOs and CMOs of SMEs and mid market companies, the goal should not be just to connect tools. The\u2026","rel":"","context":"In &quot;CRM&quot;","block_context":{"text":"CRM","link":"https:\/\/liminal.pt\/martech-magazine\/en\/category\/customer-relationship-management\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/08\/121224.jpg?fit=1200%2C647&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/08\/121224.jpg?fit=1200%2C647&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/08\/121224.jpg?fit=1200%2C647&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/08\/121224.jpg?fit=1200%2C647&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/08\/121224.jpg?fit=1200%2C647&ssl=1&resize=1050%2C600 3x"},"classes":[]}],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"https:\/\/i0.wp.com\/liminal.pt\/martech-magazine\/wp-content\/uploads\/2026\/05\/491.jpg?fit=2000%2C1597&ssl=1","_links":{"self":[{"href":"https:\/\/liminal.pt\/martech-magazine\/wp-json\/wp\/v2\/posts\/7250","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/liminal.pt\/martech-magazine\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/liminal.pt\/martech-magazine\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/liminal.pt\/martech-magazine\/wp-json\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/liminal.pt\/martech-magazine\/wp-json\/wp\/v2\/comments?post=7250"}],"version-history":[{"count":1,"href":"https:\/\/liminal.pt\/martech-magazine\/wp-json\/wp\/v2\/posts\/7250\/revisions"}],"predecessor-version":[{"id":7251,"href":"https:\/\/liminal.pt\/martech-magazine\/wp-json\/wp\/v2\/posts\/7250\/revisions\/7251"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/liminal.pt\/martech-magazine\/wp-json\/wp\/v2\/media\/7240"}],"wp:attachment":[{"href":"https:\/\/liminal.pt\/martech-magazine\/wp-json\/wp\/v2\/media?parent=7250"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/liminal.pt\/martech-magazine\/wp-json\/wp\/v2\/categories?post=7250"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/liminal.pt\/martech-magazine\/wp-json\/wp\/v2\/tags?post=7250"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}