HubSpot's Data U-Turn: What It Means for Your CRM

06.07.26 04:30 PM By Bill

HubSpot's Data U-Turn: What It Means for Your CRM

On 1 July 2026, HubSpot told customers it was updating its terms of service to feed enrichment data from customer accounts into a shared commercial dataset, opted in by default. Four days later, following vocal pushback from customers on LinkedIn, HubSpot reversed the change entirely. Co-founder and CTO Dharmesh Shah replied to one of the loudest critics with a one-line admission: "You are right. We made a mistake and have taken steps to correct it."

The episode was brief, but it exposed a question that most businesses running their operations through a SaaS CRM rarely stop to ask: once your customer and prospect data sits inside someone else's platform, who actually controls what happens to it next? For UK and Irish businesses working under UK GDPR, the answer matters more than a single terms-of-service update. It touches data governance, data sovereignty, and how much scrutiny you give a vendor's privacy policy before you sign up.

What Different SaaS Data Models Actually Do With Your Data

Not every CRM vendor treats customer data the same way. The table below sets out three broad approaches, based on how HubSpot's withdrawn Contact Discovery terms were reported and on the publicly available privacy positions of major CRM vendors.

ApproachHow it treats your dataDefault setting
Pooled enrichment (HubSpot's withdrawn model)Business-card-level contact data from your CRM feeds a shared dataset used to enrich other customers' recordsOpt-out, applied automatically
Third-party data broker enrichmentYour records are matched against externally purchased or scraped datasets, not built from your own customer baseVaries by vendor and licence
Zoho's stated privacy positionZoho states it does not sell personal data to third parties and does not use customer data for advertisingNot applicable, no cross-customer data pooling programme

I do not have a verified source confirming that every SaaS vendor in the market avoids cross-customer data pooling entirely, so treat the third row as Zoho's own stated position rather than an independently audited guarantee. It is still worth reading any vendor's current privacy policy yourself before relying on a summary, including this one.

How CRM Data Enrichment Actually Works

Data enrichment is not inherently a problem. Most CRMs use it to fill gaps in a contact record, adding a job title, a company size, or a verified email address so your sales team spends less time on manual research. The question that HubSpot's July announcement raised was not whether enrichment happens, but where the enrichment data comes from and who else benefits from it.

What Counts as Enrichment Data

According to HubSpot's own communications at the time, the fields in scope included names, job titles, company affiliations, work email addresses, and company-level data. Records such as deal notes, call recordings, and custom fields were reportedly excluded. That distinction between "business card" data and deeper CRM content is one worth checking with any vendor, because the line between the two is a policy decision, not a technical necessity.

Where the Shared Dataset Comes In

The reported HubSpot model would have used enrichment data drawn from participating customer accounts to improve records across other customers' accounts too, effectively pooling contact intelligence across the platform. That is a different proposition from enrichment sourced purely from public records or licensed third-party data, because it turns each customer's own CRM into a contributor to everyone else's dataset.

Why GDPR Sits at the Centre of This

Under UK GDPR and the EU GDPR, personal data collected for one purpose, such as running your own sales pipeline, generally needs a proper lawful basis before it is repurposed for another, such as improving a third party's dataset. Vendors often rely on "legitimate interests" as that basis, which requires a genuine balancing test against the individual's rights, not just a line in a terms update. I am not a lawyer and this is not legal advice, so if your business relies on a vendor's enrichment features, it is worth having your data protection officer or legal adviser review the current terms directly rather than relying on any summary, including this article.

The terms of service you accepted on day one rarely stay fixed. The real safeguard is knowing how to check, and how often.

Where This Shows Up in Your Business

Sales
Prospecting lists built on borrowed data

If your outbound lists lean on platform-wide enrichment, a policy change elsewhere in the vendor's business can quietly alter where those contacts came from.

Marketing
Consent records that do not travel with the data

A contact who consented to hear from you specifically may not have consented to appear in someone else's enrichment pool, even indirectly.

RevOps
Settings that change without a clear trail

Enrichment, AI training, and tracking-code sharing settings are often buried several menus deep, and defaults can shift with a terms update.

Compliance
Sub-processor lists that need active monitoring

A vendor's data processing addendum names the sub-processors handling your data today, not necessarily the ones handling it in a year.

Four Steps to Check Your Own CRM Data Governance

1
Find your current enrichment and AI training settings

Locate the specific menu in your CRM admin settings and confirm what is switched on today, rather than assuming the defaults from setup.

2
Read the current Data Processing Addendum

Check which sub-processors are named, where data is hosted, and whether cross-border transfer safeguards such as the UK Addendum or Standard Contractual Clauses are in place.

3
Confirm your lawful basis for each use of contact data

Sales outreach, marketing automation, and any enrichment sharing may each need their own lawful basis, not one blanket assumption.

4
Set a recurring review, not a one-off check

Vendor terms change. A quarterly review of privacy policy updates and settings changes catches shifts before they become a live issue.

What This Means for UK and Irish Businesses

The HubSpot reversal was fast, and the company's public apology was direct, but the underlying tension has not gone away. As CRM vendors build more AI-driven prospecting and enrichment features, the value of pooling data across customers keeps growing, and so does the pressure to find a version of that idea customers will accept. Duncan Lennox, HubSpot's Chief Product and Technology Officer, said the company still believes in the underlying goal of better-targeted outreach, and intends to revisit it with what he described as a fully and transparently opt-in model, though with no confirmed date.

For businesses operating under UK GDPR, this is a reasonable moment to ask a vendor directly, in writing, exactly how enrichment, AI model training, and cross-customer data sharing work in your account today, and where your data is hosted. Zoho publishes its privacy and GDPR positions openly, including its stated commitment not to sell personal data or use it for advertising, and offers EU-region hosting and a GDPR-aligned Data Processing Addendum on request. That does not remove your own responsibility as data controller, but it does give you a clearer starting point for the conversation.

If you are reviewing your CRM setup, your data processing agreements, or simply want a second pair of eyes on your current privacy and enrichment settings, we are happy to have that conversation without the sales pressure.

HubSpotZoho CRMData GovernanceData SovereigntyGDPRZoho Partner UKCRM Data PrivacyBusiness Automation

Not sure what your CRM does with your data?

We can walk through your current Zoho or CRM data settings, sub-processors, and GDPR position with you, no obligation attached.

Book a Zoho Discovery Call