GDPR: email and client document Compliance

This feature is for all companies that receive any private documents from clients that should not be saved in the CRM system and only be handled by specific teams or not saved at all.

Example: if a client provides a copy of their passport or medical records (or any other information classified as personal or sensitive under GDPR) to the email. This is then automatically stored in HubSpot and needs to be manually be deleted.

Currently, to more easily find these documents, companies can use the filter on the contact level “Attached file ID’s is known”. However, this catches all contacts with any type of file attached.

There can be two ways to make compliance in this regard easier.

1. Better filtering in regard to attached documents. Being able to filter more granular on where the file is. E.g. it is a file which is attached to an email and is an incoming email. Or it is a file that has not been saved in HubSpot by a HubSpot user.

2. Prevention. As soon as there is an incoming email with a document, HubSpot requests to log this email instead of logging it automatically.

Great idea!

This is a hugely important consideration — GDPR compliance isn’t just about consent for marketing emails, it extends to how we store, deliver, and track access to documents tied to personal data.

While HubSpot’s built-in features offer solid email subscription controls, there’s still a big gap when it comes to document delivery workflows — especially for onboarding forms, ID scans, contracts, and other sensitive files.

To bridge that compliance gap, we’ve developed a secure document management solution that integrates natively with HubSpot:

Box Connector by SparkGrid Software Available here on the HubSpot Marketplace: HubSpot Marketplace

What it enables:

  • GDPR-compliant file storage using Box’s encrypted, audit-trail-enabled infrastructure
  • Controlled access based on HubSpot contact properties or list membership
  • Full logging of downloads and access events (ideal for demonstrating lawful data handling)
  • “Right to be forgotten” support — remove access automatically if consent is withdrawn

This allows teams to continue using HubSpot CMS and workflows, while maintaining enterprise-grade privacy controls and protecting customer trust.

Hope it helps others navigating this space — especially those in legal, healthcare, or financial sectors where GDPR handling is non-negotiable.