Obtainer
Use case

HubSpot GDPR Compliance: HubSpot GDPR Settings, Permanent Delete, and Data Subject Requests

HubSpot ships real privacy tooling: a data request manager, a contact data export, and a permanent delete that bypasses the recycle bin. Each one is bounded in a way that only shows up on your first real request, and the boundary is almost always the same: it works on a contact, inside HubSpot.

See how it works
Discovery across your systems Human redaction gate Helps you comply, not legal advice
Request Studio
Requester
Compiled the manifest and drafted the response - illustrative sample request
0
records found
0
systems scanned
Data manifest
Response draft

Assembling the cover letter from the template...

You approve what is disclosed before anything ships

Helps you comply, not legal advice

In short

HubSpot GDPR compliance is your responsibility, not HubSpot's. HubSpot is the processor and your company is the controller, so the duty to answer an access or deletion request from a person in your CRM sits with your team. What HubSpot gives you is a set of tools to do part of that job: data privacy settings that record a lawful basis and consent to communicate, a data request manager where privacy requests can be logged and assigned, an export that compiles a contact's data, and a permanent delete that is genuinely permanent. Turning those settings on does not make an account compliant. It makes the account capable of recording the decisions you make.

The two limits worth knowing before a request arrives are both about scope. A permanent delete in HubSpot can only be performed on an individual contact record, and it cannot be run in bulk through a list, a segment or a workflow. If a person appears as a contact, in a ticket thread, in a call recording and in a custom object, the permanent delete handles the contact and you handle the rest by hand. Separately, the contact data export notes that values may be redacted where the information is sensitive in nature or where the data is stored somewhere other than the contact record, which is precisely the data an access request is most likely to be about.

HubSpot's deletion behavior also has two clocks that people confuse. An ordinary delete sends the record to the recycle bin, where HubSpot-defined records including contacts, companies, emails, products, appointments and custom objects can be restored for up to 90 days. A permanent or GDPR-related deletion is not held in the recycle bin at all: it is permanently deleted immediately from your view, and HubSpot states it may take up to 30 days to be purged from HubSpot in compliance with data privacy laws. So the answer to "is it deleted yet" depends entirely on which delete somebody clicked, and only one of them satisfies an erasure request.

Obtainer covers the part that spans systems. It intakes the request, verifies the requester, searches your connected systems for one named person, reports the source system behind every record it surfaces, compiles a single reviewable manifest, and tracks the GDPR one-month and CCPA 45-day clocks. Nothing is disclosed or deleted automatically. A human reviews, redacts and approves before anything leaves. Obtainer helps you comply. It is not legal advice, so scope calls, exemptions and any decision to refuse stay with your team. Self-serve from a planned $49/mo.

Last updated August 2026

// THE FIT

Why it fits

Marketing, revenue ops, legal and privacy teams at US companies running customer data in HubSpot.

A permanent delete is one contact at a time

HubSpot documents permanent deletion as an action on an individual contact record, and states that you cannot perform permanent deletions in bulk using segments of contacts or workflows. That is a deliberate safety design and it is fine for the volume most teams see. It becomes a problem the moment a deletion request covers a household, a former employee with several records, or a data broker style request naming dozens of people at once. There is a GDPR delete endpoint on the contacts API for teams that need to script it, but the object scope does not change.

The export can redact the data you were asked for

Exporting a contact's data from the record includes all current and historical default property data by default, and you can additionally include custom properties with their historical values, associated activities such as emails and notes, and association data. HubSpot also notes that values may be redacted if they contain information that is sensitive in nature or if the data is stored somewhere other than the contact's record. Read that second clause carefully before you treat the export as the whole response, because a lot of what a person asks to see lives on tickets, conversations and custom objects rather than on the contact.

Deleted and permanently deleted are different states

An ordinary delete is restorable for up to 90 days from the recycle bin, and the restore tool handles up to 10,000 records at a time. A permanent or GDPR-related delete never enters the recycle bin, cannot be restored, and may take up to 30 days to be purged from HubSpot's systems. If you are answering a right to erasure request and somebody used the ordinary delete, the record is still there and still restorable, which means the request is not satisfied. Write down which action was taken and when, because that note is the evidence the erasure actually happened.

Permanent delete blocklists the email address

Once a contact is permanently deleted, HubSpot will not let you add that email address, primary or additional, back into the account through the interface or an import. The person can still return by submitting a form, emailing a connected team inbox, or through an API request, and when they do a new contact record is created with none of the previous history or associations. That is usually the right behavior for a deletion request, and it is worth telling the marketing team before the fact, because it means a permanent delete is not a reversible cleanup step.

Analytics keeps the shadow after the record is gone

HubSpot is explicit that some data survives a permanent delete in anonymized form. The contact's sessions continue to be reflected in your traffic sources report, and email and form metrics remain without identifying the contact. Blog comments are called out separately and have to be deleted manually. None of that is a compliance failure by itself, since aggregate and anonymized data is treated differently under both the GDPR and the CCPA, but it does mean the honest answer to "is every trace gone" is no, and you should be able to explain which traces remain and why.

The request manager tracks the clock, not the search

The data request manager in your privacy and consent settings gives each request an owner and a completion date, and multi-brand accounts can publish a separate data privacy request page per brand, which requires the Brands add-on or Marketing Hub Enterprise. That covers intake and accountability. What it does not do is find the person in the seven other systems your company runs, which is where the one-month GDPR clock and the 45-day state clocks are actually lost.

// THE TABLE

Reference

Where a person's data actually sits in a HubSpot account

Each row is a place personal data accumulates in an ordinary HubSpot deployment. The right-hand column is what an access or deletion request requires there, which is consistently more than deleting the contact.

Where it sits in HubSpotWhat it holds about a personWhat a request requires
Contact record and propertiesName, email, phone, lifecycle stage, lawful basis, consent to communicate, and every custom property added over the years, with historical values for eachThe obvious record. Export includes current and historical default property values by default; custom properties and their history are an option you have to select
Activities: emails, calls, meetings, notes, tasksThe body of logged emails, call recordings and transcripts, meeting notes, and internal notes staff typed about the personIn scope for access, and this is usually where the narrative detail is. Exporting activities is an optional checkbox rather than the default
Tickets and conversations inboxSupport threads in the person's own words, chat transcripts, and internal comments written on the assumption nobody outside would read themIn scope. Third-party names and internal commentary here need redaction before disclosure, and tickets are not covered by the contact permanent delete
Deals, quotes, line items and paymentsCommercial history tied to a named buyer, plus billing details and anything a rep typed into a deal noteIn scope for access. Frequently retained on a legal or tax basis rather than deleted, which is a decision you should be able to state
Custom objectsWhatever this account was extended to track: applications, subscriptions, enrollments, claims, propertiesIn scope, and the most commonly missed category, because nothing about a contact-level search knows these objects exist
Forms, list memberships and workflow historyWhat the person submitted, which segments they landed in, and which automations enrolled them and whenIn scope for access. Form submissions are also the route by which a permanently deleted person can re-enter the account as a new record
Files and attachmentsContracts, identity documents, screenshots and forms holding personal data inside the file rather than in a propertyIn scope. File contents are not reachable by a property search, so these are found by association with a record instead
Recycle binRecords deleted with the ordinary delete, restorable for up to 90 daysNot yet erased. A deletion request is not complete while a restorable copy remains, so use the permanent delete or clear the record deliberately
// FAQ

Questions

Common questions about this

Is HubSpot GDPR compliant?

HubSpot provides GDPR-capable infrastructure, signs a data processing agreement as your processor, and ships privacy tooling including consent tracking, a data request manager and a permanent delete. That does not make your account compliant. Compliance depends on what you collect into it, the lawful basis you record, how long you keep it, and whether you can answer an access or deletion request on time, which is the operational half of GDPR compliance and your decision as the controller.

What do HubSpot GDPR settings actually turn on?

Turning on data privacy settings lets you record communication consent and a lawful basis for processing on contacts through import, bulk edit or manual creation. Newly created forms get a data privacy section in the footer, the cookie consent banner is turned on, unsubscribe links are added to one-to-one sales and sequence emails, and you can restrict marketing sends to contacts with a lawful basis. Email open and click tracking is not applied to contacts without a lawful basis. Existing forms and scheduling pages need updating by hand.

How do I perform a GDPR delete in HubSpot?

Open the contact record, click Actions, choose Delete, select the permanent delete option, optionally pick a user to receive the confirmation email, and confirm. It requires the permanently delete contacts permission. The deletion cannot be undone, it cannot be run in bulk through a list or workflow, and it blocklists the email address so it cannot be re-added through the interface or an import. HubSpot also exposes a GDPR delete endpoint on the contacts API for teams that need to script it.

How long does HubSpot keep deleted data?

It depends which delete was used. An ordinary delete sends the record to the recycle bin, where contacts, companies, emails, products, appointments and custom objects can be restored for up to 90 days. A permanent or GDPR-related deletion is not held in the recycle bin, is removed from your view immediately, and HubSpot states it may take up to 30 days to be purged from HubSpot in compliance with data privacy laws.

Does deleting a contact in HubSpot delete everything about that person?

No. The permanent delete acts on the contact record and its associated content, and HubSpot is explicit that anonymized analytics survive: the person's sessions still appear in your traffic sources report, and email and form metrics remain without identifying them. Blog comments have to be deleted manually. Anything about the person sitting in a system outside HubSpot, a warehouse, a support desk, a billing platform or an exported spreadsheet, is untouched, which is the ordinary cause of an incomplete deletion request.

How do I respond to a data subject access request in HubSpot?

Verify the requester first, then log the request in the data request manager with an owner and a completion date, then export the contact's data with the optional custom properties, activities and association data selected rather than the default export alone. Then search tickets, conversations, custom objects and files, because the export notes that values may be redacted where data is stored somewhere other than the contact record. Redact third-party and exempt material, then send inside the deadline. The GDPR gives you one month and the CCPA gives 45 days, and HubSpot is usually one of several systems in scope, which is why the DSAR process runs against the company rather than per tool.

Can I bulk delete contacts in HubSpot for a privacy request?

Not with the permanent delete. HubSpot states that permanent deletions cannot be performed in bulk using segments of contacts or workflows, so each one is an individual action on an individual record. You can bulk delete with the ordinary delete, but that puts the records in the recycle bin where they stay restorable for up to 90 days, which does not satisfy an erasure request. For volume, the GDPR delete endpoint on the contacts API is the practical route, one call per contact.

Who is the controller for data in my HubSpot account?

You are. HubSpot processes the data on your instructions as your processor, and the obligations that attach to the personal data in your portal, lawful basis, retention, security and answering rights requests, attach to your company. That is why HubSpot builds tools rather than answers requests for you, and why an account can be perfectly configured while the response you send is still incomplete because the person also exists in four systems HubSpot cannot see.

Run a data subject access request end to end

Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.