Skip to main content
All articles

CRM migration: who holds your data while it moves?

I read the termination clause in ten CRM contracts, asking one question: when you leave, how long do you have to get your data out? Five of the ten promise you nothing.

Toni MedicToni MedicSalestructSeptember 7, 202612 min readCRM & Pipeline
The short version
Isometric illustration of two vaults connected by a bridge of light, with data blocks travelling across it. The left vault is cracked and closing, the right one is opening.
One instance closing, one opening, and everything you own crossing a bridge you did not build.

Most migration plans start at the export and finish at user training. The contract that governs the whole thing sits unread in a drawer, and it's the only document that says what happens if you need to go back.

None of the ten refuses to hold your data. That isn't the problem. The problem is that holding it and being obliged to hand it back are two different promises, and only half of these contracts make the second one.

A CRM migration is the transfer of an organisation's customer records, pipeline history and supporting configuration from one CRM into another, including the field mapping, the relationships between records, and the automations that act on them. It differs from a CRM implementation in that the system already holds live data and a working sales motion depends on it.

This is the sister problem to what happens to records once they are sitting in the system. A migration is the one moment you get to decide what not to carry across, and almost nobody uses it.

The short version

  1. Owning your data and being able to retrieve it are separate rights. Ten CRM contracts answer the retrieval question ten different ways, from ninety days down to nothing, and five of them state no window at all.
  2. Settle custody, export rights and the abort trigger before anything moves. None of them is negotiable once the migration is running.
  3. If you are in the EU, the Data Act has given you a statutory switching right since 12 September 2025, with a two month notice cap and a 30 day transition.
  4. Matching record counts on both sides is not a passed migration. Verify relationships, routing and the three reports leadership actually opens.

What "you own your data" actually means in a CRM contract

Owning your data and being able to retrieve it are two different rights, and CRM contracts grant them separately. Pipedrive's terms say you retain all rights, title and interest in your data. The same document disclaims liability for "deletion of, corruption of, or failure to store any Client Data" and sets a deletion deadline rather than a retrieval guarantee. Both clauses survive termination. Ownership is not custody.

Here is that question asked of ten contracts, ranked, with each mark linking to the document the clause came from.

Days you are guaranteed to get your data back

After termination, per each vendor's own terms
  • Microsoft Dynamics 365 logo90days

    The only one that says the retention exists so you can extract, then 90 more days before erasure.

  • Salesforce logo30days

    On request. After that, no obligation to maintain or provide any customer data.

  • Zendesk Sell logo30days

    Then a staged deletion: records at 40 days, backups at 90, logs at a year.

  • Odoo logo21days

    A return right with no period attached, and the cloud database destroyed at three weeks. Inferred, not a published window.

  • Freshworks logo14days

    Conditional on the account being paid up, then up to three further months.

  • HubSpot logo0days

    For the Smart CRM, no access to your data after termination. Two Marketing Hub tiers get 30 days and a possible reactivation fee.

  • Pipedrive logo0days

    No retrieval right stated. Account deactivated, everything deleted within 180 days.

  • monday.com logo0days

    A read-only mode is offered, with no obligation to maintain it and the right to end it at any time without notice.

  • Zoho logo0days

    Terms silent on retrieval. Termination is defined to include deletion. Last updated March 2022.

  • GoHighLevel logo0days

    90 days for reactivation, and no deletion deadline stated anywhere. The only one of the ten with no outer bound.

Every mark links to the document the clause was read from. Marks are each vendor's own trademark, shown to identify the product under discussion. No affiliation or endorsement is implied.

Read from each vendor's own current terms on 7 and 8 September 2026. A zero is a missing entitlement, not an instant deletion: most of these vendors still hold your data for months, they simply do not promise to hand it back.

Five of the ten promise you nothing. One of them, monday.com, gets the whole problem into a single clause: it offers a read-only mode, removes any obligation to maintain it, reserves the right to end it at any time with or without notice, and disclaims liability, all in one sentence. Its own data processing agreement carries the delete-or-return duty with no timeline attached, and it is seventeen months older than the terms that hollow out the return half.

HubSpot, Product Specific Terms, Last Modified 14 April 2026

We strongly recommend retrieving your Customer Data prior to the end of your Subscription Term; for the HubSpot Smart CRM and Free Services, we will not provide you with any access to Customer Data after termination or expiration of your Subscription Term.

Quoted verbatim. See the captured original, captured 7 September 2026

HubSpot's own Product Specific Terms, section 1.3. The recommendation to retrieve your data before the subscription ends is followed by the reason: for the Smart CRM there is no access afterwards. This is the CRM itself, not an add-on.

That clause is not unique to the CRM either. The same page carries a second, near-identical sentence applying the same no-access rule to the other Hub subscription services. The 30 day window is the exception, and it covers two Marketing Hub tiers.

None of this is a scandal and none of it is hidden. It is published, current, and written plainly. It is simply that nobody reads it until the week they need it, which is the week it stops being negotiable.

The practical consequence is a sequencing one. If your retrieval window opens at termination, then cancelling the old contract before the new system is verified turns a recoverable problem into a permanent one. That is the single most expensive mistake available here, and it costs nothing to avoid.

Who is the controller and who is the processor during a CRM migration

You are the controller. The CRM vendor is a processor. A migration partner who touches the data is also a processor, and the regulation is specific about what that means: a processor acts only on documented instructions from the controller, cannot bring in a subcontractor without your written authorisation, and has to let you audit them.

One controller, three processors, and the branch nobody plans for. A partner who decides on its own which duplicates to merge, which fields to drop, or how long to keep its working copy has started determining purposes and means, and the regulation stops treating it as a processor at that point.

Then there is the sentence that actually answers the custody question, and it is worth reading slowly, because a migration is full of decisions that look technical and are not.

If a processor infringes this Regulation by determining the purposes and means of processing, the processor shall be considered to be a controller in respect of that processing.

Source note. Quoted verbatim from Regulation (EU) 2016/679, Article 28(10), read from the Official Journal on 7 September 2026. EUR-Lex, Article 28

Which of two conflicting records survives a merge. Which fields get dropped as legacy. How long the working copy lives on the partner's infrastructure after go-live. Those are purposes and means. If your partner is making them alone, the paperwork saying they are a processor has stopped describing what is happening.

The fix is not complicated and it is not legal theatre. Write the decisions down before the work starts, as instructions, and keep the record. The regulation also requires that at the end of the job the processor deletes or returns everything, at your choice, and deletes remaining copies. The European Data Protection Board's guidance goes further: you decide at the beginning, you put it in the contract, the contract says how you can change your mind, and the processor confirms back to you that deletion actually happened.

One honest note on backups, because this is where the tidy version falls apart. The UK regulator has published the sensible position: it may not be possible to delete data in backups immediately, and provided the data is put beyond use and deleted on the next destruction cycle, that can be acceptable. HubSpot's own agreement describes exactly that arrangement from the processor's side, and attaches no timeline to it beyond "in accordance with our deletion practices". Ask what the cycle is. It is a fair question with a real answer.

What the EU Data Act changed on 12 September 2025

If you are an EU or EEA customer, you now have a statutory switching right that does not depend on what your vendor felt like offering. Regulation (EU) 2023/2854 has applied since 12 September 2025, and it puts hard numbers on the exit.

The blocks are schematic rather than to scale. Read them as sequence and ceiling: every figure is a limit the provider cannot exceed, except the retrieval window, which is a floor it cannot go under.

Notice to start switching is capped at two months. The transition period is a maximum of 30 calendar days, and during it the provider has to maintain business continuity and tell you about known risks to it. After the transition ends you get a minimum of 30 calendar days to retrieve your data. After that the provider must guarantee full erasure. If the 30 day transition is technically unfeasible, they have 14 working days to tell you so, justify it, and offer an alternative that cannot exceed seven months. And from 12 January 2027 they cannot charge you for switching at all.

Three of the ten name it in a document you can read without logging in. Microsoft Dynamics 365 carries a dedicated EU Data Act section in its data protection addendum, with Switching defined as a contract term. Salesforce sets out the two month notification, the 30 day transition and the 14 working day unfeasibility notice in its Main Services Agreement. Pipedrive's terms state that an EU Data Act Addendum applies automatically to clients in scope, from the application date.

EUR-Lex, Regulation (EU) 2023/2854, Article 25(2)(a)

(a) clauses allowing the customer, upon request, to switch to a data processing service offered by a different provider of data processing services or to port all exportable data and digital assets to an on-premises ICT infrastructure, without undue delay and in any event not after the mandatory maximum transitional period of 30 calendar days, to be initiated after the maximum notice period referred to in point (d), during which the service contract remains applicable and during which the provider of data processing services shall:

Show the rest of the clause

(i) provide reasonable assistance to the customer and third parties authorised by the customer in the switching process;

(ii) act with due care to maintain business continuity, and continue the provision of the functions or services under the contract;

(iii) provide clear information concerning known risks to continuity in the provision of the functions or services on the part of the source provider of data processing services;

(iv) ensure that a high level of security is maintained throughout the switching process, in particular the security of the data during their transfer and the continued security of the data during the retrieval period specified in point (g), in accordance with applicable Union or national law;

Quoted verbatim. See the captured original, captured 7 September 2026

Article 25(2)(a) in the Official Journal. The 30 calendar day transition is a ceiling, not a target, and during it the provider has to assist the switch, maintain business continuity, disclose known risks to it, and keep the data secure in transfer.

A narrow, checkable observation about the third: HubSpot's Customer Terms of Service, Product Specific Terms and Data Processing Agreement, all fetched on 7 September 2026 and all last modified 14 April 2026, contain no occurrence of "Data Act", "2023/2854" or "switching". That is a statement about four documents on one date. It is not a compliance conclusion, and whether any given service falls inside the regulation's definition is a question for your own counsel and your own contract.

What it does mean practically: if you are in the EU, ask. The right exists whether or not the vendor's marketing mentions it.

Three questions to settle before any data moves

Illustration of a ring of keys where each key head is a simplified software window, with one key being lifted away from the ring.
Every instance you run has a keyholder. On a migration the question is only ever which one of you it is, and whether it is written down.

The rollback plan below settles the trigger and the revert window, and the controller question is settled above. These three are what is left. Each has a factual answer, each takes under an hour, and none of them stays answerable once the migration is running.

Can you produce a complete export today, on an account you hold? Not "can we request one from the vendor" and not "the agency handles that". Go and run it, on the login your own team controls, and read what actually comes out. This is the question people skip, because they assume they know the answer.

How many days after termination does your contract give you, and is the account live during them? Count them off the clause itself, not off the marketing page. Under 30 days is a problem: a migration at this size does not finish inside a fortnight, and if the account closes at termination the window is decorative. Five of the ten contracts above name no period at all, so your honest answer may be zero.

Who deletes the partner's copy when the project closes, and who confirms it back to you in writing? If the answer is "they would tell us", there is no answer. A deletion nobody confirms is a copy that still exists somewhere you cannot account for, and it stays your problem, not theirs.

None of the three needs the vendor or a partner to answer, and that is the point: a system you cannot export on a login you hold is not one you control, whatever the contract says about ownership.

The rollback plan the guides promise and never write

Every migration guide names rollback. Almost none defines it. Across the pages currently ranking for this topic there is exactly one number, a 48 hour revert window that applies to spreadsheet imports inside one product, and not a single defined trigger. The word appears, the plan does not.

The regulation is more useful here than the guides are. Security measures have to include the ability to restore availability and access to personal data in a timely manner after an incident, and there has to be a process for regularly testing whether those measures actually work. A restore you have never tested is not a restore capability, it is an assumption.

Three things turn that into something you can operate.

  1. Write the trigger before you start

    A trigger is a measurable condition, not a feeling. "More than 2% of deals arrive without an owner", "any closed-won record loses its close date", "the first delta sync produces more than 50 conflicts". Name the number and name the person who is allowed to call it. A trigger nobody is authorised to pull is decoration.

  2. Define the window, and check the old system is alive inside it

    Decide how many days you can revert within, then verify the old instance stays readable for that entire period. This is where the termination clause and the rollback plan meet: if your window is 14 days and your retrieval right expires at termination, do not cancel until day 15. Keep the old subscription running in parallel and treat it as the cost of the insurance.

  3. Restore the backup once, before you need it

    Take the backup, then restore it somewhere and open it. Count the records. Check that a deal still points at its company and its owner. Almost everyone takes the backup. Very few prove it comes back, and an unopened backup is where migrations go to fail quietly.

A clean record count is not a successful CRM migration

In 2018 TSB moved its customer and corporate services onto a new platform. The regulator's own account of what happened is worth quoting exactly, because it describes the failure mode nobody plans for: "While the data itself migrated successfully, the platform immediately experienced technical failures."

All of TSB's branches and a significant proportion of its customers were affected, and it took until December to return to business as usual.

5.2m
customers at the bank, a significant proportion of them affected by the initial failures.
Source: FCA, 2022
£32.7m
paid in redress to customers who suffered detriment.
Source: FCA, 2022
£48.65m
combined FCA and PRA fine, after a 30% settlement discount.
Source: FCA, 2022

The regulators did not find a technology failure. They found a planning one.

The firm failed to plan for the IT migration properly, the governance of the project was insufficiently robust and the firm failed to take reasonable care to organise and control its affairs responsibly and effectively.

Source note. Quoted verbatim from the FCA press notice, Mark Steward, then Executive Director of Enforcement and Market Oversight, 2022.

That is a retail bank core banking platform, not a CRM, and the scale is nothing like a typical CRM migration. Use it for the mechanism, not as a proxy for your risk. The mechanism transfers exactly: every record arrived, and the thing still did not work.

So verification cannot stop at counting rows. Count them, then check that the relationships survived, that a deal still resolves to its company and its owner, that automations fire on a test record, and that the three reports leadership actually opens still return the same numbers they did last week. Row counts match long before a system works.

Routing is the one to test hardest, because it fails silently. Nobody files a complaint about a lead that was assigned to a person who left, so the queue looks healthy right up until someone counts it.

About the failure rates you are going to be quoted

You will meet one number constantly on this topic: 83% of data migration projects fail or exceed their budgets, according to Gartner. We followed it to the end.

Follow the citation: each arrow reads "cites", top to bottom.

Agency and vendor blogs
"83% of data migration projects fail or exceed budgets, according to Gartner"
Oracle and LumenData brief
"Did you know?" box, page 2. PDF metadata gives a creation date of 16 October 2014
The attribution
Credits "Gartner", and a neighbouring figure to "Bloor Group"
No study
No report title, no year, no note ID, no link, no method. The seven page document carries no footnotes at all.
The trail for the most repeated statistic on this topic, followed on 7 September 2026. It ends in a marketing PDF.

Two further breaks. "Bloor Group" and "Bloor Research" are different firms. And Bloor Research's own 2007 white paper, which we opened, says "more than 60%", not more than 80%. Somebody added twenty points somewhere along the way.

There is also no citable figure for how much data a CRM migration typically loses. We looked. What exists is first-name anecdotes on vendor blogs. That absence is the argument for measuring your own: count the records in both systems before and after, and the number you get is true about your business, which no industry average ever is.

Both belong at the front of the order you run the project in, because everything after them depends on the answers. An hour spent on the export and the termination clause is the cheapest insurance in this whole project, and you can spend it this afternoon without asking anyone.

Sources

  1. EUR-Lex, Regulation (EU) 2016/679 (GDPR). Controller and processor definitions at Article 4(7) and 4(8); processor obligations and the controller-by-conduct rule at Article 28(3)(a), 28(2), 28(3)(g), 28(3)(h) and 28(10); security and restore capability at Article 32(1)(c) and (d). Read from the Official Journal, 7 September 2026 (2016)

  2. EUR-Lex, Regulation (EU) 2023/2854 (Data Act), Chapter VI on switching. Applies from 12 September 2025 per Article 50. Contractual minimums at Article 25(2), switching charges at Article 29 (2023)

  3. European Data Protection Board, Guidelines 07/2020 on the concepts of controller and processor in the GDPR, final version adopted 7 July 2021. Deletion or return at the end of processing, paragraphs 139 to 142 (2021)

All 9 sources and how they were checked
  1. Information Commissioner’s Office, Contracts and liabilities between controllers and processors: what needs to be included in the contract. UK GDPR guidance, cited here for the backup deletion position (2026)

  2. Salesforce, Main Services Agreement, 1 June 2026. Post-termination export at 30 days; EU Data Act Terms section (2026)

  3. HubSpot, Product Specific Terms and Data Processing Agreement, both Last Modified 14 April 2026. No post-termination access for Smart CRM at 1.3; Marketing Hub window and reactivation fee at 3.3.3; backup deletion at DPA 3.6 (2026)

  4. Pipedrive, Terms of Service, current as of 7 July 2026. Effect of termination at 13.3; liability disclaimer at 12.1; data rights at 7.1; EU Data Act Addendum at 15.10 (2026)

  5. Financial Conduct Authority, TSB fined £48.65m for operational resilience failings. Quoted for the migration mechanism and the regulator’s finding (2022)

  6. Bloor Research, Data Migration white paper, Philip Howard, September 2007. Cited only to show that its own figure is "more than 60%", against the "more than 80%" that circulates under its name. Sponsored paper, no sample size or method published (2007)

Every vendor term above is quoted from that vendor's own published contract, on the date shown, and every legal provision is quoted from the Official Journal rather than from a summary of it. No failure rate, data loss percentage or migration duration is asserted anywhere in this article, because no figure in those categories traces to a source with a stated method. The HubSpot observation is a statement about three documents fetched on one date, not a conclusion about HubSpot's compliance. This is not legal advice, and whether the Data Act applies to a particular contract is a question for your own counsel.

Common questions

You do. In a standard CRM contract the customer retains all rights, title and interest in their data, and the vendor acts as a processor. Ownership and retrieval are separate rights, though: the same contracts that confirm you own the data set strict limits on how long the vendor will keep it available to you after termination, and those limits differ by vendor.
Test it rather than assume it. Produce a complete export today using an admin login your company holds, then check what is missing. Attachments, activity history and the links between records are the three things that most often need separate handling, and discovering that during the migration is far more expensive than discovering it beforehand.
It depends entirely on the contract, and the answers are not close to each other. Salesforce commits to making data available for export on request within 30 days of termination. HubSpot states that for its Smart CRM it will not provide access to Customer Data after termination at all. Pipedrive sets a deletion deadline of 180 days rather than a retrieval guarantee. Read your own agreement before you cancel anything.
Regulation (EU) 2023/2854 has applied since 12 September 2025 and creates a statutory switching right for customers of data processing services in the EU and EEA. It caps the notice period at two months, sets a maximum 30 calendar day transition period, guarantees at least 30 calendar days afterwards to retrieve data, and bans switching charges entirely from 12 January 2027. Salesforce and Pipedrive have both published terms implementing it.
A processor, as long as they act only on your documented instructions. Under Article 28(10) of the GDPR, a processor that determines the purposes and means of processing is treated as a controller for that processing. A partner deciding alone which duplicate records survive, which fields are dropped, or how long their working copy is retained has moved beyond processing on instruction.
A measurable condition you write down before the migration starts, plus a named person authorised to call it. Useful triggers are specific: a percentage of records arriving without an owner, any closed-won deal losing its close date, or a conflict count above a set threshold on the first delta sync. The GDPR requires the ability to restore data in a timely manner and a process for testing that ability, which makes the restore test an obligation rather than a nice-to-have.
Count records in both systems, then go past the count. Check that relationships survived, so a deal still resolves to its company and its owner. Push a test record through the live process and confirm routing and automations fire. Re-run the reports leadership actually opens and compare them to last week. Matching row counts on both sides is a necessary check and not a sufficient one.
Decide it deliberately rather than by default. Set how long the old system stays readable, which should cover your entire rollback window, then set a deletion date and confirm it happened. Where a partner held a copy, the GDPR requires that they delete or return it at your choice at the end of the work, delete remaining copies, and confirm the deletion back to you.