Blog | BridgeRev

Understanding Sensitive Data in HubSpot

Written by Kaitlynn Sirotkin | September 12, 2024

As businesses grow and expand their customer base, managing and securing customer data becomes increasingly critical. One type of data that requires extra care is sensitive data. If you’re new to the concept or just starting with HubSpot, understanding what sensitive data is, how it’s used, and why it matters is essential for safeguarding your business and ensuring compliance with regulations. In this guide, we’ll break down the basics of sensitive data in HubSpot and help you understand how to use it safely.

What is Sensitive Data?

Sensitive data refers to any personal information that, if exposed, could lead to harm, identity theft, or privacy violations. It’s often subject to legal protections and requires extra security measures to prevent unauthorized access.

Examples of sensitive data include:

  • Personal identifiable information (PII) like ethnicity, gender, and age
  • Government-issued IDs like Social Security numbers or driver’s licenses
  • Financial details like bank account numbers or credit card information
  • Protected Health Information (PHI) under laws like HIPAA
  • Citizenship and immigration status
Businesses must handle this data with care, ensuring it’s stored and processed securely to avoid data breaches and comply with privacy regulations like GDPR (General Data Protection Regulation) or HIPAA (Health Insurance Portability and Accountability Act).

How Does HubSpot Define Sensitive Data?

In HubSpot, sensitive data is any data type that requires special handling due to its confidentiality or legal protection. HubSpot offers tools to securely store and manage this type of data within its Smart CRM platform. The platform allows businesses to store demographic, financial, and health-related information safely while meeting regulatory requirements.

Sensitive Data Categories Supported in HubSpot Include:

  • Demographic Information: Ethnicity, age, gender
  • Financial Data: Salary details, bank account numbers (last four digits)
  • Health Information: PHI under HIPAA regulations
  • Government Data: Citizenship, immigration status, government-issued IDs

HubSpot takes sensitive data management seriously, providing businesses with the right tools to handle this information securely across its marketing, sales, and service platforms.

How Do You Use Sensitive Data in HubSpot?

Sensitive data in HubSpot can be used to personalize customer interactions, automate processes, and ensure compliance with various privacy laws. Here’s how you can use and manage sensitive data within HubSpot:

1. Enable Sensitive Data Settings

Before you can use sensitive data in HubSpot, a Super Admin needs to enable the sensitive data settings in your account’s Privacy & Consent settings. Once enabled, sensitive data will be protected with extra security, including encryption and permission settings.

2. Create Properties to Store Sensitive Data

Once sensitive data is turned on, you can create custom properties to store this information. For example, you might create a custom property to store a customer’s last four digits of their bank account number or health-related information. These properties have added encryption, ensuring that sensitive data remains protected.

3. Manage Access with Field-Level Permissions

HubSpot allows you to restrict access to sensitive data by setting field-level permissions. This feature ensures that only specific users or teams can view or modify sensitive data properties. For example, only your billing team might have access to a customer’s payment information, while your marketing team might have access to demographic data for segmentation.

4. Use Sensitive Data Across HubSpot Tools

Sensitive data can be used in various HubSpot tools, including:

  • CRM records: Store and manage sensitive customer data directly within the contact, company, or deal records.
  • Workflows: Automate actions based on sensitive data, such as sending a specific email to customers with certain demographic profiles.
  • Forms: Collect sensitive data through forms that are encrypted upon submission, ensuring the data is securely synced into your CRM.
  • Reporting: Create reports using sensitive data to track performance metrics while ensuring the data remains secure.

Important: Sensitive data cannot be used in all HubSpot tools. For example, personalization tokens and chatbots do not support sensitive data due to security limitations.

Why is Managing Sensitive Data Important?

Properly managing sensitive data is not only a legal requirement, but it’s also essential for maintaining trust with your customers. Mishandling sensitive data can lead to severe consequences, including data breaches, hefty fines, and a damaged reputation.

Key Reasons to Handle Sensitive Data Properly:

  • Legal Compliance: Regulations like GDPR and HIPAA require businesses to secure sensitive data and allow individuals to control how their data is used.
  • Customer Trust: Consumers expect businesses to protect their personal information. Failure to do so can result in a loss of trust and customers.
  • Business Continuity: Protecting sensitive data reduces the risk of business disruptions caused by data breaches or compliance violations

The Role of Platforms

While platforms like HubSpot, Salesforce, and others provide powerful tools to support RevOps, they are only as effective as the processes they support. These platforms offer features that can enhance your processes, but without a solid foundation, they can lead to inefficiencies and confusion. The platform should be seen as an enabler, not the solution.

Best Practices for Using Sensitive Data in HubSpot

If you're just getting started with using sensitive data in HubSpot, follow these best practices to ensure your data stays safe:

1. Turn on Application-Layer Encryption

HubSpot automatically encrypts all data in transit and at rest, but sensitive data has an additional layer of encryption called application-layer encryption. This means sensitive data is stored in an even more secure environment with restricted access.

2. Use Field-Level Permissions for Sensitive Data

Limit who can access sensitive data by using HubSpot’s field-level permissions feature. Ensure that only the necessary users have access to sensitive properties, minimizing the risk of data exposure.

3. Regularly Audit Super Admin Permissions

Super Admins have the highest level of access in HubSpot, including the ability to create and manage sensitive data properties. Make sure only essential team members have Super Admin access, and regularly review your admin list to avoid unnecessary exposure.

4. Monitor Actions with Audit Logs

HubSpot provides audit logs to track user actions related to sensitive data properties. This allows you to see who accessed or modified sensitive data, helping you maintain accountability and spot potential security issues early.

5. Implement Secure Attachment Practices

When uploading files that contain sensitive information, such as health records or financial documents, ensure they are protected with additional encryption. HubSpot’s attachment feature allows you to store sensitive files securely, preventing unauthorized access.

Getting Started with Sensitive Data in HubSpot

Managing sensitive data in HubSpot is essential for businesses that want to stay compliant, protect their customers, and use this valuable data to fuel growth. By following the best practices outlined in this guide—such as enabling sensitive data settings, setting up field-level permissions, and using secure workflows—you can ensure that sensitive data is managed safely and effectively within HubSpot.

As you continue to explore HubSpot’s powerful features, remember that sensitive data requires careful handling. By leveraging HubSpot’s built-in security tools and compliance features, your business can confidently manage sensitive data while focusing on growth and customer success.

Interested in learning more? Download our eBook here - one click, no email necessary!