Support & FAQs / Digital Ecosystems

How does HubSpot handle GDPR and Australian Privacy Act compliance?

How does HubSpot handle GDPR and Australian Privacy Act compliance?
Data privacy compliance is an important consideration for any business using a CRM and marketing automation platform. HubSpot provides tools to support compliance with both GDPR (relevant for businesses with European contacts) and Australian privacy obligations under the Privacy Act 1988, though the responsibility for compliance remains with your business.HubSpot's built-in compliance tools include:Cookie consent banner: HubSpot provides a customisable cookie consent banner that can be configured to align with GDPR consent requirements. Importantly, HubSpot's tracking cookie (the analytics and CRM tracking cookie) will only activate once consent is given.Communication subscriptions and opt-out management: HubSpot manages email subscriptions at the contact level. Contacts can opt out of specific subscription types (e.g. marketing emails but not transactional emails) and HubSpot respects these preferences across email sends. Unsubscribes are logged and honoured automatically.Data deletion and portability: HubSpot allows you to delete contact records (for right-to-erasure requests) and export contact data (for portability requests). These are available through the CRM interface and via API.Processing agreements: HubSpot provides a Data Processing Agreement (DPA) through their settings, which is a requirement for GDPR-compliant use of third-party processors.Consent tracking: HubSpot allows you to record consent on contact records, including the consent source, consent text, and date.For Australian businesses specifically: the Australian Privacy Act requires that you only collect personal information you need, that you inform individuals of how their data will be used, and that you provide access to and correction of personal information on request. HubSpot's tools support these obligations, but your privacy policy, data collection practices, and subscription consent language need to be configured correctly by your implementation partner.We recommend reviewing your HubSpot configuration against your current privacy obligations annually. If you are unsure whether your portal is configured correctly for compliance, this is something we can assess as part of a portal audit.

More faqs