
Data separation in multi-client CRMs: what agencies must know
If you manage the customer data of several clients as an agency, fiduciary or consultancy, you carry a double responsibility: towards every single client – and towards the law. Data separation in a multi-client CRM means the data of different clients is structurally isolated, not just kept apart by filters and good intentions. This post shows how to get it right, practically and legally.
It is written for service providers who run or set up CRMs for several clients – and for anyone currently deciding how to organise their mandates technically. The topic sounds dry, but it decides very tangible things: whether you can hand a mandate over cleanly, how you respond to deletion requests, and what happens when a team member accidentally works in the wrong client's records.
What does data separation in a multi-client CRM mean?
Data separation means each client's contacts, deals and communication live in their own bounded area – with their own access rights, their own user management and the ability to hand over or delete the area as a whole. The separation is structural when access across mandate boundaries is technically impossible.
The opposite is "logical" separation in a shared CRM: all clients in one database, distinguished by tag, filter or pipeline. That works as long as nobody makes mistakes – and that is exactly the problem.
Why is a shared CRM with tags not enough?
Because filters are not boundaries. In a shared CRM, all clients' data sits side by side technically, and every imprecision becomes a risk:
- Wrong-place access: one misapplied filter and the intern sees the deals of a competing mandate. Field-level permissions are complex and rarely maintained cleanly.
- Blended reporting: reports and searches run across the whole database. An export of "all contacts" quickly contains data the recipient has no business seeing.
- Impossible handover: when a mandate ends, you cannot cleanly extract the data – contacts, deals and email history hang off shared structures.
- Painful deletion: if a client demands deletion of their data, you first have to identify all of it. In a shared CRM, that alone is surprisingly hard.
In short: logical separation does not scale. It requires every team member to work flawlessly every day – and no data-protection concept should rest on that. From the second or third mandate onwards, structural separation is the more robust and ultimately cheaper solution, because it does not prevent mistakes but renders them harmless.
What do the Swiss DPA and the GDPR require of agencies?
Anyone processing personal data on behalf of clients is legally a data processor (Auftragsbearbeiter under the Swiss DPA, processor under the GDPR) – with clear duties: the data may only be used for the respective mandate, it must be adequately protected, and the client must be able to fulfil access and deletion requests. Clean client separation is the technical foundation for all three.
Concretely, for each mandate you should be able to answer: which data lives where, who has access, and how can it be fully handed over or deleted. With separate workspaces these answers are trivial – in a shared CRM they are a project. Our post on handing a CRM over to the client covers the handover side in detail. (This article is not legal advice.)
Then there is the location factor: many Swiss end clients expect their customer data to stay in Switzerland. Advanzo hosts all workspaces in Switzerland – an argument you can pass straight on to your clients.
When is a shared workspace the right choice after all?
When it is not about different clients at all: a single company with several teams, brands or locations usually works better in one shared workspace with clear roles – there, the data belongs to the same controller anyway. You need separate workspaces when different companies are each in control of their own data.
A good rule of thumb: one workspace per data controller. Your own new-business pipeline as an agency is your workspace; every client mandate is its own. And very practically, the agency benefits too: your own pipeline stays free of client data, your reports show your business – and when someone leaves the agency, you revoke their mandate access one by one without touching your own CRM.
How does a workspace model separate data structurally?
By giving every client their own complete CRM: a workspace with its own contacts, deals, email connections, users and roles. In Advanzo this is the core of agency mode – you run unlimited client workspaces under one account and manage them through the agency console.
The separation works on three levels:
- Data: contacts, deals and communication exist only inside their workspace. Searches, reports and exports stop at the workspace boundary.
- Access: roles (admin, member) apply per workspace. Working at client A gives you no rights at client B – unless you are explicitly invited there.
- Lifecycle: a workspace can be transferred to the client as a whole, or wound down in an orderly way when the mandate ends. Access requests, handover and deletion always concern exactly one client.
What daily work with the console looks like is described in our post on agency mode in practice; the feature overview is on the agency console page.
Which questions should you ask every CRM vendor?
When evaluating a multi-client set-up – with any vendor – these five questions bring clarity fast:
- Is client data structurally separated or merely filtered by permissions?
- Can I hand over a mandate as a whole – including ownership, without export and re-import?
- Do roles and access rights apply per client, rather than account-wide?
- Where is the data physically hosted, and which jurisdiction applies to the vendor?
- What does the model cost per client – and what happens to the price when five mandates become twenty?
Vendors who answer the first two questions evasively usually solve client separation with filters – with all the risks described above.
How do you keep the separation clean day to day?
Technology is half the job; habits are the other half. Four rules that have proven themselves at agencies:
- No data copies outside the workspace: client lists do not belong in agency spreadsheets or private note apps. What belongs to the mandate lives in the mandate's workspace.
- Client accounts for client things: email connections and integrations run through the client's accounts, not through personal agency logins.
- An offboarding routine: define what happens at the end of a mandate: transfer or wind down the workspace, revoke access, delete residual data. Defined once, it takes ten minutes per mandate.
- Data minimisation: capture only what each mandate needs. The less superfluous personal data sits in a workspace, the easier access requests, handover and deletion become.
These rules cost almost nothing in daily work – and they make the difference when a client asks critical questions or an audit comes up. Live them from day one and you never have to clean up retroactively.
Frequently asked questions (FAQ)
Is a shared CRM for several clients illegal?
No, but it raises the risk. The Swiss DPA and the GDPR require appropriate technical measures to protect the data. Structural separation per client is the simplest way to meet that requirement demonstrably – filter-based set-ups need far more safeguarding and documentation.
How does Advanzo separate different clients' data?
Through separate workspaces: every client has their own CRM with their own data, users and roles. Access across workspace boundaries does not exist, and each workspace can be handed over or wound down individually.
Does the agency see all of its clients' workspaces?
The agency sees the workspaces it owns or that are shared with it in the agency console. Inside a workspace, the role granted there applies – and the client, as admin, can adjust or end access at any time.
Where is the data hosted?
In Switzerland. Advanzo hosts all workspaces in Switzerland and aligns with the Swiss DPA and the GDPR. For mandates with heightened confidentiality requirements – fiduciary or consulting work, for instance – that is often a basic precondition.
What does a multi-client set-up with Advanzo cost?
Every client workspace starts free with up to 25 deals; after that it costs CHF 25 per user/month (Plus) or a flat CHF 350 per month (Pro Unlimited). The number of workspaces per account is unlimited – details on the pricing page.
Want to separate your mandates cleanly without running five systems? Start Advanzo for free and create a dedicated workspace for every client – structurally separated, hosted in Switzerland, ready to hand over at any time.










































