NexBDM Blog
How to Choose a CRM: the questions that matter, and the ones that waste your time
By NexBDM Team · 2026-08-18
Key takeaways
- Feature grids do not decide a CRM. Three POPIA sections do: section 21 requires a written operator contract, section 19 sets the security measures it must carry, and section 72 governs the offshore hosting most well known CRMs use by default.
Feature grids do not decide a CRM. Three POPIA sections do: section 21 requires a written operator contract, section 19 sets the security measures it must carry, and section 72 governs the offshore hosting most well known CRMs use by default.
How to choose a CRM comes down to three questions with consequences attached: where the customer data is stored, whether the vendor will sign a written operator contract, and how you get your data out again. South African law makes the first two obligations rather than preferences, which is why feature comparisons are the wrong starting point.
Why the standard comparison is the wrong tool
Search this topic and you get scoring tables. Twelve products, twenty feature columns, a winner. The tables are not dishonest, they are just answering a question that does not decide anything.
Every CRM in the shortlist stores contacts, logs activity, moves deals through stages and sends email. The differences that show up in a feature grid are real but small, and they are almost never the reason a CRM is abandoned eighteen months later.
The reasons it gets abandoned are that nobody kept it up to date, that it did not match how the business actually sells, or that getting the data back out turned out to be somebody's whole weekend. None of those appear in a feature column.
There is also a set of questions that a South African business is legally required to have answered, and they are absent from essentially all of this coverage because most of it is written for a different country.
The questions the law makes you answer
A CRM holds names, phone numbers, email addresses and notes about people. That is personal information, so the Protection of Personal Information Act 4 of 2013 applies to it. Once you accept that, three obligations follow, and each one turns into a question you should be asking a vendor before you sign.
Your CRM vendor is an operator, and section 21 requires a written contract
Under POPIA, a business that processes personal information on your behalf is an operator. A hosted CRM does exactly that. Section 21(1) is unusually direct about what that means for you:
"A responsible party must, in terms of a written contract between the responsible party and the operator, ensure that the operator which processes personal information for the responsible party establishes and maintains the security measures referred to in section 19."
Read the structure of that sentence. The duty is on you, the business choosing the CRM. It is not satisfied by the vendor being secure. It is satisfied by a written contract in which the vendor undertakes to maintain the section 19 measures. If there is no written agreement covering it, you have not met section 21 even if the vendor's security is excellent.
Section 21(2) adds a second term that has to be live between you:
"The operator must notify the responsible party immediately where there are reasonable grounds to believe that the personal information of a data subject has been accessed or acquired by any unauthorised person."
So the question to ask is not "are you POPIA compliant". Every vendor says yes to that. The question is "will you sign an operator agreement, and does it carry a section 21(2) notification duty". That is answerable with a document, and the answer arrives quickly.
Section 19 tells you what those measures actually are
Section 19(1) requires a responsible party to secure the integrity and confidentiality of personal information in its possession or under its control, by taking appropriate, reasonable technical and organisational measures to prevent loss of, damage to or unauthorised destruction of personal information, and unlawful access to or processing of it.
Section 19(2) turns that into an ongoing process rather than a one-off: identify the reasonably foreseeable internal and external risks, establish and maintain safeguards against them, verify that the safeguards are effectively implemented, and keep them updated in response to new risks.
The practical translation for a CRM decision is that "we are hosted on a large cloud provider" is an answer about somebody else's infrastructure, not about your safeguards. Who inside your business can export the full contact list? What happens to their access on the day they leave? Those are section 19 questions and they are decided by how the CRM handles roles and permissions, which is a feature you should genuinely compare.
If the CRM is hosted outside South Africa, section 72 applies
This is the one that catches people, because most well known CRMs store data outside the country by default.
Section 72(1) prohibits transferring personal information to a third party in a foreign country unless one of five conditions is met. The first is the one that carries most business use:
the third party is "subject to a law, binding corporate rules or binding agreement which provide an adequate level of protection" with principles substantially similar to POPIA, including provisions on onward transfer to another country.
The remaining routes are the data subject consenting to the transfer, the transfer being necessary for performance of a contract between the data subject and you, the transfer being necessary for a contract concluded in the data subject's interest between you and a third party, and the transfer being for the data subject's benefit where consent is not reasonably practicable to obtain.
Note the phrase about onward transfer. It is not enough that the vendor protects the data. Substantially similar principles have to apply if that vendor moves it on again, which is a real question when a CRM uses sub-processors for email delivery, backups or support tooling.
None of this makes an offshore CRM a bad choice. It makes it a choice that needs a document behind it. The question to ask is "where is our data stored, which sub-processors touch it, and which section 72 route are we relying on".
The questions that waste your time
Having spent that much on the ones that matter, it is worth being equally direct about the ones that do not.
- Total feature count. You will use a fraction of any of them. A longer list mostly predicts a longer setup and more places for the team to get lost.
- Whether it has AI. Every CRM has AI in 2026. The question is whether it does a job you actually have, on your data, with a person checking the output.
- Reviews written for businesses at a different scale. A review by a company running forty salespeople is describing problems you do not have and will not have soon.
- Mobile app star ratings. Worth thirty seconds, not thirty minutes. Test it yourself on your own phone with your own connection.
- The demo. Every demo works. Demos are built on clean data that the vendor prepared. Yours will not be clean.
The questions worth the time instead
Does it fit how you actually sell
Write down your last ten deals, won and lost, and the stages each genuinely went through. Not the stages you would like to have. If your real process is a WhatsApp conversation, a site visit, a quote and a follow-up, then a CRM built around a seven stage enterprise funnel will be fought with, and quietly abandoned.
Many South African businesses do most of their customer conversation on WhatsApp, which is a specific requirement rather than a nice to have. If that is you, it belongs at the top of the list rather than the bottom, and it is covered separately in using WhatsApp as your CRM channel.
How does data get in without anyone typing it
The single largest predictor of whether a CRM survives is whether keeping it current is work. If a salesperson has to re-key what they already put in a quote, the CRM will drift out of date within a quarter and then everyone stops trusting it.
So the question is mechanical: when a lead comes off your website form, off WhatsApp, or off an email enquiry, does a record appear without a person creating it. When a quote goes out, does the deal value update itself. That is the difference between a CRM that reflects the business and a CRM that reflects who last had a quiet afternoon. The same principle applies across every system you run, and is worked through in automating data entry.
How do you get everything out
Ask for a full export before you sign, not after. A CSV of contacts is not a full export. You want contacts, companies, deal history, activity notes and attachments, in a format you could hand to a different system.
This matters twice. It is your exit route, and it is also a POPIA answer: section 19 covers loss of and damage to personal information, and a business that cannot retrieve its own records has a real problem the day the vendor has an outage or a billing dispute.
What changes when the choice is right
A CRM chosen on these terms does not just store information more tidily. It removes a category of recurring work, and it is worth being concrete about which.
- The enquiry stops being re-typed. Web form, WhatsApp message and email enquiry all land as a record with the source attached. Nobody copies anything into a spreadsheet, and the lead cannot be lost because one person was on leave.
- Follow-up stops depending on memory. The reminder comes from the deal record's own state, not from a person remembering. Deals that have not moved in a set number of days surface themselves.
- The quote reuses what was captured. Customer details flow from the record into the document instead of being typed again, which removes the most common source of a wrong registration number on a tax invoice.
- The operator agreement is on file. One document, signed once, that answers section 21 and records the section 72 basis. It stops being an open question you would have to reconstruct under pressure.
None of that requires the most expensive product on your shortlist. It requires the one whose data actually connects to the rest of what you run. If you are starting from nothing and want to test the shape of this before committing, the free CRM options available in South Africa are a reasonable place to learn what you need.
The surrounding POPIA obligations, beyond the three sections above, are set out in the POPIA compliance checklist.
Frequently Asked Questions
Do I legally need an agreement with my CRM provider in South Africa?
Yes. A hosted CRM processes personal information on your behalf, which makes it an operator. Section 21(1) of POPIA requires a written contract in which the operator maintains the section 19 security measures. The duty sits with your business, not the vendor.
Can I use a CRM that stores data outside South Africa?
Yes, if one of the five section 72 conditions is met. The most common is that the recipient is subject to a law, binding corporate rules or binding agreement giving adequate protection, with similar principles applying to any onward transfer. Confirm which route you are relying on.
Is a more expensive CRM better for a small business?
Not usually. Price tracks feature depth and seat count, and small teams use a narrow slice of either. Fit with how you actually sell, and whether records are created without manual typing, predict success far better than tier.
How long should choosing a CRM take?
Less time than most businesses spend. Map your real sales stages from the last ten deals, shortlist two or three that match, then test each with your own messy data and request the operator agreement and a full export. Demos on clean data prove nothing.
What is the most common reason a CRM fails after it is set up?
Keeping it current is manual. When updating the CRM is a second job on top of the work, it drifts out of date, people stop trusting it, and they go back to their own notes. Automatic record creation is what prevents that.
Where to start
The useful preparation is not a shortlist. It is an honest map of how enquiries reach you today, what gets typed more than once between first contact and invoice, and which of those steps a system could carry. That map is what a Business Autopsy produces, and it makes the CRM decision straightforward because the requirements are already written down. You can also book a discovery call to talk through your current setup first.
Sources
- Protection of Personal Information Act 4 of 2013, sections 19, 21 and 72. Government Gazette No. 37067, 26 November 2013.
Statutory text in this article was read from the published text of the Act and cross checked against two further copies. Verified 18 August 2026. This is general information about how these provisions read, not legal advice on your specific circumstances.