1) Vet the list before it reaches your CRM
Ask the supplier for clear provenance and a small sample file (50–200 rows). Confirm who collected each record, when, and by what method (web form, event, partner share). If they can’t provide provenance, treat the list as ‘unknown’ and raise the bar for consent.
Add or require these provenance fields in the CSV or mapping before import: source_name, acquired_date, original_capture_method, consent_basis (consent/legitimate_interest), consent_date, and original_file_id. These let you trace problems and filter the set later. Platforms differ in field names (HubSpot has subscription/consent properties, Salesforce has opt‑in fields; Marketo/Pardot use lists and permission records), but the operational principle is the same: record the why, who and when.
Do the GDPR checks now: ask for proof of consent where consent_basis = consent; run the supplier against your suppression lists (opt‑outs, bounced addresses, Do Not Contact). If the supplier claims legitimate interest, document their rationale and consider a more conservative engagement approach on the South Coast or for UK prospects.
2) Quarantine, sample imports and dedupe rules
Never import the whole list straight into live workflows. Create a quarantine segment or list in your CRM and map the provenance fields on import. If your CRM supports a ‘Do Not Automate’ or processing_state flag, set it on every imported record so workflows ignore them until you clear them.
Import a small sample first (1–5% or up to 200 records). This dry run checks mapping, fields, validation rules and any platform-specific behaviour (e.g. Salesforce triggers, HubSpot contact merge rules, Marketo list membership sync). Use a staging environment where possible; when not available, keep the sample in the quarantine list and exclude that list from automations.
Apply simple, conservative deduplication rules before releasing records:
- Primary key: exact email match (where present) — merge or flag duplicates.
- Secondary: name + phone + company fuzzy match for B2B — flag for manual review.
- When emails are missing, treat records as lower trust and hold for human review.
If you use an integration (Zapier/Make or native connector), add a schema validation step so malformed rows fail and land in a dead‑letter queue rather than creating partial records. If you need help setting up quarantine lists or mappings, consider a short engagement for CRM optimisation: CRM & marketing data optimisation (Fareham).
3) Gate automations, monitor, roll back and follow up safely
Before allowing any outbound activity, set gating rules: only records with consent_basis = consent and consent_date within your acceptable window (e.g. 24 months) should be eligible for marketing sends. If you can’t prove consent, use a staged re‑engagement sequence or restrict to non‑marketing contact (sales outreach with email templates that clearly include an opt‑out).
Turn on simple monitoring for 48–72 hours after any release: daily counts for bounces, hard bounces, spam complaints, unsubscribe rate and unexpected spikes in activity. Add a canary check — a handful of known test addresses outside the list — so you spot routing problems early. If metrics exceed thresholds (for example >2% hard bounces or sudden increase in spam complaints), pause sends immediately and bulk‑flag the recent import with a ‘do_not_email’ or ‘quarantine_issue’ tag.
Have rollback steps documented and practised: snapshot the imported record IDs, bulk update the processing_state to ‘blocked’ or set Do Not Email, and if necessary delete or archive the import batch. Keep the original CSV and a short audit note recording who approved the import and why.
Small follow‑up plan for safe engagement: start with a low‑impact touch (one short, consent‑focused email) to validate deliverability and engagement, wait 7–14 days, reconcile opt‑outs and bounces, then run any wider nurture only on the subset that behaved well. For sales outreach, hand off only vetted leads to reps with a clear note of provenance and a required manual verification step.
This approach keeps automations stable, reduces duplicates and limits GDPR risk for small teams in Fareham, Hampshire and across the South Coast. If you want a quick on‑site or remote review of your import checklist and quarantining approach, Optira can help with a short, practical session focused on CRM data cleanup and safe automation.