Limit CRM data on mobile devices: Disable offline access if field staff don’t need it; Check downloads, shared files and saved images for extra copies; Test offline access and pending changes after settings updates
Image: CRM Stack

Permissions

Part of CRM mobile use

Limiting sensitive CRM data stored on mobile devices

Identify and reduce customer information held on phones, including offline data, notifications and exports.

Check for CRM records and pending offline changes, downloaded files, notification content, and copies saved or shared elsewhere on the phone. Turn off offline and notification capabilities staff do not need, remove unnecessary copies, and test what remains accessible.

Map the copies a visit can create

List the account details, contacts, notes, attachments and tasks a representative needs for a visit. Check which are available offline, and look for extra copies in exports, shared files, copied text, saved images and downloads; distinguish app-managed data from content saved elsewhere on the phone.

Some CRM mobile apps provide separate capabilities for offline access and offline editing. If field staff do not need offline records, disable offline access; if they do not need to make changes offline, disable offline editing. Keep only the capability needed for the task enabled.

Test a representative account online and offline, then reconnect and check which records were available and whether changes were pending. Repeat the test after changing settings; treat every record visible offline and every pending edit as a phone copy.

For existing cached records or pending changes, use a CRM-provided clear or remove control if available, then test offline again. Do not assume that turning off offline access has already erased data stored on the phone.

Pros and cons of enabling offline access in CRM apps

Pros
Field staff can work without internet; improves productivity in remote areas
Cons
Increases risk of data exposure if device is lost, stolen, or compromised

Reduce unnecessary device exposure

Keep offline field work to the records and details needed for the task, where the CRM allows it. Check which records appear offline rather than assuming that selecting an account for a visit limits what is stored.

Avoid downloading attachments or exporting records unless they are needed. Check downloads, shared files, copied text and saved images for extra copies, and remove those no longer needed from the phone or shared location where they were saved.

In Zoho CRM for Android, tap the app icon, tap Settings, then tap Notification Categories in the Notifications section to customise categories. The Settings page’s Notifications section also lets users enable or disable notification options; switch off options staff do not need. Notification categories are supported on Android Version 8.0 and higher.

Check the actual notification on the device, including its lock-screen display. If it exposes customer detail, disable the relevant notification option or category where possible, and use brief record titles and task subjects; category settings alone do not establish what a preview exposes.

Prepare for loss or departure

Use the organisation’s device lock and update process, and make sure staff know whom to contact if a phone is lost. MDM can enrol and configure devices and provide remote actions such as locking or wiping them; confirm which actions are available for the organisation’s devices.

When a phone is reported lost, have the device administrator remotely lock the enrolled phone and wipe it if required by the organisation’s process. Have the CRM administrator revoke the user’s access or session; a wipe cannot retrieve information already accessed or copied elsewhere.

When a user leaves, have the CRM administrator revoke their access or session and the device administrator apply the organisation’s managed-device wipe process. Confirm that the phone no longer provides access to CRM data and check for separately saved files or copies.

The OAIC says APP entities must take reasonable steps to protect personal information, including technical and organisational measures. Apply the organisation’s process to mobile data and device controls.

Before rollout, use approved sample data to inspect an ordinary user’s online and offline views, pending changes, notifications and downloaded files. Record unnecessary items, adjust the available controls, and repeat the checks to confirm they are no longer accessible.

More from Permissions