HubSpot data exports: controlling permissions, monitoring activity and protecting data
Understand how to restrict HubSpot exports, monitor export activity and protect CRM information after it has been downloaded.
HubSpot allows authorised users to export CRM records and other information for analysis, reporting, backups and approved data-sharing activities.
Exports can contain personal, commercially sensitive or otherwise confidential information. Organisations should therefore control who can create exports, monitor export activity and define how downloaded files must be handled.
What can be exported from HubSpot?
Depending on the tool and the user’s permissions, data exported from HubSpot can include:
- Contact, company, deal and ticket records
- Custom object records
- Record properties and associations
- Segments and filtered record views
- Reports and reporting data
- Property history
- User and permission information
- Other HubSpot assets and account data
The contents of an export depend on where it is created and which options the user selects. For example, a CRM record export can include only the properties displayed in the current view or a wider selection of properties and associations.
Before exporting information, users should consider whether every selected field and record is required for the intended purpose.
HubSpot guide:
Export your records
Controlling export permissions
Users require the relevant Export permission to export CRM records.
Export access should be assigned according to the principle of least privilege. Only users with a genuine operational requirement should be able to remove CRM data from HubSpot.
Organisations should:
- Restrict export permissions to approved users
- Avoid granting export access by default
- Review access when a user changes role
- Remove access when it is no longer required
- Include export permissions in regular access reviews
- Limit Super Admin access to appropriate administrators
Where Enterprise permission sets are available, organisations can use them to apply consistent, role-based permissions. The assigned permissions should still be reviewed to ensure they remain appropriate.
HubSpot guide:
HubSpot user permissions guide
Monitoring export activity
HubSpot provides an export audit that records export activity within the account.
Super Admins can view exports completed by all users. Users with Export permission can access the export log for their own exports.
The audit can show information including:
- The export file name
- The source of the export
- The number of records exported
- The user who initiated it
- The date and time of the export
- Whether an export is still processing
Super Admins can also cancel an export that is still in progress.
Completed export files can be downloaded from the export audit for a limited period. The export activity itself may remain visible for longer than the downloadable file, so the audit should not be treated as permanent storage for exported data.
Monitoring downloads
For supported export types, HubSpot can provide download history showing which users downloaded an export file, together with their IP address and the date it was accessed.
Download-history availability depends on the export type and how the file was accessed. It is not available for exports containing Sensitive Data.
The audit can support an investigation, but it does not replace your organisation’s wider security monitoring, incident-response or data-governance processes.
Configuring large-export notifications
Super Admins can configure a personal notification threshold for large record exports.
Notifications can apply when a user exports records through supported sources, including:
- A segment
- A CRM index-page view
- Property history
Each Super Admin who wants to receive notifications must configure their own threshold. The setting is not automatically shared across all Super Admins.
A notification indicates that an export exceeded the configured number of records. It does not by itself mean that the export was unauthorised or unsafe.
Your organisation should define who reviews these notifications and what should happen when an unexpected export is identified.
HubSpot guide:
Set up export notifications and view a log of exports
Responding to unexpected export activity
If an export appears unexpected, the organisation should review:
- Who initiated the export
- Whether the user was authorised
- Which records and properties were included
- The stated purpose of the export
- Who downloaded or received the file
- Where the file has been stored
- Whether any personal or sensitive information was involved
- Whether internal security, privacy or incident-response procedures should be followed
Where an export is still processing, a Super Admin may be able to cancel it. Cancelling an export does not remove copies that have already been downloaded or shared.
Any decision about whether activity constitutes a security incident or personal data breach should be made through the organisation’s approved legal, compliance and incident-response processes.
Protecting exported files
Once data has been downloaded, it is stored outside HubSpot’s platform controls. Your organisation becomes responsible for protecting the resulting file.
Appropriate controls may include:
- Storing files only in approved locations
- Restricting access to authorised recipients
- Encrypting files where required
- Using secure methods when transferring information
- Avoiding unnecessary copies
- Applying documented retention periods
- Deleting files securely when they are no longer required
- Recording the purpose and recipient of sensitive exports
Users should not place CRM exports in personal email accounts, unapproved file-sharing services or unsecured local folders.
Data protection and organisational responsibility
HubSpot provides technical controls for restricting, creating and monitoring exports. It does not decide whether a particular export is lawful, proportionate or appropriate for your organisation.
Your organisation remains responsible for:
- Establishing a lawful purpose for processing personal data
- Deciding who may export information
- Approving external recipients
- Applying retention and deletion requirements
- Responding to suspected misuse or data loss
- Meeting GDPR and other applicable data-protection obligations
Where appropriate, seek advice from your organisation’s legal, compliance or data-protection specialists.
Forbidden can explain and configure HubSpot’s technical export controls, but does not provide legal advice or determine whether a particular export complies with your organisation’s legal obligations.
Recommended governance checks
Review export governance regularly and after significant changes to your team, systems or data-handling requirements.
Your review should confirm that:
- Export permissions remain limited to appropriate users
- Super Admin access is controlled
- Large-export notifications are configured for the relevant administrators
- Export activity is reviewed at an agreed frequency
- Unexpected activity has a documented escalation route
- Exported files are covered by security and retention policies
- Leavers and role changes trigger an access review
- Users understand how exported data must be handled
What can Forbidden help with?
Forbidden can help you:
- Review HubSpot export permissions
- Configure role-based access and permission sets
- Set up large-export notifications
- Explain how to review the export audit
- Document HubSpot administration and export procedures
- Train Super Admins and other authorised users
- Identify opportunities to reduce unnecessary exports through reporting or integration
Your organisation remains responsible for approving exports, defining its data-governance policies and determining its legal and regulatory obligations.
Further information