A CRM is a record of customer relationships, not an organisation’s memory. This distinction is becoming increasingly costly. Data relating to the same company or individual is now stored in parallel across CRM, ERP, helpdesk, email, marketing systems, project management tools and AI-powered applications. The problem is no longer about how to collect more information. It is about how to determine which information is up to date, where it comes from and what it may be used for.
The scale of fragmentation is growing alongside the digitalisation of business. In 2025, 53 per cent of EU companies employing at least 10 people were using ERP, CRM or BI software. Among large organisations, 65 per cent of companies used CRM alone. At the same time, 52.7 per cent of businesses were purchasing cloud services.
This means that a company’s technological landscape increasingly rarely resembles a single system. It more closely resembles a network of applications, each of which understands a different aspect of the customer.
A single database does not solve the problem
For years, centralisation was seen as the answer to silos. In practice, however, moving all data to yet another platform often simply creates a larger silo.
It is far more important to establish an architecture of data ownership. A CRM system can be the source of information on sales opportunities, a financial system on payments, and a helpdesk on support tickets. An organisation does not need a single application that contains everything. It needs a shared customer identity and rules that allow information scattered across systems to be unambiguously linked.
In practice, this means a single, stable customer identifier, a defined reference source for each type of data, and a history of relevant events. Metadata is equally important: when the information was created, which system it comes from, who can view it, how long it should be retained, and for what purpose it may be used.
Without this layer, ‘customer 360’ remains, above all, a catchy name for the aggregation of records.
Consent is not synonymous with legality
The second source of chaos is more subtle. Companies often try to manage consents in the same way they manage the ‘telephone’ or ‘customer status’ fields: they copy the same information between CRM, marketing automation and sales tools.
However, from a legal perspective, the basis for data processing must be distinguished from the right to use a specific communication channel.
The GDPR does not base all processing on consent. Article 6 also provides for, amongst other things, the performance of a contract, a legal obligation or a legitimate interest. At the same time, the Regulation requires purpose limitation, data minimisation and the limitation of the retention period.
Marketing is a separate issue. Article 398 of the Polish Electronic Communications Law prohibits the use of automated calling systems and telecommunications terminal equipment to send commercial communications, including direct marketing, without the prior consent of the subscriber or end-user. For a breach of the obligation to obtain such consent, the President of UKE may impose a fine of up to 3 per cent of the previous year’s turnover or up to 1 million PLN, whichever is the higher.
From an IT systems perspective, consent should therefore function as a controlled record, rather than a tick box copied between applications. It must be assigned a scope, purpose, channel, source, the time it was granted and any withdrawal. Otherwise, an organisation may have three systems that function correctly yet provide three different answers to the question of whether it is permissible to contact a customer.
AI without organised data only accelerates chaos
By 2025, 19.95 per cent of businesses in the EU were already using AI, whilst in the professional, scientific and technical services sector the figure stood at 40.43 per cent. In Poland, the figure was just 8.36 per cent, one of the lowest in the EU.
For service companies, the appeal of AI is obvious. The model can reconstruct a client’s history from messages, documents, CRM records and support tickets before a meeting, in a timeframe that a human would not have spent on manual searching.
Technically, however, it is easy to turn such a solution into a new, poorly controlled data warehouse. Indexing correspondence and documents in vector databases, creating transcriptions or building RAG layers results in the creation of further representations of customer information. If these do not inherit the access rules, retention policies and processing purposes from the source systems, the company is not eliminating silos. It is automating their creation.
The EROD explicitly states that the lawfulness of using personal data in AI models requires a case-by-case assessment, and that unlawful use of data during the model-building stage may also affect the lawfulness of its subsequent use. From 2 August 2026, further obligations under the AI Act will also apply, including some of the requirements concerning the transparency of AI systems.
An organisation’s ‘memory’ is therefore not just another product in the CRM category. It is a data architecture: the customer has a single identity, information has specific sources, access rights follow the data, and consent retains its context when moving to the next system.
It is only at this level of CRM that automation and AI begin to operate on the same version of reality.
