Phase 1: Decide why, in one sentence
A migration justified by “the old system is old” will be scoped as a copy. A migration justified by a business outcome will be scoped as a transformation.
Write the reason in one sentence the board would recognise. For example: “One view of every customer across Malaysia, Singapore and the Philippines, so we can grow revenue per customer and deploy AI agents in service.” Every later decision, from what to migrate to what to retire and what to redesign, is tested against that sentence.
Phase 2: Audit everything that holds customer data
List every system that touches a customer: CRM, ERP, ticketing, booking or patient systems, e-commerce, marketing tools, spreadsheets and messaging accounts. For each, record:
- What data it holds, and how many records.
- Who owns it and who uses it, by market.
- What it integrates with.
- How clean it is: duplicates, missing fields, inconsistent formats.
- What personal data it holds, and on what legal basis it was collected.
Expect surprises. The spreadsheet nobody mentions is often the most important source of truth in a market.
Phase 3: Design one customer model with room for each market
This is the most important phase and the one most often rushed.
Agree the shared definitions
One definition of a lead. One structure of deal stages. One set of service case categories. One company and contact hierarchy that reflects how your group is really organised: parent groups, subsidiaries, brands and branches.
Allow local variation where it earns its place
Different markets genuinely differ: currencies, languages, tax fields, product ranges, regulatory steps. Decide explicitly which differences are kept, and why. Everything else is standardised.
Design for multiple brands and business units
Regional groups often need brand-level separation of marketing assets, sales teams and reporting, with group-level visibility above. Design permissions, teams and reporting around that structure before any data moves.
Design for AI from the start
Ask what an AI agent will need to read and write. Clean product data, current pricing, service policies and complete interaction history are no longer nice to have. They are the context agents depend on.
Phase 4: Settle data protection and residency before you move data
Every market in scope has its own data protection law, and a migration is the moment personal data is copied, transformed and often moved across borders. Treat this phase as a gate. This playbook is not legal advice.
Know where the data will live
HubSpot hosts customer data in the EU, Canada, Australia and the United States, and has no data centre in Southeast Asia (HubSpot). For most regional enterprises, that makes the migration a cross-border transfer, which must be documented.
Market by market
- Malaysia. The PDPA amendments, phased in through 2025, replaced the whitelist approach to cross-border transfers. Transfers may now rely on bases including a destination with substantially similar law or adequate protection, assessed through a transfer impact assessment, as well as consent and contractual safeguards. The amendments also introduced mandatory breach notification, direct obligations for data processors, data portability, mandatory Data Protection Officers and maximum fines of RM1,000,000 (Mayer Brown). The DPO requirement applies, among other triggers, where processing involves personal data of more than 20,000 data subjects (DLA Piper).
- Singapore. Overseas recipients must provide protection comparable to the PDPA. Notifiable breaches must be reported to the PDPC no later than three calendar days after assessment, and every organisation must appoint a DPO (DLA Piper).
- Philippines. Under the Data Privacy Act of 2012, organisations must notify the National Privacy Commission and affected individuals within 72 hours of knowing of a reportable breach. Registration with the NPC is mandatory for organisations with 250 or more employees, among other thresholds (DLA Piper).
- Indonesia. The PDP Law's transition ended on 17 October 2024, and full compliance is now required. Breaches require written notification within 72 hours, and cross-border transfers rely on adequacy, binding safeguards or consent (DLA Piper).
- Thailand. The PDPA came into full force on 1 June 2022. Breaches must be reported, where feasible, within 72 hours, and transfers abroad need an adequate destination, consent or another lawful basis such as appropriate safeguards (DLA Piper).
Practical steps
Map each data set to its legal basis. Complete the transfer documentation. Decide what not to migrate: old records with no lawful purpose are a liability, not an asset. Appoint or confirm a DPO in each market where required. Involve legal counsel. More detail on HubSpot and data protection by country.
Phase 5: Bring messaging channels into the platform
Across much of Southeast Asia, a CRM that only sees email sees a fraction of the conversation. Customers message on WhatsApp, LINE and Viber, and many enterprise sales and service teams still run those chats on personal phones. That is a data protection risk and a blind spot.
Plan channels as part of the migration, not after it:
- WhatsApp Business connects natively to HubSpot's conversations inbox on Marketing Hub or Service Hub Professional or Enterprise (HubSpot Knowledge Base).
- LINE and Viber are not native. They connect through HubSpot's custom channels API or Marketplace apps (same source). Budget for the integration and test it in each market where it is used.
- Chat, Facebook Messenger, calling and SMS are native channels in the same inbox, subject to subscription (same source).
Agree consent capture and opt-out handling for each channel and market before go-live. When conversations are captured in one place, AI agents such as HubSpot's Customer Agent can serve customers in the channels they actually use.
Phase 6: Migrate in waves, by market
Do not move every market on one weekend. Migrate in waves.
- Pilot market. Choose a market with a supportive leader and manageable data. Migrate, run in parallel for a short period, fix what breaks.
- Refine the playbook. Update data mapping, cleansing rules and training from what the pilot taught you.
- Remaining markets. Migrate one or two at a time, each with its own cutover plan and local champion.
For each wave, cleanse before you migrate, not after. Deduplicate, standardise formats such as phone numbers and addresses across countries, and archive what you will not move. Validate record counts and samples with the business owner before sign-off.
Rebuild integrations, such as ERP, booking or patient systems, e-commerce and finance, against the new customer model rather than copying old point-to-point links.
Phase 7: Adopt, then decommission
A migration is finished when people use the new platform and the old one is switched off. Not before.
- Train by role and market, in the language teams work in, on the new process rather than the new screens.
- Name a champion in each market with time set aside for the first quarter.
- Measure adoption weekly: logins, records updated, conversations captured, pipeline in the new system.
- Set a decommission date for each legacy system, and keep it. Two systems running in parallel indefinitely is how migrations fail quietly.
Where to start
Write the Phase 1 sentence this month, then use it to scope the pilot market.