Access control is all-or-nothing
A shared spreadsheet has one access level: open it or do not. Everyone who can see the file can see every row — including leads assigned to other people, notes about clients they do not work on, and whatever historical data has accumulated at the bottom of the sheet since the file was created.
Article 5(1)(f) requires personal data to be processed in a way that ensures appropriate security, and Article 32 asks you to put technical and organisational measures in place that are appropriate to the risk. Neither names a specific technology. Both are usually satisfied by being able to say who can see what, and to change it. A shared file gives you one lever, and it is the wrong size.
The second problem is that link sharing propagates quietly. A file set to "anyone with the link" is outside your control the moment that link is forwarded, and you cannot tell from the file who currently holds it. If you cannot answer "who has access to this data today", you cannot demonstrate that your access controls are appropriate.