GDPR enforcement keeps accelerating, and the fines are steep: up to 20 million euros or 4% of global annual turnover, whichever is higher, for the most serious violations (Article 83). Many penalties stem not from major breaches but from everyday failures, such as retaining personal data too long, missing consent records, or mishandling erasure requests.
Salesforce, as the system of record for millions of customer interactions, sits at the center of this risk. While the platform provides a strong foundation through encryption, audit logs, and global certifications, compliance ultimately depends on how each organization configures, documents, and manages personal data within its own Salesforce org.
What GDPR Compliance Means in a Salesforce Context
Is Salesforce GDPR compliant? Yes, in the sense that matters most: Salesforce provides a GDPR-ready platform, acting as a data processor backed by EU-approved Binding Corporate Rules, a Data Processing Addendum, and independent certifications. But a compliant platform does not make your org compliant. As the data controller, your organization is responsible for configuring, documenting, and maintaining GDPR controls for the personal data you hold.
Organizations using Salesforce are subject to GDPR if they process personal data relating to people in the EU. The regulation sets strict requirements around data minimization, purpose limitation, storage, transparency, and security. These principles must be enforced through both platform configuration and process controls. GDPR applies regardless of where your company is based, so most Salesforce orgs with any EU customers, employees, or prospects have a direct stake in getting this right.
The controller and processor split is central. Salesforce acts as a data processor, responsible for securing the platform. Your organization acts as the data controller, responsible for the collection, use, and retention of personal data. Salesforce provides tools like encryption and audit logs, but it is up to your organization to implement compliant configurations and retention workflows.
Compliance is not a one-time task. GDPR's accountability principle (Article 5(2)) requires organizations to document and continuously demonstrate compliance. In practice, that means regularly reviewing permissions, retention rules, audit logs, and erasure workflows so they align with both the regulation and how data is actually used.
What Are the 7 GDPR Requirements?
When people ask what the 7 GDPR requirements are, they usually mean the seven data-protection principles in Article 5. Each principle maps to something you configure or document in Salesforce. The table below lays them out.
These principles are the backbone of GDPR. Meeting them is less about any single feature and more about consistent configuration, documentation, and review across your Salesforce org.
Lawfulness deserves special attention. Before you process personal data, you need a valid legal basis under Article 6, such as consent, a contract, or legitimate interests, and you should record which basis applies to each processing activity. In Salesforce, that often means documenting the basis at the object or field level and capturing consent where consent is the basis you rely on.
Is Salesforce GDPR Compliant? What the Platform Provides
Salesforce acts as a data processor under GDPR and backs this role with established legal and technical frameworks. Its Processor Binding Corporate Rules (BCRs), approved by EU regulators, ensure consistent privacy protections across Salesforce entities worldwide.
The platform also provides a data processing agreement (DPA) that includes the European Commission's Standard Contractual Clauses, a list of authorized sub-processors, and descriptions of technical safeguards such as encryption and access logging. These documents are publicly available and form the legal basis for compliant data transfers and processing.
Salesforce's security practices are independently verified through a broad set of certifications. Coverage varies by product and infrastructure, so confirm which attestations apply to each service you use. The table below summarizes the core ones.
Marketing Cloud is worth calling out. It maintains its own ISO 27001 information security management system and separate security, privacy, and architecture documentation. So GDPR in Salesforce Marketing Cloud (SFMC) centers on managing subscriber consent and preferences, honoring access and erasure requests for subscriber data, and setting retention for marketing data, using SFMC's own consent and preference tools.
For organizations with data residency requirements, Hyperforce lets Salesforce data be hosted in specific regions while maintaining the same security controls, a common consideration for GDPR data transfers. These attestations confirm that Salesforce provides a compliant infrastructure, but they do not guarantee that an individual org is compliant. Misconfigured permission sets, missing encryption, or incomplete erasure workflows can still violate GDPR. Salesforce provides the foundation; your organization is responsible for configuring, monitoring, and documenting its own controls.
The Shared-Responsibility Model: Who Owns What?
Salesforce follows a shared-responsibility model under GDPR. Salesforce covers processor duties through its infrastructure, encryption capabilities, audit tools, and documented sub-processors, and it provides breach notifications and compliance updates through its Trust site. Your organization owns the controller duties. The table below shows the split.
Signing the DPA is not enough. As the controller, your organization must regularly audit configurations, enforce least-privilege access, and maintain records that demonstrate compliance decisions and accountability. Note that where a reportable breach occurs, controllers must notify their supervisory authority without undue delay and within 72 hours where feasible (Article 33). A useful rule of thumb: if a decision involves why or how personal data is used, it is a controller decision and therefore yours; if it involves the security of the underlying platform, it is Salesforce's.
Data Subject Rights in Salesforce
GDPR gives individuals specific rights over their personal data, and your organization must be able to honor them within Salesforce. The table below maps the core rights to the article that grants them and how to handle each in Salesforce.
Build a repeatable process for these requests rather than handling each one ad hoc. Document who owns the request, how you locate the data across objects, and how you evidence that you fulfilled it within the one-month deadline GDPR allows.
Erasure is the request that most often trips up Salesforce teams. Deleting a record from production is not enough if copies persist in backups, sandboxes, or exports. Plan for those copies, and where full deletion is impractical, anonymize the data so it can no longer identify the person while preserving aggregate reporting.
How to Verify Salesforce's GDPR Posture: A Step-by-Step Checklist
Verifying Salesforce's compliance capabilities is part of demonstrating your own controller responsibilities under the accountability principle. Use the steps below to collect and organize evidence that the platform meets its processor obligations, and keep that evidence with the rest of your accountability records.
1. Collect core legal documents
- Log in to the Salesforce Trust site and download the current Data Processing Addendum (DPA).
- Request the Processor Binding Corporate Rules (BCRs) via Salesforce's legal page or support team. These confirm EU regulatory approval.
- Save a dated copy of each document for audit use.
2. Retrieve SOC 2 reports
- Access the most recent SOC 2 Type II report for every Salesforce cloud service in use.
- Focus on the Security, Availability, and Confidentiality sections.
- Note which controls are managed by Salesforce and which require internal configuration.
3. Map certifications to your services
- Use the "Applicable Documents by Service" table on Salesforce's compliance site to confirm which attestations apply to each product in your org.
- Cross-reference this list with your production environments and flag any coverage gaps.
4. Validate encryption and transport settings
- In Setup, go to Security, then Platform Encryption. Confirm Shield is active and encryption keys are applied to personal or sensitive fields.
- Verify that TLS 1.2 or higher is enforced at the org level for data in transit.
5. Review cross-border data transfer mechanisms
- Confirm that the Standard Contractual Clauses (SCCs) are included in your signed DPA.
- If your org is hosted on Hyperforce, review the region configuration for data residency.
- Document any transfers outside the EEA and the legal basis for each one.
6. Track administrator GDPR training
- Use Trailhead or internal tracking systems to confirm GDPR module completion for admins and data owners.
- Maintain a log to demonstrate that staff handling personal data are trained (Article 39).
7. Store and maintain evidence
- Compile documentation, screenshots, and reports into a centralized Salesforce GDPR evidence folder.
- Set a quarterly reminder to update files, validate settings, and refresh certifications.
This proactive process helps your team stay audit-ready and clearly demonstrates how your Salesforce configuration supports GDPR accountability. It also builds a defensible paper trail that simplifies regulator inquiries and strengthens trust with internal stakeholders and external partners.
Documenting Your Compliance for Audits
GDPR audits often come with little warning, so a complete, current evidence pack is critical for responding quickly. Regulators typically request a mix of organizational records and platform-specific artifacts. The table below maps the common requirements to where each lives.
Also maintain a meta-audit trail: records of when privacy policies were reviewed, which users updated security settings, and how long it took to fulfill data-subject requests. These details show that your compliance program is actively managed and auditable. Assign an owner for the evidence pack and review it on a fixed cadence, since stale documentation is as much an audit finding as a missing control.
Security Controls You Still Need to Configure in Salesforce
Salesforce provides the tools for GDPR-grade data protection, but it is up to your organization to configure them correctly. The controls below address the gaps that most often leave orgs exposed, and each maps to a specific GDPR obligation.
Misconfigurations, not missing features, are the root cause of most GDPR gaps in Salesforce. Applying these settings consistently across environments keeps personal data protected by design and by default (Article 25). Beyond configuration, monitor for drift: Shield Event Monitoring and login history help you spot unusual access to personal data, and regular permission reviews catch the privilege creep that quietly widens your exposure between audits.
Maintaining GDPR Compliance with Flosum
GDPR compliance in Salesforce comes down to how data is configured, secured, and governed day to day, which is exactly the accountability and shared-responsibility work described above. Flosum helps teams do that work inside Salesforce, so evidence and controls stay close to the data rather than scattered across external tools.
Flosum offers a Salesforce-native deployment option that keeps records inside your org, plus tamper-evident audit trails and version-controlled deployments that give you a complete, verifiable history of changes. That directly supports GDPR's accountability principle (Article 5(2)) and simplifies audit preparation. Access control, backup, sandbox seeding, and erasure workflows are managed through one interface, giving teams clear visibility and control across environments.
Flosum's platform is built to support global compliance obligations at scale, including GDPR, SOX, and HIPAA, and the company holds certifications including ISO 27001, ISO 27701, and SOC 2 Type II. You can explore Flosum's full list of compliance capabilities and certifications to see how it fits your accountability program.
Frequently Asked Questions (FAQ)
Thank you for subscribing



