Resources /
Blog

Salesforce GDPR Compliance Explained

Submit your details to get a book

Min Read
Resources /
Blog

Salesforce GDPR Compliance Explained

Download

Submit your details to get a book

Min Read

GDPR enforcement keeps accelerating, and the fines are steep: up to 20 million euros or 4% of global annual turnover, whichever is higher, for the most serious violations (Article 83). Many penalties stem not from major breaches but from everyday failures, such as retaining personal data too long, missing consent records, or mishandling erasure requests.

Salesforce, as the system of record for millions of customer interactions, sits at the center of this risk. While the platform provides a strong foundation through encryption, audit logs, and global certifications, compliance ultimately depends on how each organization configures, documents, and manages personal data within its own Salesforce org.

What GDPR Compliance Means in a Salesforce Context

Is Salesforce GDPR compliant? Yes, in the sense that matters most: Salesforce provides a GDPR-ready platform, acting as a data processor backed by EU-approved Binding Corporate Rules, a Data Processing Addendum, and independent certifications. But a compliant platform does not make your org compliant. As the data controller, your organization is responsible for configuring, documenting, and maintaining GDPR controls for the personal data you hold.

Organizations using Salesforce are subject to GDPR if they process personal data relating to people in the EU. The regulation sets strict requirements around data minimization, purpose limitation, storage, transparency, and security. These principles must be enforced through both platform configuration and process controls. GDPR applies regardless of where your company is based, so most Salesforce orgs with any EU customers, employees, or prospects have a direct stake in getting this right.

The controller and processor split is central. Salesforce acts as a data processor, responsible for securing the platform. Your organization acts as the data controller, responsible for the collection, use, and retention of personal data. Salesforce provides tools like encryption and audit logs, but it is up to your organization to implement compliant configurations and retention workflows.

Compliance is not a one-time task. GDPR's accountability principle (Article 5(2)) requires organizations to document and continuously demonstrate compliance. In practice, that means regularly reviewing permissions, retention rules, audit logs, and erasure workflows so they align with both the regulation and how data is actually used.

What Are the 7 GDPR Requirements?

When people ask what the 7 GDPR requirements are, they usually mean the seven data-protection principles in Article 5. Each principle maps to something you configure or document in Salesforce. The table below lays them out.

Principle (Article 5)What It RequiresSalesforce Control
Lawfulness, fairness, transparencyProcess data on a valid legal basis, openly.Document lawful basis (Article 6); privacy notices; consent tracking.
Purpose limitationUse data only for the stated purpose.Document field and object purpose; restrict unrelated use.
Data minimizationCollect only what you need.Limit fields; validation rules; data classification.
AccuracyKeep data correct and current.Duplicate rules; validation; update workflows.
Storage limitationKeep data only as long as needed.Retention policies; scheduled deletion or anonymization.
Integrity and confidentialityProtect data with appropriate security (Article 32).Shield encryption; permissions; field-level security; audit trails.
AccountabilityDemonstrate compliance (Article 5(2)).Audit trails; Record of Processing Activities; evidence documentation.

These principles are the backbone of GDPR. Meeting them is less about any single feature and more about consistent configuration, documentation, and review across your Salesforce org.

Lawfulness deserves special attention. Before you process personal data, you need a valid legal basis under Article 6, such as consent, a contract, or legitimate interests, and you should record which basis applies to each processing activity. In Salesforce, that often means documenting the basis at the object or field level and capturing consent where consent is the basis you rely on.

Is Salesforce GDPR Compliant? What the Platform Provides

Salesforce acts as a data processor under GDPR and backs this role with established legal and technical frameworks. Its Processor Binding Corporate Rules (BCRs), approved by EU regulators, ensure consistent privacy protections across Salesforce entities worldwide.

The platform also provides a data processing agreement (DPA) that includes the European Commission's Standard Contractual Clauses, a list of authorized sub-processors, and descriptions of technical safeguards such as encryption and access logging. These documents are publicly available and form the legal basis for compliant data transfers and processing.

Salesforce's security practices are independently verified through a broad set of certifications. Coverage varies by product and infrastructure, so confirm which attestations apply to each service you use. The table below summarizes the core ones.

CertificationWhat It VerifiesApplies To
ISO 27001A formal information security management system (ISMS).Core clouds, Marketing Cloud, and more (per service).
ISO 27017Cloud-specific security controls.Cloud services.
ISO 27018Protection of personal data (PII) in the cloud.Cloud services handling PII.
SOC 1 / SOC 2 Type IIFinancial-reporting and security, availability, and confidentiality controls.Core cloud services.
PCI-DSSControls for handling payment card data.Services in payment scope.

Marketing Cloud is worth calling out. It maintains its own ISO 27001 information security management system and separate security, privacy, and architecture documentation. So GDPR in Salesforce Marketing Cloud (SFMC) centers on managing subscriber consent and preferences, honoring access and erasure requests for subscriber data, and setting retention for marketing data, using SFMC's own consent and preference tools.

For organizations with data residency requirements, Hyperforce lets Salesforce data be hosted in specific regions while maintaining the same security controls, a common consideration for GDPR data transfers. These attestations confirm that Salesforce provides a compliant infrastructure, but they do not guarantee that an individual org is compliant. Misconfigured permission sets, missing encryption, or incomplete erasure workflows can still violate GDPR. Salesforce provides the foundation; your organization is responsible for configuring, monitoring, and documenting its own controls.

The Shared-Responsibility Model: Who Owns What?

Salesforce follows a shared-responsibility model under GDPR. Salesforce covers processor duties through its infrastructure, encryption capabilities, audit tools, and documented sub-processors, and it provides breach notifications and compliance updates through its Trust site. Your organization owns the controller duties. The table below shows the split.

AreaSalesforce (Data Processor)Your Organization (Data Controller)
Infrastructure and platform securityPhysical, network, and cloud security; encryption capabilities.Configure and apply those controls in your org.
Certifications and legal frameworkBCRs, DPA with SCCs, sub-processor list, attestations.Sign the DPA; audit and evidence your own configuration.
Lawful basis and consentNot Salesforce's role.Define lawful basis (Article 6); capture and track consent.
Retention and data subject requestsProvides the tools.Enforce retention; fulfill access, erasure, and portability requests.
Access controlProvides roles, permission sets, field-level security.Configure least-privilege access and review it.
Breach handlingNotifies customers and provides breach information.Notify your supervisory authority within 72 hours where required (Article 33).

Signing the DPA is not enough. As the controller, your organization must regularly audit configurations, enforce least-privilege access, and maintain records that demonstrate compliance decisions and accountability. Note that where a reportable breach occurs, controllers must notify their supervisory authority without undue delay and within 72 hours where feasible (Article 33). A useful rule of thumb: if a decision involves why or how personal data is used, it is a controller decision and therefore yours; if it involves the security of the underlying platform, it is Salesforce's.

Data Subject Rights in Salesforce

GDPR gives individuals specific rights over their personal data, and your organization must be able to honor them within Salesforce. The table below maps the core rights to the article that grants them and how to handle each in Salesforce.

RightGDPR ArticleHandle It in Salesforce With
AccessArticle 15Reports and exports plus a DSAR process to compile the person's data.
RectificationArticle 16Record edits with validation and update workflows.
Erasure ("right to be forgotten")Article 17Delete or anonymize records (including backups and sandboxes).
RestrictionArticle 18Record flags and access controls to limit processing.
PortabilityArticle 20Export the person's data in a structured format (Data Loader, reports).
ObjectionArticle 21Honor opt-outs; update consent and marketing preferences.

Build a repeatable process for these requests rather than handling each one ad hoc. Document who owns the request, how you locate the data across objects, and how you evidence that you fulfilled it within the one-month deadline GDPR allows.

Erasure is the request that most often trips up Salesforce teams. Deleting a record from production is not enough if copies persist in backups, sandboxes, or exports. Plan for those copies, and where full deletion is impractical, anonymize the data so it can no longer identify the person while preserving aggregate reporting.

How to Verify Salesforce's GDPR Posture: A Step-by-Step Checklist

Verifying Salesforce's compliance capabilities is part of demonstrating your own controller responsibilities under the accountability principle. Use the steps below to collect and organize evidence that the platform meets its processor obligations, and keep that evidence with the rest of your accountability records.

1. Collect core legal documents

  • Log in to the Salesforce Trust site and download the current Data Processing Addendum (DPA).
  • Request the Processor Binding Corporate Rules (BCRs) via Salesforce's legal page or support team. These confirm EU regulatory approval.
  • Save a dated copy of each document for audit use.

2. Retrieve SOC 2 reports

  • Access the most recent SOC 2 Type II report for every Salesforce cloud service in use.
  • Focus on the Security, Availability, and Confidentiality sections.
  • Note which controls are managed by Salesforce and which require internal configuration.

3. Map certifications to your services

  • Use the "Applicable Documents by Service" table on Salesforce's compliance site to confirm which attestations apply to each product in your org.
  • Cross-reference this list with your production environments and flag any coverage gaps.

4. Validate encryption and transport settings

  • In Setup, go to Security, then Platform Encryption. Confirm Shield is active and encryption keys are applied to personal or sensitive fields.
  • Verify that TLS 1.2 or higher is enforced at the org level for data in transit.

5. Review cross-border data transfer mechanisms

  • Confirm that the Standard Contractual Clauses (SCCs) are included in your signed DPA.
  • If your org is hosted on Hyperforce, review the region configuration for data residency.
  • Document any transfers outside the EEA and the legal basis for each one.

6. Track administrator GDPR training

  • Use Trailhead or internal tracking systems to confirm GDPR module completion for admins and data owners.
  • Maintain a log to demonstrate that staff handling personal data are trained (Article 39).

7. Store and maintain evidence

  • Compile documentation, screenshots, and reports into a centralized Salesforce GDPR evidence folder.
  • Set a quarterly reminder to update files, validate settings, and refresh certifications.

This proactive process helps your team stay audit-ready and clearly demonstrates how your Salesforce configuration supports GDPR accountability. It also builds a defensible paper trail that simplifies regulator inquiries and strengthens trust with internal stakeholders and external partners.

Documenting Your Compliance for Audits

GDPR audits often come with little warning, so a complete, current evidence pack is critical for responding quickly. Regulators typically request a mix of organizational records and platform-specific artifacts. The table below maps the common requirements to where each lives.

RequirementPlatform ArtifactWhere to Find It
Record of Processing Activities (Article 30)Processing records and data map.Internal register plus your Salesforce object and field inventory.
DPIA (Article 35)Impact assessments for high-risk workflows.Internal documentation referencing the relevant processes.
Consent recordsConsent and preference logs.Consent fields, campaign and subscriber data.
Access reviewPermission set and role reports.Setup > Users, Permission Sets; field-level security reports.
Encryption configurationShield encryption policy and key config.Setup > Platform Encryption.
Retention and erasure evidenceRetention and deletion workflow logs.Scheduled jobs and audit trail.
Incident responseIR documentation and breach notices.Internal records plus Salesforce Trust notifications.

Also maintain a meta-audit trail: records of when privacy policies were reviewed, which users updated security settings, and how long it took to fulfill data-subject requests. These details show that your compliance program is actively managed and auditable. Assign an owner for the evidence pack and review it on a fixed cadence, since stale documentation is as much an audit finding as a missing control.

Security Controls You Still Need to Configure in Salesforce

Salesforce provides the tools for GDPR-grade data protection, but it is up to your organization to configure them correctly. The controls below address the gaps that most often leave orgs exposed, and each maps to a specific GDPR obligation.

ControlSalesforce FeatureGDPR Article It Supports
Encrypt sensitive fieldsShield Platform EncryptionArticle 32 (security)
Protect sandbox dataData Mask (pseudonymize / anonymize)Articles 25 and 32
Least-privilege accessPermission sets, roles, field-level securityArticle 32
Classify personal dataData ClassificationArticles 5 and 30

Misconfigurations, not missing features, are the root cause of most GDPR gaps in Salesforce. Applying these settings consistently across environments keeps personal data protected by design and by default (Article 25). Beyond configuration, monitor for drift: Shield Event Monitoring and login history help you spot unusual access to personal data, and regular permission reviews catch the privilege creep that quietly widens your exposure between audits.

Maintaining GDPR Compliance with Flosum

GDPR compliance in Salesforce comes down to how data is configured, secured, and governed day to day, which is exactly the accountability and shared-responsibility work described above. Flosum helps teams do that work inside Salesforce, so evidence and controls stay close to the data rather than scattered across external tools.

Flosum offers a Salesforce-native deployment option that keeps records inside your org, plus tamper-evident audit trails and version-controlled deployments that give you a complete, verifiable history of changes. That directly supports GDPR's accountability principle (Article 5(2)) and simplifies audit preparation. Access control, backup, sandbox seeding, and erasure workflows are managed through one interface, giving teams clear visibility and control across environments.

Flosum's platform is built to support global compliance obligations at scale, including GDPR, SOX, and HIPAA, and the company holds certifications including ISO 27001, ISO 27701, and SOC 2 Type II. You can explore Flosum's full list of compliance capabilities and certifications to see how it fits your accountability program.

Frequently Asked Questions (FAQ)

What are the 7 GDPR requirements?
The seven GDPR requirements are the data-protection principles in Article 5: lawfulness, fairness, and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality (security); and accountability. Together they govern how you collect, use, secure, retain, and document personal data, and you must be able to demonstrate that you meet each one.
What exactly is GDPR compliance?
GDPR compliance means meeting the EU General Data Protection Regulation's obligations for handling the personal data of people in the EU. In practice that means having a lawful basis for processing, following the Article 5 principles, upholding data subject rights, securing data (Article 32), and documenting everything so you can demonstrate accountability on request.
Does Salesforce comply with GDPR?
Salesforce provides a GDPR-ready platform. As a data processor, it offers EU-approved Binding Corporate Rules, a Data Processing Addendum with Standard Contractual Clauses, and independent certifications. However, that does not make your org compliant by itself. As the data controller, your organization must configure, document, and maintain its own GDPR controls.
What is GDPR in Salesforce Marketing Cloud (SFMC)?
GDPR in Salesforce Marketing Cloud (SFMC) is about how the regulation applies to subscriber and marketing data. It covers capturing and honoring consent and preferences, fulfilling access and erasure requests for subscriber data, and setting retention for marketing data. SFMC maintains its own security and privacy documentation and provides consent and preference management tools.
Is Salesforce a data controller or a data processor under GDPR?
For the personal data you store in Salesforce, Salesforce is the data processor and your organization is the data controller, meaning you decide why and how that data is processed. Salesforce acts as a controller only for the limited data it collects about your use of its services. This distinction sets who is responsible for each GDPR obligation.
How long does Salesforce keep personal data?
Salesforce retains personal data according to your instructions, because retention is the controller's responsibility, not the platform's. Your organization sets retention and deletion rules. Deleted records sit in the Recycle Bin for about 15 days before permanent removal, so you should enforce your own retention and erasure workflows to meet storage-limitation requirements.
Table Of Contents
Author
Stay Up-to-Date
Get flosum.com news in your inbox.

Thank you for subscribing