Salesforce

Last Reviewed: 17 Jun 2026

GDPR Addressed

At a Glance

Salesforce's DPA addresses the key GDPR requirements, covering EU, UK, Swiss, US and Asia-Pacific requirements, with SCCs and Binding Corporate Rules in place. Audit rights are structured: third-party certifications are provided first, with on-site audits available once per year on three weeks' notice.

Company & Product Details

HQ

United States

Products

CRM Platform

Product description

Cloud-based customer relationship management platform providing sales, service, marketing, and business applications.

What data is being processed?

First and last name, title, position, employer, contact information (company, email, phone, physical business address), ID data, professional life data, personal life data, localisation data; may include special categories of personal data at customer discretion

Document Details

Date of DPA

10 Apr 2026

Additional date information

Document is titled "Revision April 2026". The primary signatory (Scott Siamas, Senior VP & Associate General Counsel, Salesforce Inc.) signed on 4/10/2026. Other SFDC entity signatories signed between 4/9/2026 and 4/15/2026. No single stated effective date on the face of the document.

What jurisdictions are covered?

The DPA explicitly covers the European Union, the European Economic Area and their member states, Switzerland, and the United Kingdom (defined together as "Europe" in section 12). US law (CCPA/CPRA) is also explicitly addressed (section 1 Definitions). APEC PRP certification is referenced for Asia-Pacific transfers (section 13). EU-US Data Privacy Framework is referenced for eligible US entity transfers (section 12.3).

Is the DPA incorporated into service or customer agreements?

Yes
The DPA explicitly states that it "forms part of the Main Services Agreement or other written or electronic agreement between SFDC and Customer for the purchase of online services" (preamble). It may also be incorporated into individual Order Forms where the Customer entity signing the DPA has executed an Order Form but is not itself a party to the Main Services Agreement (preamble, "HOW THIS DPA APPLIES"). The DPA becomes legally binding upon receipt by SFDC of the signed DPA (section 14).

Location & Transfers

Where is data held or processed?

Not Explicitly Stated The DPA does not explicitly list countries where data is held in its main body. The specific locations of data processing and sub-processor countries are set out in the Infrastructure and Sub-processor Documentation accessible via the SFDC Trust and Compliance webpage (sections 5.2 and 12.4). Section 12.3 acknowledges that European Personal Data may be subject to Third-Country Transfers.

Could there be a transfer out of the EU/UK?

Yes

Are there SCCs or other measures in place?

Yes
Standard Contractual Clauses (EU Commission Implementing Decision 2021/914) are incorporated by reference as an integral part of the DPA (Schedule 1, section 2.2). Both SCC Module 2 (Controller-to-Processor) and SCC Module 3 (Processor-to-Processor) are incorporated (Schedule 1, sections 2.1 and 3). The UK Approved Addendum (ICO template B.1.0, 2 February 2022) applies for UK data transfers (Schedule 1, section 2.15). Swiss Data Protection Laws adaptations apply for Swiss transfers (Schedule 1, section 2.16). The Salesforce Processor BCR also applies as an alternative transfer mechanism for BCR Services (Schedule 1, section 1).

Security Measures

Are the technical measures contractual?

Yes

Detail of measures

SFDC shall maintain appropriate technical and organisational measures for protection of the security, confidentiality and integrity of Customer Data as set forth in the Security, Privacy and Architecture Documentation (accessible at the SFDC Trust and Compliance webpage). SFDC regularly monitors compliance and will not materially decrease the overall security of the Services during a subscription term (section 6.1). SFDC has obtained ISO 27001 certifications and SSAE 18 SOC 2 reports for applicable Services, and commits to maintain these or comparable successors for the duration of the Agreement (section 6.2).

Non Processor Data Use

Does the company process data solely as a processor?

Yes
The DPA is silent on Salesforce claiming any independent controller rights or right to use Customer Data for its own purposes, enrichment of its own database, or product improvement. Section 2.2 restricts processing strictly to Customer's documented instructions: (i) in accordance with the Agreement, (ii) as initiated by Users in using the Services, and (iii) to comply with other documented reasonable instructions from Customer. No language granting SFDC independent controller rights was found. Per the applicable rules, silence defaults to Yes. (clause 2.2)

Subprocessing

General authorization

General
Customer gives SFDC general authorisation to engage both SFDC Affiliates and third-party Sub-processors (section 5.1). SFDC must enter a written agreement with each Sub-processor containing data protection obligations no less protective than those in the Agreement (section 5.1). The current sub-processor list (including processing activities and countries of location) is published in the Infrastructure and Sub-processor Documentation on the SFDC Trust and Compliance webpage (section 5.2). Customers may subscribe to notifications of new Sub-processors before they are authorised. Customers may object to new Sub-processors within 30 days of notice; if SFDC cannot accommodate the objection within 60 days, Customer may terminate the relevant Order Form with a refund of prepaid fees (section 5.3). SCC Option 2 (general authorisation) applies (Schedule 1, section 2.7).

Do all the DPA terms flow down to sub-processors?

Yes
SFDC has entered a written agreement with each Sub-processor containing data protection obligations no less protective than those in the DPA (section 5.1). SFDC is liable for the acts and omissions of its Sub-processors to the same extent SFDC would be liable if performing those services directly (section 5.4). Sub-processors are also subject to Government Access Request commitments from the SCCs and Salesforce Processor BCR (section 8.2).

Is data only processed on the instruction of the controller?

Yes
SFDC shall treat Personal Data as Confidential Information and shall Process Personal Data on behalf of and only in accordance with Customer's documented instructions for the following purposes: (i) Processing in accordance with the Agreement and applicable Order Forms; (ii) Processing initiated by Users in their use of the Services; and (iii) Processing to comply with other documented reasonable instructions provided by Customer (section 2.2). SFDC shall inform Customer immediately if an instruction constitutes a breach of the GDPR or if SFDC is unable to follow Customer's instructions (section 2.4). The DPA and Agreement together constitute Customer's complete and final documented instructions at the time of signature (Schedule 1, section 2.4).

Rights & Responsibilities

Does the company provide assistance for the data subject's rights?

Yes
SFDC shall promptly notify Customer of any Data Subject Request (including requests for access, rectification, restriction of processing, erasure, data portability, objection, or not to be subject to automated individual decision-making) (section 3.1). SFDC shall assist Customer by appropriate technical and organisational measures for fulfilment of Customer's obligation to respond to Data Subject Requests (section 3.2). Where Customer does not have the ability to address a Data Subject Request through the Services, SFDC shall use commercially reasonable efforts to assist upon Customer's request, with Customer responsible for associated costs (section 3.3).

Does the contract include staff confidentiality clauses?

Yes
SFDC shall ensure that its personnel engaged in Processing Personal Data are informed of the confidential nature of the Personal Data, have received appropriate training on their responsibilities, and have executed written confidentiality agreements. Confidentiality obligations survive termination of the personnel engagement. SFDC takes commercially reasonable steps to ensure reliability of personnel and limits access to Personal Data to those performing Services in accordance with the Agreement (section 4.1).

Are there audit rights for the data?

Structured
The DPA sets out a structured audit programme (section 6.3). The primary mechanism is access to third-party certifications and audit reports: upon written request at reasonable intervals, SFDC provides copies of its most recent third-party audits or certifications (e.g. ISO 27001, SOC 2) and third-party sub-processor audit reports (section 6.3.1). On-site audits are available but structured: limited to once per year, require at least three weeks' advance written notice, must occur during normal business hours, must not unreasonably interfere with SFDC's operations, scope and duration must be agreed in advance, and Customer bears the reimbursement costs (sections 6.3.2–6.3.3). SFDC may adapt scope to protect other customers' confidentiality and service levels. Third-party auditors must not be SFDC competitors and must sign an NDA (section 6.3.4). Audit rights under the SCCs and BCR are channelled through this same section 6.3 process (Schedule 1, sections 1.2 and 2.6).

Is there assistance with DPIA requests?

Yes
Upon Customer's request, SFDC shall provide reasonable cooperation and assistance needed to fulfil Customer's obligation under Data Protection Laws and Regulations to carry out a data protection impact assessment (DPIA) related to Customer's use of the Services, to the extent Customer does not otherwise have access to the relevant information and it is available to SFDC (section 6.4).

How much notice is provided for data breaches?

SFDC shall notify Customer without undue delay after becoming aware of any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Data (a "Customer Data Incident") (section 7). No specific number of hours is stated in the DPA body; notification is "without undue delay" in line with GDPR Article 33 convention. SFDC shall make reasonable efforts to identify the cause and remediate it. Obligations do not apply to incidents caused by Customer or Customer's Users.

What happens to the data on termination?

SFDC shall return Customer Data to Customer and, to the extent allowed by applicable law, delete Customer Data in accordance with the procedures and timeframes specified in the Security, Privacy and Architecture Documentation (section 9). Until Customer Data is deleted or returned, SFDC shall continue to comply with the DPA. Certification of deletion is provided only upon Customer's written request (Schedule 1, section 2.5).