Salesforce
Last Reviewed: 17 Jun 2026
At a Glance
Salesforce's DPA addresses the key GDPR requirements, covering EU, UK, Swiss, US and Asia-Pacific requirements, with SCCs and Binding Corporate Rules in place. Audit rights are structured: third-party certifications are provided first, with on-site audits available once per year on three weeks' notice.
Company & Product Details
HQ
United States
Products
CRM Platform
Product description
Cloud-based customer relationship management platform providing sales, service, marketing, and business applications.
What data is being processed?
First and last name, title, position, employer, contact information (company, email, phone, physical business address), ID data, professional life data, personal life data, localisation data; may include special categories of personal data at customer discretion
Document Details
Date of DPA
10 Apr 2026
Additional date information
Document is titled "Revision April 2026". The primary signatory (Scott Siamas, Senior VP & Associate General Counsel, Salesforce Inc.) signed on 4/10/2026. Other SFDC entity signatories signed between 4/9/2026 and 4/15/2026. No single stated effective date on the face of the document.
What jurisdictions are covered?
The DPA explicitly covers the European Union, the European Economic Area and their member states, Switzerland, and the United Kingdom (defined together as "Europe" in section 12). US law (CCPA/CPRA) is also explicitly addressed (section 1 Definitions). APEC PRP certification is referenced for Asia-Pacific transfers (section 13). EU-US Data Privacy Framework is referenced for eligible US entity transfers (section 12.3).
Is the DPA incorporated into service or customer agreements?
Link
Location & Transfers
Where is data held or processed?
Not Explicitly Stated The DPA does not explicitly list countries where data is held in its main body. The specific locations of data processing and sub-processor countries are set out in the Infrastructure and Sub-processor Documentation accessible via the SFDC Trust and Compliance webpage (sections 5.2 and 12.4). Section 12.3 acknowledges that European Personal Data may be subject to Third-Country Transfers.
Could there be a transfer out of the EU/UK?
Are there SCCs or other measures in place?
Security Measures
Are the technical measures contractual?
Detail of measures
SFDC shall maintain appropriate technical and organisational measures for protection of the security, confidentiality and integrity of Customer Data as set forth in the Security, Privacy and Architecture Documentation (accessible at the SFDC Trust and Compliance webpage). SFDC regularly monitors compliance and will not materially decrease the overall security of the Services during a subscription term (section 6.1). SFDC has obtained ISO 27001 certifications and SSAE 18 SOC 2 reports for applicable Services, and commits to maintain these or comparable successors for the duration of the Agreement (section 6.2).
Non Processor Data Use
Does the company process data solely as a processor?
Subprocessing
General authorization
Do all the DPA terms flow down to sub-processors?
Is data only processed on the instruction of the controller?
Rights & Responsibilities
Does the company provide assistance for the data subject's rights?
Does the contract include staff confidentiality clauses?
Are there audit rights for the data?
Is there assistance with DPIA requests?
How much notice is provided for data breaches?
SFDC shall notify Customer without undue delay after becoming aware of any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Data (a "Customer Data Incident") (section 7). No specific number of hours is stated in the DPA body; notification is "without undue delay" in line with GDPR Article 33 convention. SFDC shall make reasonable efforts to identify the cause and remediate it. Obligations do not apply to incidents caused by Customer or Customer's Users.
What happens to the data on termination?
SFDC shall return Customer Data to Customer and, to the extent allowed by applicable law, delete Customer Data in accordance with the procedures and timeframes specified in the Security, Privacy and Architecture Documentation (section 9). Until Customer Data is deleted or returned, SFDC shall continue to comply with the DPA. Certification of deletion is provided only upon Customer's written request (Schedule 1, section 2.5).