This provision describes a technical process that replaces PII and proprietary business data with non-identifiable tokens before prompts are transmitted to the LLM, with the original data restored after the response is generated.
This analysis describes what Salesforce Einstein's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision describes a technical de-identification mechanism that operates on data in transit to third-party LLMs, which is directly relevant to compliance obligations under GDPR, CCPA, and HIPAA regarding the processing of personal and sensitive data by AI systems. The effectiveness of this mechanism as a de-identification or anonymization control under applicable law depends on the specific tokenization methodology and whether re-identification risk is adequately mitigated.
Interpretive note: The adequacy of the described tokenization mechanism as de-identification or anonymization under GDPR, CCPA, and HIPAA depends on technical implementation details not fully specified in the document.
Under this provision, PII and proprietary business data in prompts are replaced with non-identifiable tokens before transmission to third-party LLMs, with the document stating this process shields confidential information while preserving response quality. Enterprise customers processing sensitive personal data through Salesforce AI features should assess whether this tokenization mechanism satisfies their specific de-identification or anonymization obligations under applicable data protection law.
Cross-platform context
See how other platforms handle Data Masking of PII Before LLM Transmission and similar clauses.
Compare across platforms →"Complementing this, data masking is the process that replaces sensitive Personally Identifiable Information (PII) or proprietary business data with non-identifiable tokens before the prompt is sent to the LLM. This shields confidential information while still providing the necessary context for the LLM to generate a personalized and useful response.Excerpt from Salesforce Einstein's Salesforce Trusted AI Principles
(1) REGULATORY LANDSCAPE: This provision engages GDPR pseudonymization and anonymization standards, CCPA definitions of personal information and de-identified data, and HIPAA Safe Harbor and Expert Determination de-identification standards for covered entities.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision describes a technical de-identification mechanism that operates on data in transit to third-party LLMs, which is directly relevant to compliance obligations under GDPR, CCPA, and HIPAA regarding the processing of personal and sensitive data by AI systems. The effectiveness of this mechanism as a de-identification or anonymization control under applicable law depends on the specific tokenization methodology and …
Under this provision, PII and proprietary business data in prompts are replaced with non-identifiable tokens before transmission to third-party LLMs, with the document stating this process shields confidential information while preserving response quality. Enterprise customers processing sensitive personal data through Salesforce AI features should assess whether this tokenization mechanism satisfies their specific de-identification or anonymization obligations under applicable data protection …
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Salesforce Einstein.