9 Total
0 High severity
6 Medium severity
3 Low severity
Summary

This document establishes Salesforce's practices for collecting, using, and sharing personal information from individuals who interact with Salesforce websites, attend events, receive marketing communications, or otherwise engage with the company. The statement authorizes Salesforce to share personal data with third parties including event sponsors, partners, and advertising networks for purposes including advertising on non-Salesforce websites. Individuals in the EU, UK, and California are granted specific rights including data access, deletion, and objection to automated decision-making, exercisable through Salesforce's privacy request form or email to privacy@salesforce.com.

Technical / Legal Breakdown

This document is Salesforce's full Privacy Statement (effective August 26, 2025), governing the collection, use, sharing, and processing of Personal Data by Salesforce, Inc. and its affiliates acting as data controllers, explicitly excluding Salesforce's role as a processor on behalf of enterprise customers. The statement asserts that Personal Data is collected across websites, events, marketing communications, office visits, and service interactions for purposes including personalized advertising, sales prospecting, research, and legal compliance; the terms authorize sharing with service providers, affiliates, event sponsors, partners, AppExchange partners, and public authorities. Notably, the document addresses cross-border data transfers through multiple mechanisms including EU-U.S. and Swiss-U.S. Data Privacy Frameworks, EU and UK Binding Corporate Rules, and Standard Contractual Clauses, and explicitly discloses advertising-related data sharing that triggers opt-out rights, including for those under 16; the document is explicit that it does not govern data processed in Salesforce's processor capacity, which is a significant carve-out affecting enterprise customer data handled through Salesforce's CRM and cloud platforms. The statement engages GDPR, CCPA, UK GDPR, APEC CBPR and PRP frameworks, and the EU-U.S. Data Privacy Framework administered by the U.S. Department of Commerce and enforceable by the FTC; jurisdiction-dependent rights such as data portability, automated decision-making objection, and minor-specific opt-in requirements create materially different compliance obligations depending on where data subjects are located.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial

1 important change detected

3 versions captured · Last updated: May 2026

What changed Salesforce removed the direct contact method (email and form link) from the main contact section of its Privacy Statement and replaced it with a new 'Transparency Reports' section. The updated policy now links to Salesforce's annual Transparency Reports (2020-2025) that describe how the company handles government requests for customer data. The change shifts focus from immediate contact channels to published disclosure of government data request practices.
Why this matters This change removes the direct email and web form contact method from the main Privacy Statement but preserves the contact information itself (it remains in the 'Contact Information' section at the end). Users seeking to exercise privacy rights or ask questions can still use the existing form and email, but Salesforce now emphasizes published Transparency Reports as the primary disclosure mechanism for how it handles government data requests. The practical impact on individual consumers is minimal, as the contact channels remain functional; the change primarily shifts documentation toward aggregate disclosure rather than individual inquiry.
View full change record →
Medium — 6 provisions
Low — 3 provisions

Monitoring

Salesforce has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle Third-Party Data Sharing for Advertising and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
FAA
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
VPPA
United States Federal
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured May 1, 2026 06:15 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000202
Version ID CA-V-002057
SHA-256 906367235ff8fca154a96b8875671b5ce81f50e21d644d966ef899d5c1e5e037
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans