Track 3 platforms and get the weekly governance digest. No credit card required.
This page describes what the document states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability may vary by jurisdiction. Methodology
This is Salesforce's Privacy Statement governing how Salesforce collects, uses, and shares Personal Data when individuals interact with Salesforce's own websites, events, marketing communications, offices, and controller-mode services. The statement authorizes collection of identifiers, financial account information, biometric data (with consent at events), behavioral and device data, and data purchased from third-party providers including job titles, email addresses, IP addresses, LinkedIn URLs, and behavioral inferences for targeted advertising. The document also discloses that Salesforce uses artificial intelligence to process Personal Data, including to develop and deploy AI systems, and states this applies where Salesforce acts as a controller.
This document is Salesforce's full Privacy Statement (effective August 26, 2025), governing Salesforce's processing of Personal Data as a controller across its websites, services, events, offices, marketing activities, and supplier relationships; it explicitly excludes processing conducted as a data processor on behalf of customers. The statement asserts a broad range of processing purposes including personalized advertising, AI-assisted processing, sales prospecting, phone call recording, CCTV surveillance, biometric data collection at events (where consent is provided), and sharing Personal Data with service providers, affiliates, event sponsors, partners, third-party advertising networks, and public authorities. Notably, the document authorizes the use of artificial intelligence to process Personal Data 'to develop and deploy AI systems,' collects personal identifiers, professional data, behavioral data, and inferences from third-party advertising data providers for tailored advertising, and states that it does not commit to responding to browser DNT signals. The statement references compliance with GDPR, CCPA, the EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the DPF, EU Processor Binding Corporate Rules, UK Processor Binding Corporate Rules, APEC CBPR and PRP certifications, and standard contractual clauses for international data transfers. Compliance teams should note the controller-versus-processor distinction as a material scoping boundary, the assertion of legitimate interest as a legal basis for a wide range of processing activities including direct marketing and personalized advertising, the collection of special categories of Personal Data (biometric, health) under consent at events, and the cross-border transfer framework relying on DPF certification and SCCs, which may require evaluation under applicable EU, UK, and Swiss data protection law.
Institutional analysis available with Compliance
Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Compliance.
Get Compliance1 important change detected
3 versions captured · Last updated: May 2026
Every distinct legal provision identified in this document. Featured provisions appear above with analysis.
Monitoring
Salesforce has updated this document before.
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
Compliance Governance Intelligence
Need provision-level monitoring and regulatory mapping?
Compliance includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.
Get ComplianceCross-platform context
See how other platforms handle Adequate protection required for international transfers and similar clauses.
Compare across platforms →Governance Monitoring
Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.