82 Total
37 High severity
44 Medium severity
1 Low severity
Summary

This is Salesforce's Privacy Statement governing how Salesforce collects, uses, and shares Personal Data when individuals interact with Salesforce's own websites, events, marketing communications, offices, and controller-mode services. The statement authorizes collection of identifiers, financial account information, biometric data (with consent at events), behavioral and device data, and data purchased from third-party providers including job titles, email addresses, IP addresses, LinkedIn URLs, and behavioral inferences for targeted advertising. The document also discloses that Salesforce uses artificial intelligence to process Personal Data, including to develop and deploy AI systems, and states this applies where Salesforce acts as a controller.

Technical / Legal Breakdown

This document is Salesforce's full Privacy Statement (effective August 26, 2025), governing Salesforce's processing of Personal Data as a controller across its websites, services, events, offices, marketing activities, and supplier relationships; it explicitly excludes processing conducted as a data processor on behalf of customers. The statement asserts a broad range of processing purposes including personalized advertising, AI-assisted processing, sales prospecting, phone call recording, CCTV surveillance, biometric data collection at events (where consent is provided), and sharing Personal Data with service providers, affiliates, event sponsors, partners, third-party advertising networks, and public authorities. Notably, the document authorizes the use of artificial intelligence to process Personal Data 'to develop and deploy AI systems,' collects personal identifiers, professional data, behavioral data, and inferences from third-party advertising data providers for tailored advertising, and states that it does not commit to responding to browser DNT signals. The statement references compliance with GDPR, CCPA, the EU-U.S. Data Privacy Framework, Swiss-U.S. Data Privacy Framework, UK Extension to the DPF, EU Processor Binding Corporate Rules, UK Processor Binding Corporate Rules, APEC CBPR and PRP certifications, and standard contractual clauses for international data transfers. Compliance teams should note the controller-versus-processor distinction as a material scoping boundary, the assertion of legitimate interest as a legal basis for a wide range of processing activities including direct marketing and personalized advertising, the collection of special categories of Personal Data (biometric, health) under consent at events, and the cross-border transfer framework relying on DPF certification and SCCs, which may require evaluation under applicable EU, UK, and Swiss data protection law.

Institutional Analysis

Institutional analysis available with Compliance

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Compliance.

Get Compliance

1 important change detected

3 versions captured · Last updated: May 2026

What changed Salesforce removed the direct contact method (email and form link) from the main contact section of its Privacy Statement and replaced it with a new 'Transparency Reports' section. The updated policy now links to Salesforce's annual Transparency Reports (2020-2025) that describe how the company handles government requests for customer data. The change shifts focus from immediate contact channels to published disclosure of government data request practices.
Why this matters This change removes the direct email and web form contact method from the main Privacy Statement but preserves the contact information itself (it remains in the 'Contact Information' section at the end). Users seeking to exercise privacy rights or ask questions can still use the existing form and email, but Salesforce now emphasizes published Transparency Reports as the primary disclosure mechanism for how it handles government data requests. The practical impact on individual consumers is minimal, as the contact channels remain functional; the change primarily shifts documentation toward aggregate disclosure rather than individual inquiry.
View full change record →
Featured — High severity
Featured — Medium severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

82 provisions
12 featured
16 clause types
37 high severity
privacy_rights 22
data_sharing 14
data_collection 10
contract_terms 9
ai_automated 5
liability_limitation 4
data_retention 3
legal_jurisdiction 3
arbitration 2
enforcement_actions 2
policy_changes 2
targeting_restrictions 2
acceptable_use 1
data_usage 1
disclosure_requirements 1
restricted_content 1

Monitoring

Salesforce has updated this document before.

Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →

Compliance Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Compliance includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Get Compliance

Cross-platform context

See how other platforms handle Adequate protection required for international transfers and similar clauses.

Compare across platforms →
Archival ProvenanceSource & Archival Record
Last Captured May 1, 2026 06:15 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000202
Version ID CA-V-002057
SHA-256 906367235ff8fca154a96b8875671b5ce81f50e21d644d966ef899d5c1e5e037
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans