The statement discloses that Personal Data may be transferred to and stored in the United States and by affiliates and third parties in other jurisdictions, potentially in locations with different data protection standards, and states that Salesforce relies on SCCs, DPF certification (EU-U.S., Swiss-U.S., and UK Extension), and other approved mechanisms as transfer safeguards.
This analysis describes what Salesforce's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the legal mechanisms Salesforce asserts for cross-border data transfers, which are subject to ongoing regulatory and judicial scrutiny; DPF adequacy status and SCC compliance require monitoring, as changes in either framework could affect the lawfulness of transfers.
Interpretive note: DPF adequacy status is subject to potential future legal or political challenge; the operational fallback to SCCs and the specific SCC module applicable to each transfer relationship is not specified in the excerpted text.
Under this provision, Personal Data of individuals in the EU, UK, Switzerland, and other jurisdictions may be transferred to the United States under DPF certification or SCCs. The agreement states that individuals in the EEA or UK who have unresolved complaints may contact TRUSTe as a dispute resolution provider or lodge a complaint with their competent supervisory authority.
Cross-platform context
See how other platforms handle International Data Transfers and DPF Certification and similar clauses.
Compare across platforms →"Your Personal Data may be transferred to, and stored by us, in the United States and by our affiliates and third parties (as disclosed in the full Privacy Statement) as listed in the Privacy Statement. Therefore, your Personal Data may be processed and stored outside your country or jurisdiction, including in places that may not provide the same level of protection. As described in the 'International transfers of Personal Data' section of our full Privacy Statement, we have implemented safeguards to ensure an adequate level of protection where your Personal Data is transferred, including, where required, standard contractual clauses or an alternative mechanism for the transfer of Personal Data as approved by the European Commission. Salesforce also commits to comply with the EU-U.S. Data Privacy Framework, the Swiss-U.S. Data Privacy Framework, and the UK Extension to the EU-U.S. Data Privacy Framework (collectively, the 'DPF') and certifies its adherence to the DPF Principles as set forth by the U.S. Department of Commerce.Excerpt from Salesforce's Privacy Statement
(1) REGULATORY LANDSCAPE: This provision engages GDPR Chapter V (international transfers), UK GDPR transfer mechanisms, Swiss Federal Act on Data Protection, and the EU-U.S.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes the legal mechanisms Salesforce asserts for cross-border data transfers, which are subject to ongoing regulatory and judicial scrutiny; DPF adequacy status and SCC compliance require monitoring, as changes in either framework could affect the lawfulness of transfers.
Under this provision, Personal Data of individuals in the EU, UK, Switzerland, and other jurisdictions may be transferred to the United States under DPF certification or SCCs. The agreement states that individuals in the EEA or UK who have unresolved complaints may contact TRUSTe as a dispute resolution provider or lodge a complaint with their competent supervisory authority.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Salesforce.