Your personal data may be transferred to and stored in the United States or other countries that may have different (potentially weaker) privacy laws than your home country.
This analysis describes what Salesforce's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the operational framework for cross-border data flows, defining how Salesforce manages compliance obligations under GDPR Article 46 and similar international data protection regimes when transferring data to jurisdictions without formal adequacy determinations.
EU, UK, and Swiss users' data is transferred to the US under Standard Contractual Clauses, Binding Corporate Rules, and Data Privacy Framework certifications — providing some legal safeguards, but these have been subject to legal challenge in the past.
How other platforms handle this
Whenever we transfer personal data internationally, we use tools and transfer agreements to: make sure the data transfer complies with applicable law; and help to give your data the same level of protection as it has in the EU...
we also transfer personal information to all other countries in which Adobe or its affiliates, providers, and partners operate. We carry out these transfers in compliance with applicable laws – for example, by putting data transfer agreements in place...
we may share data between our affiliates for the safety and security of our users and may take necessary actions if we believe you have violated these Terms, including banning you from our Services and/or our affiliates' services...
"Your Personal Data may be transferred to and stored by us in the United States and by our affiliates and third-parties listed in Section 6 above. Therefore, your Personal Data may be processed and stored outside your country or jurisdiction, including in places that are not subject to an adequacy decision by the European Commission or your local legislature or regulator, and that may not provide for the same level of data protection. We ensure that the recipient of your Personal Data provides an adequate level of protection and security, by entering into appropriate agreements, including, where required, standard contractual clauses or an alternative mechanism for the transfer of Personal Data as approved by the European Commission (Art. 46 GDPR) or other applicable regulators or legislators.Excerpt from Salesforce's Privacy Statement
Salesforce relies on SCCs, EU and UK Binding Corporate Rules, the EU-U.S./Swiss-U.S.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
ConductAtlas detected a major restructuring of Meta’s privacy policy that removed detailed consumer rights disclosures and relocated them to separate documents.
Your genetic data may be transferred to a new owner as a business asset. Here is what the Terms of Service actually say and what you can do right now.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes the operational framework for cross-border data flows, defining how Salesforce manages compliance obligations under GDPR Article 46 and similar international data protection regimes when transferring data to jurisdictions without formal adequacy determinations.
EU, UK, and Swiss users' data is transferred to the US under Standard Contractual Clauses, Binding Corporate Rules, and Data Privacy Framework certifications — providing some legal safeguards, but these have been subject to legal challenge in the past.
ConductAtlas has identified this type of provision across 287 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Salesforce.