Salesforce maintains a privacy information section covering how they collect, use, and protect personal data across their products and website.
The scope of data Salesforce collects, the legal bases for processing, international transfer mechanisms, and data subject rights (including access, deletion, and portability) are defined in the privacy documentation linked from this section.
Cross-platform context
See how other platforms handle Privacy Information Hub and similar clauses.
Compare across platforms →The privacy documentation linked here governs how Salesforce handles personal data for customers, website visitors, and employees of Salesforce's business customers — with direct implications for GDPR and CCPA compliance.
(1) REGULATORY FRAMEWORK: Privacy documentation implicates GDPR (Regulation 2016/679, enforced by EU Data Protection Authorities), CCPA/CPRA (Cal. Civ. Code §1798.100 et seq., enforced by the California Privacy Protection Agency), UK GDPR (Data Protection Act 2018, enforced by the ICO), PIPEDA (Canada, enforced by the OPC), and potentially LGPD (Brazil). As a processor of customer data, Salesforce's privacy practices also engage GDPR Article 28 requirements. (2)
Compliance intelligence locked
Regulatory citations, enforcement risk, and due diligence action items.
Watcher: regulatory citations. Professional: full compliance memo.