As of September 12, 2025, the EU Data Act gives Salesforce customers in the EU the right to access, transfer, or delete their data, providing more control and flexibility over how their information is used.
This analysis describes what Salesforce's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The clause operationalizes EU Data Act compliance mechanisms, establishing procedural requirements for data access, portability, and customer control rights that affect how Salesforce manages and provides access to customer-generated data within its systems.
EU customers now have enforceable rights to request access to, portability of, and deletion of their data held by Salesforce under the EU Data Act. This directly affects data sovereignty and the ability to switch providers without losing access to business data.
How other platforms handle this
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
Further, you may take legal actions in relation to any potential breach of your rights regarding the processing of your Personal Information, as well as to lodge complaints before the competent data prot...
The EU Data Act (Regulation 2023/2854), effective September 12, 2025, imposes mandatory data portability and deletion obligations on data holders like Salesforce.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The clause operationalizes EU Data Act compliance mechanisms, establishing procedural requirements for data access, portability, and customer control rights that affect how Salesforce manages and provides access to customer-generated data within its systems.
EU customers now have enforceable rights to request access to, portability of, and deletion of their data held by Salesforce under the EU Data Act. This directly affects data sovereignty and the ability to switch providers without losing access to business data.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Salesforce.