
Salesforce and GDPR/CCPA: How to Manage Personal Data Compliantly
Since GDPR took effect in 2018 — and with CCPA and a growing wave of US state privacy laws — companies using Salesforce as their central CRM face strict obligations around personal data collection and processing. Here's how to stay compliant without disrupting your sales operations.
Salesforce Objects Designed for Privacy Compliance
- Individual Object: a record linked to each Contact/Lead that stores privacy preferences and consent flags
- Data Privacy Records: manages marketing consent and communication preferences
- Privacy Center (add-on module): automates data access requests and deletion (right to erasure) workflows
5 Compliance Checkpoints to Verify
- 1. Tracked consent: every lead must have documented consent with date, source, and method of collection
- 2. Right to erasure: a defined process to delete all data linked to a contact on request — within legal deadlines
- 3. Right of access: ability to export all data linked to an individual within 30 days (GDPR) or 45 days (CCPA)
- 4. Data retention limits: automatic archiving or deletion of inactive data after a defined period
- 5. Access security: profiles and permissions scoped to the minimum necessary — principle of least privilege
Practical Salesforce Configuration
- Enable privacy settings in Setup > Privacy Center
- Build a Flow to handle erasure requests automatically
- Configure Data Retention Policies for inactive records
- Add consent capture fields to web forms via Web-to-Lead
GDPR/CCPA compliance in Salesforce isn't a one-time project — it's an ongoing process. Audit your access logs, stored data, and collected consents regularly to stay ahead of regulatory changes.
Real-World Example
A B2B insurance brokerage receives a data erasure request from a prospect. With their Salesforce Privacy Center configuration, the team identifies all linked records (Lead, Contact, Case, archived emails) in 10 minutes and triggers the automated deletion process via a dedicated Flow. An execution report is generated and retained as compliance proof in case of a regulatory audit. Without this automation, the manual process would have taken 3–4 hours and carried a real risk of missing records.
Pour aller plus loin
Need a privacy compliance audit of your Salesforce org? Our team can help. See our security and compliance services.
Contactez-nous
Notre équipe est disponible du lundi au vendredi de 9h à 18h pour répondre à vos questions.