Privacy Overview
Trust is our #1 value.
Our customers trust us to help them build meaningful relationships with their own customers. Salesforce’s top priority is the security and privacy of the data that we are entrusted to protect.
Trust is our #1 value.
Our customers trust us to help them build meaningful relationships with their own customers. Salesforce’s top priority is the security and privacy of the data that we are entrusted to protect.
As the #1 CRM platform, Salesforce provides companies like yours with the tools to build trust while enhancing customer experiences. Gain increased transparency and control of your customers’ data, all while harnessing the power of that data to connect with customers in new ways.
Helping our customers operate on a global scale is something we do every day. We continuously monitor the global privacy landscape and adapt our privacy program accordingly. Whether it is the European Union’s GDPR, the US’s healthcare-focused privacy law (HIPAA), California’s new privacy law (CCPA), or the new Brazilian privacy law (LGPD), we are here to assist our customers on their compliance journeys. The trusted Salesforce Cloud makes it possible for companies to go beyond compliance and leverage the world’s #1 CRM to turn privacy into an opportunity to enhance the customer experience.
The General Data Protection Regulation (GDPR) is a comprehensive data protection law that regulates the use of personal data of EU residents and provides individuals rights to exercise control over their data. The GDPR does not only apply to European companies, it extends to any organization worldwide that targets or offers services or products to EU residents.
The GDPR requires companies to be transparent and accountable for their use of personal data, and to be able to demonstrate this to both regulators and the individuals concerned. There is no requirement for personal data to stay in the EU, but transfers outside of the European Economic Area are restricted, meaning that unless the European Commission has assessed the country’s privacy regime and declared it to be “adequate”, the data must be further protected by contract, or other EU-approved means. For any transfers to non-adequate countries, Salesforce’s data processing addendum incorporates such EU-approved means, namely our Processor Binding Corporate Rules and the European Commission’s standard contractual clauses. Customers can rely on these protections to transfer EU personal data using our services.
Data Processing Addendum
Get guidance and best practices to help you meet the requirements of whichever regulations and policies your company must comply with.
Salesforce’s Data Transfer Mechanism FAQs: Binding Corporate Rules and Standard Contractual Clauses
Answers to common questions about international data transfers mechanisms such as BCRs, Privacy Shield and Standard Contractual Clauses.
EU Privacy Law Basics
Learn about the General Data Protection Regulation (GDPR) and how to comply.
Japan and countries throughout the Asia-Pacific region (APAC) have their own data protection laws, which vary from light-touch to more prescriptive.
Despite the patchwork of laws and regulations, there is a common non-binding baseline formed by the APEC Privacy Framework. The Asia-Pacific Economic Cooperation (APEC) is a regional economic forum aimed at increasing prosperity for the region by promoting balanced, inclusive, sustainable, innovative and secure growth and accelerating regional economic integration. As part of this cooperation, the APEC Privacy Framework was adopted. The Framework sets out a series of privacy principles to ensure continued trade and economic growth and, in particular, free flow of personal data within the APEC region. Companies can certify under the Privacy Recognition for Processors (PRP) Framework to demonstrate compliance with the APEC Privacy Framework and help their customers on their privacy journey.
Salesforce was one of the first companies globally to obtain PRP certification. Find more information here.
Japan’s Act on the Protection of Personal Information (APPI) is based on principles similar to the GDPR. In 2019, Japan and the EU acknowledged each other’s data protection frameworks to be “adequate”, thus allowing personal data to flow freely between the two economies without the need for further protections such as binding corporate rules or the European Commission’s standard contractual clauses.
Since 2008, Salesforce has also been PrivacyMark certified. PrivacyMark is a Japanese privacy certification that focuses on enhancing individuals' awareness of the protection of personal data and incentivizing businesses to build trusted connections with their customers. To obtain the certification, companies must show they take appropriate measures to protect personal data of individuals. The requirements for PrivacyMark certification are governed by the Japan Institute for Promotion of Digital Economy and Community.
Japan Privacy Law FAQ
プライバシー保護の状況(日本)よくあるご質問(FAQ)
Get the Australian and New Zealand and New Zealand Privacy Laws FAQ
In the United States, there is no comprehensive privacy law that applies across all industries and types of personal data. Rather, a patchwork of federal and state laws govern how businesses must manage personal data. These include federal laws that focus on certain industries, sensitive data types, or processing activities like direct marketing. For example, health-related data about patients and individuals collected by businesses in the healthcare industry is regulated by the federal Health Insurance Portability and Accountability Act (HIPAA), personal data collected and used by financial institutions is covered by the Gramm-Leach-Bliley Act (GLBA), the sending of commercial emails is covered by the CAN-SPAM Act, and children's data is regulated by the Family Educational Rights and Privacy Act (FERPA) and the Children’s Online Privacy Protection Act (COPPA). Additionally, US state laws, such as the California Consumer Privacy Act (CCPA), impact how companies conduct business by regulating how they process and protect the personal data of individuals that reside in those states.
Get the FERPA and COPPA FAQ
Get the CCPA FAQ
Learn more about CCPA with the CCPA: Fiction versus Fact White Paper
Salesforce Chairman and Co-CEO Marc Benioff has advocated for a national privacy law to be implemented in the United States, so that a US individual’s privacy is not dependent on their ZIP code. Similar to the GDPR in the EU, a national US privacy law would require that companies disclose how they collect and use personal data and recognize individuals’ rights to have a say in how businesses manage their data.
Salesforce’s cloud services are designed to help customers comply with this patchwork of US federal and state laws, including for some services—like Health Cloud and Financial Services Cloud—complying with the special requirements of HIPAA and GLBA.
Take the Trail
Get the HIPAA FAQ
Get the Financial Services FAQ
The Personal Information Protection and Electronic Documents Act (PIPEDA) is Canada’s national privacy law that regulates how private-sector organizations collect, use, and disclose personal data when engaged in commercial activities. PIPEDA provides specific protections for individuals’ personal data, including individuals’ rights to consent to the collection, use or disclosure of their personal data, to access their personal data held by an organization, and to challenge the accuracy of that personal data.
In Latin America and the Caribbean, a number of national and local laws govern how organizations use personal data. Several Latin American and Caribbean countries have enacted privacy rules that are loosely based on European requirements, but sectoral and industry-specific rules still remain throughout the region. Brazil has enacted a national law (LGPD) which is similar to the GDPR but with its own Brazil-specific requirements. Salesforce is closely monitoring developments around LGPD and other laws in Latin American and Caribbean countries. Salesforce’s data processing addendum, other privacy and product documentation, as well as our internal practices are designed for global use and we update them as necessary to continue to deliver our services to customers in Latin America and the Caribbean in accordance with legal requirements.
Get the Brazil Privacy Law FAQ
Obtenha as perguntas frequentes sobre a LGPD
Across sales, service, marketing, and more, we’re dedicated to keeping your customers’ data safe and secure.
As data intelligence becomes more prevalent as a way for companies to understand and serve customers better, it is critical that companies remain accountable for safeguarding the privacy and security of individuals’ data. As the #1 CRM platform, Salesforce provides companies like yours with the tools to build trust while enhancing customer experiences. Gain increased transparency and control of your customers' data, all while harnessing the power of that data to connect with customers in new ways.
Accountability and Transparency
Salesforce offers customers a robust data processing addendum containing strong privacy commitments. This addendum contains data transfer mechanisms to enable our customers to lawfully transfer personal data to Salesforce from any geography by relying (depending on the service) on Salesforce’s Processor Binding Corporate Rules or the European Commission’s standard contractual clauses. This addendum also contains specific provisions to assist customers in their compliance with applicable data protection laws.
Security
Salesforce has security built into every layer of the Platform. The infrastructure layer comes with replication, backup, and disaster recovery planning. Network services have encryption in transit and advanced threat detection. Our application services implement identity, authentication, and user permissions. We also offer an additional layer of trust with Salesforce Shield, including Platform Encryption, Event Monitoring, and Field Audit Trail.
Honoring Privacy Rights of Individual
You may need to access, export, delete or update customer data in order to comply with data protection regulations. Platform offers customers a rich set of features to help you meet your legal obligations. Topics like restriction of processing, consent, portability and the right to be forgotten are all covered in our Help & Training Documentation.
Privacy Compliance Automation
Customer 360 Privacy Center is your complete privacy and data management solution that simplifies data privacy, compliance, and archiving.
At Salesforce, we believe respecting privacy is a tremendous opportunity for marketers to deliver greater value, and a deeper, more trusted relationship with customers. To navigate customer privacy and to continue to blaze a trail in marketing, you need to balance customer-centricity, governance, and compliance — and Marketing Cloud can help you do just that.
Accountability and Transparency
Salesforce offers customers a robust data processing addendum containing strong privacy commitments. This addendum contains data transfer mechanisms to enable our customers to lawfully transfer personal data to Salesforce from any geography by relying (depending on the service) on Salesforce’s Processor Binding Corporate Rules or the European Commission’s standard contractual clauses. This addendum also contains specific provisions to assist customers in their compliance with applicable data protection laws.
Security
Marketing Cloud provides our customers with a secure solution in accordance with our Trust and Compliance documentation.
Honoring Privacy Right of Individuals
You may need to access, export, delete or update customer data in order to comply with data protection and privacy regulations. Marketing Cloud offers a rich set of features to help you meet your obligations under the law for customers. Topics like restriction of processing, consent, portability and the right to be forgotten are all covered in our Help & Training Documentation.
B2C Commerce Cloud (formerly Commerce Cloud) empowers retailers to unify customer experiences across all points of commerce — web, social, mobile, and in-store. From shopping to customer service, B2C Commerce delivers 1-to-1 shopping experiences that delight customers, increasing engagement, loyalty, and conversion. Nothing is more important to us than enabling the success of our clients. This commitment defines who we are and everything we do. That extends to building tools and features that help merchants comply with regulatory policies and serving as a trusted partner to ensure commerce operations remain reliable, compliant, and secure.
Accountability and Transparency
Salesforce offers customers a robust data processing addendum containing strong privacy commitments. This addendum contains data transfer mechanisms to enable our customers to lawfully transfer personal data to Salesforce from any geography by relying (depending on the service) on Salesforce’s Processor Binding Corporate Rules or the European Commission’s standard contractual clauses. This addendum also contains specific provisions to assist customers in their compliance with applicable data protection laws.
Security
Protecting the security and privacy of customer and cardholder data is as much of a priority for Salesforce and B2C Commerce as it is for our merchants. B2C Commerce continuously implements robust technical and organizational security controls to ensure that commerce operations remain reliable, compliant, and secure — all without adding extra costs or infrastructure. For more information on Commerce Cloud Trust and Compliance, refer to our documentation in the link below.
Honoring Privacy Rights of Individuals
You may need to access, export, delete or update customer data in order to comply with data protection and privacy regulations. B2C Commerce offers a rich set of features to help you meet your obligations under the law for customers. Topics like restriction of processing, consent, portability and the right to be forgotten are all covered in our Help & Training Documentation.
At Salesforce, we see privacy as a tremendous opportunity for marketers to deliver greater value and a deeper, more trusted relationship with customers and partners. To navigate regulatory policies and to continue to blaze a trail in marketing, you need to balance customer-centricity, governance, and compliance. Marketing Cloud Account Engagement allows marketers to face regulations with confidence, and to use privacy as a catalyst for customer centricity.
Accountability and Transparency
Salesforce offers customers a robust data processing addendum containing strong privacy commitments. This addendum contains data transfer mechanisms to enable our customers to lawfully transfer personal data to Salesforce from any geography by relying (depending on the service) on Salesforce’s Processor Binding Corporate Rules or the European Commission’s standard contractual clauses. This addendum also contains specific provisions to assist customers in their compliance with applicable data protection laws.
Security
Marketing Cloud Account Engagement provides our customers with a secure solution in accordance with our Trust and Compliance documentation.
Honoring Privacy Rights of Individuals
You may need to access, export, delete or update customer data in order to comply with data protection and privacy regulations. Marketing Cloud Account Engagement offers a rich set of features to help you meet your obligations under the law for customers. Topics like restriction of processing, consent, portability and the right to be forgotten are all covered in the links below.
Learn about Unsubscribe
Learn more about the Email Preference Center
Learn more about Opt Out
Learn more about Restriction of Processing
Learn more about Data Portability
Learn more about Deletion
At Salesforce, we're committed to protecting personal data and we see privacy as an opportunity for Quip to forge a deeper partnership with our customers by supporting them on their compliance journey.
Accountability and Transparency
Salesforce offers customers a robust data processing addendum containing strong privacy commitments. This addendum contains data transfer mechanisms to enable our customers to lawfully transfer personal data to Salesforce from any geography by relying (depending on the service) on Salesforce’s Processor Binding Corporate Rules or the European Commission’s standard contractual clauses. This addendum also contains specific provisions to assist customers in their compliance with applicable data protection laws.
Security
Quip provides our customers with a secure solution in accordance with our Trust and Compliance documentation.
Honoring Privacy Rights of Individual
You may need to access, export, delete or update customer data in order to comply with data protection and privacy regulations. Quip offers a rich set of features to help you meet your obligations under the law for customers. Topics like restriction of processing, consent, portability and the right to be forgotten are all covered in our Help & Training Documentation.
In many jurisdictions, some industries, such as healthcare and financial services, are more closely regulated than others. Salesforce enables customers to operate on a global scale — offering tools and resources to help them comply with regional, national, and local laws. For us, security and privacy is an opportunity to enhance the customer experience.
Nothing is more important than the trusted relationship between Salesforce, its customers, and everyone in the Salesforce ecosystem. Salesforce earns the trust of its stakeholders through transparency, security, privacy, compliance and performance. We are trusted advisors, and we deliver the most trusted infrastructure in the industry.
Trust.Salesforce.com is the Salesforce community’s home for real-time information on system availability, performance, security and compliance. Having trust at the foundation of our culture is how we maintain our pace of innovation and deep customer and stakeholder relationships at scale.
Salesforce is committed to supporting our customers on their financial services compliance journeys and we have created this Financial Services Webpage in support of that effort. We recognize that each of our customers will have differing compliance requirements depending on the characteristics of their specific financial institution, their particular business model, and the way in which they use our services.
We encourage our customers to evaluate how their use of our services, given our comprehensive security and privacy program, contractual commitments, and the controls available within our services, enable them to meet, and demonstrate compliance with applicable rules and regulations. We also engage with regulators to better understand sectoral rules and regulations, which allows Salesforce to build solutions and develop features to better support our customers’ independent compliance efforts.
You can see here how our services have successfully been used by some of the largest financial institutions across the globe.
In the US, healthcare and life sciences companies must address numerous laws and regulations that impact activities ranging from how these companies conduct their operations to how they interact with their patients and customers.
What you need to know about HIPAA
Among the most important of these laws is HIPAA (Health Insurance Portability and Accountability Act), the federal healthcare law that requires particular healthcare and life sciences companies to safeguard the privacy and security of their patients’ and customers’ protected health information.
Organizations covered by HIPAA must comply with comprehensive regulations that strictly govern the collection, use, storage, and disclosure of protected health information. HIPAA also requires these companies to pass on their data protection obligations to their service providers, if they provide their service providers with protected health information.
Who Salesforce Can Help
Many of Salesforce’s key services for healthcare and life sciences customers include features and functionality that help our customers meet HIPAA’s stringent privacy, security, and data protection requirements. By working together, Salesforce and our customers can address the challenges of HIPAA compliance while protecting patients by safeguarding their most sensitive information — their personal health data.
The Salesforce trusted cloud make it possible for healthcare and life sciences companies to strengthen compliance and improve visibility and transparency, while allowing them to leverage the power of the world's #1 CRM. Learn more about how Salesforce helps our healthcare and life sciences customers with HIPAA compliance by visiting our Compliance website.
To support our customers on their compliance journeys, Salesforce has developed the below country-specific content for financial institutions using our services, as well as a dedicated mapping on the applicable EU Outsourcing Guidelines (under the Europe section). The Key Resources and Compliance Programs sections below provide an overview across all countries. All of this content is available in a helpful downloadable FAQ in each of the country sections.
Europe
Where can information about how Salesforce’s Online Services map to EU Outsourcing Guidelines be found?
Please see Salesforce’s informational paper on Financial Services EU Outsourcing Guidelines Mapping for Online Services here.
Where can I learn more about the EU's Digital Operational Resilience Act and Salesforce's approach to compliance?
Please see Salesforce's FAQ on DORA here.
Please refer to our DORA Article 30 contractual mapping resource here showing how and where the FSA addresses the specific contractual requirements set out under DORA.
Denmark
Can financial institutions use Salesforce?
Yes. Financial institutions are permitted to use cloud services in Denmark, provided they comply with applicable rules and regulations, such as those described below.
Who is the financial regulator?
The Danish Financial Supervisory Authority (in Danish: Finanstilsynet) is responsible for conduct regulation of financial institutions subject to the Danish Financial Business Act (i.e., banks, mortgage credit institutions, investment firms, investment management companies, or insurance companies) and is also the prudential regulator.
What rules and regulations could apply to financial institutions using Salesforce?
Financial institutions may be subject to specific rules under Danish law insofar as the use of Salesforce cloud services constitutes an outsourcing. In that context, the specific rules will depend on the type of financial institution.
The rules are supplemented by nonbinding guidance from EU and Danish authorities. For example, the EBA Guidelines have been published, which apply to credit institutions, investment firms, and payment institutions. Furthermore, the EU Insurance and Occupational Pensions Authority (EIOPA) has published guidelines on system of governance, which includes guidelines on outsourcing by insurance companies. The Danish FSA has also published guidance in the form of, among others, guidelines on the Danish Executive Order on Outsourcing (May 2010) and guidance for the use of cloud services as part of IT-outsourcing (March 2017). The key rules and regulations that may apply to financial institutions in the context of outsourcing are contained in:
Mandatory law:
· AIFMD
· MiFID II
· MiFID II Organisation Regulation
· Solvency II
· Solvency II Delegated Regulation
· UCITS
· The Danish Financial Business Act
· The Danish Executive Order on Outsourcing
Guidance:
· EBA guidelines on outsourcing arrangements
· EIOPA guidelines on system of governance document
What are the key data privacy considerations for financial institutions using Salesforce?
See the Regional Privacy Laws section of our privacy website, which includes information and tools to help enable our customer’s success.
This information is provided to assist in answering questions raised by customers when evaluating Salesforce’s online services. This information is not legal advice. Salesforce urges its customers to consult with their own counsel to familiarize themselves with the supervisory and data protection requirements that govern their specific situations. While we aim to keep this information updated, it may not account for changes after publication.
France
Can financial institutions use Salesforce?
Yes. Financial institutions are permitted to use cloud services in France, provided they comply with applicable rules and regulations, such as those described below.
Who is the financial regulator?
France has two main financial supervisory authorities, the French Autorité de Contrôle Prudentiel et de Résolution (the Prudential Supervision and Resolution Authority or ACPR) and the French Autorité des Marchés Financiers (the Financial Markets Authority or AMF). The ACPR is responsible for supervising French credit institutions, financing companies, investment firms (such as broker-dealers and investment advisers), payment institutions, e-money institutions, and insurance companies. The AMF is responsible for supervising French asset managers and, insofar as business conduct rules are concerned, French investment services providers (i.e., credit institutions authorized to provide investment services and investment firms).
What rules and regulations could apply to financial institutions using Salesforce?
The use of Salesforce cloud services would generally only trigger regulatory requirements insofar as Salesforce cloud services constitute an outsourcing. In that context, the specific rules will depend on the type of financial institution.
For example, MiFID investment firms and credit institutions which are authorized to provide investment services may be required to comply with applicable rules arising from MiFID II as implemented in France. Insurance firms are subject to different rules and requirements. However, these requirements are supplemented by nonbinding guidance by EU and French regulatory authorities. For example, the European Banking Authority has published general guidelines on outsourcing arrangements (February 2019) which apply to credit institutions and investment firms, and payment and e-money institutions (the “EBA guidelines”). There is also guidance for insurance undertakings from the EU Insurance and Occupational Pensions Authority in their guidelines on system of governance document (“EIOPA guidelines”). In February 2020, EIOPA issued guidelines on outsourcing to cloud service providers, which provide guidance to market participants on how the outsourcing provisions set forth in Solvency II, in the Solvency II Delegated Regulation and in EIOPA guidelines need to be applied in the case of outsourcing to cloud service providers. The key rules and regulations that may apply to financial institutions in the context of outsourcing are contained in:
Mandatory law:
· AIFMD
· MiFID II
· MiFID II Organisation Regulation
· Solvency II
· Solvency II, Delegated Regulation
· UCITS
Guidance:
· EBA guidelines on outsourcing arrangements
· EIOPA guidelines on system of governance document
What are the key data privacy considerations for financial institutions using Salesforce?
See the Regional Privacy Laws section of our privacy website, which includes information and tools to help enable our customer’s success.
This information is provided to assist in answering questions raised by customers when evaluating Salesforce’s online services. This information is not legal advice. Salesforce urges its customers to consult with their own counsel to familiarize themselves with the supervisory and data protection requirements that govern their specific situations. While we aim to keep this information updated, it may not account for changes after publication.
Germany
Can financial institutions use Salesforce?
Yes. Financial institutions are permitted to use cloud services in Germany, provided they comply with applicable rules and regulations, such as those described below.
Who is the financial regulator?
The German Financial Supervisory Authority (BaFin) and the German Central Bank (Bundesbank). The main regulator in Germany is BaFin. BaFin is responsible for supervising all credit institutions, investment firms, capital management companies, and insurance undertakings. BaFin is supported in its supervisory activities by Bundesbank who assist in particular with the allocation of data collected from regulatory reporting and with onsite inspections.
What rules and regulations could apply to financial institutions using Salesforce?
The use of Salesforce cloud services would generally only trigger regulatory requirements insofar as Salesforce cloud services constitute an outsourcing. In that context, the specific rules will depend on the type of financial institution.
For example, credit institutions and investment firms may be required to comply with the requirements imposed by the KWG, WpHG, and the MaRisk. Insurance firms may be subject to rules and requirements imposed by the VAG and the MaGo. Capital investment management companies may need to observe the rules of the KAGB and KAMaRisk. In addition, the European Banking Authority has published general guidelines on outsourcing arrangements (February 2019) which apply to credit institutions and investment firms (the “EBA guidelines”). There is also guidance for insurance undertakings from the EU Insurance and Occupational Pensions Authority (“EIOPA guidance”) in their guidelines on system of governance document. BaFin has also published guidance on outsourcing to cloud service providers which apply to all financial institutions (“BaFin guidance”). The key rules and regulations that may apply to financial institutions in the context of outsourcing can be found below.
Mandatory law:
· AIFMD
· MiFID II
· MiFID II Organisation Regulation
· Solvency II
· Solvency II, Delegated Regulation
· UCITS
· KWG
· WpHG
· VAG
· KAGB
Guidance:
· EBA guidelines on outsourcing arrangements
· EIOPA guidelines on system of governance document
· MaRisk
· MaGo
· KAMaRisk
· BaFin’s guidance on outsourcing to cloud service providers
What are the key data privacy considerations for financial institutions using Salesforce?
See the Regional Privacy Laws section of our privacy website, which includes information and tools to help enable our customer’s success.
This information is provided to assist in answering questions raised by customers when evaluating Salesforce’s online services. This information is not legal advice. Salesforce urges its customers to consult with their own counsel to familiarize themselves with the supervisory and data protection requirements that govern their specific situations. While we aim to keep this information updated, it may not account for changes after publication.
Italy
Can financial institutions use Salesforce?
Yes. Financial institutions are permitted to use cloud services in Italy, provided they comply with applicable rules and regulations, such as those described below.
Who is the financial regulator?
Banca d'Italia, Commissione Nazionale per le Società e la Borsa and/or Istituto per la Vigilanza sulle Assicurazioni.
Italy has three main regulators, Banca d’Italia (BoI), Commissione Nazionale per le Società e la Borsa (Consob) and/or Istituto per la Vigilanza sulle Assicurazioni (IVASS). BoI is the prudential regulator for the main credit and financial institutions such as banks, investment firms, asset managers. BoI is also responsible for conduct regulation of authorized credit and financial institutions engaging in banking business. Consob is responsible for conduct regulation of authorized investment firms and asset managers. IVASS is the prudential regulator for the insurance and reinsurance undertakings. IVASS is also responsible for conduct regulation of authorized insurance and reinsurance undertakings.
What rules and regulations could apply to financial institutions using Salesforce?
The use of Salesforce cloud services would generally only trigger regulatory requirements insofar as Salesforce cloud services constitute an outsourcing. In that context, the specific rules will depend on the type of financial institution.
For example, MiFID investment firms may be required to comply with applicable rules arising from MiFID2 as implemented in Italy. Banks and insurance undertakings may respectively be subject to different rules and requirements. In addition, the European Banking Authority has published general guidelines on outsourcing arrangements (February 2019) which apply to credit institutions and investment firms (the “EBA guidelines”). There is also guidance for insurance undertakings from the EU Insurance and Occupational Pensions Authority (“EIOPA guidance”) in their guidelines on system of governance document. The key rules and regulations that may apply to financial institutions in the context of outsourcing are contained in:
Mandatory law:
· AIFMD
· MiFID II
· MiFID II Organisation Regulation
· Solvency II
· Solvency II, Delegated Regulation
· UCITS
· BoI Circular 285/2013
· BoI Circular 288/2015
· BoI Resolution 23 July 2019
· BoI Regulation 5 December 2019
· IVASS Regulation 38 2018
Guidance:
· EBA guidelines on outsourcing arrangements
· EIOPA guidelines on system of governance document
· BoI Guidance on Circular 285
· BoI Guidance on Circular 288
· BoI Consob Guidance
What are the key data privacy considerations for financial institutions using Salesforce?
See the Regional Privacy Laws section of our privacy website, which includes information and tools to help enable our customer’s success.
This information is provided to assist in answering questions raised by customers when evaluating Salesforce’s online services. This information is not legal advice. Salesforce urges its customers to consult with their own counsel to familiarize themselves with the supervisory and data protection requirements that govern their specific situations. While we aim to keep this information updated, it may not account for changes after publication.
Luxembourg
Can financial institutions use Salesforce?
Yes. Financial institutions are permitted to use cloud services in Luxembourg, provided they comply with applicable rules and regulations, such as those described below.
Who is the financial regulator?
The Commission de Surveillance du Secteur Financier or the Commissariat aux Assurances. The Commission de Surveillance du Secteur Financier (CSSF) regulates and supervises, among others, banks, professionals of the financial sector, including investment firms and investment fund managers, including UCITS management companies and alternative investment fund managers. The Commissariat aux Assurances (CAA) regulates and supervises insurance and reinsurance undertakings.
What rules and regulations could apply to financial institutions using Salesforce?
The use of Salesforce cloud services could trigger regulatory requirements applicable to outsourcing for Luxembourg financial institutions insofar as Salesforce cloud services constitute an outsourcing/delegation for the institutions. In that context, the specific rules will depend on the type of financial institution.
Financial institutions and insurance companies are subject to different rules and requirements. In addition, the European Banking Authority has published general guidelines on outsourcing arrangements (February 2019) which apply to credit institutions and investment firms (the “EBA guidelines”). There is also guidance for insurance undertakings from the EU Insurance and Occupational Pensions Authority (the “EIOPA guidance”) in their guidelines on system of governance document. The key rules and regulations that may apply to financial institutions in the context of outsourcing are contained in:
Mandatory Law:
· AIFMD
· MiFID II
· MiFID II Organisation Regulation, Articles 30-32
· Solvency II, Article 38, 49
· Solvency II, Delegated Regulation, Article 274
· UCITS
· FSL
· Insurance Sector Law
· Luxembourg Data Protection Law
· Luxembourg Cyber-Security Law
· Cloud Circular
· Central Administration Circular
· CSSF Circular Letter 18/698
· IML Circular 96/126
· CSSF Circular 17/656
Guidance:
· FAQ on cloud computing
· FAQ on the assessment of IT outsourcing materiality
· EIOPA Guideline on System Governance
· EIOPA Guidelines on Cloud Outsourcing
What are the key data privacy considerations for financial institutions using Salesforce?
See the Regional Privacy Laws section of our privacy website, which includes information and tools to help enable our customer’s success.
This information is provided to assist in answering questions raised by customers when evaluating Salesforce’s online services. This information is not legal advice. Salesforce urges its customers to consult with their own counsel to familiarize themselves with the supervisory and data protection requirements that govern their specific situations. While we aim to keep this information updated, it may not account for changes after publication.
Netherlands
Can financial institutions use Salesforce?
Yes. Financial institutions are permitted to use cloud services in the Netherlands, provided they comply with applicable rules and regulations, such as those described below.
Who is the financial regulator?
The Netherlands has two main financial regulators: the Dutch Central Bank (De Nederlandsche Bank, DNB) and the Authority for the Financial Markets (Autoriteit Financiële Markten, AFM). DNB is responsible for prudential regulation and supervises, among others, credit institutions (banks) and insurers. The AFM is responsible for conducting supervision and the main supervisor for, among others, investment firms, managers of alternative investment funds (AIFMs), and managers of undertakings for collective investment in transferable securities (“UCITS managers”), the latter two referred to as “asset managers.”
What rules and regulations could apply to financial institutions using Salesforce?
The use of Salesforce cloud services may generally only trigger regulatory requirements insofar as Salesforce cloud services constitute an outsourcing. In that context, the specific rules will depend on the type of financial institution.
Requirements set out in the FSA and EU regulations are binding. However, these requirements are supplemented by nonbinding guidance by EU and Dutch regulators. For example, the European Banking Authority has published general guidelines on outsourcing arrangements (February 2019) which apply to banks and investment firms (the “EBA guidelines”). There is also guidance for insurance undertakings from the EU Insurance and Occupational Pensions Authority (the “EIOPA guidance”) in their guidelines on system of governance document (“EIOPA guidelines”). In February 2020, EIOPA issued guidelines on outsourcing to cloud service providers, which provide guidance to market participants on how the outsourcing provisions set forth in Solvency II, in the Solvency II Delegated Regulation, and in EIOPA guidelines may need to be applied in the case of outsourcing to cloud service providers. The key rules and regulations that may apply to financial institutions in the context of outsourcing are contained in:
Mandatory law:
· AIFMD
· AIFMD Delegated Regulation
· MiFID II
· MiFID II Organisation Regulation
· Solvency II
· Solvency II, Delegated Regulation
· UCITS
· Dutch Financial Supervision Act, Article 3:18 and Article 4:16
· Decree Prudential Rules, Part 5
· Decree Conduct Supervision, Part 6
Guidance:
· EBA guidelines on outsourcing arrangements
· EIOPA guidelines on system of governance document
· DNB Explanatory Notes
· DNB Risk analysis outsourcing
· DNB Good practice Outsourcing Insurers
· DNB Good practices for managing outsourcing risks
· DNB Good practice information security
· AFM Outsourcing Guidance
What are the key data privacy considerations for considerations for financial institutions using Salesforce?
See the Regional Privacy Laws section of our privacy website, which includes information and tools to help enable our customer’s success.
This information is provided to assist in answering questions raised by customers when evaluating Salesforce’s online services. This information is not legal advice. Salesforce urges its customers to consult with their own counsel to familiarize themselves with the supervisory and data protection requirements that govern their specific situations. While we aim to keep this information updated, it may not account for changes after publication.
Poland
Can financial institutions use Salesforce?
Yes. Financial institutions are permitted to use cloud services in Poland, provided they comply with applicable rules and regulations, such as those described below.
Who is the financial regulator?
The Polish Financial Supervision Authority (KNF). KNF is responsible for supervising all credit institutions, investment firms, investment funds management companies, pension funds companies, payment institutions, e-money institutions and insurance undertakings.
What rules and regulations could apply to financial institutions using Salesforce?
The use of Salesforce cloud services would generally only trigger statutory law requirements insofar as Salesforce cloud services constitute an outsourcing. In that context, the specific rules will depend on the type of financial institution.
For example, credit institutions and investment firms may be required to comply respectively with the requirements imposed by the Polish Banking Law and the Polish Act on Trading in Financial Instruments. Investment funds management companies may need to observe the rules of the Polish Act on Investment Funds, whereas pension funds companies may be subject to requirements stipulated in the Polish Act on Pension Funds. Outsourcing requirements for payment and e-money institutions are stipulated in the Polish Act on Payment Services. Insurance undertakings may be subject to rules and requirements imposed by the Polish Act on Insurance and Reinsurance Activity. In addition, the European Banking Authority has published general guidelines on outsourcing arrangements (February 2019) which apply to credit institutions and investment firms (the “EBA guidelines”). There is also guidance for insurance undertakings from the EU Insurance and Occupational Pensions Authority (“EIOPA guidance”) in their guidelines on system of governance document. KNF has also published guidance on outsourcing to cloud service providers which apply to all financial institutions (“KNF guidance on outsourcing to cloud service providers”) along with the respective follow-up in the form of Q&A. On a more general level, KNF also issued recommendations and guidelines on the management of information technology and ICT environment security addressed to specific types of financial institutions. The key rules and regulations that may apply to financial institutions in the context of outsourcing can be found below.
Mandatory law:
· AIFMD
· MiFID II
· MiFID II Organisation Regulation
· Solvency II
· Solvency II, Delegated Regulation
· UCITS
· Polish Banking Law
· Polish Act on Trading in Financial Instruments
· Polish Act on Investment Funds
· Polish Act on Pension Funds
· Polish Act on Payment Services
· Polish Act on Insurance and Reinsurance Activity
Guidance:
· EBA guidelines on outsourcing arrangements
· EIOPA guidelines on system of governance document
· KNF’s guidance on outsourcing to cloud service providers
· KNF’s Q&A to guidance on outsourcing to cloud service providers
· KNF’s Recommendation D On the Management of Information Technology and ICT Environment Security at Banks
· KNF’s Guidelines on the Management of Information Technology and ICT Environment Security at Investment Firms
· KNF’s Guidelines on the Management of Information Technology and ICT Environment Security at Investment Funds Management Companies
· KNF’s Guidelines on the Management of Information Technology and ICT Environment Security at Pension Funds Companies
· KNF’s Guidelines on the Management of Information Technology and ICT Environment Security for Insurance and Reinsurance Undertakings
What are the key data privacy considerations for financial institutions using Salesforce?
See the Regional Privacy Laws section of our privacy website, which includes information and tools to help enable our customer’s success.
This information is provided to assist in answering questions raised by customers when evaluating Salesforce’s online services. This information is not legal advice. Salesforce urges its customers to consult with their own counsel to familiarize themselves with the supervisory and data protection requirements that govern their specific situations. While we aim to keep this information updated, it may not account for changes after publication.
This information is provided to assist in answering questions raised by customers when evaluating Salesforce’s online services. This information is not legal advice. Salesforce urges its customers to consult with their own counsel to familiarize themselves with the supervisory and data protection requirements that govern their specific situations. While we aim to keep this information updated, it may not account for changes after publication.
Spain
Can financial institutions use Salesforce?
Yes. Financial institutions are permitted to use cloud services in Spain, provided they comply with applicable rules and regulations, such as those described below.
Who is the financial regulator?
Spain has three (3) main financial regulators:
· Bank of Spain (BoS) is the national central bank and supervises public debt markets, certain financial institutions (establecimientos financieros de crédito), payment services entities, and electronic money entities, among others. In addition, within the framework of the Single Supervisory Mechanism (SSM), BoS is the direct supervisor of the Spanish less significant credit entities along with the European Central Bank that supervises directly any significant credit entities of the eurozone.
· Spanish Securities Market Commission (CNMV) is the regulator responsible for the supervision and inspection of Spanish securities markets and the activity of all those involved in them, such as investment firms, collective investment undertakings, asset managers, securitization vehicles, etc.
· Spanish Insurance and Pension Funds General Directorate (Dirección General de Seguros y Fondos de Pensiones) is the main regulator in charge of supervising the activities of Spanish insurance companies and pension funds.
What rules and regulations could apply to financial institutions using Salesforce?
The use of Salesforce cloud services would generally only trigger regulatory requirements insofar as Salesforce cloud services constitute an outsourcing. The key rules and regulations that may apply to financial institutions in the context of outsourcing are contained in:
Mandatory law:
· MiFID II
· MiFID II Organisation Regulation, Articles 30-32
· UCITS
· AIFMD
· Solvency II, Article 38, 49
· Solvency II, Delegated Regulation, Article 274
· CNMV Circular 1/2006
· CNMV Circular 6/2009
Guidance:
· EBA guidelines on outsourcing arrangements
· EIOPA guidelines on system of governance document
What are the key data privacy considerations for financial institutions using Salesforce?
See the Regional Privacy Laws section of our privacy website, which includes information and tools to help enable our customer’s success.
This information is provided to assist in answering questions raised by customers when evaluating Salesforce’s online services. This information is not legal advice. Salesforce urges its customers to consult with their own counsel to familiarize themselves with the supervisory and data protection requirements that govern their specific situations. While we aim to keep this information updated, it may not account for changes after publication.
Sweden
Can financial institutions use Salesforce?
Yes. Financial institutions are permitted to use cloud services in Sweden, provided they comply with applicable rules and regulations, such as those described below.
Who is the financial regulator?
The Swedish Financial Supervisory Authority (the SFSA) (Finansinspektionen in Swedish).
What rules and regulations could apply to financial institutions using Salesforce?
Financial institutions are subject to varying sector-specific rules insofar as any services they obtain from Salesforce amount to an outsourcing. Guidelines issued by the European Banking Authority are viewed by the SFSA as a common frame of reference for interpretation and application of the varying sector-specific legally mandatory rules. The key rules and regulations that may apply to financial institutions in the context of outsourcing are contained in:
Mandatory law:
· AIFMD
· MiFID II
· MiFID II Organisation Regulation
· Solvency II
· Solvency II Delegated Regulation
· UCITS
· FFFS 2010:3
· FFFS 2013:9
· FFFS 2013:10
· FFFS 2014:1
Guidance:
· EBA guidelines on outsourcing arrangements
· EIOPA cloud outsourcing guidelines
· EIOPA guidelines on system of governance document
What are the key data privacy considerations for financial institutions using Salesforce?
See the Regional Privacy Laws section of our privacy website, which includes information and tools to help enable our customer’s success.
This information is provided to assist in answering questions raised by customers when evaluating Salesforce’s online services. This information is not legal advice. Salesforce urges its customers to consult with their own counsel to familiarize themselves with the supervisory and data protection requirements that govern their specific situations. While we aim to keep this information updated, it may not account for changes after publication.
Switzerland
Can financial institutions use Salesforce?
Yes. Financial institutions are permitted to use cloud services in Switzerland, provided they comply with applicable rules and regulations, such as those described below.
Who is the financial regulator?
The Swiss financial regulator is the Financial Markets Supervisory Authority (FINMA). FINMA’s role covers licensing duties, prudential supervisory activities, and enforcement tasks. In addition, systemically important financial market infrastructures (stock exchanges, multilateral trading facilities, trade repositories, etc.) are subject to the oversight of the Swiss National Bank (central bank, SNB). Health insurers are regulated by the Swiss Federal Office of Public Health, not FINMA.
What rules and regulations could apply to financial institutions using Salesforce?
The use of Salesforce cloud services would generally only trigger regulatory requirements insofar as Salesforce cloud services constitute an outsourcing. The key rules and regulations that may apply to financial institutions in the context of outsourcing are contained in:
· FINMA Circular 2018/3, Outsourcing Circular
· Federal Act on Banks and Savings Banks (Bundesgesetz über Banken und Sparkassen, BankG)
· Federal Act on the Swiss Financial Market Supervisory Authority (Bundesgesetz über die Eidgenössische Finanzmarktaufsicht, FINMAG)
· Federal Act on Financial Institutions (Bundesgesetz über die Finanzinstitute, FINIG)
· Swiss Federal Data Protection Act
· FINMA Circular 2008/21, Operational Risks
· Federal Health Insurance Surveillance Act
· Federal Act on the Supervision of Insurance Companies (Bundesgesetz betreffend die Aufsicht über Versicherungsunternehmen, VAG)
What are the key data privacy considerations for financial institutions using Salesforce?
See the Regional Privacy Laws section of our privacy website, which includes information and tools to help enable our customer’s success.
This information is provided to assist in answering questions raised by customers when evaluating Salesforce’s online services. This information is not legal advice. Salesforce urges its customers to consult with their own counsel to familiarize themselves with the supervisory and data protection requirements that govern their specific situations. While we aim to keep this information updated, it may not account for changes after publication.
United Kingdom
Can financial institutions use Salesforce?
Yes. Financial institutions are permitted to use cloud services in the U.K., provided they comply with applicable rules and regulations, such as those described below.
Who is the financial regulator?
The U.K. has two main financial regulators, the Financial Conduct Authority (FCA) and the Prudential Regulation Authority (PRA). The FCA is responsible for conduct regulation of all authorized financial institutions and is also the prudential regulator for financial institutions who are not otherwise regulated by the PRA, such as asset managers and investment firms. The PRA is the prudential regulator for systemically important organizations such as banks, insurers, building societies, and major investment firms.
What rules and regulations could apply to financial institutions using Salesforce?
The use of Salesforce would only trigger financial services regulatory requirements insofar as Salesforce cloud services constitute an outsourcing. The use of Salesforce by a financial institution would amount to an outsourcing insofar as any Salesforce cloud services are a process, service, or activity that would otherwise be undertaken by the financial institution itself. In that context, the specific rules will depend on the type of financial institution. For example, MiFID Investment firms and banks may be required to comply with applicable rules arising from MiFID2 as implemented in the U.K. Insurance firms may be subject to different rules and regulations. The key U.K. rules and regulations that may apply to financial institutions in the context of outsourcing are contained in:
Mandatory law:
· AIFM Law
· MiFID II
· MiFID II Organisation Regulation, Articles 30–32
· Solvency II, Article 38, 49
· Solvency II, Delegated Regulation, Article 274
· SYSC 8
· SYSC 13.9
· SYSC 14.1
· SUP 2.3
· PRA Handbook: Outsourcing Part
· PRA Handbook: Outsourcing Part (for insurers)
Guidance: In addition, the European Banking Authority has published general guidelines on outsourcing arrangements (February 2019) which apply to credit institutions and investment firms (the “EBA guidelines”). There is also guidance for insurance undertakings from the EU Insurance and Occupational Pensions Authority (the “EIOPA guidance”) in their guidelines on system of governance document. The guidelines can be found below:
· EBA guidelines on outsourcing arrangements
· EIOPA guidelines on system of governance document
What are the key data privacy considerations for financial institutions using Salesforce?
See the Regional Privacy Laws section of our privacy website, which includes information and tools to help enable our customer’s success.
This information is provided to assist in answering questions raised by customers when evaluating Salesforce’s online services. This information is not legal advice. Salesforce urges its customers to consult with their own counsel to familiarize themselves with the supervisory and data protection requirements that govern their specific situations. While we aim to keep this information updated, it may not account for changes after publication.
Australia
Can financial institutions use Salesforce?
Yes. Financial institutions are permitted to use cloud services in Australia, provided they comply with applicable rules and regulations, such as those described below.
Who is the financial regulator?
There are three regulators of Australian financial institutions.
· The Australian Prudential Regulatory Authority (APRA), which regulates institutions across banking, general insurance, life insurance, and superannuation. APRA is the chief prudential regulator.
· The Australian Securities and Investments Commissions (ASIC), which regulates companies, financial markets, and the financial services sector. ASIC is the chief conduct regulator. ASIC regulates companies and financial services more broadly.
· The Australian Securities Exchange (ASX), which regulates market participants (including broker-dealers).
What rules and regulations could apply to financial institutions using Salesforce?
The specific rules depend on the type of financial institution. For example, banks, insurance companies, and superannuation funds are required to comply with the APRA Prudential Standards. Market participants (e.g., broker-dealers) are required to comply with ASX Clear Operating Rules. If a market participant is a bank, or is owned by a bank, it may have to comply with the APRA Prudential Standards and the ASX Clear Operating rules. The ASIC regulatory guides generally apply to all financial services businesses, though some apply only to specific sectors.
APRA’s prudential framework applies to outsourcing arrangements involving material business activities. Some of APRA’s Prudential Standards apply to all APRA regulated bodies, while others apply to specific financial institutions, e.g., banking/insurance/life insurance, health insurance, or superannuation.
Relevant Standards and guidance for banking, insurance, and life insurance institutions are:
· Prudential Standard CPS 231 Outsourcing
· Prudential Practice Guide PPG 231 – Outsourcing
· Prudential Standard CPS 232 Business Continuity Management
Relevant Standards and guidance for RSE licensees (i.e., superannuation trustees) are:
· Prudential Practice Guide: SPG 231 – Outsourcing
· Prudential Standard SPS 232 Business Continuity Management
Relevant Standards and guidance for health insurance institutions are:
· Prudential Standard HPS 231 Outsourcing
Other relevant standards include;
· APRA Prudential Standard: Information Security (CPS 234)
· APRA Prudential Standard: Business Continuity Management (CPS 232)
· APRA Prudential Standard: Risk Management (CPS 220)
What are the key data privacy considerations for financial institutions using Salesforce?
See the Regional Privacy Laws section of our privacy website, which includes information and tools to help enable our customer’s success.
This information is provided to assist in answering questions raised by customers when evaluating Salesforce’s online services. This information is not legal advice. Salesforce urges its customers to consult with their own counsel to familiarize themselves with the supervisory and data protection requirements that govern their specific situations. While we aim to keep this information updated, it may not account for changes after publication.
India
Can financial institutions use Salesforce?
Yes. Financial institutions are permitted to use cloud services in India, provided they comply with applicable rules and regulations, such as those described below.
Who is the financial regulator?
The Reserve Bank of India (RBI), the Securities and Exchange Board of India (SEBI) and Insurance Regulatory and Development Authority of India (IRDA)
India has three key financial regulators that regulate financial institutions:
· RBI is responsible for management of currency and supervising/regulating financial institutions such as commercial banks and nonbanking financial institutions (NBFCs).
· SEBI has been constituted to protect the interests of investors in securities and to promote the development of, and to regulate the securities markets. Accordingly, SEBI is empowered to regulate inter alia stock-brokers, mutual funds, alternative investment funds, real estate investment trusts, infrastructure investment trusts, investment advisors (collectively, “SEBI regulated entities”).
· IRDA has been empowered to regulate companies in the insurance business.
What rules and regulations could apply to financial institutions using Salesforce?
Insofar as Salesforce cloud services constitute an outsourcing, the requirements under the outsourcing guidelines may be triggered.
Additionally, the RBI Guidelines on Information Security, Electronic Banking, Technology Risk Management, and Cyber Frauds dated April 29, 2011, read with RBI Cyber Security Framework in Banks circular dated June 02, 2016 (“RBI IT Guidelines”), may be applicable to banks; RBI Master Direction — Information Technology Framework for the NBFC Sector dated June 08, 2017, may be applicable to NBFCs (“NBFC IT Guidelines”).
Similarly, SEBI Cyber Security & Cyber Resilience framework dated December 03, 2018, and January 10, 2019, may be applicable to stock brokers and mutual funds (“SEBI Cyber Security Framework”), and insurers may be required to comply with Guidelines on Information and Cyber Security for insurers dated April 07, 2017 (“IRDA Cyber Security Guidelines”).
Some of the key rules and regulations that may apply to financial institutions in the context of outsourcing can be found below:
RBI:
· Guidelines on Information Security, Electronic Banking, Technology Risk Management and Cyber Frauds, 2011
· RBI Cyber Security Framework, 2016
· Information Technology Framework for the NBFC Sector 2017
SEBI
· Cyber Security & Cyber Resilience framework for Stock Brokers 2018
· Cyber Security and Cyber Resilience framework for Mutual Funds 2019
IRDA
· Guidelines on Information and Cyber Security for Insurers 2017
· IRDAI (Outsourcing of activities by Indian Insurers) Regulations, 2017
What are the key data privacy considerations for financial institutions using Salesforce?
See the Regional Privacy Laws section of our privacy website, which includes information and tools to help enable our customer’s success.
This information is provided to assist in answering questions raised by customers when evaluating Salesforce’s online services. This information is not legal advice. Salesforce urges its customers to consult with their own counsel to familiarize themselves with the supervisory and data protection requirements that govern their specific situations. While we aim to keep this information updated, it may not account for changes after publication.
Japan
Can financial institutions use Salesforce?
Yes. Financial institutions are permitted to use cloud services in Japan, provided they comply with applicable rules and regulations, such as those described below.
Who is the financial regulator?
The Financial Services Agency of Japan (the “JFSA”) is the major regulator.
What rules and regulations could apply to financial institutions using Salesforce?
The use of Salesforce cloud services by a financial institution would amount to outsourcing insofar as any Salesforce cloud services are a service that would otherwise be undertaken by the financial institution itself.
There is no unified single outsourcing rule which applies to all financial institutions. The specific rules applicable to outsourcing vary depending on the type of regulated business/financial institution.
Mandatory law:
Banks
· Article 12-2, Paragraph 2 of the Banking Act
· Article 13-6-5 and Article 13-6-8, Paragraph 1 of the Ordinance for Enforcement of the Banking Act
Insurance Companies
· Article 100-2 of the Insurance Business Act
· Article 53-8 and Article 53-11 of the Ordinance for Enforcement of the Insurance Business Act
Trust Business Operators
· Article 22 of the Trust Business Act
· Article 40, Paragraph 6 of the Regulation for Enforcement of the Trust Business Act
Fund Transfer Service Providers (FTSPs)
· Article 50 of the Payment Services Act
· Article 27 of the Cabinet Office Order on FTSPs
Crypto-assets Exchange Service Providers (CESPs)
· Article 63-9 of the Payment Services Act
· Article 13 of the Cabinet Office Order on VCESPs
Money Lending Business Operators (MLBOs)
· Article 10-2 and 10-5 of the Ordinance for Enforcement of the Money Lending Business Act
JFSA Guidance:
· III-3-3-4 of the Comprehensive Guidelines for Supervision of Major Banks, etc. (the "Banking Guidelines")
· II-4-5-2 and II-5-1-2 of the Comprehensive Guidelines for Supervision of Insurance Companies, etc. (the "Insurance Business Guidelines")
· III-4-5, III-5-4 and III-5-5(4) of the Comprehensive Guidelines for Supervision of TBOs, etc. (the "Trust Business Guidelines")
· I-2-3-3-1 of the Administrative Guidelines No.3 (for FTSPs) (the "FTSP Guidelines")
· II-2-3-3-2 of the Administrative Guidelines No.3 (for CESPs) (the "CESP Guidelines")
· II-2-3 of the Comprehensive Guidelines for Supervision of MLBOs (the "MLBO Guidelines")
· III-2-4 and III-2-7 (2) of the Comprehensive Guidelines for FIBOs, etc. (the "FIBO Guidelines")
· Policy towards strengthening Cybersecurity in the Financial field
FISC Guidance:
The guidelines/standards published by Financial Industry Information System (FISC) can be voluntarily observed, including among others:
"Safety Measures Standards/commentary for Computer Systems of Financial Institutions"
What are the key data privacy considerations for financial institutions using Salesforce?
See the Regional Privacy Laws section of our privacy website, which includes information and tools to help enable our customer’s success.
This information is provided to assist in answering questions raised by customers when evaluating Salesforce’s online services. This information is not legal advice. Salesforce urges its customers to consult with their own counsel to familiarize themselves with the supervisory and data protection requirements that govern their specific situations. While we aim to keep this information updated, it may not account for changes after publication.
Singapore
Can financial institutions use Salesforce?
Yes. Financial institutions are permitted to use cloud services in Singapore, provided they comply with applicable rules and regulations, such as those described below.
Who is the financial regulator?
The Monetary Authority of Singapore (“MAS”) is the regulator in Singapore.
What rules and regulations could apply to financial institutions using Salesforce?
Should the use of Salesforce cloud services constitute an outsourcing the Guidelines on Outsourcing may apply to financial institutions. In addition, financial institutions which are banks and merchant banks may be subject to bank secrecy obligations.
The key rules and regulations that may apply to financial institutions in the context of outsourcing are contained in:
· Guidelines on Outsourcing
· Notice 634 Banking Secrecy – Conditions for Outsourcing
· Appendix 1 to Notice 634
· Notice 1108 Banking Secrecy – Conditions for Outsourcing
· Appendix 1 to Notice 1108
What are the key data privacy considerations for financial institutions using Salesforce?
See the Regional Privacy Laws section of our privacy website, which includes information and tools to help enable our customer’s success.
This information is provided to assist in answering questions raised by customers when evaluating Salesforce’s online services. This information is not legal advice. Salesforce urges its customers to consult with their own counsel to familiarize themselves with the supervisory and data protection requirements that govern their specific situations. While we aim to keep this information updated, it may not account for changes after publication.
Brazil
Can financial institutions use Salesforce?
Yes. Financial institutions are permitted to use cloud services in Brazil, provided they comply with applicable rules and regulations, such as those described below.
Who is the financial regulator?
The National Monetary Council (CMN) and the Central Bank of Brazil (BACEN)
What rules and regulations could apply to financial institutions using Salesforce?
The following rules may apply to financial institutions using Salesforce cloud services in Brazil:
· Resolution No. 4,658 of April 26, 2018 (“Resolution 4,658/2018”)
· Circular No.3,909, of August 16, 2018 (“Circular 3,909/2018”)
These regulations establish several requirements for the outsourcing of data processing and storage and cloud-computing services:
Resolution No. 4,658 of April 26, 2018 (“Resolution 4,658/2018”) is generally applicable to financial institutions and other institutions authorized to operate by the Central Bank. On the other hand, Circular No.3,909, of August 16, 2018 (“Circular 3,909/2018”) is applicable to regulated payment institutions.
What are the key data privacy considerations for financial institutions using Salesforce?
See the Regional Privacy Laws section of our privacy website, which includes information and tools to help enable our customer’s success.
This information is provided to assist in answering questions raised by customers when evaluating Salesforce’s online services. This information is not legal advice. Salesforce urges its customers to consult with their own counsel to familiarize themselves with the supervisory and data protection requirements that govern their specific situations. While we aim to keep this information updated, it may not account for changes after publication.
Mexico
Can financial institutions use Salesforce?
Yes. Financial institutions are permitted to use cloud services in Mexico, provided they comply with applicable rules and regulations, such as those described below.
Who is the financial regulator?
Mexico has four principal financial regulators:
· the Ministry of Finance and Public Credit (Secretaría de Hacienda y Crédito Público), which regulates financial groups and is in charge of policy and regulation of the financial system in general;
· the Central Bank (Banco de México), which regulates monetary policy, interest rates and foreign exchange transactions;
· the Mexican National Banking and Securities Commission (Comisión Nacional Bancaria y de Valores; the “CNBV”), which regulates banks, broker-dealers, and investment funds; and
· the Mexican National Insurance and Bonding Commission (Comisión Nacional de Seguros y Finazas; the “CNSF”), which regulates insurance companies.
What rules and regulations could apply to financial institutions using Salesforce?
The use of Salesforce cloud services may trigger regulatory requirements applicable to outsourcing for Mexican financial institutions. The specific rules will depend on the type of financial institution.
The key rules and regulations that may apply to financial institutions in the context of outsourcing are contained in:
Banking institutions: Article 317 et seq. of the Banking Circular
Broker-dealers: Article 205 et seq. of the Broker-Dealer Circular
Investment funds: Article 64 Bis 10 et seq. of the Investment Funds Circular
Insurance companies: Rule 12.1.1 et seq. of the Insurance Circular
What are the key data privacy considerations for financial institutions using Salesforce?
See the Regional Privacy Laws section of our privacy website, which includes information and tools to help enable our customer’s success.
This information is provided to assist in answering questions raised by customers when evaluating Salesforce’s online services. This information is not legal advice. Salesforce urges its customers to consult with their own counsel to familiarize themselves with the supervisory and data protection requirements that govern their specific situations. While we aim to keep this information updated, it may not account for changes after publication.
Security
How does Salesforce secure Customer Data?
We strongly encourage customers to follow security best practices and use available tools to strengthen the security of their Salesforce instance. Security does not start and end with Salesforce — it is a trusted partnership with our customers.
As set forth in more detail in our SPARC Documentation (available here by selecting the relevant service), Salesforce has implemented technical and administrative security measures designed to protect our services and Customer Data. Salesforce’s technical security measures include protections against system vulnerabilities, logical separation of Customer Data, robust network security, encryption of data in transmission, and options for encryption of data at rest. Salesforce’s administrative security measures include limiting access to Customer Data to those personnel who require such access to perform their current job functions, comprehensive security policies regarding the handling of Customer Data, and robust security training and awareness programs.
Salesforce offers its customers controllable features that permit them to configure the security settings of their respective instances of the Salesforce services as individual customers deem appropriate for the sensitivity of their Customer Data.
For more information on the application security features Salesforce provides, please refer to this help article on Protecting Your Salesforce Organization.
Where can a customer get details of Salesforce’s security and compliance controls?
· Salesforce’s compliance website details our audit/compliance certifications and attestations, e.g., ISO and SOC. This compliance website can be filtered by country and industry.
· Salesforce offers its customers a comprehensive security and privacy framework which is contractually underpinned by the Salesforce DPA. In our DPA, Salesforce contractually commits to maintain appropriate technical and organizational measures designed to protect Customer Data, as set forth in the applicable SPARC Documentation, available here by selecting the relevant service.
· The Salesforce Security Guide, details customer-controllable security features of Salesforce services (including encryption)
· Our trust.salesforce.com website shows real-time information on system performance and security.
· The Salesforce Shield for Financial Services white paper contains further information on additional security measures such as encryption of data, monitoring, and access controls.
· The External Security Assessments in the Trust and Compliance Documentation contain attestations of penetration tests and security assessments performed by third parties for certain Salesforce services.
· Security Health Check: This standard Salesforce feature analyzes your Salesforce org’s security settings against a default or custom baseline. It provides a score and specific recommendations. Refer to the Help and Training article titled “Security Health Check” for additional information.
· Additional resources can be found on the Help and Training Portal and Security page.
Under what circumstances does Salesforce access or use Customer Data?
Salesforce provides contractual assurance to its customers that Salesforce has measures in place designed to maintain the confidentiality of Customer Data and to prevent access to that data by Salesforce, except under specified circumstances. As set out in the DPA, Salesforce processes Customer Data on behalf of customers and only in accordance with their documented instructions for limited purposes: (i) processing under the customer’s agreement with Salesforce for the purchase of online services; (ii) processing initiated by customers’ users in using Salesforce’s services; and (iii) processing to comply with other customer instructions.
How does Salesforce segregate one customer’s data from the data of other customers in its environment?
Salesforce serves its customers through what is known as “multi-tenant” application architecture, designed for security, efficiency, availability, and rapid innovation. A multi-tenant application is one that can be accessed and used by many users simultaneously, with logical separation of data in hardware and software. The logical separation of data is designed to allow each Salesforce customer to view only their “instance” of Salesforce’s services and their associated data. Salesforce’s multi-tenant architecture is analogous to that used to provide online banking and brokerage services (which can also be accessed and used by thousands of users simultaneously through the logical – not physical – separation of data).
How does Salesforce handle Customer Data incidents?
Customer Data incident, management and notification is addressed at Section 7 of the DPA.
* ’Customer Data’ means electronic data and information submitted by or for a customer to the Salesforce services, as defined in the DPA.
Due Diligence, ongoing review, and audit
How does Salesforce support customer due diligence, ongoing review, and audit?
Salesforce is committed to offering customers a strong compliance framework and advanced tools and security measures. When conducting due diligence and ongoing review customers should gain a clear understanding of Salesforce’s technology and its underlying architecture, and then evaluate how, using Salesforce’s framework, tools and measures, customers may meet and demonstrate compliance with applicable rules and regulations. The following resources can support customers in this regard:
· Salesforce offers its customers audit rights in the DPA and SPARC Documentation, available here by selecting the relevant service.
· Salesforce’s Compliance website details our compliance certifications and attestations. Also, our trust.salesforce.com website shows real-time information on system availability and performance.
· Additional resources and consultation may be available upon discussion with your Account Executive. Please note, Salesforce cannot provide legal advice and will not interpret regulations for customer’s own particular circumstances.
· Further corporate information about Salesforce can be found in the company overview, as well as the "About Us" section on the Salesforce website.
Where can information about Salesforce’s compliance programs be found?
Please see Salesforce’s Compliance Center website detailing our audit/compliance certifications and attestations, e.g., ISO and SOC. This compliance website can be filtered on a country and industry basis.
Data location and sub-contractors
How does Salesforce support customer due diligence, ongoing review, and audit?
Salesforce is committed to offering customers a strong compliance framework and advanced tools and security measures. When conducting due diligence and ongoing review customers should gain a clear understanding of Salesforce’s technology and its underlying architecture, and then evaluate how, using Salesforce’s framework, tools and measures, customers may meet and demonstrate compliance with applicable rules and regulations. The following resources can support customers in this regard:
· Salesforce offers its customers audit rights in the DPA and SPARC Documentation, available here by selecting the relevant service.
· Salesforce’s Compliance website details our compliance certifications and attestations. Also, our trust.salesforce.com website shows real-time information on system availability and performance.
· Additional resources and consultation may be available upon discussion with your Account Executive. Please note, Salesforce cannot provide legal advice and will not interpret regulations for customer’s own particular circumstances.
· Further corporate information about Salesforce can be found in the company overview, as well as the "About Us" section on the Salesforce website.
Where can information about Salesforce’s compliance programs be found?
Please see Salesforce’s Compliance Center website detailing our audit/compliance certifications and attestations, e.g., ISO and SOC. This compliance website can be filtered on a country and industry basis.
Business continuity and disaster recovery
Does Salesforce have business continuity and disaster recovery plans?
Salesforce has a formally documented global business continuity and disaster recovery program. As part of this, Salesforce has staff who are certified business continuity planners and Salesforce employs leading consultants to assist in the ongoing development of business continuity and disaster recovery plans and procedures. This program is overseen by senior management for each of the key functional areas within Salesforce, and is supported by executive leadership at the highest level.
A summary of the Salesforce Business Continuity Plan (as well as information about data replication, reliability, and disaster recovery) can be found in the applicable SPARC Documentation available here by selecting the relevant service.
Salesforce maintains a disaster recovery plan that supports a robust business continuity strategy for the production services and platforms as described on the Disaster Recovery and BCP website.
Termination
How and when will Salesforce return Customer Data upon termination of the service agreement?
Salesforce’s customers own their Customer Data and the services are designed to always give customers access to it. In addition, at the end of the agreement, Salesforce returns Customer Data to its customers as per the contractual commitments set forth in the applicable agreement and SPARC Documentation. Information about the return and deletion of Customer Data can be found in the SPARC Documentation available here by selecting the relevant service.
* ’Customer Data’ means electronic data and information submitted by or for a customer to the Salesforce services, as defined in the DPA.
Privacy
Where can information about Salesforce’s privacy program be found?
The protection of our customer’s data is paramount, and Salesforce is committed to helping our customers on their global compliance journeys in our role as trusted advisor. Our customers trust us to help them build meaningful relationships with their own customers, and Salesforce’s top priority is the security and privacy of the data that we are entrusted to protect.
We have five privacy principles that highlight our commitment and focus on trust: customer control, security, transparency, compliance, and partnership. Our privacy website includes global privacy information, resources and tools (such as Salesforce’s DPA, International Data Transfers FAQ, and documentation to support data protection impact assessments) to help enable our customers’ success.
Government access to customer data
How does Salesforce handle government requests for access to Customer Data, also known as compelled disclosure requests?
Please see Salesforce’s Principles for Government Requests for Customer Data.
Salesforce’s Compliance Center details our audit/compliance certifications and attestations, e.g., ISO and SOC. This compliance website can be filtered on a country and industry basis.
Information about Salesforce's principles for handling government requests for customer data and the relevant annual figures regarding such requests.
Salesforce's Transparency Report (H1 2025)
Salesforce's Transparency Report (2024)
Salesforce's Transparency Report (2023)
Salesforce's Transparency Report (2022)
Ask about Salesforce products, pricing, implementation, or anything else. Our highly trained reps are standing by, ready to help.