DPIA on Salesforce Sales and Cloud services

Scope of the DPIA
The DPIA contains a technical analysis and legal assessment of the data processing through the two tested Salesforce services.
Sales Cloud and Service Cloud are offered on the Salesforce platform as Software as a Service (SaaS), and are based on the same personal data provided by the government organisation. The main difference is the workflow. With the Sales Cloud service, organisations can centrally manage contact data of inhabitants /customers/ suppliers and/or employees. Thanks to browser access, employees can link Sales Cloud to incoming e-mails and update the relationship data easily, from any location.
Service Cloud facilitates customer service. The platform offers a ticketing system to automatically connect support requests or reports from inhabitants to the right employee. The platform combines incoming messages from different channels (chatbot, email, WhatsApp, phone, social networks). Tasks are prioritised in a dashboard and external contractors can share information in real time with government officials via an app.

GDPR roles of Salesforce
As a result of the negotiations with the Dutch government, Salesforce has become a data processor for the five relevant categories of personal data: Content Data, Account Data, Diagnostic Data, Support Data and the Restricted Access Website Data. Salesforce may only process these personal data for 3 agreed purposes:
- Delivering well-functioning Services and support, including providing functionally customized user experiences;
- Troubleshooting and providing support, including preventing, detecting, investigating, repairing and responding to technical and maintenance issues;
- Ongoing and continual functional improvement of the Services and support (including updating the Help Portal and Services and improving security, reliability, efficiency and use).
The Dutch government specifically authorises Salesforce in the new Data Processing Addendum to further process limited personal data as data controller for a limitative list of (grouped) legitimate business purposes, to the extent such processing is necessary. These purposes range from billing and account management to use of Support Data for training and quality usage, and from licensing compliance to the investigation, detection and prevention of suspicious activity, fraud and cybercrime.
Data transfers
A much discussed risk is the risk of disclosure of personal data to government authorities in the USA.
As Salesforce Inc. is a US-based company, Privacy Company assessed whether it is possible to limit the data transfer risks by ensuring that personal data are processed exclusively within the EU. Salesforce offers EUOZ, but this only applies to the Content Data, not to the other 4 relevant categories of personal data. Privacy Company also used Salesforce’s encryption service for the Content Data, called Shield Platform Encryption. This service does not provide absolute protection against decryption by Salesforce, even though Salesforce contractually commits never to use its (technical) decryption options.
As long as the European Commission’s adequacy decision for the USA remains in force, there are no formal legal objections to the use of the tested services in the tested setup. However, public sector organisations must take into account the risks of potential unavailability of personal data due to political developments. The DPIA therefore recommends arranging for backups outside the tested services for critical processes.
Conclusion
The DPIA identifies 11 risks to the protection of personal data. Salesforce has mitigated many of these risks by taking technical and contractual measures. Provided that the government bodies implement all the recommended measures, there are no longer any known high data protection risks.

