01
Accountability
Role map
Roles depend on who decides purpose and means, who acts on instructions, and what each party actually does. Record the conclusion and its evidence; do not infer it from the vendor label.
- Name business owners for each object and process.
- Separate system administrators, integration users, delegated admins and data stewards.
- Assess Salesforce and installed-package providers from contracts and actual processing.
02
Collection surfaces
Collection and notice touchpoints
Walk each entry path as a real user. Save the notice, fields, choices, time and destination rather than relying on a policy page alone.
- Web-to-lead, service intake, imports, API writes and manual entry.
- Activities, email sync, notes, files and custom-object relationships.
- AppExchange packages, data enrichment, marketing and support integrations.
03
Purpose discipline
Purpose and data minimisation checks
Every field and copy should have a named operating reason, accountable owner and review event.
- Map standard and custom fields to purpose and owner.
- Review formulas, histories, files and free text for unnecessary duplication.
- Limit broad reports, extracts and sandbox copies.
04
Choice evidence
Consent and preference evidence
When consent is relied on, preserve the affirmative action and withdrawal path. Where another legal route is assessed, record that analysis instead of manufacturing a consent record.
- Carry notice and preference provenance into relevant records.
- Test preference propagation across campaigns and integrated senders.
- Distinguish platform permission from the individual’s valid choice.
05
Least privilege
Access control and privileged roles
Test ordinary view, sensitive fields, bulk action, export, configuration and integration access separately.
- Review profiles, permission sets, groups, sharing, queues and integration users.
- Test object, field, record and export access separately.
- Exercise deactivation, token revocation and record reassignment.
06
Lifecycle
Retention, deletion, backup and export behaviour
A delete button is not a lifecycle rule. Record the start event, end event, exception, system action, residual copy and accountable approver.
- Define retention by object, record state and business event.
- Test recycle, archive, backup, sandbox and exported-copy effects.
- Document what standard exports and APIs include.
07
Service chain
Processor, sub-processor and contract checks
Use the current contract and actual architecture. A product page cannot establish the complete role allocation for your organisation.
- Retrieve current terms, DPA, location and sub-processor information.
- Inventory installed packages and external credentials.
- Document exit, assistance, deletion and incident commitments.
08
Detection + response
Logs, monitoring and breach evidence
Coverage, event types, retention and exportability vary. Preserve an evidence timeline without claiming that one log proves the complete event.
- Confirm available setup and user-event logs for the edition.
- Sample permission, export, login and configuration events.
- Link alerts to the internal incident and breach-assessment workflow.
09
Request workflow
Rights-request search, export, correction and erasure workflow
- 01
Search standard and custom objects using verified identifiers.
- 02
Include activities, files, cases, email and integrated systems.
- 03
Apply reviewed exceptions before correction or deletion.
- 04
Record downstream actions and residual archive or backup treatment.
10
Bounded configuration
Configuration checklist
Object, field, record and export access match job need.
- Admin path
- Verify in the current admin console
- Evidence to save
- Profile and permission-set review with exceptions.
Export scope, custody and disposal are controlled.
- Admin path
- Verify in the current admin console
- Evidence to save
- Test export inventory and disposal record.
The org can retrieve required configuration and user events.
- Admin path
- Verify in the current admin console
- Evidence to save
- Dated event sample and coverage limitation.
No menu-path fiction: open the current vendor documentation and your live console together. Feature names, paths and entitlements can change.
11
Retrievable proof
Evidence to save
Object and field map
Profile and permission review
Package and integration inventory
Export sample
Audit sample
Rights-search and deletion exercise
Save redacted configuration evidence in an approved internal location. This private preview does not accept uploads or store these records.
12
Do not overclaim
Known limitations and questions for the vendor
Known limitations
- Edition and add-ons affect audit and retention capabilities.
- Custom code and packages can bypass an assumed standard flow.
- Sandbox, backup and exported copies require separate treatment.
Questions to resolve
- Which custom objects contain personal data?
- Which integrations can read or write the broadest scope?
- Which exports and sandboxes exist?
- Which logs are available under the current edition?
13
Traceable record
Official vendor sources, DPDP sources and corrections
Vendor documentation supports configuration questions only. DPDP statements are mapped separately to official Indian sources and phased commencement records.
Official vendor documentation
Official DPDP record
- Act No. 22 of 2023Ministry of Law and Justice, Government of India · checked 2026-09-27 ↗
- G.S.R. 843(E)Ministry of Electronics and Information Technology, Government of India · checked 2026-09-27 ↗
- G.S.R. 846(E)Ministry of Electronics and Information Technology, Government of India · checked 2026-09-27 ↗
- G.S.R. 892(E)Ministry of Electronics and Information Technology, Government of India · checked 2026-09-27 ↗
Reviewed · not counsel-reviewed · educational implementation guidance, not legal advice, certification or a legal conclusion.
Report or inspect a correctionSalesforce is a trademark of Salesforce, Inc. It is referenced nominatively; no affiliation or endorsement is implied.