Independent DPDP educationBrowser-only workspace · no accounts, analytics or submissions

CRM + serviceSystem guide · implementation aid

Salesforce: follow the evidence.

Connect objects, fields, permissions, integrations and evidence to one owned data journey.

00 What usually flows through Salesforce

A working data journey, not a legal conclusion.

Leads, contacts, accounts, opportunities, cases, activities, files, custom objects and integration events. Replace this editorial model with the systems, data and roles your organisation can actually evidence.

Typical Salesforce data journeySix stages show information moving from collection through operational systems, evidence and an end-of-lifecycle decision.010203040506
  1. 01Collectweb · import · API
  2. 02Objectsstandard · custom · files
  3. 03Processflow · case · campaign
  4. 04Packagesapp · sync · export
  5. 05Evidencehistory · audit · report
  6. 06Endarchive · delete · residual
Illustrative operating model. Verify actual fields, destinations, contracts, regions, retention and access.

01

Accountability

Role map

Roles depend on who decides purpose and means, who acts on instructions, and what each party actually does. Record the conclusion and its evidence; do not infer it from the vendor label.

  • Name business owners for each object and process.
  • Separate system administrators, integration users, delegated admins and data stewards.
  • Assess Salesforce and installed-package providers from contracts and actual processing.

02

Collection surfaces

Collection and notice touchpoints

Walk each entry path as a real user. Save the notice, fields, choices, time and destination rather than relying on a policy page alone.

  • Web-to-lead, service intake, imports, API writes and manual entry.
  • Activities, email sync, notes, files and custom-object relationships.
  • AppExchange packages, data enrichment, marketing and support integrations.

03

Purpose discipline

Purpose and data minimisation checks

Every field and copy should have a named operating reason, accountable owner and review event.

  • Map standard and custom fields to purpose and owner.
  • Review formulas, histories, files and free text for unnecessary duplication.
  • Limit broad reports, extracts and sandbox copies.

04

Choice evidence

Consent and preference evidence

When consent is relied on, preserve the affirmative action and withdrawal path. Where another legal route is assessed, record that analysis instead of manufacturing a consent record.

  • Carry notice and preference provenance into relevant records.
  • Test preference propagation across campaigns and integrated senders.
  • Distinguish platform permission from the individual’s valid choice.

05

Least privilege

Access control and privileged roles

Test ordinary view, sensitive fields, bulk action, export, configuration and integration access separately.

  • Review profiles, permission sets, groups, sharing, queues and integration users.
  • Test object, field, record and export access separately.
  • Exercise deactivation, token revocation and record reassignment.

06

Lifecycle

Retention, deletion, backup and export behaviour

A delete button is not a lifecycle rule. Record the start event, end event, exception, system action, residual copy and accountable approver.

  • Define retention by object, record state and business event.
  • Test recycle, archive, backup, sandbox and exported-copy effects.
  • Document what standard exports and APIs include.

07

Service chain

Processor, sub-processor and contract checks

Use the current contract and actual architecture. A product page cannot establish the complete role allocation for your organisation.

  • Retrieve current terms, DPA, location and sub-processor information.
  • Inventory installed packages and external credentials.
  • Document exit, assistance, deletion and incident commitments.
Open the processor-register guide

08

Detection + response

Logs, monitoring and breach evidence

Coverage, event types, retention and exportability vary. Preserve an evidence timeline without claiming that one log proves the complete event.

  • Confirm available setup and user-event logs for the edition.
  • Sample permission, export, login and configuration events.
  • Link alerts to the internal incident and breach-assessment workflow.

09

Request workflow

Rights-request search, export, correction and erasure workflow

  1. 01

    Search standard and custom objects using verified identifiers.

  2. 02

    Include activities, files, cases, email and integrated systems.

  3. 03

    Apply reviewed exceptions before correction or deletion.

  4. 04

    Record downstream actions and residual archive or backup treatment.

10

Bounded configuration

Configuration checklist

Permission model

Object, field, record and export access match job need.

Admin path
Verify in the current admin console
Evidence to save
Profile and permission-set review with exceptions.
Data export

Export scope, custody and disposal are controlled.

Admin path
Verify in the current admin console
Evidence to save
Test export inventory and disposal record.
Audit evidence

The org can retrieve required configuration and user events.

Admin path
Verify in the current admin console
Evidence to save
Dated event sample and coverage limitation.

No menu-path fiction: open the current vendor documentation and your live console together. Feature names, paths and entitlements can change.

11

Retrievable proof

Evidence to save

Object and field map

Profile and permission review

Package and integration inventory

Export sample

Audit sample

Rights-search and deletion exercise

Save redacted configuration evidence in an approved internal location. This private preview does not accept uploads or store these records.

12

Do not overclaim

Known limitations and questions for the vendor

Known limitations

  • Edition and add-ons affect audit and retention capabilities.
  • Custom code and packages can bypass an assumed standard flow.
  • Sandbox, backup and exported copies require separate treatment.

Questions to resolve

  1. Which custom objects contain personal data?
  2. Which integrations can read or write the broadest scope?
  3. Which exports and sandboxes exist?
  4. Which logs are available under the current edition?

13

Traceable record

Official vendor sources, DPDP sources and corrections

Vendor documentation supports configuration questions only. DPDP statements are mapped separately to official Indian sources and phased commencement records.

Editorial status

Reviewed · not counsel-reviewed · educational implementation guidance, not legal advice, certification or a legal conclusion.

Report or inspect a correction

Salesforce is a trademark of Salesforce, Inc. It is referenced nominatively; no affiliation or endorsement is implied.

14 Continue the workspace

Turn this system review into owned gaps.

The browser-only readiness map can capture what is evidenced, partial, unknown or missing. It does not produce a pass, certificate or legal conclusion.

Answer the linked readiness itemTrace RIGHTS-01 to evidence Read: Processor contracts in operation
Related system guides

Zoho CRMCRM + service

Freshworks / FreshsalesCRM + service

All system guidesSearch the complete stack