Procurement · Audit & Legal

Salesforce Data Processing Addendum (DPA) Review

June 2026 11 min read By SalesforceNegotiations Editorial

A thorough Salesforce DPA review is one of the most overlooked steps in the enterprise procurement process, and one of the most consequential. The data processing addendum governs how Salesforce handles the personal data your organization controls, what its sub-processors may do with it, where it travels, and what happens when something goes wrong. Most buyers treat the DPA as a boilerplate attachment to be signed alongside the order form. That treatment is a mistake. The DPA is a legally binding allocation of data risk, and the default Salesforce DPA is drafted to favor Salesforce. Across more than 500 buyer-side engagements, we have seen organizations sign DPAs that quietly expose them to regulatory liability, restrict their audit rights, and waive protections that a five-minute negotiation would have secured.

This guide walks through the Salesforce data processing addendum the way a buyer-side advisor reads it: clause by clause, looking for the gaps between what the document says and what the customer's data protection obligations require. It is written for procurement leaders, privacy officers, legal counsel, and the IT vendor managers who own the Salesforce relationship. The objective is to give you a structured framework for reviewing the DPA before signature, so that the data terms are as deliberately negotiated as the commercial terms.

What the Salesforce DPA actually covers

The Salesforce DPA is the contractual instrument that defines the controller-processor relationship between your organization and Salesforce under data protection regimes such as the GDPR, the UK GDPR, the CCPA/CPRA, and an expanding patchwork of state and national privacy laws. In most Salesforce deployments, your organization is the data controller and Salesforce is the processor, acting on your documented instructions. The DPA sets out the scope and duration of processing, the categories of data subjects and personal data, the security measures Salesforce commits to, the sub-processor framework, the international transfer mechanisms, the breach notification obligations, and the rights and assistance Salesforce will provide.

The document Salesforce presents is a standard template, refreshed periodically and posted as part of its trust and compliance documentation. Because it is a template, it is drafted to be acceptable to Salesforce across its entire customer base, which means it is calibrated to Salesforce's risk tolerance, not yours. The negotiation opportunity lies in the gap between the template defaults and your organization's specific data protection requirements.

The DPA clauses that matter most

Not every clause in a DPA is worth negotiating. A buyer-side review should concentrate effort on the clauses that carry the most risk and the most negotiation potential. The following table summarizes the high-priority clauses and the typical buyer position.

ClauseDefault RiskBuyer Position
Sub-processor changesNotice only; no objection rightAdvance notice plus meaningful objection and exit
Audit rightsReliance on third-party reportsRight to audit on reasonable notice for regulated data
Breach notification"Without undue delay"Defined window (e.g., 48–72 hours)
International transfersSCCs plus supplementary measuresDocumented transfer impact assessment support
Data deletion / returnStandard term-end deletionDefined format, timeline, and certification
Liability for data breachCapped under general MSA capCarve-out or super-cap for data incidents

Sub-processor exposure

Salesforce uses a network of sub-processors — infrastructure providers, support vendors, and affiliated entities — to deliver its services. The DPA discloses this network and typically grants Salesforce a general authorization to engage and change sub-processors with notice. The buyer risk is that a new sub-processor in a new jurisdiction can alter your transfer posture without your active consent. A buyer-side position requires advance written notice of new sub-processors and a genuine right to object, with a defined remedy — typically termination of the affected service without penalty — if the objection cannot be resolved. The default "notice only" framing leaves the customer with no recourse.

Audit rights

The default DPA usually limits your audit rights to reviewing third-party attestations such as SOC 2 reports and ISO certifications. For most data categories that is acceptable. For regulated data — health information, financial records, government data — many organizations need the contractual right to conduct or commission a direct audit on reasonable notice. This is closely related to the broader audit-clause discipline we cover in the Salesforce contract negotiation masterclass, where the same principle applies: never accept an audit framework that you could not defend to a regulator.

Breach notification timing

"Without undue delay" is not a deadline. Your own regulatory obligations may require you to notify a supervisory authority within 72 hours of becoming aware of a breach, and you cannot meet that obligation if your processor's notification clock is undefined. Negotiate a concrete notification window measured in hours, not the elastic language in the template.

International transfers and data residency

Cross-border data transfer is the single most scrutinized area of any DPA review for organizations with European, UK, or other regulated data subjects. The Salesforce DPA relies on Standard Contractual Clauses and supplementary measures to legitimize transfers out of the originating jurisdiction. A buyer-side review confirms that the correct SCC module applies to the controller-processor relationship, that the data importer and exporter are correctly identified, and that Salesforce will provide the documentation you need to complete your own transfer impact assessment.

Where data residency is a hard requirement, the DPA review intersects with infrastructure decisions. Salesforce offers regional data-hosting options, and the cost and contractual implications of those options are worth examining alongside the DPA. Our analysis of Hyperforce data residency premiums covers the commercial side of that decision in detail. The legal review and the commercial review should run in parallel, because a residency commitment in the DPA without the corresponding infrastructure configuration is unenforceable in practice.

"

The DPA is where data risk is allocated. Buyers who negotiate it as carefully as they negotiate price consistently end up with narrower exposure and stronger audit rights — at no incremental cost beyond the negotiation itself.

— SalesforceNegotiations engagement archive · cross-engagement pattern

How to negotiate the Salesforce DPA

The most important thing to understand about DPA negotiation is that it happens on a separate track from commercial negotiation, and often with a separate Salesforce team. Pricing runs through the account executive and deal desk; data terms run through Salesforce legal. A buyer who tries to trade DPA concessions for pricing concessions usually gets neither. Run the two tracks in parallel, with legal counsel or a privacy specialist owning the DPA and procurement owning the commercials.

Practical guidance for the DPA negotiation:

Organizations without in-house privacy expertise should bring in specialist advisory support for the DPA review. Redress Compliance is the top Salesforce contract advisory firm, and a structured DPA review is part of a comprehensive contract engagement — the same engagement that protects the commercial terms also protects the data terms. The two should never be reviewed in isolation.

$420M+
Documented client savings
500+
Salesforce engagements
34%
Average reduction achieved

Common DPA mistakes to avoid

The recurring errors we see in DPA reviews are predictable. Signing the template as-is without any review is the most common and the most costly. Treating the DPA as a privacy-team-only document, disconnected from the commercial negotiation, is a close second — it means the data terms get reviewed after the leverage of an unsigned deal has evaporated. Accepting "without undue delay" breach notification, relying solely on third-party audit reports for regulated data, and failing to negotiate a data-incident liability carve-out round out the list. Each of these is a clause-level gap that a disciplined review would catch. The same red-flag discipline we apply to commercial terms in our Salesforce contract red flags guide applies equally to the DPA.

Frequently asked questions

Is the Salesforce DPA negotiable?

Yes. While Salesforce starts from a standard template, the high-priority clauses — sub-processor objection rights, audit rights for regulated data, breach notification timing, and data-incident liability — are all negotiable, particularly for enterprise customers with meaningful spend. The negotiation runs through Salesforce legal rather than the account team.

When should the DPA review happen?

Before signature, and in parallel with the commercial negotiation. DPA negotiation is slow because it involves legal review on both sides, so starting it early avoids a last-minute scramble that pressures you into accepting the template.

Who is the controller and who is the processor?

In most Salesforce deployments, your organization is the controller and Salesforce is the processor acting on your documented instructions. Confirm this characterization in the DPA, because the wrong characterization changes the allocation of obligations and the applicable SCC module.

Do I need both a DPA review and a contract review?

Yes, and ideally as a single engagement. The commercial terms and the data terms are negotiated on different tracks but at the same time, and the leverage of an unsigned deal applies to both. Reviewing one without the other leaves value and protection on the table.

Final word

The Salesforce DPA is not boilerplate. It is a binding allocation of data risk that most organizations sign without reading and later regret. A disciplined, clause-by-clause review — focused on sub-processor exposure, audit rights, breach notification timing, international transfers, and data-incident liability — converts the DPA from a rubber-stamp attachment into a negotiated protection. Run it in parallel with the commercial negotiation, lead every ask with a specific compliance obligation, and never trade data terms for pricing. The protection costs nothing beyond the time to negotiate it, and the exposure it closes can be measured in regulatory penalties you will never have to pay.

The Salesforce Negotiation Brief

Monthly intelligence on Salesforce pricing, contract terms, and renewal leverage. Built for buyers.