SlideShare a Scribd company logo
FORCEWEST BREAKFAST
18 JULY 2018
SALESFORCE & GDPR
WHAT HAPPENS NEXT?
A Brief History
Introduction
Introduction
Stephan Chandler-Garcia
Salesforce Practice Lead & Architect - Methods
Founder - GDPR Superheroes
@SGarcia421
@GDPRSuperheroes
/in/stephanwgarcia
UK Public Sector
User Group
GDPR & Personal Data
Data
Processor
Data
Controller
Data
Subject
GDPR & Personal Data
Personal Data
any information relating to an identified or identifiable natural person;
Online Identifiers
IP Address
Cookies
RFID Tags
Direct Identifiers
Name
Contact Details
ID Number
Location Data
Indirect Identifiers
Physical
Physiological
Genetic
Mental
Economic
Cultural
Social Identity
GDPR & Personal Data
Processing
Any operation or set of operations which is performed on personal data or
on sets of personal data, whether or not by automated means, such as
collection, recording, organisation, structuring, storage, adaptation or
alteration, retrieval, consultation, use, disclosure by transmission,
dissemination or otherwise making available, alignment or combination,
restriction, erasure or destruction.
GDPR & Personal Data
Profiling
Any structured set of personal data which are accessible according to specific
criteria, whether centralised, decentralised or dispersed on a functional or
geographical basis.
GDPR & Personal Data
The Right
to
Rectification
The Right
of
Access The Right
to
Erasure
The Right
to be
Informed
The Right
to Restrict
Processing
The Right
to
Object
The Right
to Data
Portability
The Rights
In relation to
Automated
Decision
Making and
Processing
GDPR & Personal Data
Article 6
Lawfulness of
Processing
GDPR & Personal Data
Requirements
1. Consent
2. A Contract
3. Vital Interests
4. Legal Obligation
5. A Public Task
6. Legitimate Interest
Article 6
Lawfulness of
Processing
GDPR & Personal Data
Principles
1. Purpose Limitations
2. Storage Limitations
3. Data Minimisation
4. Accuracy
5. Right to Erasure
GDPR & Personal Data
The Right to Erasure
Individuals have a right to have personal data
erased in specific circumstances:
1. It is no longer necessary in relation to the purpose for which it was
originally collected/processed;
2. when the individual withdraws consent;
3. when the individual objects to the processing and there is no overriding
legitimate interest for continuing the processing;
4. when the personal data was unlawfully processed;
5. when the personal data has to be erased in order to comply with a legal
obligation; or
6. when the personal data is processed in relation to the offer of information
society services to a child.
How has this played out?
The calm before the storm
1. The media ‘frenzy’ was very short lived
2. Enhanced awareness
3. Temporary Solutions
Results
Companies spent months scrambling to prepare for this, what
has been the result?
1. Some acted on bad legal advice
2. Lots of lost data
3. Wait and see
Lawsuits
There have been a few big-name lawsuits filed already. What do
they actually mean?
1. The are mostly PR
2. Individuals do not have the right to press charges
Salesforce Changes
Platform Changes
Salesforce have made changes to their platform to aid compliance
1. The Individual Object… more on that shortly!
2. Internal Logging
3. Apex Method for User Deletion & more to come
Salesforce Changes
The Individual Object
A New Standard Object!
1. Must be Enabled
2. No Storage Limits
3. Related to Contact, Lead, Person Account, &
User by Default
Post-GDPR
Whats Next?
1. Emerging Regulations
a. E Privacy Regulation
b. California Consumer Privacy Act
2. the GDPR ‘rebrand'
Resources
Where can I find more information?
GDPR Superheroes - GDPRSuperheroes.com
Information Commissioner's Office - ico.org.uk
Data Privacy Manager - elements.cloud/dpm
GDPR Superheroes
THANK YOU!

More Related Content

PDF
GDPR Learning Lab: Gartner Data & Analytics 2018 Slides
PDF
GDPR Compliance
PPT
Enterprise Discovery: Taking Control, Driving Change
PDF
GDPR Affects Email Worldwide
PDF
What is GDPR Data Flow Mapping
PPTX
GDPR non-compliance risks & GDPR365
PDF
GDPR 
- The Do’s and Don'ts for Marketeers
PDF
12 steps to prepare for GDPR
GDPR Learning Lab: Gartner Data & Analytics 2018 Slides
GDPR Compliance
Enterprise Discovery: Taking Control, Driving Change
GDPR Affects Email Worldwide
What is GDPR Data Flow Mapping
GDPR non-compliance risks & GDPR365
GDPR 
- The Do’s and Don'ts for Marketeers
12 steps to prepare for GDPR

What's hot (15)

PDF
GDPR 12 Steps infographic
PDF
What does GDPR laws mean for Australian businesses
PPTX
Data Governance in the Enterprise: Highlights from Our Research Report
PDF
An Overview of GDPR by Pathway Group
PDF
hipaa compliance requirements for business associates
PDF
HIPAA Compliance Requirements for Business Associates
PDF
HIPAA compliance tuneup 2016
PPT
Privacy & Transparency in Digital Life
PPT
Stressing about GDPR? Key Facts
PDF
BigID PII & PI Discovery for GDPR Data Sheet
PPTX
Managing SharePoint within Office 365
PDF
CIO Summit talk: EU GDPR
PPTX
Personally Identifiable Information – FTC: Identity theft is the most common ...
DOCX
What is data protection and why it is important for business
GDPR 12 Steps infographic
What does GDPR laws mean for Australian businesses
Data Governance in the Enterprise: Highlights from Our Research Report
An Overview of GDPR by Pathway Group
hipaa compliance requirements for business associates
HIPAA Compliance Requirements for Business Associates
HIPAA compliance tuneup 2016
Privacy & Transparency in Digital Life
Stressing about GDPR? Key Facts
BigID PII & PI Discovery for GDPR Data Sheet
Managing SharePoint within Office 365
CIO Summit talk: EU GDPR
Personally Identifiable Information – FTC: Identity theft is the most common ...
What is data protection and why it is important for business
Ad

Similar to Salesforce & GDPR: What happens next? (20)

PDF
What is GDPR and why does it matter to me?
PDF
Data Protection Seminar_GDPR_ISOLAS_26-06-17
PDF
Innovation day Oslo FSI breakout
PPTX
GDPR Data Lifecycle
PPTX
How GDPR will change Personal Data Control and Affect Everyone
PPTX
Webinar: Introduction to GDPR - What It Is and How It Will Affect Your Business
PPTX
GDPR Data Life Cycle
PPTX
GDPR: 3 Months On | Guest Speaker: Data Protection Commissioners
PDF
GDPR Is Coming - Get Over It Webinar
PDF
GDPR – Readiness in IT offshore organization
PDF
GDPR and Analytics
PDF
GDPR Whitepaper
PPTX
GDPR in the Healthcare Industry
PDF
Gdpr presentation
PDF
Life with GDPR 2018 - From Governance to Optimisation
PDF
GDPR: What does it mean for your business?
PPTX
General Data Protection Regulation (GDPR)
PDF
Impact of GDPR on User Experience
PDF
The Essential Guide to GDPR
PDF
The Essential Guide to GDPR
What is GDPR and why does it matter to me?
Data Protection Seminar_GDPR_ISOLAS_26-06-17
Innovation day Oslo FSI breakout
GDPR Data Lifecycle
How GDPR will change Personal Data Control and Affect Everyone
Webinar: Introduction to GDPR - What It Is and How It Will Affect Your Business
GDPR Data Life Cycle
GDPR: 3 Months On | Guest Speaker: Data Protection Commissioners
GDPR Is Coming - Get Over It Webinar
GDPR – Readiness in IT offshore organization
GDPR and Analytics
GDPR Whitepaper
GDPR in the Healthcare Industry
Gdpr presentation
Life with GDPR 2018 - From Governance to Optimisation
GDPR: What does it mean for your business?
General Data Protection Regulation (GDPR)
Impact of GDPR on User Experience
The Essential Guide to GDPR
The Essential Guide to GDPR
Ad

More from Desynit (8)

PPTX
Nessy Learnings Salesforce Marketing Automation Case Study
PPTX
How to create an inbound marketing engine
PPTX
Are you ready for Lightning to strike?
PPTX
Dreamforce 2015 - 4 days in 4 minutes
PDF
Stories of sustainability on the Salesforce platform
PPTX
Intro to Salesforce Lightning for Admins
PPTX
Le Tour de Salesforce 2014
PPTX
Customer experience with IPC Media & Bluewolf
Nessy Learnings Salesforce Marketing Automation Case Study
How to create an inbound marketing engine
Are you ready for Lightning to strike?
Dreamforce 2015 - 4 days in 4 minutes
Stories of sustainability on the Salesforce platform
Intro to Salesforce Lightning for Admins
Le Tour de Salesforce 2014
Customer experience with IPC Media & Bluewolf

Recently uploaded (20)

DOCX
80 DE ÔN VÀO 10 NĂM 2023vhkkkjjhhhhjjjj
PDF
NewBase 12 August 2025 Energy News issue - 1812 by Khaled Al Awadi_compresse...
PPTX
Project Management_ SMART Projects Class.pptx
PDF
Solaris Resources Presentation - Corporate August 2025.pdf
PDF
ANALYZING THE OPPORTUNITIES OF DIGITAL MARKETING IN BANGLADESH TO PROVIDE AN ...
PDF
Technical Architecture - Chainsys dataZap
PDF
Module 3 - Functions of the Supervisor - Part 1 - Student Resource (1).pdf
PDF
Satish NS: Fostering Innovation and Sustainability: Haier India’s Customer-Ce...
PDF
1911 Gold Corporate Presentation Aug 2025.pdf
PDF
Tortilla Mexican Grill 发射点犯得上发射点发生发射点犯得上发生
PDF
Blood Collected straight from the donor into a blood bag and mixed with an an...
PPTX
BUSINESS CYCLE_INFLATION AND UNEMPLOYMENT.pptx
PDF
Cours de Système d'information about ERP.pdf
PPTX
Slide gioi thieu VietinBank Quy 2 - 2025
PPTX
Astra-Investor- business Presentation (1).pptx
PDF
PMB 401-Identification-of-Potential-Biotechnological-Products.pdf
PDF
NEW - FEES STRUCTURES (01-july-2024).pdf
PDF
NISM Series V-A MFD Workbook v December 2024.khhhjtgvwevoypdnew one must use ...
PDF
Charisse Litchman: A Maverick Making Neurological Care More Accessible
PPTX
Negotiation and Persuasion Skills: A Shrewd Person's Perspective
80 DE ÔN VÀO 10 NĂM 2023vhkkkjjhhhhjjjj
NewBase 12 August 2025 Energy News issue - 1812 by Khaled Al Awadi_compresse...
Project Management_ SMART Projects Class.pptx
Solaris Resources Presentation - Corporate August 2025.pdf
ANALYZING THE OPPORTUNITIES OF DIGITAL MARKETING IN BANGLADESH TO PROVIDE AN ...
Technical Architecture - Chainsys dataZap
Module 3 - Functions of the Supervisor - Part 1 - Student Resource (1).pdf
Satish NS: Fostering Innovation and Sustainability: Haier India’s Customer-Ce...
1911 Gold Corporate Presentation Aug 2025.pdf
Tortilla Mexican Grill 发射点犯得上发射点发生发射点犯得上发生
Blood Collected straight from the donor into a blood bag and mixed with an an...
BUSINESS CYCLE_INFLATION AND UNEMPLOYMENT.pptx
Cours de Système d'information about ERP.pdf
Slide gioi thieu VietinBank Quy 2 - 2025
Astra-Investor- business Presentation (1).pptx
PMB 401-Identification-of-Potential-Biotechnological-Products.pdf
NEW - FEES STRUCTURES (01-july-2024).pdf
NISM Series V-A MFD Workbook v December 2024.khhhjtgvwevoypdnew one must use ...
Charisse Litchman: A Maverick Making Neurological Care More Accessible
Negotiation and Persuasion Skills: A Shrewd Person's Perspective

Salesforce & GDPR: What happens next?

  • 1. FORCEWEST BREAKFAST 18 JULY 2018 SALESFORCE & GDPR WHAT HAPPENS NEXT?
  • 3. Introduction Stephan Chandler-Garcia Salesforce Practice Lead & Architect - Methods Founder - GDPR Superheroes @SGarcia421 @GDPRSuperheroes /in/stephanwgarcia UK Public Sector User Group
  • 4. GDPR & Personal Data Data Processor Data Controller Data Subject
  • 5. GDPR & Personal Data Personal Data any information relating to an identified or identifiable natural person; Online Identifiers IP Address Cookies RFID Tags Direct Identifiers Name Contact Details ID Number Location Data Indirect Identifiers Physical Physiological Genetic Mental Economic Cultural Social Identity
  • 6. GDPR & Personal Data Processing Any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
  • 7. GDPR & Personal Data Profiling Any structured set of personal data which are accessible according to specific criteria, whether centralised, decentralised or dispersed on a functional or geographical basis.
  • 8. GDPR & Personal Data The Right to Rectification The Right of Access The Right to Erasure The Right to be Informed The Right to Restrict Processing The Right to Object The Right to Data Portability The Rights In relation to Automated Decision Making and Processing
  • 9. GDPR & Personal Data Article 6 Lawfulness of Processing
  • 10. GDPR & Personal Data Requirements 1. Consent 2. A Contract 3. Vital Interests 4. Legal Obligation 5. A Public Task 6. Legitimate Interest Article 6 Lawfulness of Processing
  • 11. GDPR & Personal Data Principles 1. Purpose Limitations 2. Storage Limitations 3. Data Minimisation 4. Accuracy 5. Right to Erasure
  • 12. GDPR & Personal Data The Right to Erasure Individuals have a right to have personal data erased in specific circumstances: 1. It is no longer necessary in relation to the purpose for which it was originally collected/processed; 2. when the individual withdraws consent; 3. when the individual objects to the processing and there is no overriding legitimate interest for continuing the processing; 4. when the personal data was unlawfully processed; 5. when the personal data has to be erased in order to comply with a legal obligation; or 6. when the personal data is processed in relation to the offer of information society services to a child.
  • 13. How has this played out? The calm before the storm 1. The media ‘frenzy’ was very short lived 2. Enhanced awareness 3. Temporary Solutions
  • 14. Results Companies spent months scrambling to prepare for this, what has been the result? 1. Some acted on bad legal advice 2. Lots of lost data 3. Wait and see
  • 15. Lawsuits There have been a few big-name lawsuits filed already. What do they actually mean? 1. The are mostly PR 2. Individuals do not have the right to press charges
  • 16. Salesforce Changes Platform Changes Salesforce have made changes to their platform to aid compliance 1. The Individual Object… more on that shortly! 2. Internal Logging 3. Apex Method for User Deletion & more to come
  • 17. Salesforce Changes The Individual Object A New Standard Object! 1. Must be Enabled 2. No Storage Limits 3. Related to Contact, Lead, Person Account, & User by Default
  • 18. Post-GDPR Whats Next? 1. Emerging Regulations a. E Privacy Regulation b. California Consumer Privacy Act 2. the GDPR ‘rebrand'
  • 19. Resources Where can I find more information? GDPR Superheroes - GDPRSuperheroes.com Information Commissioner's Office - ico.org.uk Data Privacy Manager - elements.cloud/dpm