Salesforce Einstein AI GDPR and SOC 2 compliance guide
Salesforce has embedded AI across its platform for years, lead scoring, opportunity insights, case classification, but Einstein Copilot represents a significant expansion: generative AI that can access and act on your CRM data using large language models. If your company runs on Salesforce, understanding what the AI features do with your data is now a compliance requirement, not an optional deep dive.

The two categories of Salesforce Einstein AI
Understanding the compliance implications requires distinguishing between two types of Einstein:
Predictive Einstein: The original Einstein features: lead scoring, opportunity insights, activity capture recommendations, case classification, email recommendations. These use machine learning models trained on patterns across Salesforce's customer base and your specific data. These features have been available since 2016 and their data handling is mature and well-documented.
Generative Einstein (Einstein Copilot): The newer generative AI assistant that uses large language models (including OpenAI's GPT models) to generate responses, summaries, email drafts, and other content using your CRM data as context. Governed by the Einstein Trust Layer.
The compliance frameworks apply differently to each.
GDPR requirements
Data Processing Agreement
Salesforce provides a Data Processing Addendum (DPA) as part of its Main Services Agreement. The DPA covers Einstein AI features, both predictive and generative, as part of the Salesforce platform. If you have an active Salesforce contract, the DPA is typically incorporated by reference.
Verify your DPA is current and covers:
- Einstein AI features (both predictive and generative/Copilot)
- The sub-processors Salesforce uses for AI processing (particularly for Einstein Copilot, which uses third-party LLMs)
- Standard Contractual Clauses for EU data transfers
Salesforce's DPA is updated periodically. If your DPA is more than 18 months old, verify the current version covers generative AI features that may not have existed when you signed.
The Einstein Trust Layer and training
For Einstein Copilot (generative AI), Salesforce's Einstein Trust Layer provides:
- Zero data retention: the LLM provider (e.g., OpenAI) does not retain your data after the API call
- No training on your data: your CRM data is not used to train the underlying LLM
- Data masking: sensitive fields can be masked before being sent to the LLM
- Toxicity detection: content is screened before being returned to users
- Audit trail: Einstein Copilot activity is logged
These commitments are Salesforce's contractual guarantees to you, backed by their agreements with the underlying LLM providers. The Einstein Trust Layer documentation is available in Salesforce's Help & Training portal.
For predictive Einstein features, your data contributes to Salesforce's shared AI models, which is standard for predictive ML. This is disclosed in Salesforce's privacy documentation.
Data residency
Salesforce supports data residency in the EU (EU Operating Zone) for customers on qualifying plans. If you have a Salesforce EU Operating Zone configuration, verify whether Einstein AI features honor your data residency settings. Salesforce's documentation specifies which features respect data residency boundaries.
SOC 2 requirements
Updating your Salesforce vendor entry (CC9.1)
Your Salesforce entry in your vendor inventory should be updated to reflect Einstein AI:
- Service scope: CRM platform including Einstein AI features (predictive and generative)
- Data processed: Contact records, lead data, opportunity data, case data, email content (if Einstein Activity Capture is enabled), custom object data relevant to AI features
- AI features enabled: Specify which Einstein features are active in your org (lead scoring, Einstein Copilot, etc.)
- Einstein Trust Layer: Document the zero-retention and no-training commitments for Copilot
- DPA status: Salesforce DPA current and covering AI features
- Sub-processors for AI: OpenAI (for Copilot via Einstein Trust Layer), documented in Salesforce's sub-processor list
Access controls (CC6)
- Who has access to Einstein Copilot in your Salesforce org?
- Are Einstein Copilot permissions controlled by profile or permission set?
- Can Einstein Copilot access all object data or is access scoped to specific objects?
- Is Einstein Activity Capture (which syncs email to Salesforce) enabled and for whom?
Salesforce's permission system is granular. Document which profiles and permission sets have Einstein Copilot access and which Einstein features are enabled.
Acceptable use policy (CC1)
Update your policy to address:
- Which Einstein AI features employees may use for work
- Guidance on reviewing Einstein Copilot-generated content before sending (for external communications)
- Whether Einstein Copilot can be used with data classified above a certain sensitivity level
- Employee responsibilities for AI-generated content accuracy
Configuring Einstein for compliance
In Salesforce Setup:
Review which features are enabled and which users have access (Setup → Einstein Copilot).
Review data masking rules for sensitive fields (Setup → Einstein Generative AI → Trust Layer).
If Einstein Activity Capture syncs email, understand what email content flows into Salesforce (Setup → Einstein Activity Capture).
Einstein Copilot actions are logged in the Einstein Copilot Audit Log. Configure retention and review processes.
Getting Salesforce Einstein audit-ready comes down to mapping its data flows to your SOC 2 and GDPR controls, confirming the DPA and sub-processors, and keeping that evidence current as the service changes. If you would rather a security leader owned that work than track it in a spreadsheet, book a call.
Related reading
- AI tools and GDPR/SOC 2: the complete guide
- Microsoft Copilot GDPR and SOC 2 compliance
- SOC 2 vendor management: how to satisfy CC9.1
- ISO 42001: AI management systems for SaaS
Want a security leader to run this?
Xorabyte is a fractional CISO for startups who can review your cloud for the gaps found first, so a blocked deal or an audit stops being your problem to carry alone. Book a call and you will leave with a clear path, not a sales pitch.