2026-04-20 · 5 min read

Salesforce Einstein AI GDPR and SOC 2 compliance guide

Salesforce has embedded AI across its platform for years, lead scoring, opportunity insights, case classification, but Einstein Copilot represents a significant expansion: generative AI that can access and act on your CRM data using large language models. If your company runs on Salesforce, understanding what the AI features do with your data is now a compliance requirement, not an optional deep dive.

3 Salesforce Einstein tiers, 3 different data policies

The two categories of Salesforce Einstein AI

Understanding the compliance implications requires distinguishing between two types of Einstein:

Predictive Einstein: The original Einstein features: lead scoring, opportunity insights, activity capture recommendations, case classification, email recommendations. These use machine learning models trained on patterns across Salesforce's customer base and your specific data. These features have been available since 2016 and their data handling is mature and well-documented.

Generative Einstein (Einstein Copilot): The newer generative AI assistant that uses large language models (including OpenAI's GPT models) to generate responses, summaries, email drafts, and other content using your CRM data as context. Governed by the Einstein Trust Layer.

The compliance frameworks apply differently to each.

GDPR requirements

Data Processing Agreement

Salesforce provides a Data Processing Addendum (DPA) as part of its Main Services Agreement. The DPA covers Einstein AI features, both predictive and generative, as part of the Salesforce platform. If you have an active Salesforce contract, the DPA is typically incorporated by reference.

Verify your DPA is current and covers:

  • Einstein AI features (both predictive and generative/Copilot)
  • The sub-processors Salesforce uses for AI processing (particularly for Einstein Copilot, which uses third-party LLMs)
  • Standard Contractual Clauses for EU data transfers

Salesforce's DPA is updated periodically. If your DPA is more than 18 months old, verify the current version covers generative AI features that may not have existed when you signed.

The Einstein Trust Layer and training

For Einstein Copilot (generative AI), Salesforce's Einstein Trust Layer provides:

  • Zero data retention: the LLM provider (e.g., OpenAI) does not retain your data after the API call
  • No training on your data: your CRM data is not used to train the underlying LLM
  • Data masking: sensitive fields can be masked before being sent to the LLM
  • Toxicity detection: content is screened before being returned to users
  • Audit trail: Einstein Copilot activity is logged

These commitments are Salesforce's contractual guarantees to you, backed by their agreements with the underlying LLM providers. The Einstein Trust Layer documentation is available in Salesforce's Help & Training portal.

For predictive Einstein features, your data contributes to Salesforce's shared AI models, which is standard for predictive ML. This is disclosed in Salesforce's privacy documentation.

Data residency

Salesforce supports data residency in the EU (EU Operating Zone) for customers on qualifying plans. If you have a Salesforce EU Operating Zone configuration, verify whether Einstein AI features honor your data residency settings. Salesforce's documentation specifies which features respect data residency boundaries.

SOC 2 requirements

Updating your Salesforce vendor entry (CC9.1)

Your Salesforce entry in your vendor inventory should be updated to reflect Einstein AI:

  • Service scope: CRM platform including Einstein AI features (predictive and generative)
  • Data processed: Contact records, lead data, opportunity data, case data, email content (if Einstein Activity Capture is enabled), custom object data relevant to AI features
  • AI features enabled: Specify which Einstein features are active in your org (lead scoring, Einstein Copilot, etc.)
  • Einstein Trust Layer: Document the zero-retention and no-training commitments for Copilot
  • DPA status: Salesforce DPA current and covering AI features
  • Sub-processors for AI: OpenAI (for Copilot via Einstein Trust Layer), documented in Salesforce's sub-processor list

Access controls (CC6)

  • Who has access to Einstein Copilot in your Salesforce org?
  • Are Einstein Copilot permissions controlled by profile or permission set?
  • Can Einstein Copilot access all object data or is access scoped to specific objects?
  • Is Einstein Activity Capture (which syncs email to Salesforce) enabled and for whom?

Salesforce's permission system is granular. Document which profiles and permission sets have Einstein Copilot access and which Einstein features are enabled.

Acceptable use policy (CC1)

Update your policy to address:

  • Which Einstein AI features employees may use for work
  • Guidance on reviewing Einstein Copilot-generated content before sending (for external communications)
  • Whether Einstein Copilot can be used with data classified above a certain sensitivity level
  • Employee responsibilities for AI-generated content accuracy

Configuring Einstein for compliance

In Salesforce Setup:

01Einstein Copilot settings

Review which features are enabled and which users have access (Setup → Einstein Copilot).

02Einstein Trust Layer configuration

Review data masking rules for sensitive fields (Setup → Einstein Generative AI → Trust Layer).

03Activity Capture

If Einstein Activity Capture syncs email, understand what email content flows into Salesforce (Setup → Einstein Activity Capture).

04Audit logs

Einstein Copilot actions are logged in the Einstein Copilot Audit Log. Configure retention and review processes.

Getting Salesforce Einstein audit-ready comes down to mapping its data flows to your SOC 2 and GDPR controls, confirming the DPA and sub-processors, and keeping that evidence current as the service changes. If you would rather a security leader owned that work than track it in a spreadsheet, book a call.

Related reading

Want a security leader to run this?

Xorabyte is a fractional CISO for startups who can review your cloud for the gaps found first, so a blocked deal or an audit stops being your problem to carry alone. Book a call and you will leave with a clear path, not a sales pitch.

Frequently asked questions

Is Salesforce Einstein AI GDPR compliant?
Salesforce Einstein AI is GDPR compliant for customers who have executed Salesforce's Data Processing Addendum (DPA). Salesforce's DPA covers Einstein AI features as part of the core platform. Salesforce is GDPR-certified under the EU-US Data Privacy Framework and includes Standard Contractual Clauses in its DPA for EU data transfers. Einstein processes your CRM data (contacts, leads, opportunities, cases) to power its AI features, all under the existing Salesforce DPA.
Does Salesforce Einstein train on your CRM data?
Salesforce distinguishes between models trained on your specific data (tenant-specific models) and shared models. For Einstein features like lead scoring and opportunity insights, models are trained on aggregated, anonymized data across the Salesforce customer base plus your own data. Salesforce's Einstein Trust Layer (introduced in 2023) provides zero data retention and no training on your prompts for generative AI features in Einstein Copilot. Review the Einstein Trust Layer documentation for current commitments.
What is the Einstein Trust Layer?
The Einstein Trust Layer is Salesforce's framework for generative AI safety in its platform. Key commitments include: your data is not used to train third-party AI models (like OpenAI models used by Einstein Copilot), zero data retention by AI providers after the API call completes, dynamic grounding using only your org's data, and toxicity detection. The Trust Layer applies to Einstein Copilot and related generative AI features, not to older predictive Einstein features like lead scoring.
What SOC 2 controls apply to Salesforce Einstein AI?
Salesforce as your primary CRM is already in your vendor inventory. With Einstein AI enabled, update the Salesforce entry to reflect AI feature usage: document which Einstein features are active, what data those features process, and the Einstein Trust Layer commitments. If Einstein Copilot is enabled, document the third-party AI providers (OpenAI, etc.) and their zero-retention commitments as part of your CC9.1 vendor documentation for AI systems.
Is Salesforce Einstein Copilot the same as Einstein AI?
No. Einstein AI refers to Salesforce's broader set of AI features, including predictive models like lead scoring, opportunity insights, and case classification, features that have existed since 2016. Einstein Copilot is Salesforce's generative AI assistant, launched in 2024, that uses large language models (including OpenAI's models) to generate responses, summaries, and draft content within Salesforce. The compliance implications differ: predictive Einstein features use Salesforce's own models; Einstein Copilot uses third-party LLMs via the Einstein Trust Layer.

Xorabyte

Get a security leader in your corner.

Xorabyte is a fractional CISO for startups facing SOC 2, security questionnaires, and enterprise security reviews. Tell us what triggered the need and we will map the path.