Compliance audit · findings summary
Salesforce org: production and full-copy sandboxes
Of organizations experienced a non-production data breach (Perforce State of Data Compliance, 2025)
Your sandbox has your customers' real data in it right now
Your last sandbox refresh pulled the full Contact database: names, dates of birth, Social Security numbers, health records. Your development team and offshore contractors have full query access. IT flagged it as standard procedure. GDPR does not have an exception for test environments.
“When we copy the data into full copy Sandbox, any developer who can get access, they can see everything, all the PII data.”
Enterprise Architect, US based Credit Union
Average cost of manually processing a single DSAR (Gartner, 2023)
One deletion request. Six hours. Across how many objects?
A customer emails "delete my data." Your privacy team opens Salesforce. There is no button. They start at Contacts. Then Cases. Then Contracts. Then Opportunities. Then Marketing Cloud. Each step is manual search, review, and deletion. Get a cascade wrong and you destroy related records. The 30-day GDPR clock started 10 days ago.
“We have a manual process for data deletion and is quite laborious.”
IT Product Owner, Swiss Construction Enterprise
Of global annual revenue: maximum GDPR Article 83 penalty
Every expired record in your org is documented liability waiting to be found
You have retention policies. They are in a spreadsheet. Your org has Contact records from 2017, closed-lost deals from 2018, support cases from 2016. GDPR Article 5 requires data minimization. Your own database is evidence it is not happening. When an auditor subpoenas your Salesforce data, they do not need to look far.
“Taking data out is always something that can be quite anxious about. As a former DBA I know.”
Enterprise Architect, European Insurance Company