Salesforce orgs a single enterprise may operate across functions, channels, regions, and acquisitions
Multi-org is not an accident, it's often the right architectural decision. Sales, Service, and Marketing run on separate orgs. B2B and B2C have different data models. AMER, EMEA, and APAC each need data sovereignty. And every acquisition adds another org to the estate. When a GDPR RTBF request arrives, every one of those orgs must respond, simultaneously, without manual coordination.
One deletion request. Dozens of orgs. No coordination.
Salesforce orgs a single Fortune 500 enterprise may operate
Your Salesforce estate is fragmented: acquired company orgs, regional CRMs, departmental Service Cloud instances, and sandbox farms. Each org holds customer data independently. When a GDPR RTBF or CCPA deletion request arrives, every relevant org must process it. Your team has no automated way to coordinate that at scale.
GDPR response window for confirming RTBF execution
GDPR requires controllers to confirm erasure without undue delay and within one month. With manual coordination across dozens of orgs, meeting that deadline is operationally impossible at scale. A single missed org creates a compliance failure: GDPR fines reach €20 million or 4% of global annual turnover.
centralized audit records when deletion is coordinated by email
When DSAR coordination happens over email and spreadsheets, there is no unified audit trail. Regulators and internal auditors cannot verify that deletion was complete across all orgs. Each org has its own records, or no records at all. An audit becomes a forensic exercise across every silo. MOPS Hub creates a single, complete audit log in your Hub Org for every DSAR across every spoke.
Set it up once in the Hub App. Every Spoke App executes locally.
Two-App Architecture
Two separate AppExchange apps work together. The Hub App (installed in your Hub Org) orchestrates requests across the enterprise. The Spoke App (installed on every business org) processes privacy and security requests locally within its own security boundary.
Secure Org-to-Org Authentication
Each Hub-to-spoke connection uses Salesforce Connected App OAuth. No shared credentials. No password exchange. Every callout is logged in the Hub audit trail with timestamp and confirmation status.
Enterprise Dashboard
Real-time processing status across every connected spoke org. Filter by request type, regulation, date range, or org. One screen shows compliance completeness across your entire Salesforce estate.
REST & APEX API + External Portal Integration
Connect external DSAR master systems, OneTrust, Osano, or home-grown portals, directly to your Hub via REST/CC API. Subject requests flow in; deletion confirmations flow out. Fully documented API, no custom middleware.
Privacy & Security Use Cases
Beyond RTBF: the Spoke App handles portability requests, consent and opt-in management, sandbox data masking, ringfencing, legal hold, and user de-provisioning across orgs and sandboxes for DLP, all orchestrated from the Hub.
Turnkey Deployment
Pre-built orchestration flows, documented onboarding playbook, and guided spoke-org connection setup. Install the Hub App once, connect each Spoke App via Connected App OAuth. Go live in weeks, not months.
The third enterprise hub strategy, after Customer 360 and CI/CD.
Privacy + Security, Both Orchestrated
MOPS Hub covers both sides of the multi-org compliance challenge. Data Privacy: RTBF, portability, consent management. Data Security: sandbox masking, ringfencing, legal hold, user de-provisioning. One hub strategy for the entire compliance surface.
Audit-Ready Across the Enterprise
Every request, DSAR, masking job, legal hold, its origin, processing steps, and completion, is logged in the Hub. Single audit trail for your entire Salesforce estate, regardless of org count. Supports GDPR, CCPA/CPRA, and HIPAA audit requirements.
Fits Your Multi-Org Reality
Multi-org happens by design, by function (Sales/Service/Marketing), by channel (B2B/B2C), by region (AMER/EMEA/APAC), or by acquisition. MOPS Hub meets each pattern. Pair with Privacy Rights Automation for single-org DSARs or Data Retention for automated record lifecycle management.
How it works
Install the Hub App in your Hub Org
Install the Hub App (AppExchange managed package) in your designated Hub Org. This is where all DSAR and privacy requests are received, orchestrated, and audited.
Connect spoke orgs via Salesforce Connected App OAuth
Install the Spoke App on each business org. Connect it to the Hub via a Salesforce Connected App using OAuth 2.0. No passwords shared. No credentials exchanged. Every callout is logged with timestamp and status.
Submit a DSAR or privacy request via Hub
A deletion, portability, or security request arrives in the Hub (via UI, REST API, or integration with OneTrust, Osano, or any DSAR portal). The Hub App dispatches instructions to every relevant Spoke App simultaneously.
Each Spoke App executes locally
Each Spoke App processes the request within its own org security boundary. No customer data crosses org boundaries: only orchestration instructions and status confirmations are exchanged.
Unified audit trail in the Hub
Every request, its origin, processing steps, and completion status across all spoke orgs is logged in the Hub. One audit trail for your entire Salesforce estate. Ready for GDPR, CCPA, or HIPAA audits.
Regulations driving multi-org DSAR orchestration
MOPS Hub supports the compliance workflows that apply to multi-org Salesforce estates. Automates processes. Does not guarantee outcomes.
General Data Protection Regulation
Article 17 Right to Erasure applies across all systems and sub-processors holding EU resident data, including every Salesforce org in your estate.
California Consumer Privacy Act / California Privacy Rights Act
CCPA deletion requests must cover all systems holding California resident data. Multi-org Salesforce estates require coordinated deletion across every relevant org.
Health Insurance Portability and Accountability Act
Minimum necessary standard and access controls apply across all environments where PHI is held. Each org in a multi-org Health Cloud estate requires independent compliance.
UK General Data Protection Regulation
Post-Brexit data protection obligations mirror GDPR Article 17. Enterprises operating both EU and UK orgs must orchestrate deletion across both jurisdictions.
Lei Geral de Proteção de Dados
Brazil's LGPD grants data subjects the right to deletion. Enterprises with Brazilian Salesforce orgs must include them in DSAR orchestration workflows.
US State Privacy Law Patchwork
Virginia, Colorado, Connecticut, and 15+ additional US states have enacted deletion rights. Multi-org orchestration ensures each state's residents are covered regardless of which org holds their data.
Key Takeaways
Two AppExchange apps: Hub App orchestrates, Spoke App executes locally in each org
Privacy use cases: RTBF, portability DSARs, consent and opt-in management
Security use cases: sandbox masking, ringfencing, legal hold, user de-provisioning across orgs
Connects to external DSAR portals: OneTrust, Osano, or any REST-capable system
Enterprise dashboard: real-time status across all spoke orgs in one screen
100% native, Hub-to-spoke communication via OAuth, no data leaves your Salesforce estate
Frequently Asked Questions
The Hub Org is a designated Salesforce org where all DSAR/RTBF requests are received and orchestrated. It connects to spoke orgs via Salesforce Connected Apps and dispatches deletion or portability workflows to each. The Hub Org also maintains the central audit trail for every DSAR across your entire estate.
Each spoke org is connected via a Salesforce Connected App using OAuth 2.0. No credentials are shared. No passwords are exchanged. Every API callout from the Hub to a spoke org is logged in the Hub audit trail with a timestamp, response status, and confirmation record.
MOPS Hub has been deployed in enterprises managing 50+ spoke orgs. The architecture is designed to scale horizontally, adding a spoke org is a configuration task, not a development project. There is no hard limit on spoke org count.
No. MOPS Hub orchestrates deletion instructions and status updates, it does not copy or move customer data between orgs. Each spoke org executes deletion locally within its own security boundary. A deletion confirmation is returned to the Hub; no personal data is transferred.
GDPR RTBF, CCPA deletion, CPRA deletion, HIPAA minimum necessary, UK GDPR, LGPD, and any US state privacy law requiring deletion workflows. Regulation rules are configured per spoke org, so each org enforces the rules relevant to its geography and data.
Most enterprise deployments go live in 3–4 weeks. Cloud Compliance provides a documented onboarding playbook covering Hub configuration, spoke org connection via Connected App, and orchestration flow setup. No Apex development is required from your team.
They are two separate AppExchange managed packages. The Hub App is installed in your designated Hub Org, it orchestrates privacy and security requests across your enterprise, maintains the central audit trail, and exposes the REST/APEX API. The Spoke App is installed on every business org in your estate, it receives instructions from the Hub and processes requests locally within that org's security boundary. No personal data moves between them: only orchestration instructions and status confirmations.
Yes. MOPS Hub exposes a REST/CC API that any external DSAR master system can call, OneTrust, Osano, home-grown portals, or any system capable of making an API call. The DSAR request flows in via API to the Hub Org; the Hub App dispatches to every relevant Spoke App; deletion confirmations are returned. No manual handoff, no middleware layer.
Both. The platform covers two categories of multi-org challenges. Data Privacy: RTBF (GDPR Article 17), portability requests, and consent and opt-in management. Data Security: sandbox data masking, ringfencing, legal hold, and user de-provisioning across orgs and sandboxes for DLP. The Hub App orchestrates all of these from a single enterprise command center.
Complete Your Privacy Infrastructure
Privacy Rights Automation
DSAR processing within a single Salesforce org
Data Retention Manager
Automated retention policy enforcement
Financial Services Compliance
FINRA-ready compliance for FinServ teams
GDPR Compliance
Automate GDPR RTBF and data subject rights


