Overview
We talked earlier about masking sandboxes. The second step is to reduce production data. The idea here is that obsolete information in your Salesforce production org is just increasing your cost, risk and potentially the chances of non-compliance, related fines and embarrassment.
To address all of that, build consensus.
For building this consensus, we need to collaborate with internal stakeholders such as IT, business, legal, compliance, InfoSec and risk management.
All of these stakeholders will provide input that helps us produce a solid data reduction strategy. So let’s take a look at how this works.
Run a Salesforce data coverage tool, such as Cloud Compliance’s personal data discovery or Fieldtrip. This gives us a snapshot of the state of data in your Salesforce org.
Now, you know, how much data exists in each of your object, what fields are populated, what is the oldest record? And does it potentially violate any of the security, data minimization and retention, or other related policies.
This is a great step to start with facts.
Once you have all of this information, share your findings and highlight the benefit of reducing this data to your stakeholders.
For example, with each function within your organization, give them a benefit or a value proposition that is relevant to their goals.
In case of marketing that could be having more updated data ensures that we are respecting customer communication preferences. We are also more compliant with laws such as GDPR.
In addition, stale data with potentially erroneous email addresses and contact preferences is not going to get us beneficial results.
Another important function is legal and compliance. They are already laying down policies around compliance for laws like GDPR and to reduce future risk of lawsuits arising from data breaches and spills.
This is one of the dominant groups in helping businesses build a case for reducing data in Salesforce production Orgs.
Of course, another important stakeholder is the IT itself. More data means an increased amount of complexity of processing, storing and securing obsolete data.
In fact, we often refer to it as the ‘Undead’ data because it just roams around in your systems, like a zombie and delivers no value.
It just sucks the technology dollar blood out of your organization, slows down your projects, your data migrations take longer, your validations take longer. So the step two is a really important aspect of data reduction framework.
Give it a try, and please share your comments with us. Please refer to the link for the entire data reduction framework from Cloud Compliance.
Thank you so much.
Download the Free Trial of DataMasker App from AppExchange
Related Resources
How to Evaluate Salesforce Data Masking Tools: 12 Criteria That Matter
What Is a Data Processing Agreement (DPA)?
A Data Processing Agreement is not optional paperwork. GDPR Article 28(3) requires a written contract whenever a processor handles personal data on your behalf, and it specifies eight things that contract must cover. Most DPA reviews check that one exists and skip what it says.
What Is a DPIA (Data Protection Impact Assessment)?
A Data Protection Impact Assessment is a documented risk assessment carried out before high-risk processing begins. GDPR Article 35 makes it mandatory in defined cases, and several of those cases are triggered by things Salesforce teams do routinely, including deploying AI features over customer data.
What Is a Record of Processing Activities (RoPA)?
The Record of Processing Activities is the document a regulator asks for first. Article 30 sets out exactly what it must contain. The under-250-employee exemption sounds broad and turns out to cover almost nobody, because it excludes any processing that is regular rather than occasional.
What Is a Sub-Processor?
Controller, processor, sub-processor is a chain of responsibility, and GDPR Article 28 governs how each link is authorised and contracted. Every vendor that touches personal data on your behalf becomes a link, which is why adding tools has a compliance cost that is separate from their licence fee.
Learn More About Cloud Compliance
Explore our native Salesforce data privacy products.