SP Service Provider Legal and Compliance 2 — Questions and Answers
Question 1: A Salesforce Service Provider is asked to handle customer PII on behalf of a client. Which document primarily governs how the SP may process that data?
- Non-Disclosure Agreement (NDA)
- Data Processing Agreement (DPA) (Correct answer)
- Master Subscription Agreement (MSA)
- Statement of Work (SOW)
Correct answer: Data Processing Agreement (DPA)
A Data Processing Agreement defines the roles, responsibilities, and obligations of each party when personal data is processed on behalf of a controller.
Question 2: Under the Salesforce Partner Program Agreement, what must a Service Provider do before sublicensing Salesforce technology to an end customer?
- Obtain written approval from Salesforce Partner Operations
- Ensure the end customer signs a Salesforce-compliant end-user license agreement (Correct answer)
- Register the sublicense in the Salesforce Partner Community portal
- Notify the Salesforce legal team via email
Correct answer: Ensure the end customer signs a Salesforce-compliant end-user license agreement
Service Providers must flow down appropriate license terms to end customers through a compliant end-user license agreement before any sublicensing occurs.
Question 3: A SP engagement involves migrating data from a legacy system into Salesforce. Which compliance consideration is MOST critical during the data migration phase?
- Ensuring all migrated records include a timestamp
- Validating that data transfer complies with applicable data residency and privacy laws (Correct answer)
- Compressing data files to reduce transfer time
- Mapping all legacy fields to standard Salesforce objects
Correct answer: Validating that data transfer complies with applicable data residency and privacy laws
Data residency and privacy regulations (e.g., GDPR, CCPA) govern where and how personal data may be transferred, making legal compliance the top priority.
Question 4: Which Salesforce compliance program certification demonstrates that a Service Provider's implementation practices meet cloud security standards relevant to US federal agencies?
- ISO 27001
- SOC 2 Type II
- FedRAMP (Correct answer)
- PCI DSS
Correct answer: FedRAMP
FedRAMP (Federal Risk and Authorization Management Program) is the US government standard for cloud service security, required for federal agency engagements.
Question 5: A Service Provider discovers a potential data breach involving a client's Salesforce org. What is the FIRST required action under most privacy regulations?
- Immediately notify all affected end users by email
- Contain the breach and assess scope before any notifications (Correct answer)
- Disable the Salesforce org to prevent further exposure
- File a report with the FTC within 24 hours
Correct answer: Contain the breach and assess scope before any notifications
Best practice and most regulations require containment and assessment first to determine breach scope and applicability before notification obligations are triggered.
Question 6: In the context of Salesforce AppExchange listings, which legal requirement must a Service Provider fulfill regarding end-user data collected through a listed app?
- Publish a privacy policy that discloses data collection and use practices (Correct answer)
- Store all collected data exclusively on Salesforce infrastructure
- Obtain Salesforce's written consent before collecting any user data
- Limit data collection to no more than 10 fields per user
Correct answer: Publish a privacy policy that discloses data collection and use practices
AppExchange security review and Salesforce policies require all listed apps to have a publicly accessible privacy policy disclosing data practices.
Question 7: A Service Provider's SOW includes a clause limiting liability to the total fees paid in the prior 12 months. What type of legal provision is this?
- Indemnification clause
- Limitation of liability clause (Correct answer)
- Force majeure clause
- Intellectual property assignment clause
Correct answer: Limitation of liability clause
A limitation of liability clause caps the maximum financial exposure a party faces in the event of a claim or breach of contract.
A Salesforce Service Provider is asked to handle customer PII on behalf of a client.
Which document primarily governs how the SP may process that data?