SP Service Provider Legal and Compliance 3 — Questions and Answers
Question 1: Which Salesforce policy requires Service Providers to immediately report a known security vulnerability found in a client's production Salesforce org?
- Salesforce Acceptable Use Policy
- Salesforce Partner Code of Conduct
- Salesforce Responsible Disclosure Policy (Correct answer)
- Salesforce Trust and Compliance Documentation
Correct answer: Salesforce Responsible Disclosure Policy
Salesforce's Responsible Disclosure Policy outlines the proper process for reporting security vulnerabilities to protect customers and the platform.
Question 2: A client operating in the healthcare sector wants a Salesforce implementation. Which compliance framework would most directly govern how PHI is handled within the platform?
- PCI DSS
- HIPAA (Correct answer)
- SOX
- FERPA
Correct answer: HIPAA
HIPAA (Health Insurance Portability and Accountability Act) governs the handling of Protected Health Information (PHI) for healthcare-related entities.
Question 3: When a Salesforce Service Provider uses a third-party tool integrated with a client's org, who bears primary responsibility for ensuring that tool's compliance with the client's DPA?
- Salesforce, as the platform owner
- The third-party tool vendor exclusively
- The Service Provider, as it introduced the tool into the engagement (Correct answer)
- The client, as the Salesforce org owner
Correct answer: The Service Provider, as it introduced the tool into the engagement
The Service Provider is responsible for vetting and ensuring third-party tools it introduces meet the client's contractual and compliance obligations.
Question 4: Which element is REQUIRED in a Salesforce Service Provider's engagement contract to satisfy GDPR Article 28 when processing EU personal data?
- A copy of the SP's ISO 27001 certificate
- A Data Processing Agreement specifying processing instructions (Correct answer)
- An EU Standard Contractual Clause addendum only
- Proof of SP's Salesforce certification level
Correct answer: A Data Processing Agreement specifying processing instructions
GDPR Article 28 mandates that controllers use only processors who provide sufficient guarantees, formalized through a Data Processing Agreement with specific required clauses.
Question 5: A Service Provider wants to use client data from a completed project to improve its own internal AI models. Under standard contractual terms, this would typically:
- Be permitted if the data is anonymized before use
- Require explicit written consent from the client (Correct answer)
- Be automatically allowed under the SP's software license
- Only require notification to Salesforce Partner Operations
Correct answer: Require explicit written consent from the client
Using client data for the SP's own purposes beyond the contracted scope requires explicit written consent, as it exceeds the authorized processing purpose.
Question 6: In a Salesforce Service Provider engagement, 'right to audit' clauses typically allow the client to:
- Access and review the SP's source code repositories at any time
- Inspect the SP's compliance controls and data handling practices (Correct answer)
- Terminate the agreement without notice if any audit finding exists
- Require the SP to share audit results with Salesforce directly
Correct answer: Inspect the SP's compliance controls and data handling practices
Right-to-audit clauses give clients the ability to verify that the Service Provider is adhering to contracted security and compliance standards.
Question 7: Which Salesforce trust resource should a Service Provider consult to verify current platform compliance certifications and security documentation for client proposals?
- Salesforce AppExchange
- Salesforce Trust (trust.salesforce.com) (Correct answer)
- Salesforce Trailhead
- Salesforce Partner Community Help Center
Correct answer: Salesforce Trust (trust.salesforce.com)
trust.salesforce.com is Salesforce's official resource for system status, compliance certifications, and security documentation used in client-facing proposals.
Which Salesforce policy requires Service Providers to immediately report a known security vulnerability found in a client's production Salesforce org?