Skip to main content

I have done a bunch of googling and cannot seem to find what I'm looking for. I'm hoping someone here might be able to point me in the right direction. We're a small Native-led nonprofit expanding services to youth (specifically Indigenous youth). On the Salesforce side, our question is around data retention of those youth's personal information. Can we retain it securely online (ie in Salesforce)? If so, for how long? Are there things we can't retain? 

 

From what I've read, COPPA doesn't apply because we're a nonprofit and (I don't believe any of our program participants will be under 13). Are there laws that do apply? 

 

Thanks in advance for any recommendations or resources!

2 respostas
  1. 6 de set. de 2023, 19:06

    While NonProfits may be exempt from certain things, more and more states are adding protections and including nonprofits in those laws, etc.  Your data "should" be secure in SF, as they have product lines that include such sectors as Financial and Health care.  A lot of it is up to you as the Admin and organization to make sure that you are following best practices, state, local and federal laws/guidelines.  Even data like a person's full name, birthday, address etc, could be considered "sensitive" information.  If you need SSN's at all you will need to encrypt that data in SF and limit who can and can't see it.  There are also ways to note if a certain field should be considered PII, HIPPA, senstive, etc.  I would not personally rely on the fact that nonprofit's are "exempt" from certain laws.  I would recomend talking with someone who knows about privacy laws, etc and get their feedback.

0/9000