How would you handle a requirement to store highly sensitive data such as national identifiers in Salesforce?
Suggested answer
First I would test whether it needs to be in Salesforce at all, because the cheapest control is not holding the data:
1. Challenge the requirement: Is the full identifier needed, or would a tokenised reference, a last-four fragment, or a boolean 'verified' flag satisfy the process? This resolves the requirement more often than people expect.
2. If it must be stored: Shield Platform Encryption on the field, with the understanding that encryption affects filtering, sorting, and matching rules — so I check what breaks before enabling it, not after.
3. Layer access control: Field-level security restricted to the minimum profiles and permission sets, sharing designed so the record itself is not broadly visible, and no exposure of the field in reports or list views used by wider populations.
4. Classify and audit: Data Classification metadata marking sensitivity and compliance category, Field Audit Trail on the field, and event monitoring where the licence allows.
5. Control the copies: Sandbox seeding must mask or exclude the field, integrations must not log it, and the retention and erasure process must cover archives and backups. Sensitive data leaking through a sandbox or an integration log is a far more common failure than the production field being compromised.
Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.
Community comments (0)
No comments yet.
Sign in or create a free account to add a comment. Comments are moderated before they appear.