Patent pending | LegisGate Compass™ Report
Salesforce Einstein AI | Report ID: 967905096

AI Tool Regulatory Obligation Report

LegisGate™ - Regulatory Intelligence for AI Deployments

LegisGate Compass™

LegisGate Compass™ Report | by LegisGate™

Patent pending

Report ID: 967905096

Salesforce Einstein AI

Vendor: Salesforce

Prepared for LegisGate Technology

Purchaser & terms

Sara Mitchell | sara.mitchell@legisgatetechnology.com

Terms accepted Aug 21, 2026, 3:07 AM UTC | v2.0

Sales voucher clickwrap agreement

A mid-size B2B software company deploys Salesforce Einstein AI to score and rank sales leads and opportunities. The AI analyzes historical CRM data - deal history, customer interactions, firmographic data, and behavioral signals - to predict which leads are most likely to convert and which open opportunities are most likely to close. Sales representatives use the scores to prioritize their outreach. The scores influence which prospects receive follow-up and when.

Binding laws in scope
4 laws
Obligations identified
15 obligations
Assessments required
3 assessments
Jurisdictions in scope
California, Colorado, Illinois, Texas; United Kingdom
Jurisdictions with findings
California, Texas; United Kingdom
Industry
Technology
Enterprise Software and SaaS
Generated
Aug 26, 2026, 8:18 PM
Geographic footprint
United Kingdom, US
Findings
15 findings
SHA-256 digest
0cabadf60bc7...9c12e68b

Scope note. Jurisdictions in scope are the U.S. states selected in intake plus non-U.S. footprint jurisdictions (United Kingdom). Jurisdictions with findings are the subset where this report identified duties. Non-U.S. jurisdictions with findings (United Kingdom) are listed on the cover alongside U.S. state counts.

Vendor Intelligence Brief

Vendor research for this deployment is published as a separate brief - AI-assisted public research only, not regulatory substance. Obligations, findings, and citations stay in this Compass report.

Open Vendor Intelligence Brief

01 | Obligations List

Obligations List - duties derived from Findings (requirement, evidence, jurisdiction, owner).

15 obligation rows

Same substance as the Obligations List - What it requires + Evidence - sorted by severity, then deadline band. Use Show more after any truncated requirement for the full Meridian text.

SeqIDSevObligation | what it requiresJurisdictionOwner
1OBL-01HIGH

CPPA regulations - cybersecurity audit

Cal. Code Regs. tit. 11, Sec.Sec. 7120-7124 (Cybersecurity Audits)

11 CCR Sec. 7120 requires a business whose processing of consumers' personal information presents significant risk to consumers' security to complete an annual...

Evidence & deadline

Evidence: Retain written evidence sufficient for counsel to demonstrate discharge of: CPPA regulations - cybersecurity audit. Include documented controls, assigned owner, and retention of review/assessment artifacts mapped to the cited Meridian provision.

Deadline: Before deployment

CaliforniaPrivacy Counsel
2OBL-02HIGH

UK GDPR Art. 28 - confirm executed processor terms with the vendor

UK GDPR (assimilated Regulation (EU) 2016/679) art. 28

Where a vendor processes personal data on the controller's behalf under the UK GDPR, art. 28 requires a binding written contract with the same core processor...

Evidence & deadline

Evidence: Executed Art. 28 processor agreement (or controller-processor terms) with the AI vendor, including instructions, confidentiality, sub-processor, assistance, deletion/return, and audit clauses. Current sub-processor list for the AI service with flow-down confirmation. Record of the pre-engagement vendor assessment demonstrating sufficient guarantees.

Deadline: Before deployment

United KingdomContracts Manager
3OBL-03HIGH

UK GDPR Art. 35 - DPIA where processing is likely high risk

UK GDPR (assimilated Regulation (EU) 2016/679) art. 35

UK GDPR (assimilated Regulation (EU) 2016/679) art. 35 requires a data protection impact assessment before processing that is likely to result in a high risk...

Evidence & deadline

Evidence: Completed DPIA for the AI deployment (or the documented threshold assessment concluding none is required), signed and dated. DPO advice recorded within the DPIA where a DPO is appointed. Mitigation register tying each identified risk to an implemented measure and owner.

Deadline: Before deployment

United KingdomData Protection Officer
4OBL-04HIGH

UK GDPR Art. 46 - document transfer safeguard for restricted transfers

UK GDPR (assimilated Regulation (EU) 2016/679) art. 46

UK GDPR art. 46 requires appropriate safeguards for restricted transfers. Confirm the mechanism covering this AI vendor (IDTA/SCCs/adequacy) is current and...

Evidence & deadline

Evidence: Identification of each restricted transfer in the AI tool's data flows (vendor hosting, sub-processors, support access). The safeguard relied on per transfer (UK IDTA / Addendum, adequacy) with the executed instrument. Transfer risk assessment for each safeguard where required.

Deadline: Before deployment

United KingdomContracts Manager
5OBL-05HIGH

UK GDPR Art. 6 - documented lawful basis for Salesforce Einstein AI

UK GDPR (assimilated Regulation (EU) 2016/679) art. 6

UK GDPR Art. 6(1) requires processing of personal data to rest on at least one lawful basis (consent, contract, legal obligation, vital interests, public...

Evidence & deadline

Evidence: Record of the Art. 6 lawful basis selected for each processing purpose the AI tool serves, with the assessment supporting that basis (legitimate-interest assessment where relied on). Privacy-notice extract showing the lawful basis disclosed for the AI processing. Review log showing the basis was re-confirmed after material changes to the tool's processing.

Deadline: Before deployment

United KingdomLegal Counsel
6OBL-06HIGH

UK GDPR Arts. 13-14 transparency notices identified for AI processing

UK GDPR (assimilated Regulation (EU) 2016/679) Arts. 13-14

Where Salesforce Einstein AI processes personal data of individuals in the UK, UK GDPR Arts. 13-14 require that affected individuals are provided specific...

Evidence & deadline

Evidence: UK GDPR Arts. 13-14 transparency notices covering this AI processing: controller identity, purposes, lawful basis, retention, rights, and automated decision-making information where applicable. Notices delivered through channels appropriate to the data subjects (e.g. applicant/candidate notices for hiring tools - not patient-facing materials unless clinical). Evidence of notice content and delivery retained for ICO audit.

Deadline: Before deployment

United KingdomRequesting Team / Operations Lead
7OBL-07HIGH

Access, correction, deletion, portability, and profiling opt-out

Tex. Bus. & Com. Code Sec. 541.051 - Consumer privacy rights

Grants consumers rights to access, correct, delete, obtain portable copies, and opt out of certain profiling. AI systems must locate personal data in prompts,...

Evidence & deadline

Evidence: Consumer rights fulfillment workflows under Tex. Bus. & Com. Code Sec. 541.051 mapped to AI data stores for this tool (access, correction, deletion, and other Sec. 541.051 rights as applicable). Request intake, honor timelines, and response templates retained.

Deadline: Near-term

TexasLegal Counsel
8OBL-08HIGH

Assessment for high-risk processing

Tex. Bus. & Com. Code Sec. 541.105 - Data protection assessments

Requires documented assessments for heightened-risk processing including sensitive data and consequential profiling. Document model purpose, data...

Evidence & deadline

Evidence: Completed data protection assessment under Tex. Bus. & Com. Code Sec. 541.105 retained for the applicable heightened-risk triggers for this AI use. Sole-basis vs one-input determination, benefits vs risks, and mitigations documented. Assessment producible to the Texas Attorney General under Sec. 541.105.

Deadline: Near-term

TexasLegal Counsel
9OBL-09HIGH

Controller duties - purpose limitation, data minimization, nondiscrimination, and sensitive-data consent (Tex. Bus. & Com. Code Sec. 541.101)

Tex. Bus. & Com. Code Sec. 541.101 - Controller duties / sensitive data

Tex. Bus. & Com. Code Sec. 541.101 imposes the Texas Data Privacy and Security Act's controller-duty core: limit collection of personal data to what is adequate,...

Evidence & deadline

Evidence: Sensitive-data consent under Tex. Bus. & Com. Code Sec. 541.101 evidenced where sensitive categories are processed by this AI use. Consent capture, purpose limitation, and withdrawal handling retained. If sensitive categories are not processed, retain the determination that Sec. 541.101 does not attach.

Deadline: Near-term

TexasLegal Counsel
10OBL-10HIGH

Processor contract terms identified before Texas personal data enters AI systems

Tex. Bus. & Com. Code Sec. 541.104 - Processor contracts

Where Salesforce Einstein AI or its subprocessors process Texas personal data as processors, execute Sec. 541.104 terms (instructions, confidentiality,...

Evidence & deadline

Evidence: Executed Tex. Bus. & Com. Code Sec. 541.104 processor contract terms retained for this AI vendor / subprocessor relationship - controller instructions, confidentiality, deletion-or-return of data at contract end, and flow-down of these terms to any further subprocessors. Terms executed before Texas personal data enters the AI environment.

Deadline: Near-term

TexasLegal Counsel
11OBL-11HIGH

Prohibited manipulation

Tex. Bus. & Comm. Code Sec. 552.052 - Manipulation of Human Behavior

Prohibits intentional use of AI to manipulate human behavior in the manner barred by Sec. 552.052. Sec. 552.052 is the manipulation prohibition - not a general...

Evidence & deadline

Evidence: Retain written evidence sufficient for counsel to demonstrate discharge of: Prohibited manipulation. Include documented controls, assigned owner, and retention of review/assessment artifacts mapped to the cited Meridian provision.

Deadline: Near-term

TexasLegal Counsel
12OBL-12HIGH

Prohibited unlawful discrimination

Tex. Bus. & Comm. Code Sec. 552.056 - Unlawful Discrimination

A person may not develop or deploy an AI system with the intent to unlawfully discriminate against a protected class in violation of state or federal law....

Evidence & deadline

Evidence: Retain written evidence sufficient for counsel to demonstrate discharge of: Prohibited unlawful discrimination. Include documented controls, assigned owner, and retention of review/assessment artifacts mapped to the cited Meridian provision.

Deadline: Near-term

TexasLegal Counsel
13OBL-13HIGH

Targeted advertising opt-out identified for Texas consumers

Tex. Bus. & Com. Code Sec. 541.051(b)(1) - Targeted advertising opt-out

Where Salesforce Einstein AI processes personal data of Texas consumers for targeted advertising, Tex. Bus. & Com. Code Sec. 541.051(b)(1) requires an...

Evidence & deadline

Evidence: Opt-out intake; advertising suppression; request logs

Deadline: Near-term

TexasLegal Counsel
14OBL-14MEDIUM

UK GDPR Art. 32 - confirm AI incident escalation path

UK GDPR (assimilated Regulation (EU) 2016/679) art. 32

UK GDPR art. 32 requires appropriate organisational measures. Confirm a documented AI incident escalation path for this tool.

Evidence & deadline

Evidence: Documented escalation path for AI-related incidents (misuse, breach, malfunction) naming owners and timeframes, integrated with the personal-data-breach procedure. Test or tabletop record exercising the escalation path for an AI-specific scenario. Incident log entries showing AI events routed through the documented path.

Deadline: Near-term

United KingdomLegal Counsel
15OBL-15MEDIUM

UK GDPR Art. 5(1)(e) - storage limitation for Salesforce Einstein AI personal data

UK GDPR (assimilated Regulation (EU) 2016/679) art. 5

UK GDPR Art. 5(1)(e) requires that personal data be kept in a form that permits identification of data subjects for no longer than is necessary for the...

Evidence & deadline

Evidence: Retention schedule entries covering the AI tool's inputs, outputs, logs, and any model-improvement datasets, each with a period and basis. Deletion/anonymisation job records demonstrating the schedule executes against the tool's stores. Documented storage-limitation review for prompts and embeddings retained beyond the underlying record.

Deadline: Near-term

United KingdomLegal Counsel

02 | Evaluation Ledger - Every Applicable Instrument

Evaluation ledger - every applicable instrument with selection or non-selection reasons.

Selected findings and explicit non-selection reasons. Silence (never evaluated) is an engine error and cannot appear here.

Assessed - instrument applicability & enforcement posture

  • California AB 2013 (generative AI training-data transparency, Cal. Civ. Code Sec. 3110 et seq.) was assessed for this California footprint. No developer training-data disclosure duty was selected on these facts - this deployment does not declare that the organization develops or makes available a generative AI system to Californians such that the statute's developer transparency obligations attach.
  • California's CPPA Automated Decision-Making Technology Regulations (11 CCR Sec.Sec. 7150, 7220-7222) were assessed for this California footprint. No ADMT pre-use notice, opt-out, or access duty was selected on these facts - this deployment does not declare a significant decision (employment, housing, credit/lending, education, healthcare, insurance, or essential goods/services) made or substantially facilitated by automated decision-making technology.
  • California's Civil Rights Council automated-decision-system employment regulations (Cal. Code Regs. tit. 2, div. 4.1, ch. 5, subch. 2) were assessed for this California footprint. No anti-bias testing, recordkeeping, or applicant-notice duty was selected on these facts - this deployment does not declare an automated-decision system used in recruitment, hiring, promotion, or other employment decisions affecting California employees or applicants.
  • All Intelligence Library register rows for colorado-ai-act are currently held: Colorado ADMT duties are not downgraded here. SB 26-189, approved May 14, 2026, repealed and reenacted part 17 of article 1 of title 6 of the Colorado Revised Statutes; section 5 of the act takes effect January 1, 2027 and applies to consequential decisions made on or after that date. Separately, in X.AI, LLC v. Weiser, No. 1:26-cv-01515-DDD-CYC (D. Colo. Apr. 27, 2026) (minute order, ECF No. 24), the court entered the parties' stipulation that the Attorney General will not initiate enforcement - including an investigation - for alleged violations of SB 24-205 or legislation replacing or amending it that occur on or before 14 days after the court rules on xAI's forthcoming preliminary-injunction motion, which xAI must file within 28 days after final adoption of implementing rulemaking. That stipulation was entered in litigation to which this organization is not a party and does not move the January 1, 2027 compliance date. Sufficiency and go-live timing remain for your counsel.
  • Intake declares Social Security numbers. Under the intake taxonomy, SSN is ordinary PII - not a TDPSA Sec. 541.101 / Minnesota Sec. 325M.16 sensitive category and not UK/EU GDPR Art. 9 special-category data by itself. No sensitive-consent or Art. 9 finding was selected solely because of SSN. Counsel should review whether collecting SSN for this AI use is necessary (data-minimisation); that judgment is not auto-certified here.
  • The Illinois Artificial Intelligence Video Interview Act was assessed for this Illinois footprint. No AIVIA notice or consent duty was selected on these facts - this deployment does not declare AI analysis of applicant video interviews for an Illinois position.
  • The Illinois Biometric Information Privacy Act (740 ILCS 14/1 et seq.) was assessed for this Illinois footprint. No Sec. 15 written-release, retention-and-destruction, no-profit, disclosure, or security duty was selected on these facts - this deployment does not declare that a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry (or information derived from one and used to identify an individual) is collected, stored, disclosed, or otherwise handled for an Illinois individual. 740 ILCS 14/10 excludes photographs, writing samples, written signatures, demographic data, physical descriptions, health-care-setting and HIPAA data, and Genetic Information Privacy Act materials from the definition, and 740 ILCS 14/25 excludes a financial institution or affiliate subject to Title V of the Gramm-Leach-Bliley Act, Private Detective Act licensees, and State or local government contractors from the Act.
  • The Illinois Human Rights Act's AI-in-employment provisions (775 ILCS 5/2-101, 2-102, Public Act 103-804) were assessed for this Illinois footprint. No AI-employment-discrimination notice or zip-code proxy duty was selected on these facts - this deployment does not declare AI used in recruitment, hiring, promotion, discipline, or other employment decisions affecting Illinois employees or applicants.
  • No employee / job-applicant subject class declared

Evaluation ledger - every applicable instrument

  • California AB 2013assessed no dutyCalifornia AB 2013 (generative AI training-data transparency, Cal. Civ. Code Sec. 3110 et seq.) was assessed for this California footprint. No developer training-data disclosure duty was selected on these facts - this deployment does not declare that the organization develops or makes available a generative AI system to Californians such that the statute's developer transparency obligations attach.
  • California ADMTassessed no dutyCalifornia's CPPA Automated Decision-Making Technology Regulations (11 CCR Sec.Sec. 7150, 7220-7222) were assessed for this California footprint. No ADMT pre-use notice, opt-out, or access duty was selected on these facts - this deployment does not declare a significant decision (employment, housing, credit/lending, education, healthcare, insurance, or essential goods/services) made or substantially facilitated by automated decision-making technology.
  • California CRD Employment AIassessed no dutyCalifornia's Civil Rights Council automated-decision-system employment regulations (Cal. Code Regs. tit. 2, div. 4.1, ch. 5, subch. 2) were assessed for this California footprint. No anti-bias testing, recordkeeping, or applicant-notice duty was selected on these facts - this deployment does not declare an automated-decision system used in recruitment, hiring, promotion, or other employment decisions affecting California employees or applicants.
  • CCPA / CPRAselected
  • Colorado AI Actcitation holdAll Intelligence Library register rows for colorado-ai-act are currently held: Colorado ADMT duties are not downgraded here. SB 26-189, approved May 14, 2026, repealed and reenacted part 17 of article 1 of title 6 of the Colorado Revised Statutes; section 5 of the act takes effect January 1, 2027 and applies to consequential decisions made on or after that date. Separately, in X.AI, LLC v. Weiser, No. 1:26-cv-01515-DDD-CYC (D. Colo. Apr. 27, 2026) (minute order, ECF No. 24), the court entered the parties' stipulation that the Attorney General will not initiate enforcement - including an investigation - for alleged violations of SB 24-205 or legislation replacing or amending it that occur on or before 14 days after the court rules on xAI's forthcoming preliminary-injunction motion, which xAI must file within 28 days after final adoption of implementing rulemaking. That stipulation was entered in litigation to which this organization is not a party and does not move the January 1, 2027 compliance date. Sufficiency and go-live timing remain for your counsel.
  • Illinois AIVIAassessed no dutyThe Illinois Artificial Intelligence Video Interview Act was assessed for this Illinois footprint. No AIVIA notice or consent duty was selected on these facts - this deployment does not declare AI analysis of applicant video interviews for an Illinois position.
  • Illinois BIPAassessed no dutyThe Illinois Biometric Information Privacy Act (740 ILCS 14/1 et seq.) was assessed for this Illinois footprint. No Sec. 15 written-release, retention-and-destruction, no-profit, disclosure, or security duty was selected on these facts - this deployment does not declare that a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry (or information derived from one and used to identify an individual) is collected, stored, disclosed, or otherwise handled for an Illinois individual. 740 ILCS 14/10 excludes photographs, writing samples, written signatures, demographic data, physical descriptions, health-care-setting and HIPAA data, and Genetic Information Privacy Act materials from the definition, and 740 ILCS 14/25 excludes a financial institution or affiliate subject to Title V of the Gramm-Leach-Bliley Act, Private Detective Act licensees, and State or local government contractors from the Act.
  • Illinois HB 3773assessed no dutyThe Illinois Human Rights Act's AI-in-employment provisions (775 ILCS 5/2-101, 2-102, Public Act 103-804) were assessed for this Illinois footprint. No AI-employment-discrimination notice or zip-code proxy duty was selected on these facts - this deployment does not declare AI used in recruitment, hiring, promotion, discipline, or other employment decisions affecting Illinois employees or applicants.
  • Texas TDPSAselected
  • Texas TRAIGAselected
  • UK Equality Actassessed no dutyNo employee / job-applicant subject class declared
  • UK GDPRselected

Obligation evaluation - fired vs set aside

After a law reaches this deployment, each Intelligence Library obligation is recorded as selected or suppressed at applicability, scope, or trigger. Silence is not a result.

  • California AB 2013 - 0 selected of 4 considered; 4 triggerentity_roles condition but the deployment's entity classification is not declared | use_case label does not match the declared deployment narrative
  • CCPA / CPRA - 2 selected of 9 considered; 5 trigger; 2 applicabilityscope_basis does not match this deployment | use_case label does not match the declared deployment narrative
  • NIST AI RMF - 1 selected of 5 considered; 4 triggeruse_case label does not match the declared deployment narrative
  • Texas TDPSA - 6 selected of 12 considered; 6 triggerTDPSA Sec. 541.051(b)(5) - no significant-decision domain declared | sensitive-data consent row - no sensitive data type declared | use_case label does not match the declared deployment narrative
  • Texas TRAIGA - 2 selected of 5 considered; 1 trigger; 2 applicabilitysector / industry condition does not match this deployer | use_case label does not match the declared deployment narrative
  • UK GDPR - 10 selected of 23 considered; 13 triggerArt. 22 solely-automated row - no significant-decision domain declared | GDPR Art. 9 special-category row - no special-category data type declared | provision use_case label does not match the declared deployment narrative | use_case label does not match the declared deployment narrative

03 | Assessment Documents

DPIA, FRIA, PRA, and DPA assessments this deployment requires.

The cards below identify which DPIA, FRIA, PRA, and DPA assessments findings triggered for Report ID 967905096. This report identifies the assessments; it does not produce the completed documents. Counsel determines sufficiency.

EU / UK assessmentU.S. state assessment- jurisdiction family, not severity or status

UK GDPR (assimilated Regulation (EU) 2016/679) art. 35

UK Data Protection Impact Assessment

UK GDPR Art. 35

Required by: UK GDPR (assimilated Regulation (EU) 2016/679) art. 35 - identified in this report

Applies to: United Kingdom operations

Buyer: Data Protection Officer

Source report: 967905096

Assessment required for UK operations. Counsel determines sufficiency.

Texas - Privacy Risk Assessment

Privacy Risk Assessment - Texas

Tex. Bus. & Com. Code Sec. 541.105(a)-(b), (e)-(f) (Data Protection Assessment Requirement)

Required by: Tex. Bus. & Com. Code Sec. 541.105(a)-(b), (e)-(f) (Data Protection Assessment Requirement) (effective July 1, 2024) - distinct from Tex. Bus. & Comm. Code Ch. 552 (TRAIGA) (prohibited-use law, no assessment obligation) - identified in this report

Buyer: Privacy Counsel | Senior executive attestation required

Source report: 967905096

Assessment identified as an obligation for this state footprint. Counsel determines sufficiency.

California - Privacy Risk Assessment

Privacy Risk Assessment - California

CCR Title 11 Sec. 7150

Required by: CCR Title 11 Sec. 7150 (effective January 1, 2026) - identified in this report

Buyer: Privacy Counsel | Senior executive attestation required

Source report: 967905096

Assessment identified as an obligation for this state footprint. Counsel determines sufficiency.

04 | Findings

Statute-cited findings by severity - the regulatory basis for each obligation in the Obligations List.

15 total | statute-cited findings by severity

Critical 0High 13Medium 2Low 0

Critical

A highest-exposure obligation for this deployment - typically a core duty with immediate operational or enforcement consequence if left unaddressed.

Why this level: Assigned from curated obligation severity on the linked Meridian / Intelligence Library finding (and any critical-priority action item), not by counting how many findings share a framework's maximum fine. Two findings under the same statute can differ in severity when the duties differ. Whether a Critical item must be closed before production use is determined by your organization and counsel - not by LegisGate™.

High

A material legal or regulatory obligation that should be closed on a defined timeline before or shortly after deployment.

Why this level: Assigned from curated obligation severity for binding requirements with significant administrative or sector enforcement exposure for this deployment profile (e.g. processor agreements, high-risk deployer duties, state AI transparency laws).

Medium

A control or documentation gap that should be tracked and remediated but is unlikely to drive the headline risk rating on its own.

Why this level: Assigned when the obligation is real but narrower in scope, depends on implementation detail, or carries moderate enforcement relative to Critical/High findings for this deployment.

Low

Advisory, preparatory, or lower-enforcement guidance - still worth documenting but not driving the headline risk rating.

Why this level: Assigned for best-practice hardening, informational transparency items, or obligations where the engine sees limited immediate enforcement pressure for this deployment.

HIGH (13)
HIGHCaliforniaCal. Civ. Code Sec. 1798.100 et seq.

Cal. Civ. Code Sec. 1798.100 et seq. - CPPA regulations - cybersecurity audit

11 CCR Sec. 7120 requires a business whose processing of consumers' personal information presents significant risk to consumers' security to complete an annual cybersecurity audit. Sec. 7121 sets the timing requirements for audits and audit reports; Sec. 7122 requires thoroughness and independence of the audit (with Sec.Sec. 7123-7124 supporting certification and submission mechanics). These are the cybersecurity-audit regulations of CPPA rulemaking under Cal. Civ. Code Sec. 1798.185 - distinct from the Sec.Sec. 7150-7157 risk-assessment regulations and the Sec.Sec. 7200s ADMT regulations.

Remediation steps

Cal. Civ. Code Sec. 1798.100 et seq. - Complete CCR Title 11 risk assessment and cybersecurity audit for Salesforce Einstein AI.

Regulatory citation

Cal. Civ. Code Sec. 1798.100 et seq. - Cal. Code Regs. tit. 11, Sec.Sec. 7120-7124 (Cybersecurity Audits)

Verified | LegisGate Meridian™

Learn more about this finding with Meridian

Meridian record ID: ccpa-cpra:ccr-7120-7124

Verified in Meridian: 2026-08-25

ProvenanceSource: Obligation selection engine (IL + Meridian) | validated 2026-08-25
HIGHPrivacy | TexasTex. Bus. & Com. Code ch. 541

Tex. Bus. & Com. Code ch. 541 - Targeted advertising opt-out identified for Texas consumers

Where Salesforce Einstein AI processes personal data of Texas consumers for targeted advertising, Tex. Bus. & Com. Code Sec. 541.051(b)(1) requires an operational opt-out. This duty attaches on declared targeted-advertising facts and is distinct from Sec. 541.051(b)(5) profiling for legal or similarly significant effects.

Remediation steps

Tex. Bus. & Com. Code ch. 541 - Implement Sec. 541.051(b)(1) targeted-advertising opt-out for Salesforce Einstein AI.

Regulatory citation

Tex. Bus. & Com. Code Sec. 541.051(b)(1) - Targeted advertising opt-out

Verified | LegisGate Meridian™

Learn more about this finding with Meridian

Meridian record ID: texas-tdpsa:sec-541-051-b-1

Verified in Meridian: 2026-08-19

ProvenanceSource: Obligation selection engine (IL + Meridian) | validated 2026-08-19
HIGHTexasTex. Bus. & Com. Code ch. 541

Tex. Bus. & Com. Code ch. 541 - Controller duties - purpose limitation, data minimization, nondiscrimination, and sensitive-data consent (Tex. Bus. & Com. Code Sec. 541.101)

Tex. Bus. & Com. Code Sec. 541.101 imposes the Texas Data Privacy and Security Act's controller-duty core: limit collection of personal data to what is adequate, relevant, and reasonably necessary for the disclosed purposes; do not process personal data for purposes that are neither reasonably necessary to nor compatible with the disclosed purposes absent consent; establish reasonable administrative, technical, and physical data security practices; and do not discriminate against a consumer for exercising chapter rights. These limbs bind every in-scope controller processing Texas personal data through Salesforce Einstein AI. The section's sensitive-data limb - opt-in consent before processing sensitive personal data (racial/ethnic origin, religious beliefs, health diagnosis, sexuality, citizenship or immigration status, genetic or biometric data processed to identify an individual, precise geolocation, or a known child's data) - is not triggered where no such category is declared in intake; Social Security numbers are ordinary personal data under the Act's sensitive-data taxonomy, not a Sec. 541.101 sensitive category. If sensitive categories are later processed, opt-in consent is required before that processing begins.

Remediation steps

Tex. Bus. & Com. Code ch. 541 - Obtain Sec. 541.101 sensitive-data consent for Salesforce Einstein AI.

Regulatory citation

Tex. Bus. & Com. Code Sec. 541.101 - Controller duties / sensitive data

Verified | LegisGate Meridian™

Learn more about this finding with Meridian

Meridian record ID: texas-tdpsa:sec-541-101

Verified in Meridian: 2026-08-19

ProvenanceSource: Obligation selection engine (IL + Meridian) | validated 2026-08-19
HIGHTexasTex. Bus. & Com. Code ch. 541

Tex. Bus. & Com. Code ch. 541 - Processor contract terms identified before Texas personal data enters AI systems

Where Salesforce Einstein AI or its subprocessors process Texas personal data as processors, execute Sec. 541.104 terms (instructions, confidentiality, deletion/return, flow-down) before data enters the AI environment.

Remediation steps

Tex. Bus. & Com. Code ch. 541 - Execute Sec. 541.104 processor terms for Salesforce Einstein AI.

Regulatory citation

Tex. Bus. & Com. Code Sec. 541.104 - Processor contracts

Verified | LegisGate Meridian™

Learn more about this finding with Meridian

Meridian record ID: texas-tdpsa:sec-541-104

Verified in Meridian: 2026-08-19

ProvenanceSource: Obligation selection engine (IL + Meridian) | validated 2026-08-19
HIGHTexasTex. Bus. & Com. Code ch. 541

Tex. Bus. & Com. Code ch. 541 - Access, correction, deletion, portability, and profiling opt-out

Grants consumers rights to access, correct, delete, obtain portable copies, and opt out of certain profiling. AI systems must locate personal data in prompts, fine-tuning sets, vector stores, and logs to respond within statutory timelines under Sec. 541.051. Profiling opt-out for decisions with legal or similarly significant effects lives in Sec. 541.051(b)(5). Undocumented retention in model hosts is a common gap - controllers should map AI data stores to consumer rights workflows before scaling Texas-facing features.

Remediation steps

Tex. Bus. & Com. Code ch. 541 - Wire Sec. 541.051 consumer rights workflows for Salesforce Einstein AI.

Regulatory citation

Tex. Bus. & Com. Code Sec. 541.051 - Consumer privacy rights

Verified | LegisGate Meridian™

Learn more about this finding with Meridian

Meridian record ID: texas-tdpsa:sec-541-051

Verified in Meridian: 2026-08-19

ProvenanceSource: Obligation selection engine (IL + Meridian) | validated 2026-08-19
HIGHTexasTex. Bus. & Com. Code ch. 541

Tex. Bus. & Com. Code ch. 541 - Assessment for high-risk processing

Requires documented assessments for heightened-risk processing including sensitive data and consequential profiling. Document model purpose, data minimization, bias and accuracy risks, and safeguards before deploying AI that profiles Texas consumers for significant decisions.

Remediation steps

Tex. Bus. & Com. Code ch. 541 - Complete the Sec. 541.105 data protection assessment for Salesforce Einstein AI.

Regulatory citation

Tex. Bus. & Com. Code Sec. 541.105 - Data protection assessments

Verified | LegisGate Meridian™

Learn more about this finding with Meridian

Meridian record ID: texas-tdpsa:sec-541-105:metadata-applicability

Verified in Meridian: 2026-08-19

ProvenanceSource: Obligation selection engine (IL + Meridian) | validated 2026-08-19
HIGHTexasTex. Bus. & Comm. Code Ch. 552

Tex. Bus. & Comm. Code Ch. 552 - Prohibited manipulation

Prohibits intentional use of AI to manipulate human behavior in the manner barred by Sec. 552.052. Sec. 552.052 is the manipulation prohibition - not a general 'prohibited intentional uses' umbrella. Companion prohibitions live in Sec. 552.053 (social scoring by governmental entities), Sec. 552.054 (biometric capture limits), Sec. 552.055 (constitutional protections), Sec. 552.056 (unlawful discrimination), and Sec. 552.057 (sexually explicit / child-exploitation content).

Remediation steps

Tex. Bus. & Comm. Code Ch. 552 - Complete Tex. Bus. & Comm. Code Sec. 552.052 - Manipulation of Human Behavior fairness / adverse-action review for Salesforce Einstein AI.

Regulatory citation

Tex. Bus. & Comm. Code Sec. 552.052 - Manipulation of Human Behavior

Verified | LegisGate Meridian™

Learn more about this finding with Meridian

Meridian record ID: texas-traiga:sec-552-052

Verified in Meridian: 2026-08-03

ProvenanceSource: Obligation selection engine (IL + Meridian) | validated 2026-08-03
HIGHTexasTex. Bus. & Comm. Code Ch. 552

Tex. Bus. & Comm. Code Ch. 552 - Prohibited unlawful discrimination

A person may not develop or deploy an AI system with the intent to unlawfully discriminate against a protected class in violation of state or federal law. Intent-based standard: disparate impact alone is not sufficient by itself to demonstrate intent to discriminate. Protected class means a group or class of persons with a characteristic, quality, belief, or status protected from discrimination by state or federal civil rights law -- includes race, color, national origin, sex, age, religion, and disability. Insurance entities subject to applicable unfair-discrimination/unfair-competition insurance statutes are carved out. One of the two headline intent-based prohibitions the framework's scope note names (companion: Sec. 552.052 manipulation, provision:2).

Remediation steps

Tex. Bus. & Comm. Code Ch. 552 - Document non-discriminatory intent for Salesforce Einstein AI's AI design and deployment.

Regulatory citation

Tex. Bus. & Comm. Code Sec. 552.056 - Unlawful Discrimination

Verified | LegisGate Meridian™

Learn more about this finding with Meridian

Meridian record ID: texas-traiga:sec-552-056

Verified in Meridian: 2026-08-24

ProvenanceSource: Obligation selection engine (IL + Meridian) | validated 2026-08-24
HIGHUnited KingdomUK GDPR (assimilated Regulation (EU) 2016/679) art. 6

UK GDPR Art. 6 - documented lawful basis for Salesforce Einstein AI

UK GDPR Art. 6(1) requires processing of personal data to rest on at least one lawful basis (consent, contract, legal obligation, vital interests, public task, or legitimate interests). For Salesforce Einstein AI, identify each processing purpose (inference, logging, analytics, model improvement, support) and record the Art. 6(1) basis relied on before go-live. Where special-category data is processed, an Art. 9(2) condition is also required. Legitimate interests (Art. 6(1)(f)) require a documented balancing test. Purpose drift - e.g. using support prompts to train a general model without a compatible basis - fails Art. 6. The record of processing / DPIA should cite the basis per purpose; rubber-stamp ‘legitimate interests’ without analysis is not sufficient.

Remediation steps

Document the UK GDPR Art. 6 lawful basis matrix for Salesforce Einstein AI.

Regulatory citation

UK GDPR (assimilated Regulation (EU) 2016/679) art. 6

Verified | LegisGate Meridian™

Learn more about this finding with Meridian

Meridian record ID: uk-gdpr:art-6

Verified in Meridian: 2026-08-19

ProvenanceSource: Obligation selection engine (IL + Meridian) | validated 2026-08-19
HIGHUnited KingdomUK GDPR (assimilated Regulation (EU) 2016/679) art. 28

UK GDPR Art. 28 - confirm executed processor terms with the vendor

Where a vendor processes personal data on the controller's behalf under the UK GDPR, art. 28 requires a binding written contract with the same core processor terms as EU GDPR Art. 28. Confirm an executed processor agreement covers Salesforce Einstein AI.

Remediation steps

Execute art. 28 processor / contractual terms for Salesforce Einstein AI.

Regulatory citation

UK GDPR (assimilated Regulation (EU) 2016/679) art. 28

Verified | LegisGate Meridian™

Learn more about this finding with Meridian

Meridian record ID: uk-gdpr:art-28

Verified in Meridian: 2026-08-19

ProvenanceSource: Obligation selection engine (IL + Meridian) | validated 2026-08-19
HIGHUnited KingdomUK GDPR (assimilated Regulation (EU) 2016/679) art. 35

UK GDPR Art. 35 - DPIA where processing is likely high risk

UK GDPR (assimilated Regulation (EU) 2016/679) art. 35 requires a data protection impact assessment before processing that is likely to result in a high risk to individuals' rights and freedoms. Art. 35(3) lists processing that is systematic and extensive evaluation of personal aspects based on automated processing (including profiling) and on which decisions are based that produce legal or similarly significant effects. For Salesforce Einstein AI, apply those criteria to the declared purposes, data categories, scale, and decision effects. If the threshold is met, complete and retain a DPIA before the processing continues.

Remediation steps

Complete or resolve the UK GDPR Art. 35 DPIA determination for Salesforce Einstein AI.

Regulatory citation

UK GDPR (assimilated Regulation (EU) 2016/679) art. 35

Verified | LegisGate Meridian™

Learn more about this finding with Meridian

Meridian record ID: uk-gdpr:art-35

Verified in Meridian: 2026-08-19

ProvenanceSource: Obligation selection engine (IL + Meridian) | validated 2026-08-19
HIGHUnited KingdomUK GDPR (assimilated Regulation (EU) 2016/679) art. 46

UK GDPR Art. 46 - document transfer safeguard for restricted transfers

UK GDPR art. 46 requires appropriate safeguards for restricted transfers. Confirm the mechanism covering this AI vendor (IDTA/SCCs/adequacy) is current and scoped.

Remediation steps

Document UK GDPR Art. 46 transfer safeguard for Salesforce Einstein AI.

Regulatory citation

UK GDPR (assimilated Regulation (EU) 2016/679) art. 46

Verified | LegisGate Meridian™

Learn more about this finding with Meridian

Meridian record ID: uk-gdpr:art-46

Verified in Meridian: 2026-08-19

ProvenanceSource: Obligation selection engine (IL + Meridian) | validated 2026-08-19
HIGHUnited KingdomUK GDPR (assimilated Regulation (EU) 2016/679) Arts. 13-14

UK GDPR Arts. 13-14 transparency notices identified for AI processing

Where Salesforce Einstein AI processes personal data of individuals in the UK, UK GDPR Arts. 13-14 require that affected individuals are provided specific information about the processing at the time data is collected or within one month where data is not collected directly from the individual. For AI systems this includes information about automated decision-making logic where applicable. Transparency notices must cover the controller identity, processing purposes, lawful basis, data retention periods, and data subject rights.

Remediation steps

Implement Arts. 13-14 controls for Salesforce Einstein AI.

Regulatory citation

UK GDPR (assimilated Regulation (EU) 2016/679) Arts. 13-14

Verified | LegisGate Meridian™

Learn more about this finding with Meridian

Meridian record ID: uk-gdpr-arts-13-14

Verified in Meridian: 2026-08-19

ProvenanceSource: Obligation selection engine (IL + Meridian) | validated 2026-08-19
MEDIUM (2)
MEDIUMUnited KingdomUK GDPR (assimilated Regulation (EU) 2016/679) art. 32
MEDIUMUnited KingdomUK GDPR (assimilated Regulation (EU) 2016/679) art. 5

05 | Intake Information Submitted

Checkout intake answers - submitter, tool, footprint, data, and declared controls.

The fields below are exactly what was submitted on Review & submit. They scope laws, findings, and vendor intelligence to this deployment.

Submitted by

Submitter
Sara Mitchell | sara.mitchell@legisgatetechnology.com
Department
Privacy
Organization
LegisGate Technology

Tool & deployment

AI tool / product
Salesforce Einstein AI
Model provider
Not specified
Use case

A mid-size B2B software company deploys Salesforce Einstein AI to score and rank sales leads and opportunities. The AI analyzes historical CRM data - deal history, customer interactions, firmographic data, and behavioral signals - to predict which leads are most likely to convert and which open opportunities are most likely to close. Sales representatives use the scores to prioritize their outreach. The scores influence which prospects receive follow-up and when.

AI system type
Predictive or analytical AI - forecasts, scores, or ranks
Hosting
In the vendor's cloud (typical SaaS)
Industry
Technology | Enterprise Software and SaaS
Who the tool interacts with / decides about
External individuals only (customers, patients, citizens, members of the public)

Geographic scope

Geographic footprint
United Kingdom, US
U.S. states in scope
California, Colorado, Illinois, Texas
EU/EEA operations
No - not declared in intake
CCPA “business” threshold (California)
Yes - meets at least one CCPA “business” threshold

Data & automated decisions

Data types in scope
PII - Names, PII - Email, PII - Phone, PII - SSN, PII - Address, Customer / member data
Estimated data subjects
15,000
Combines / cross-references personal data from multiple sources
Yes
Processes personal data about vulnerable people
No
Influences decisions about individuals
Yes - declared in intake
Decision description

The AI scoring directly influences which prospects are prioritized for sales outreach and which receive follow-up contact. Sales rep decisions are shaped by the AI output.

Scores, ranks, predicts, or segments individuals (profiling)
Yes
Significant-decision domains
None of these
Credit / loan decisioning
No - recommendations, fraud alerts, or other non-credit decisions only
Employment / workplace decisioning
No - this AI does not make or influence employment or workplace decisions
Targeted or behavioral advertising
Yes
Sells or shares personal data for valuable consideration
No

AI training & data practices

Vendor uses customer data to train / improve AI models
Don't know
Vendor retention of prompts / inputs / outputs
Don't know
Vendor logs or stores prompts
Don't know

Declared controls & existing safeguards

Color reflects what you declared at intake (yes / no / not sure) - not a severity or risk rating.

Document / ControlStatus DeclaredWhat this covers
A signed data processing agreement with this vendorNot sureA contract (sometimes called a DPA) covering how the vendor handles personal data on your behalf. Required under GDPR Article 28 when the vendor processes EU or UK personal data for you.
A safeguard for sending EU/UK personal data outside that regionNot sureNeeded when EU/EEA or UK personal data leaves that region for the vendor to process. Common forms: EU Standard Contractual Clauses (SCCs), the UK IDTA, or an adequacy decision.
A privacy notice telling people about this AI useNot sureWhether the people whose data this tool uses have been told what's collected and why. Required under GDPR Articles 13-14.
Documented legal grounds for using sensitive personal dataNot sure"Sensitive" data includes things like health, racial or ethnic origin, or religious belief. If this tool touches any of it, whether you've recorded your legal basis for that under GDPR Article 9.
Documented rules for how long this data is keptNot sureWhether you have written retention periods and a deletion process for personal data this tool touches. Required under GDPR Article 5.
Data protection / AI risk impact assessment (DPIA)Not sureA documented assessment of the privacy and AI risks for this specific use.
AI risk classification documented (e.g., EU AI Act risk tier)Not sureWhether you have recorded this tool's risk tier under a law such as the EU AI Act.
Meaningful human review of the AI's outputs or decisionsYes - a person reviews or can override every timeWhether a person reviews or can override the AI before it affects someone. If review only happens sometimes - e.g. only for high-risk cases, or it exists on paper but isn't consistently followed - pick Partial and describe it.
AI literacy training for employees who use or oversee this toolNot sureStaff training on how this AI works, its limits, and escalation - not vendor model-training on your data. Binding under EU AI Act Art. 4 when EU/EEA (or UK-adjacent) footprint applies; still useful evidence for US-only deployments.
Named owner for human oversight of this AI systemNot sureWhether a specific person or role is assigned to oversee this system (competence and authority to intervene).
Documented escalation path for AI incidents or serious risksNot sureWhether there is a written path to escalate serious AI malfunctions, biased outcomes, or safety incidents.
This intake record is frozen at the time of report generation and forms part of the SHA-256 integrity record. The fields above are exactly as submitted - they scope every finding and obligation in this report to this specific deployment at this point in time.

06 | Report Reading Guide

Severity definitions, glossary, initiation record, and SHA-256 help.

Quick definitions for the counts and sections in this document. This is reference material only - it does not change the substantive analysis above.

Finding severity

Each finding is tagged Critical, High, Medium, or Low based on the analysis pass. The card shows the category, a short narrative, a regulatory citation (the hook statute or program), optional evidence lines, and a recommendation when one was generated.

Evaluation ledger

The Evaluation Ledger records every applicable instrument the engine assessed - selected findings and explicit non-selection reasons. Silence (never evaluated) is an engine error and cannot appear there.

Acronym glossary

Plain-language expansions for the acronyms that appear in this report.

ADMT
- Automated Decision-Making Technology
DPIA
- Data Protection Impact Assessment
DPO
- Data Protection Officer
GDPR
- General Data Protection Regulation (EU)
IDTA
- International Data Transfer Agreement (UK)
SCC
- Standard Contractual Clauses (EU cross-border transfer mechanism)

Vendor Intelligence Brief

Vendor research is published as a separate brief (open Vendor Intelligence Brief - AI-assisted public research only, not regulatory substance. Obligations, findings, and citations stay in this Compass report.

Regulatory Review Initiation Record

A system-generated statement on the cover page documenting when this report was generated and its scope at that time. It records the initiation of a review as a fact; it does not certify compliance or the sufficiency of any subsequent action. The record is bound into the report's SHA-256 digest.

SHA-256 digest

The hash on the cover and again under Integrity, Verification and Legal Disclaimer fingerprints the finalized report payload. Compare digests to confirm the document you are viewing matches what was issued.

07 | Integrity, Verification and Legal Disclaimer

Integrity digest, technical audit identifiers, and legal disclaimer.

SHA-256 digest

0cabadf60bc79a36d9435a3be79b735841d5784267ecb3b108d5253e9c12e68b

Generated when this report was finalized. Use this value to confirm the delivered document has not been modified since issuance.

The Regulatory Review Initiation Record on the cover page is included in the hashed report payload. The digest above therefore also verifies the initiation date, scope counts, and record text against the report as issued.

Technical audit identifiers

Terms acceptance context

IP address
127.0.0.1
User agent
LegisGate marketing-sample

Report scope & provenance

What this report documents

Template-first: active

Finding provenance in this report

  • Meridian library templates: 15
  • Declared-control templates: 0
  • Deterministic pipeline: 0
  • Not yet curated (neutral notice): 0

What this report asserts

  • Regulatory findings are generated by the LegisGate™ Intelligence Engine from declared intake, geographic footprint, and the curated intelligence library corpus.
  • Finding severity is assigned from the curated Meridian / Intelligence Library template for each provision - not by a generative model score, and not as a composite risk score.
  • Each finding includes a provenance line stating whether substance is a curated Meridian library template, a declared-control template, or a deterministic pipeline rule for this intake profile. The engine never authors regulatory analysis with a generative model; any obligation not yet curated shows a neutral 'not currently curated' notice instead.
  • Library templates marked Meridian reference passed the machine-enforced Meridian citation and template-integrity bar (citation resolution, template integrity, substantive content quality); the provenance line states the validation level and last-reviewed date when available.
  • 15 finding(s) use curated Meridian library primary templates (Meridian reference corpus); the remainder are declared-control templates or deterministic pipeline rules.

Does not represent

  • This report is not legal advice and does not replace counsel review.
  • Meridian reference: confirmed by the LegisGate Meridian to meet our completeness and sourcing standard - structurally verified, source-linked, and reproducible. This is a machine-enforced validation, not a substantive legal review. Findings are not legal advice; counsel decides.
  • Vendor intelligence reflects public research at generation time and does not attest to executed contracts (BAA, DPA, etc.) for your organization.

Product scope (LegisGate Compass™ Report)

Includes

  • Point-in-time regulatory intelligence for one declared AI tool deployment (intake-driven footprint).
  • Provenance-tagged findings, counsel obligations derived from those findings, and SHA-256 report integrity digest.
  • Evaluation ledger showing why each in-scope instrument was assessed, retained, or recorded as pending.

Excludes

  • Continuous monitoring, workflow approvals, or tracked remediation state - available in the enterprise assessment workspace.
  • Counsel sign-off, regulatory filing, or certification of compliance for your organization.
  • Attestation that executed vendor contracts (BAA, DPA, etc.) are in place for this deployment.
LegisGate™ | Regulatory Intelligence for AI Deployments - Patent pendingReport ID: 967905096 | Aug 26, 2026, 8:18 PM | © 2026 LegisGate Inc.legisgate.com