AI Tool Regulatory Obligation Report
LegisGate Compass™
LegisGate Compass™ Report | by LegisGate™
Patent pending
Salesforce Einstein AI
Vendor: Salesforce
Prepared for LegisGate Technology
Purchaser & terms
Sara Mitchell | sara.mitchell@legisgatetechnology.com
Terms accepted Aug 21, 2026, 3:07 AM UTC | v2.0
Sales voucher clickwrap agreement
A mid-size B2B software company deploys Salesforce Einstein AI to score and rank sales leads and opportunities. The AI analyzes historical CRM data - deal history, customer interactions, firmographic data, and behavioral signals - to predict which leads are most likely to convert and which open opportunities are most likely to close. Sales representatives use the scores to prioritize their outreach. The scores influence which prospects receive follow-up and when.
- Binding laws in scope
- 4 laws
- Obligations identified
- 15 obligations
- Assessments required
- 3 assessments
- Jurisdictions in scope
- California, Colorado, Illinois, Texas; United Kingdom
- Jurisdictions with findings
- California, Texas; United Kingdom
- Industry
- TechnologyEnterprise Software and SaaS
- Generated
- Aug 26, 2026, 8:18 PM
- Geographic footprint
- United Kingdom, US
- Findings
- 15 findings
- SHA-256 digest
- 0cabadf60bc7...9c12e68b
Scope note. Jurisdictions in scope are the U.S. states selected in intake plus non-U.S. footprint jurisdictions (United Kingdom). Jurisdictions with findings are the subset where this report identified duties. Non-U.S. jurisdictions with findings (United Kingdom) are listed on the cover alongside U.S. state counts.
Vendor Intelligence Brief
Vendor research for this deployment is published as a separate brief - AI-assisted public research only, not regulatory substance. Obligations, findings, and citations stay in this Compass report.
01 | Obligations List
Obligations List - duties derived from Findings (requirement, evidence, jurisdiction, owner).
15 obligation rows
Same substance as the Obligations List - What it requires + Evidence - sorted by severity, then deadline band. Use Show more after any truncated requirement for the full Meridian text.
| Seq | ID | Sev | Obligation | what it requires | Jurisdiction | Owner |
|---|---|---|---|---|---|
| 1 | OBL-01 | HIGH | CPPA regulations - cybersecurity audit Cal. Code Regs. tit. 11, Sec.Sec. 7120-7124 (Cybersecurity Audits) 11 CCR Sec. 7120 requires a business whose processing of consumers' personal information presents significant risk to consumers' security to complete an annual... Evidence & deadlineEvidence: Retain written evidence sufficient for counsel to demonstrate discharge of: CPPA regulations - cybersecurity audit. Include documented controls, assigned owner, and retention of review/assessment artifacts mapped to the cited Meridian provision. Deadline: Before deployment | California | Privacy Counsel |
| 2 | OBL-02 | HIGH | UK GDPR Art. 28 - confirm executed processor terms with the vendor UK GDPR (assimilated Regulation (EU) 2016/679) art. 28 Where a vendor processes personal data on the controller's behalf under the UK GDPR, art. 28 requires a binding written contract with the same core processor... Evidence & deadlineEvidence: Executed Art. 28 processor agreement (or controller-processor terms) with the AI vendor, including instructions, confidentiality, sub-processor, assistance, deletion/return, and audit clauses. Current sub-processor list for the AI service with flow-down confirmation. Record of the pre-engagement vendor assessment demonstrating sufficient guarantees. Deadline: Before deployment | United Kingdom | Contracts Manager |
| 3 | OBL-03 | HIGH | UK GDPR Art. 35 - DPIA where processing is likely high risk UK GDPR (assimilated Regulation (EU) 2016/679) art. 35 UK GDPR (assimilated Regulation (EU) 2016/679) art. 35 requires a data protection impact assessment before processing that is likely to result in a high risk... Evidence & deadlineEvidence: Completed DPIA for the AI deployment (or the documented threshold assessment concluding none is required), signed and dated. DPO advice recorded within the DPIA where a DPO is appointed. Mitigation register tying each identified risk to an implemented measure and owner. Deadline: Before deployment | United Kingdom | Data Protection Officer |
| 4 | OBL-04 | HIGH | UK GDPR Art. 46 - document transfer safeguard for restricted transfers UK GDPR (assimilated Regulation (EU) 2016/679) art. 46 UK GDPR art. 46 requires appropriate safeguards for restricted transfers. Confirm the mechanism covering this AI vendor (IDTA/SCCs/adequacy) is current and... Evidence & deadlineEvidence: Identification of each restricted transfer in the AI tool's data flows (vendor hosting, sub-processors, support access). The safeguard relied on per transfer (UK IDTA / Addendum, adequacy) with the executed instrument. Transfer risk assessment for each safeguard where required. Deadline: Before deployment | United Kingdom | Contracts Manager |
| 5 | OBL-05 | HIGH | UK GDPR Art. 6 - documented lawful basis for Salesforce Einstein AI UK GDPR (assimilated Regulation (EU) 2016/679) art. 6 UK GDPR Art. 6(1) requires processing of personal data to rest on at least one lawful basis (consent, contract, legal obligation, vital interests, public... Evidence & deadlineEvidence: Record of the Art. 6 lawful basis selected for each processing purpose the AI tool serves, with the assessment supporting that basis (legitimate-interest assessment where relied on). Privacy-notice extract showing the lawful basis disclosed for the AI processing. Review log showing the basis was re-confirmed after material changes to the tool's processing. Deadline: Before deployment | United Kingdom | Legal Counsel |
| 6 | OBL-06 | HIGH | UK GDPR Arts. 13-14 transparency notices identified for AI processing UK GDPR (assimilated Regulation (EU) 2016/679) Arts. 13-14 Where Salesforce Einstein AI processes personal data of individuals in the UK, UK GDPR Arts. 13-14 require that affected individuals are provided specific... Evidence & deadlineEvidence: UK GDPR Arts. 13-14 transparency notices covering this AI processing: controller identity, purposes, lawful basis, retention, rights, and automated decision-making information where applicable. Notices delivered through channels appropriate to the data subjects (e.g. applicant/candidate notices for hiring tools - not patient-facing materials unless clinical). Evidence of notice content and delivery retained for ICO audit. Deadline: Before deployment | United Kingdom | Requesting Team / Operations Lead |
| 7 | OBL-07 | HIGH | Access, correction, deletion, portability, and profiling opt-out Tex. Bus. & Com. Code Sec. 541.051 - Consumer privacy rights Grants consumers rights to access, correct, delete, obtain portable copies, and opt out of certain profiling. AI systems must locate personal data in prompts,... Evidence & deadlineEvidence: Consumer rights fulfillment workflows under Tex. Bus. & Com. Code Sec. 541.051 mapped to AI data stores for this tool (access, correction, deletion, and other Sec. 541.051 rights as applicable). Request intake, honor timelines, and response templates retained. Deadline: Near-term | Texas | Legal Counsel |
| 8 | OBL-08 | HIGH | Assessment for high-risk processing Tex. Bus. & Com. Code Sec. 541.105 - Data protection assessments Requires documented assessments for heightened-risk processing including sensitive data and consequential profiling. Document model purpose, data... Evidence & deadlineEvidence: Completed data protection assessment under Tex. Bus. & Com. Code Sec. 541.105 retained for the applicable heightened-risk triggers for this AI use. Sole-basis vs one-input determination, benefits vs risks, and mitigations documented. Assessment producible to the Texas Attorney General under Sec. 541.105. Deadline: Near-term | Texas | Legal Counsel |
| 9 | OBL-09 | HIGH | Controller duties - purpose limitation, data minimization, nondiscrimination, and sensitive-data consent (Tex. Bus. & Com. Code Sec. 541.101) Tex. Bus. & Com. Code Sec. 541.101 - Controller duties / sensitive data Tex. Bus. & Com. Code Sec. 541.101 imposes the Texas Data Privacy and Security Act's controller-duty core: limit collection of personal data to what is adequate,... Evidence & deadlineEvidence: Sensitive-data consent under Tex. Bus. & Com. Code Sec. 541.101 evidenced where sensitive categories are processed by this AI use. Consent capture, purpose limitation, and withdrawal handling retained. If sensitive categories are not processed, retain the determination that Sec. 541.101 does not attach. Deadline: Near-term | Texas | Legal Counsel |
| 10 | OBL-10 | HIGH | Processor contract terms identified before Texas personal data enters AI systems Tex. Bus. & Com. Code Sec. 541.104 - Processor contracts Where Salesforce Einstein AI or its subprocessors process Texas personal data as processors, execute Sec. 541.104 terms (instructions, confidentiality,... Evidence & deadlineEvidence: Executed Tex. Bus. & Com. Code Sec. 541.104 processor contract terms retained for this AI vendor / subprocessor relationship - controller instructions, confidentiality, deletion-or-return of data at contract end, and flow-down of these terms to any further subprocessors. Terms executed before Texas personal data enters the AI environment. Deadline: Near-term | Texas | Legal Counsel |
| 11 | OBL-11 | HIGH | Prohibited manipulation Tex. Bus. & Comm. Code Sec. 552.052 - Manipulation of Human Behavior Prohibits intentional use of AI to manipulate human behavior in the manner barred by Sec. 552.052. Sec. 552.052 is the manipulation prohibition - not a general... Evidence & deadlineEvidence: Retain written evidence sufficient for counsel to demonstrate discharge of: Prohibited manipulation. Include documented controls, assigned owner, and retention of review/assessment artifacts mapped to the cited Meridian provision. Deadline: Near-term | Texas | Legal Counsel |
| 12 | OBL-12 | HIGH | Prohibited unlawful discrimination Tex. Bus. & Comm. Code Sec. 552.056 - Unlawful Discrimination A person may not develop or deploy an AI system with the intent to unlawfully discriminate against a protected class in violation of state or federal law.... Evidence & deadlineEvidence: Retain written evidence sufficient for counsel to demonstrate discharge of: Prohibited unlawful discrimination. Include documented controls, assigned owner, and retention of review/assessment artifacts mapped to the cited Meridian provision. Deadline: Near-term | Texas | Legal Counsel |
| 13 | OBL-13 | HIGH | Targeted advertising opt-out identified for Texas consumers Tex. Bus. & Com. Code Sec. 541.051(b)(1) - Targeted advertising opt-out Where Salesforce Einstein AI processes personal data of Texas consumers for targeted advertising, Tex. Bus. & Com. Code Sec. 541.051(b)(1) requires an... Evidence & deadlineEvidence: Opt-out intake; advertising suppression; request logs Deadline: Near-term | Texas | Legal Counsel |
| 14 | OBL-14 | MEDIUM | UK GDPR Art. 32 - confirm AI incident escalation path UK GDPR (assimilated Regulation (EU) 2016/679) art. 32 UK GDPR art. 32 requires appropriate organisational measures. Confirm a documented AI incident escalation path for this tool. Evidence & deadlineEvidence: Documented escalation path for AI-related incidents (misuse, breach, malfunction) naming owners and timeframes, integrated with the personal-data-breach procedure. Test or tabletop record exercising the escalation path for an AI-specific scenario. Incident log entries showing AI events routed through the documented path. Deadline: Near-term | United Kingdom | Legal Counsel |
| 15 | OBL-15 | MEDIUM | UK GDPR Art. 5(1)(e) - storage limitation for Salesforce Einstein AI personal data UK GDPR (assimilated Regulation (EU) 2016/679) art. 5 UK GDPR Art. 5(1)(e) requires that personal data be kept in a form that permits identification of data subjects for no longer than is necessary for the... Evidence & deadlineEvidence: Retention schedule entries covering the AI tool's inputs, outputs, logs, and any model-improvement datasets, each with a period and basis. Deletion/anonymisation job records demonstrating the schedule executes against the tool's stores. Documented storage-limitation review for prompts and embeddings retained beyond the underlying record. Deadline: Near-term | United Kingdom | Legal Counsel |
02 | Evaluation Ledger - Every Applicable Instrument
Evaluation ledger - every applicable instrument with selection or non-selection reasons.
Selected findings and explicit non-selection reasons. Silence (never evaluated) is an engine error and cannot appear here.
Assessed - instrument applicability & enforcement posture
- California AB 2013 (generative AI training-data transparency, Cal. Civ. Code Sec. 3110 et seq.) was assessed for this California footprint. No developer training-data disclosure duty was selected on these facts - this deployment does not declare that the organization develops or makes available a generative AI system to Californians such that the statute's developer transparency obligations attach.
- California's CPPA Automated Decision-Making Technology Regulations (11 CCR Sec.Sec. 7150, 7220-7222) were assessed for this California footprint. No ADMT pre-use notice, opt-out, or access duty was selected on these facts - this deployment does not declare a significant decision (employment, housing, credit/lending, education, healthcare, insurance, or essential goods/services) made or substantially facilitated by automated decision-making technology.
- California's Civil Rights Council automated-decision-system employment regulations (Cal. Code Regs. tit. 2, div. 4.1, ch. 5, subch. 2) were assessed for this California footprint. No anti-bias testing, recordkeeping, or applicant-notice duty was selected on these facts - this deployment does not declare an automated-decision system used in recruitment, hiring, promotion, or other employment decisions affecting California employees or applicants.
- All Intelligence Library register rows for colorado-ai-act are currently held: Colorado ADMT duties are not downgraded here. SB 26-189, approved May 14, 2026, repealed and reenacted part 17 of article 1 of title 6 of the Colorado Revised Statutes; section 5 of the act takes effect January 1, 2027 and applies to consequential decisions made on or after that date. Separately, in X.AI, LLC v. Weiser, No. 1:26-cv-01515-DDD-CYC (D. Colo. Apr. 27, 2026) (minute order, ECF No. 24), the court entered the parties' stipulation that the Attorney General will not initiate enforcement - including an investigation - for alleged violations of SB 24-205 or legislation replacing or amending it that occur on or before 14 days after the court rules on xAI's forthcoming preliminary-injunction motion, which xAI must file within 28 days after final adoption of implementing rulemaking. That stipulation was entered in litigation to which this organization is not a party and does not move the January 1, 2027 compliance date. Sufficiency and go-live timing remain for your counsel.
- Intake declares Social Security numbers. Under the intake taxonomy, SSN is ordinary PII - not a TDPSA Sec. 541.101 / Minnesota Sec. 325M.16 sensitive category and not UK/EU GDPR Art. 9 special-category data by itself. No sensitive-consent or Art. 9 finding was selected solely because of SSN. Counsel should review whether collecting SSN for this AI use is necessary (data-minimisation); that judgment is not auto-certified here.
- The Illinois Artificial Intelligence Video Interview Act was assessed for this Illinois footprint. No AIVIA notice or consent duty was selected on these facts - this deployment does not declare AI analysis of applicant video interviews for an Illinois position.
- The Illinois Biometric Information Privacy Act (740 ILCS 14/1 et seq.) was assessed for this Illinois footprint. No Sec. 15 written-release, retention-and-destruction, no-profit, disclosure, or security duty was selected on these facts - this deployment does not declare that a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry (or information derived from one and used to identify an individual) is collected, stored, disclosed, or otherwise handled for an Illinois individual. 740 ILCS 14/10 excludes photographs, writing samples, written signatures, demographic data, physical descriptions, health-care-setting and HIPAA data, and Genetic Information Privacy Act materials from the definition, and 740 ILCS 14/25 excludes a financial institution or affiliate subject to Title V of the Gramm-Leach-Bliley Act, Private Detective Act licensees, and State or local government contractors from the Act.
- The Illinois Human Rights Act's AI-in-employment provisions (775 ILCS 5/2-101, 2-102, Public Act 103-804) were assessed for this Illinois footprint. No AI-employment-discrimination notice or zip-code proxy duty was selected on these facts - this deployment does not declare AI used in recruitment, hiring, promotion, discipline, or other employment decisions affecting Illinois employees or applicants.
- No employee / job-applicant subject class declared
Evaluation ledger - every applicable instrument
- California AB 2013assessed no dutyCalifornia AB 2013 (generative AI training-data transparency, Cal. Civ. Code Sec. 3110 et seq.) was assessed for this California footprint. No developer training-data disclosure duty was selected on these facts - this deployment does not declare that the organization develops or makes available a generative AI system to Californians such that the statute's developer transparency obligations attach.
- California ADMTassessed no dutyCalifornia's CPPA Automated Decision-Making Technology Regulations (11 CCR Sec.Sec. 7150, 7220-7222) were assessed for this California footprint. No ADMT pre-use notice, opt-out, or access duty was selected on these facts - this deployment does not declare a significant decision (employment, housing, credit/lending, education, healthcare, insurance, or essential goods/services) made or substantially facilitated by automated decision-making technology.
- California CRD Employment AIassessed no dutyCalifornia's Civil Rights Council automated-decision-system employment regulations (Cal. Code Regs. tit. 2, div. 4.1, ch. 5, subch. 2) were assessed for this California footprint. No anti-bias testing, recordkeeping, or applicant-notice duty was selected on these facts - this deployment does not declare an automated-decision system used in recruitment, hiring, promotion, or other employment decisions affecting California employees or applicants.
- CCPA / CPRAselected
- Colorado AI Actcitation holdAll Intelligence Library register rows for colorado-ai-act are currently held: Colorado ADMT duties are not downgraded here. SB 26-189, approved May 14, 2026, repealed and reenacted part 17 of article 1 of title 6 of the Colorado Revised Statutes; section 5 of the act takes effect January 1, 2027 and applies to consequential decisions made on or after that date. Separately, in X.AI, LLC v. Weiser, No. 1:26-cv-01515-DDD-CYC (D. Colo. Apr. 27, 2026) (minute order, ECF No. 24), the court entered the parties' stipulation that the Attorney General will not initiate enforcement - including an investigation - for alleged violations of SB 24-205 or legislation replacing or amending it that occur on or before 14 days after the court rules on xAI's forthcoming preliminary-injunction motion, which xAI must file within 28 days after final adoption of implementing rulemaking. That stipulation was entered in litigation to which this organization is not a party and does not move the January 1, 2027 compliance date. Sufficiency and go-live timing remain for your counsel.
- Illinois AIVIAassessed no dutyThe Illinois Artificial Intelligence Video Interview Act was assessed for this Illinois footprint. No AIVIA notice or consent duty was selected on these facts - this deployment does not declare AI analysis of applicant video interviews for an Illinois position.
- Illinois BIPAassessed no dutyThe Illinois Biometric Information Privacy Act (740 ILCS 14/1 et seq.) was assessed for this Illinois footprint. No Sec. 15 written-release, retention-and-destruction, no-profit, disclosure, or security duty was selected on these facts - this deployment does not declare that a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry (or information derived from one and used to identify an individual) is collected, stored, disclosed, or otherwise handled for an Illinois individual. 740 ILCS 14/10 excludes photographs, writing samples, written signatures, demographic data, physical descriptions, health-care-setting and HIPAA data, and Genetic Information Privacy Act materials from the definition, and 740 ILCS 14/25 excludes a financial institution or affiliate subject to Title V of the Gramm-Leach-Bliley Act, Private Detective Act licensees, and State or local government contractors from the Act.
- Illinois HB 3773assessed no dutyThe Illinois Human Rights Act's AI-in-employment provisions (775 ILCS 5/2-101, 2-102, Public Act 103-804) were assessed for this Illinois footprint. No AI-employment-discrimination notice or zip-code proxy duty was selected on these facts - this deployment does not declare AI used in recruitment, hiring, promotion, discipline, or other employment decisions affecting Illinois employees or applicants.
- Texas TDPSAselected
- Texas TRAIGAselected
- UK Equality Actassessed no dutyNo employee / job-applicant subject class declared
- UK GDPRselected
Obligation evaluation - fired vs set aside
After a law reaches this deployment, each Intelligence Library obligation is recorded as selected or suppressed at applicability, scope, or trigger. Silence is not a result.
- California AB 2013 - 0 selected of 4 considered; 4 triggerentity_roles condition but the deployment's entity classification is not declared | use_case label does not match the declared deployment narrative
- CCPA / CPRA - 2 selected of 9 considered; 5 trigger; 2 applicabilityscope_basis does not match this deployment | use_case label does not match the declared deployment narrative
- NIST AI RMF - 1 selected of 5 considered; 4 triggeruse_case label does not match the declared deployment narrative
- Texas TDPSA - 6 selected of 12 considered; 6 triggerTDPSA Sec. 541.051(b)(5) - no significant-decision domain declared | sensitive-data consent row - no sensitive data type declared | use_case label does not match the declared deployment narrative
- Texas TRAIGA - 2 selected of 5 considered; 1 trigger; 2 applicabilitysector / industry condition does not match this deployer | use_case label does not match the declared deployment narrative
- UK GDPR - 10 selected of 23 considered; 13 triggerArt. 22 solely-automated row - no significant-decision domain declared | GDPR Art. 9 special-category row - no special-category data type declared | provision use_case label does not match the declared deployment narrative | use_case label does not match the declared deployment narrative
03 | Assessment Documents
DPIA, FRIA, PRA, and DPA assessments this deployment requires.
The cards below identify which DPIA, FRIA, PRA, and DPA assessments findings triggered for Report ID 967905096. This report identifies the assessments; it does not produce the completed documents. Counsel determines sufficiency.
EU / UK assessmentU.S. state assessment- jurisdiction family, not severity or status
UK Data Protection Impact Assessment
UK GDPR Art. 35
Required by: UK GDPR (assimilated Regulation (EU) 2016/679) art. 35 - identified in this report
Applies to: United Kingdom operations
Buyer: Data Protection Officer
Source report: 967905096
Assessment required for UK operations. Counsel determines sufficiency.
Privacy Risk Assessment - Texas
Tex. Bus. & Com. Code Sec. 541.105(a)-(b), (e)-(f) (Data Protection Assessment Requirement)
Required by: Tex. Bus. & Com. Code Sec. 541.105(a)-(b), (e)-(f) (Data Protection Assessment Requirement) (effective July 1, 2024) - distinct from Tex. Bus. & Comm. Code Ch. 552 (TRAIGA) (prohibited-use law, no assessment obligation) - identified in this report
Buyer: Privacy Counsel | Senior executive attestation required
Source report: 967905096
Assessment identified as an obligation for this state footprint. Counsel determines sufficiency.
Privacy Risk Assessment - California
CCR Title 11 Sec. 7150
Required by: CCR Title 11 Sec. 7150 (effective January 1, 2026) - identified in this report
Buyer: Privacy Counsel | Senior executive attestation required
Source report: 967905096
Assessment identified as an obligation for this state footprint. Counsel determines sufficiency.
04 | Findings
Statute-cited findings by severity - the regulatory basis for each obligation in the Obligations List.
15 total | statute-cited findings by severity
Critical
A highest-exposure obligation for this deployment - typically a core duty with immediate operational or enforcement consequence if left unaddressed.
Why this level: Assigned from curated obligation severity on the linked Meridian / Intelligence Library finding (and any critical-priority action item), not by counting how many findings share a framework's maximum fine. Two findings under the same statute can differ in severity when the duties differ. Whether a Critical item must be closed before production use is determined by your organization and counsel - not by LegisGate™.
High
A material legal or regulatory obligation that should be closed on a defined timeline before or shortly after deployment.
Why this level: Assigned from curated obligation severity for binding requirements with significant administrative or sector enforcement exposure for this deployment profile (e.g. processor agreements, high-risk deployer duties, state AI transparency laws).
Medium
A control or documentation gap that should be tracked and remediated but is unlikely to drive the headline risk rating on its own.
Why this level: Assigned when the obligation is real but narrower in scope, depends on implementation detail, or carries moderate enforcement relative to Critical/High findings for this deployment.
Low
Advisory, preparatory, or lower-enforcement guidance - still worth documenting but not driving the headline risk rating.
Why this level: Assigned for best-practice hardening, informational transparency items, or obligations where the engine sees limited immediate enforcement pressure for this deployment.
HIGH (13)
Cal. Civ. Code Sec. 1798.100 et seq. - CPPA regulations - cybersecurity audit
11 CCR Sec. 7120 requires a business whose processing of consumers' personal information presents significant risk to consumers' security to complete an annual cybersecurity audit. Sec. 7121 sets the timing requirements for audits and audit reports; Sec. 7122 requires thoroughness and independence of the audit (with Sec.Sec. 7123-7124 supporting certification and submission mechanics). These are the cybersecurity-audit regulations of CPPA rulemaking under Cal. Civ. Code Sec. 1798.185 - distinct from the Sec.Sec. 7150-7157 risk-assessment regulations and the Sec.Sec. 7200s ADMT regulations.
Cal. Civ. Code Sec. 1798.100 et seq. - Complete CCR Title 11 risk assessment and cybersecurity audit for Salesforce Einstein AI.
Cal. Civ. Code Sec. 1798.100 et seq. - Cal. Code Regs. tit. 11, Sec.Sec. 7120-7124 (Cybersecurity Audits)
Verified | LegisGate Meridian™
Learn more about this finding with MeridianMeridian record ID: ccpa-cpra:ccr-7120-7124
Verified in Meridian: 2026-08-25
Tex. Bus. & Com. Code ch. 541 - Targeted advertising opt-out identified for Texas consumers
Where Salesforce Einstein AI processes personal data of Texas consumers for targeted advertising, Tex. Bus. & Com. Code Sec. 541.051(b)(1) requires an operational opt-out. This duty attaches on declared targeted-advertising facts and is distinct from Sec. 541.051(b)(5) profiling for legal or similarly significant effects.
Tex. Bus. & Com. Code ch. 541 - Implement Sec. 541.051(b)(1) targeted-advertising opt-out for Salesforce Einstein AI.
Tex. Bus. & Com. Code Sec. 541.051(b)(1) - Targeted advertising opt-out
Verified | LegisGate Meridian™
Learn more about this finding with MeridianMeridian record ID: texas-tdpsa:sec-541-051-b-1
Verified in Meridian: 2026-08-19
Tex. Bus. & Com. Code ch. 541 - Controller duties - purpose limitation, data minimization, nondiscrimination, and sensitive-data consent (Tex. Bus. & Com. Code Sec. 541.101)
Tex. Bus. & Com. Code Sec. 541.101 imposes the Texas Data Privacy and Security Act's controller-duty core: limit collection of personal data to what is adequate, relevant, and reasonably necessary for the disclosed purposes; do not process personal data for purposes that are neither reasonably necessary to nor compatible with the disclosed purposes absent consent; establish reasonable administrative, technical, and physical data security practices; and do not discriminate against a consumer for exercising chapter rights. These limbs bind every in-scope controller processing Texas personal data through Salesforce Einstein AI. The section's sensitive-data limb - opt-in consent before processing sensitive personal data (racial/ethnic origin, religious beliefs, health diagnosis, sexuality, citizenship or immigration status, genetic or biometric data processed to identify an individual, precise geolocation, or a known child's data) - is not triggered where no such category is declared in intake; Social Security numbers are ordinary personal data under the Act's sensitive-data taxonomy, not a Sec. 541.101 sensitive category. If sensitive categories are later processed, opt-in consent is required before that processing begins.
Tex. Bus. & Com. Code ch. 541 - Obtain Sec. 541.101 sensitive-data consent for Salesforce Einstein AI.
Tex. Bus. & Com. Code Sec. 541.101 - Controller duties / sensitive data
Verified | LegisGate Meridian™
Learn more about this finding with MeridianMeridian record ID: texas-tdpsa:sec-541-101
Verified in Meridian: 2026-08-19
Tex. Bus. & Com. Code ch. 541 - Processor contract terms identified before Texas personal data enters AI systems
Where Salesforce Einstein AI or its subprocessors process Texas personal data as processors, execute Sec. 541.104 terms (instructions, confidentiality, deletion/return, flow-down) before data enters the AI environment.
Tex. Bus. & Com. Code ch. 541 - Execute Sec. 541.104 processor terms for Salesforce Einstein AI.
Tex. Bus. & Com. Code Sec. 541.104 - Processor contracts
Verified | LegisGate Meridian™
Learn more about this finding with MeridianMeridian record ID: texas-tdpsa:sec-541-104
Verified in Meridian: 2026-08-19
Tex. Bus. & Com. Code ch. 541 - Access, correction, deletion, portability, and profiling opt-out
Grants consumers rights to access, correct, delete, obtain portable copies, and opt out of certain profiling. AI systems must locate personal data in prompts, fine-tuning sets, vector stores, and logs to respond within statutory timelines under Sec. 541.051. Profiling opt-out for decisions with legal or similarly significant effects lives in Sec. 541.051(b)(5). Undocumented retention in model hosts is a common gap - controllers should map AI data stores to consumer rights workflows before scaling Texas-facing features.
Tex. Bus. & Com. Code ch. 541 - Wire Sec. 541.051 consumer rights workflows for Salesforce Einstein AI.
Tex. Bus. & Com. Code Sec. 541.051 - Consumer privacy rights
Verified | LegisGate Meridian™
Learn more about this finding with MeridianMeridian record ID: texas-tdpsa:sec-541-051
Verified in Meridian: 2026-08-19
Tex. Bus. & Com. Code ch. 541 - Assessment for high-risk processing
Requires documented assessments for heightened-risk processing including sensitive data and consequential profiling. Document model purpose, data minimization, bias and accuracy risks, and safeguards before deploying AI that profiles Texas consumers for significant decisions.
Tex. Bus. & Com. Code ch. 541 - Complete the Sec. 541.105 data protection assessment for Salesforce Einstein AI.
Tex. Bus. & Com. Code Sec. 541.105 - Data protection assessments
Verified | LegisGate Meridian™
Learn more about this finding with MeridianMeridian record ID: texas-tdpsa:sec-541-105:metadata-applicability
Verified in Meridian: 2026-08-19
Tex. Bus. & Comm. Code Ch. 552 - Prohibited manipulation
Prohibits intentional use of AI to manipulate human behavior in the manner barred by Sec. 552.052. Sec. 552.052 is the manipulation prohibition - not a general 'prohibited intentional uses' umbrella. Companion prohibitions live in Sec. 552.053 (social scoring by governmental entities), Sec. 552.054 (biometric capture limits), Sec. 552.055 (constitutional protections), Sec. 552.056 (unlawful discrimination), and Sec. 552.057 (sexually explicit / child-exploitation content).
Tex. Bus. & Comm. Code Ch. 552 - Complete Tex. Bus. & Comm. Code Sec. 552.052 - Manipulation of Human Behavior fairness / adverse-action review for Salesforce Einstein AI.
Tex. Bus. & Comm. Code Sec. 552.052 - Manipulation of Human Behavior
Verified | LegisGate Meridian™
Learn more about this finding with MeridianMeridian record ID: texas-traiga:sec-552-052
Verified in Meridian: 2026-08-03
Tex. Bus. & Comm. Code Ch. 552 - Prohibited unlawful discrimination
A person may not develop or deploy an AI system with the intent to unlawfully discriminate against a protected class in violation of state or federal law. Intent-based standard: disparate impact alone is not sufficient by itself to demonstrate intent to discriminate. Protected class means a group or class of persons with a characteristic, quality, belief, or status protected from discrimination by state or federal civil rights law -- includes race, color, national origin, sex, age, religion, and disability. Insurance entities subject to applicable unfair-discrimination/unfair-competition insurance statutes are carved out. One of the two headline intent-based prohibitions the framework's scope note names (companion: Sec. 552.052 manipulation, provision:2).
Tex. Bus. & Comm. Code Ch. 552 - Document non-discriminatory intent for Salesforce Einstein AI's AI design and deployment.
Tex. Bus. & Comm. Code Sec. 552.056 - Unlawful Discrimination
Verified | LegisGate Meridian™
Learn more about this finding with MeridianMeridian record ID: texas-traiga:sec-552-056
Verified in Meridian: 2026-08-24
UK GDPR Art. 6 - documented lawful basis for Salesforce Einstein AI
UK GDPR Art. 6(1) requires processing of personal data to rest on at least one lawful basis (consent, contract, legal obligation, vital interests, public task, or legitimate interests). For Salesforce Einstein AI, identify each processing purpose (inference, logging, analytics, model improvement, support) and record the Art. 6(1) basis relied on before go-live. Where special-category data is processed, an Art. 9(2) condition is also required. Legitimate interests (Art. 6(1)(f)) require a documented balancing test. Purpose drift - e.g. using support prompts to train a general model without a compatible basis - fails Art. 6. The record of processing / DPIA should cite the basis per purpose; rubber-stamp ‘legitimate interests’ without analysis is not sufficient.
Document the UK GDPR Art. 6 lawful basis matrix for Salesforce Einstein AI.
UK GDPR (assimilated Regulation (EU) 2016/679) art. 6
Verified | LegisGate Meridian™
Learn more about this finding with MeridianMeridian record ID: uk-gdpr:art-6
Verified in Meridian: 2026-08-19
UK GDPR Art. 28 - confirm executed processor terms with the vendor
Execute art. 28 processor / contractual terms for Salesforce Einstein AI.
UK GDPR (assimilated Regulation (EU) 2016/679) art. 28
Verified | LegisGate Meridian™
Learn more about this finding with MeridianMeridian record ID: uk-gdpr:art-28
Verified in Meridian: 2026-08-19
UK GDPR Art. 35 - DPIA where processing is likely high risk
UK GDPR (assimilated Regulation (EU) 2016/679) art. 35 requires a data protection impact assessment before processing that is likely to result in a high risk to individuals' rights and freedoms. Art. 35(3) lists processing that is systematic and extensive evaluation of personal aspects based on automated processing (including profiling) and on which decisions are based that produce legal or similarly significant effects. For Salesforce Einstein AI, apply those criteria to the declared purposes, data categories, scale, and decision effects. If the threshold is met, complete and retain a DPIA before the processing continues.
Complete or resolve the UK GDPR Art. 35 DPIA determination for Salesforce Einstein AI.
UK GDPR (assimilated Regulation (EU) 2016/679) art. 35
Verified | LegisGate Meridian™
Learn more about this finding with MeridianMeridian record ID: uk-gdpr:art-35
Verified in Meridian: 2026-08-19
UK GDPR Art. 46 - document transfer safeguard for restricted transfers
Document UK GDPR Art. 46 transfer safeguard for Salesforce Einstein AI.
UK GDPR (assimilated Regulation (EU) 2016/679) art. 46
Verified | LegisGate Meridian™
Learn more about this finding with MeridianMeridian record ID: uk-gdpr:art-46
Verified in Meridian: 2026-08-19
UK GDPR Arts. 13-14 transparency notices identified for AI processing
Where Salesforce Einstein AI processes personal data of individuals in the UK, UK GDPR Arts. 13-14 require that affected individuals are provided specific information about the processing at the time data is collected or within one month where data is not collected directly from the individual. For AI systems this includes information about automated decision-making logic where applicable. Transparency notices must cover the controller identity, processing purposes, lawful basis, data retention periods, and data subject rights.
Implement Arts. 13-14 controls for Salesforce Einstein AI.
UK GDPR (assimilated Regulation (EU) 2016/679) Arts. 13-14
Verified | LegisGate Meridian™
Learn more about this finding with MeridianMeridian record ID: uk-gdpr-arts-13-14
Verified in Meridian: 2026-08-19
MEDIUM (2)
05 | Intake Information Submitted
Checkout intake answers - submitter, tool, footprint, data, and declared controls.
The fields below are exactly what was submitted on Review & submit. They scope laws, findings, and vendor intelligence to this deployment.
Submitted by
- Submitter
- Sara Mitchell | sara.mitchell@legisgatetechnology.com
- Department
- Privacy
- Organization
- LegisGate Technology
Tool & deployment
- AI tool / product
- Salesforce Einstein AI
- Model provider
- Not specified
- Use case
A mid-size B2B software company deploys Salesforce Einstein AI to score and rank sales leads and opportunities. The AI analyzes historical CRM data - deal history, customer interactions, firmographic data, and behavioral signals - to predict which leads are most likely to convert and which open opportunities are most likely to close. Sales representatives use the scores to prioritize their outreach. The scores influence which prospects receive follow-up and when.
- AI system type
- Predictive or analytical AI - forecasts, scores, or ranks
- Hosting
- In the vendor's cloud (typical SaaS)
- Industry
- Technology | Enterprise Software and SaaS
- Who the tool interacts with / decides about
- External individuals only (customers, patients, citizens, members of the public)
Geographic scope
- Geographic footprint
- United Kingdom, US
- U.S. states in scope
- California, Colorado, Illinois, Texas
- EU/EEA operations
- No - not declared in intake
- CCPA “business” threshold (California)
- Yes - meets at least one CCPA “business” threshold
Data & automated decisions
- Data types in scope
- PII - Names, PII - Email, PII - Phone, PII - SSN, PII - Address, Customer / member data
- Estimated data subjects
- 15,000
- Combines / cross-references personal data from multiple sources
- Yes
- Processes personal data about vulnerable people
- No
- Influences decisions about individuals
- Yes - declared in intake
- Decision description
The AI scoring directly influences which prospects are prioritized for sales outreach and which receive follow-up contact. Sales rep decisions are shaped by the AI output.
- Scores, ranks, predicts, or segments individuals (profiling)
- Yes
- Significant-decision domains
- None of these
- Credit / loan decisioning
- No - recommendations, fraud alerts, or other non-credit decisions only
- Employment / workplace decisioning
- No - this AI does not make or influence employment or workplace decisions
- Targeted or behavioral advertising
- Yes
- Sells or shares personal data for valuable consideration
- No
AI training & data practices
- Vendor uses customer data to train / improve AI models
- Don't know
- Vendor retention of prompts / inputs / outputs
- Don't know
- Vendor logs or stores prompts
- Don't know
Declared controls & existing safeguards
Color reflects what you declared at intake (yes / no / not sure) - not a severity or risk rating.
| Document / Control | Status Declared | What this covers |
|---|---|---|
| A signed data processing agreement with this vendor | Not sure | A contract (sometimes called a DPA) covering how the vendor handles personal data on your behalf. Required under GDPR Article 28 when the vendor processes EU or UK personal data for you. |
| A safeguard for sending EU/UK personal data outside that region | Not sure | Needed when EU/EEA or UK personal data leaves that region for the vendor to process. Common forms: EU Standard Contractual Clauses (SCCs), the UK IDTA, or an adequacy decision. |
| A privacy notice telling people about this AI use | Not sure | Whether the people whose data this tool uses have been told what's collected and why. Required under GDPR Articles 13-14. |
| Documented legal grounds for using sensitive personal data | Not sure | "Sensitive" data includes things like health, racial or ethnic origin, or religious belief. If this tool touches any of it, whether you've recorded your legal basis for that under GDPR Article 9. |
| Documented rules for how long this data is kept | Not sure | Whether you have written retention periods and a deletion process for personal data this tool touches. Required under GDPR Article 5. |
| Data protection / AI risk impact assessment (DPIA) | Not sure | A documented assessment of the privacy and AI risks for this specific use. |
| AI risk classification documented (e.g., EU AI Act risk tier) | Not sure | Whether you have recorded this tool's risk tier under a law such as the EU AI Act. |
| Meaningful human review of the AI's outputs or decisions | Yes - a person reviews or can override every time | Whether a person reviews or can override the AI before it affects someone. If review only happens sometimes - e.g. only for high-risk cases, or it exists on paper but isn't consistently followed - pick Partial and describe it. |
| AI literacy training for employees who use or oversee this tool | Not sure | Staff training on how this AI works, its limits, and escalation - not vendor model-training on your data. Binding under EU AI Act Art. 4 when EU/EEA (or UK-adjacent) footprint applies; still useful evidence for US-only deployments. |
| Named owner for human oversight of this AI system | Not sure | Whether a specific person or role is assigned to oversee this system (competence and authority to intervene). |
| Documented escalation path for AI incidents or serious risks | Not sure | Whether there is a written path to escalate serious AI malfunctions, biased outcomes, or safety incidents. |
06 | Report Reading Guide
Severity definitions, glossary, initiation record, and SHA-256 help.
Quick definitions for the counts and sections in this document. This is reference material only - it does not change the substantive analysis above.
Finding severity
Each finding is tagged Critical, High, Medium, or Low based on the analysis pass. The card shows the category, a short narrative, a regulatory citation (the hook statute or program), optional evidence lines, and a recommendation when one was generated.
Evaluation ledger
The Evaluation Ledger records every applicable instrument the engine assessed - selected findings and explicit non-selection reasons. Silence (never evaluated) is an engine error and cannot appear there.
Acronym glossary
Plain-language expansions for the acronyms that appear in this report.
- ADMT
- - Automated Decision-Making Technology
- DPIA
- - Data Protection Impact Assessment
- DPO
- - Data Protection Officer
- GDPR
- - General Data Protection Regulation (EU)
- IDTA
- - International Data Transfer Agreement (UK)
- SCC
- - Standard Contractual Clauses (EU cross-border transfer mechanism)
Vendor Intelligence Brief
Vendor research is published as a separate brief (open Vendor Intelligence Brief - AI-assisted public research only, not regulatory substance. Obligations, findings, and citations stay in this Compass report.
Regulatory Review Initiation Record
A system-generated statement on the cover page documenting when this report was generated and its scope at that time. It records the initiation of a review as a fact; it does not certify compliance or the sufficiency of any subsequent action. The record is bound into the report's SHA-256 digest.
SHA-256 digest
The hash on the cover and again under Integrity, Verification and Legal Disclaimer fingerprints the finalized report payload. Compare digests to confirm the document you are viewing matches what was issued.
07 | Integrity, Verification and Legal Disclaimer
Integrity digest, technical audit identifiers, and legal disclaimer.
SHA-256 digest
0cabadf60bc79a36d9435a3be79b735841d5784267ecb3b108d5253e9c12e68b
Generated when this report was finalized. Use this value to confirm the delivered document has not been modified since issuance.
The Regulatory Review Initiation Record on the cover page is included in the hashed report payload. The digest above therefore also verifies the initiation date, scope counts, and record text against the report as issued.
Technical audit identifiers
Terms acceptance context
- IP address
- 127.0.0.1
- User agent
- LegisGate marketing-sample
Report scope & provenance
What this report documents
Finding provenance in this report
- Meridian library templates: 15
- Declared-control templates: 0
- Deterministic pipeline: 0
- Not yet curated (neutral notice): 0
What this report asserts
- Regulatory findings are generated by the LegisGate™ Intelligence Engine from declared intake, geographic footprint, and the curated intelligence library corpus.
- Finding severity is assigned from the curated Meridian / Intelligence Library template for each provision - not by a generative model score, and not as a composite risk score.
- Each finding includes a provenance line stating whether substance is a curated Meridian library template, a declared-control template, or a deterministic pipeline rule for this intake profile. The engine never authors regulatory analysis with a generative model; any obligation not yet curated shows a neutral 'not currently curated' notice instead.
- Library templates marked Meridian reference passed the machine-enforced Meridian citation and template-integrity bar (citation resolution, template integrity, substantive content quality); the provenance line states the validation level and last-reviewed date when available.
- 15 finding(s) use curated Meridian library primary templates (Meridian reference corpus); the remainder are declared-control templates or deterministic pipeline rules.
Does not represent
- This report is not legal advice and does not replace counsel review.
- Meridian reference: confirmed by the LegisGate Meridian to meet our completeness and sourcing standard - structurally verified, source-linked, and reproducible. This is a machine-enforced validation, not a substantive legal review. Findings are not legal advice; counsel decides.
- Vendor intelligence reflects public research at generation time and does not attest to executed contracts (BAA, DPA, etc.) for your organization.
Product scope (LegisGate Compass™ Report)
Includes
- Point-in-time regulatory intelligence for one declared AI tool deployment (intake-driven footprint).
- Provenance-tagged findings, counsel obligations derived from those findings, and SHA-256 report integrity digest.
- Evaluation ledger showing why each in-scope instrument was assessed, retained, or recorded as pending.
Excludes
- Continuous monitoring, workflow approvals, or tracked remediation state - available in the enterprise assessment workspace.
- Counsel sign-off, regulatory filing, or certification of compliance for your organization.
- Attestation that executed vendor contracts (BAA, DPA, etc.) are in place for this deployment.
Legal & methodology
LegisGate™ Disclaimer
About LegisGate™ LegisGate Compass™ Reports
The LegisGate Compass™ Report combines the LegisGate Meridian™ - a curated regulatory intelligence reference - deterministic regulatory rules, and citations resolved to Meridian records linked to primary statutory sources. Finding substance is Meridian templates or deterministic rules - never LLM-authored.
Regulatory findings are never AI-authored. Each finding is produced by a validated Meridian™ template or by a Deterministic Rule applied to your confirmed intake, geographic footprint, and deployment context. Finding text, obligation substance, severity tied to regulatory requirements, and citations come from that Meridian™ and rules layer - not from a language model.
The deterministic rules engine identifies applicable laws and regulations, applies obligation-based logic from confirmed intake, enforces jurisdiction-specific citation rules, applies severity floors, and runs structured classification sequences (including the EU AI Act mandatory classification path) as deterministic code.
An LLM is used only for live vendor documentation research summaries - within bounds set by the engine. Executive summary, finding substance, obligation text, evidence requirements, and citations are Meridian™ templates and deterministic rules; they are never LLM-authored. Vendor research prose is advisory and separate from that regulatory substance.
Each regulatory citation resolves to a Meridian™ record that points at the authoritative primary statutory source it claims - binding regulation, official guidance, enforcement precedent, or recognized standard. Each finding includes provenance stating whether substance is a curated Meridian™ template or a deterministic pipeline rule.
LegisGate™'s regulatory intelligence methodology is Patent pending.
Not Legal Advice
This report does not constitute legal advice, legal opinion, or a legal determination of compliance with any applicable law or regulation.
Findings represent regulatory research and analysis intended to inform qualified human compliance decisions - not to replace them. Review by qualified privacy counsel, legal counsel, or compliance professionals is recommended before making compliance determinations, deployment decisions, or regulatory representations based on LegisGate™ findings.
Accuracy and Limitations
LegisGate™'s intelligence engine is designed to surface applicable regulatory findings with specific legal citations based on available intake information. The accuracy and completeness of findings depends in part on the accuracy and completeness of information provided during intake.
Laws and regulations evolve continuously. LegisGate™ maintains the LegisGate Meridian™ and an active regulatory intelligence cache updated through the LegisGate™ Intelligence and Opportunity Engine - however no platform can guarantee real-time coverage of all regulatory developments. Organizations should maintain independent regulatory monitoring appropriate to their obligations.
LegisGate™ findings do not represent a complete or exhaustive regulatory analysis. They represent structured regulatory intelligence designed to inform and support the work of qualified legal, compliance, and privacy professionals.
Human Decision Authority
LegisGate™ produces LegisGate Compass™ Reports. Deployment decisions - approved, conditionally approved, or denied - are made by qualified human professionals within your organization. LegisGate™ documents the findings and the evidence base that support those decisions. LegisGate™ does not make compliance determinations on behalf of any organization.
No Regulatory Guarantee
Use of LegisGate™ does not guarantee regulatory compliance, exemption from enforcement, or protection from fines or penalties. Regulatory authorities make their own determinations of compliance independently of any third-party compliance tool or report.
Trademark and Patent
LegisGate™ is a trademark of LegisGate™ Inc. The LegisGate™ regulatory intelligence methodology - including the curated Meridian citation library, rules engine architecture, deterministic obligation mapping layer, jurisdiction footprint detection, EU AI Act mandatory classification sequence, and citation verification - is Patent pending.
© 2026 LegisGate™ Inc. All rights reserved.