8 Salesforce Backup Controls for HIPAA and GDPR
- Mar 11
- 7 min read
Quick Answer
Keeping Salesforce backup compliance intact in 2026 means satisfying two requirements simultaneously — protecting data against the user mistakes that cause most Salesforce data loss, and meeting the retention, audit, and data control compliance requirements organizations face under HIPAA, the General Data Protection Regulation, and other regulatory frameworks.
Salesforce's native tools satisfy neither requirement fully. Enterprise IT teams that close the gap use purpose-built backup platforms that automate continuous protection, produce audit-ready evidence, and keep backup data inside infrastructure they control — not on vendor servers.
The compliance gap most IT teams discover too late
The gap between having a backup and having a compliant backup is wider than most organizations realize. A compliant Salesforce backup is not just a copy of your data. It is a governed, auditable, continuously maintained record of every change, every deletion, and every access event — stored in infrastructure your organization controls, retained long term for the period your regulatory framework requires, and recoverable at the precision level that incident response demands.
User error sits at the intersection of both problems. The Enterprise Strategy Group found that 73% of Salesforce data loss stems from internal incidents — accidental deletions, bad data imports, misconfigured automation, and integration failures. These are the incidents that HIPAA compliance standards and the data protection regulation GDPR hold your organization responsible for preventing and recovering from. User error prevention alone is not enough.
Your organization also needs the backup infrastructure to demonstrate, with evidence, that it detected, contained, and recovered from each incident correctly. Understanding exactly what security and compliance obligations require — and exactly where native Salesforce tools fall short — is the starting point for building a backup strategy that holds up under scrutiny.
What HIPAA and GDPR require from your Salesforce backup
Health insurance portability and accountability requirements establish specific technical safeguards for electronic protected health information including data such as patient records, IP addresses, and other regulated identifiers. For Salesforce environments in healthcare — Health Cloud implementations, CRM at payers and providers, life sciences CRM — these requirements create specific backup obligations that go well beyond what most IT teams have in place.
The Contingency Plan standard requires covered entities to create and maintain retrievable exact copies of ePHI. A weekly CSV export is a copy. An exact, retrievable copy that your team can restore to a specific point in time, at a specific record, without corrupting surrounding data is a meaningfully different capability — and the one that HIPAA compliance actually requires.
The Audit Controls standard requires complete data audit trails for every field on every object that contains ePHI — retained for the full six-year period. Access controls must limit backup access by user, by object, and by operation type. Any platform processing ePHI on your behalf requires a signed Business Associate Agreement, making cloud-hosted backup platforms a source of ongoing security and compliance monitoring obligations.
The General Data Protection Regulation GDPR requirements extend across multiple articles. Article 5's integrity and confidentiality principle requires that data — including data collected through Salesforce — be protected against accidental loss, destruction, ransomware attacks, and unauthorized access across all operating systems involved in the backup chain.
Article 17's right to erasure requires deletion requests to extend to backup copies in cloud storage — not just production records. Article 20's data portability requirement means your organization must produce personal data in a structured, machine-readable format when data subjects request it. Article 30 requires documenting the backup architecture itself — what data is backed up, where it is stored, how long it is retained, and under what legal basis data collection and processing occurs. Article 32 requires encryption in transit and at rest, reducing the risk of unauthorized access throughout the backup lifecycle.
For organizations subject to both frameworks, the six-year HIPAA and seven-year SOX retention requirements define the long-term minimum. Your backup platform must support customer-defined retention periods that satisfy the most stringent applicable requirement.
Where Salesforce's native tools fall short
Native Salesforce regulatory compliance tools address some IT data protection needs at a surface level but leave meaningful gaps across every compliance requirement.
Data Export Service produces full org exports as CSV files on a weekly or daily schedule. It does not provide continuous backup, does not support record-level or field-level recovery, and restoring from a CSV export means overwriting current production data with data that may be days old — creating additional compliance exposure rather than resolving it.
Field History Tracking logs changes to up to 20 fields per object and retains data audit trails for 18 months. For compliance frameworks requiring six or seven years of field-level history including data from complex custom objects, the 20-field cap and 18-month window are structurally insufficient.
The recycle bin retains deleted records for 15 days before permanent removal. For compliance scenarios where records deleted months ago need to be produced — including data related to litigation holds or GDPR erasure verification — 15-day retention provides no recovery path.
Setup Audit Trail captures configuration changes for 180 days — insufficient for multi-year information security documentation requirements.
None of these tools store backup or audit data outside of Salesforce's own infrastructure — meaning your compliance evidence and production data share the same platform, the same access controls, and the same security vulnerabilities including ransomware attacks.
Building a compliant backup strategy
A backup strategy that satisfies HIPAA compliance, the data protection regulation GDPR, and the operational realities of user error recovery is built around five capabilities working together.
Continuous automated backup at compliant intervals
For HIPAA environments and GDPR-sensitive personal data, five to fifteen minute backup intervals represent the standard of care in 2026, reducing the risk of significant data loss between backup points. Sesame Software's Backup Scheduler runs automated backups as frequently as every five minutes — creating a continuous recovery timeline that closes the gap between backup points to minutes rather than hours or days.
Complete data audit trails beyond native retention limits
Every field on every object containing regulated data needs complete change history retained long term for the duration of your compliance framework's requirement. Sesame Software captures complete field-level data audit trails with no field count limits and no platform-imposed ceiling. Deleted records — including data tied to active litigation holds — are retained for the customer-defined retention period, enabling compliance teams to produce complete lifecycle history for any record regardless of when it was deleted.
Granular point-in-time recovery for user error incidents
User error prevention is important — but recovery precision matters equally. When a data import overwrites field values across thousands of records, restoring those specific field values without touching legitimate changes requires field-level point-in-time restore. Sesame Software's recovery operates at the record level, the field level, and the value level, with relational integrity preserved automatically.
Non-technical users — compliance managers, Salesforce administrators, legal team members — execute targeted restores through the visual interface without engaging a data engineer.
Customer-controlled storage outside Salesforce infrastructure
Under the General Data Protection Regulation, vendor-hosted backup creates documented data processor obligations for all data subjects. Under HIPAA compliance requirements, ePHI on vendor infrastructure requires a signed BAA. Sesame Software stores all backup data — including data in cloud storage — in the customer's own environment, in the required geographic region.
Sesame Software retains no copies. The organization controls storage location, retention period, access controls, and encryption keys — satisfying IT data protection and information security requirements by architecture rather than by contract.
Governed erasure workflow for GDPR deletion requests
GDPR Article 17 requires deletion requests to extend to backup copies. Your backup platform must support targeted deletion of specific data subjects' records from backup storage and cloud storage — not just from Salesforce production. Sesame Software's platform supports governed deletion as part of a complete GDPR erasure workflow, with documented evidence of every deletion execution, supporting data portability and erasure compliance requirements simultaneously.
How Sesame Software closes the compliance gap
Sesame Software was built on the principle that enterprise organizations should have complete control over their data — where it lives, how it is protected, who can access it, and how long it is retained. That principle is reflected in every aspect of the Backup Scheduler platform.
Automated backups run as frequently as every five minutes, creating continuous protection across your entire Salesforce org — data and metadata, standard and custom objects, production records and deleted records.
Complete field-level data audit trails with no field count limits and no platform-imposed ceiling satisfy health insurance portability requirements for six years and SOX's seven-year requirements without architectural compromise. Point-in-time restore gives compliance teams the recovery precision that user error incidents require. Customer-controlled storage satisfies data residency and information security requirements by architecture.
With 23+ years of enterprise data management expertise and a customer base that includes Procter & Gamble, Bank of America, and the U.S. Government, Sesame Software scales to enterprise data volumes without performance degradation — and without billing surprises, thanks to predictable connector-based annual pricing that never grows with your record counts.
Talk to a Sesame Software data expert today at sesamesoftware.com.
Frequently asked questions
What makes a Salesforce backup HIPAA compliant?
HIPAA compliance requirements organizations must meet include automated backup at sub-hourly intervals, complete field-level audit trails retained for six years, access controls limiting backup access to authorized personnel, encryption in transit and at rest, and backup data stored in infrastructure the covered entity controls. Sesame Software's customer-hosted architecture and five-minute backup intervals satisfy all health insurance portability requirements for Salesforce environments containing ePHI.
Does the General Data Protection Regulation require backup data deletion on erasure requests?
Yes. The data protection regulation GDPR Article 17 requires erasure requests to extend to all copies of customer data including backup copies and cloud storage. Sesame Software's platform supports governed deletion from backup storage with compliance documentation of every deletion execution for data subjects who submit requests.
How does user error create GDPR and HIPAA compliance exposure?
User error creates compliance exposure when it results in unauthorized modification, deletion, or exposure of regulated data — and when the organization cannot demonstrate, with evidence, that it detected, contained, and recovered from the incident correctly. User error prevention is essential, but so is maintaining the backup and data audit trails infrastructure that enables documented recovery. Sesame Software's field-level history and point-in-time restore provide both.
How long should Salesforce backup data be retained?
HIPAA requires six years for ePHI. SOX requires seven years for financial records. The General Data Protection Regulation requires retention for the duration of the legitimate purpose plus any applicable litigation period. Configure your backup platform to the longest applicable requirement across all frameworks. Sesame Software supports customer-defined retention periods with no ceiling — supporting long-term IT data protection obligations.
Is Salesforce's native backup sufficient for compliance?
No. Field History Tracking retains 18 months across 20 fields. The recycle bin holds deleted records for 15 days. Setup Audit Trail retains configuration changes for 180 days. None satisfy the requirements organizations face under HIPAA, SOX, or GDPR. None store backup data outside Salesforce's infrastructure. Purpose-built regulatory compliance tools are required to close the security and compliance gap.
Can non-technical compliance and legal team members access Salesforce backup data?
Yes. Sesame Software's visual interface allows compliance managers, legal team members, and Salesforce administrators to access data audit trails, run data subject access reports, and initiate targeted restores without filing IT tickets or requiring data engineering support — a meaningful advantage for IT data protection teams under time pressure during regulatory inquiries.

