Loading
Connectivity issues between Mulesoft and customer corporate network.Read More
Salesforce Enforces New Security Requirements in Summer 2026Read More
Manage Users and Data Access
Personal User Information Policies and Timelines

Personal User Information Policies and Timelines

To protect your external users’ data, Salesforce introduced security settings that let you control personal user information visibility. Use this topic as a starting point to understand all the security improvements and updates, including timelines for enforcement and how to prepare for the changes.

Required Editions

Available in: Salesforce Classic and Lightning Experience
Available in: Enterprise, Performance, Unlimited, and Developer Editions

The Salesforce security policy encompasses all public sites created in a Salesforce org, including Lightning Platform, Site.com, or Experience Cloud. These settings are included in the policy for personal user information.

Enhanced Personal Information Management Using Field Sets

This setting hides personal information fields in user records from external users. Use a field set to modify which fields are classified as personal information and concealed. If you enabled Enhanced Personal Information Management before Spring ’22, you can use Compliance Categorization on user object fields.

When you use the PersonalInfo_EPIM field set to classify fields as personal information, both First Name and Last Name are concealed by default. But you can specify which components of a user’s name or address to hide. For example, if you want to make your users’ first names visible you can choose to hide Last Name only.

For more information on this setting, see Manage Personal User Information Visibility for External Users.

Enhanced Personal Information Management Using Compliance Categorization

In orgs that enabled this feature before Spring ’22, admins manage which personal information fields are visible by using Compliance Categorization on the user object. If your org uses Compliance Categorization, make sure to classify the Name field as personal information.

For more information on this setting, see Manage Personal User Information Visibility for External Users.

Enhanced Personal Information Management and the Show Nicknames Setting

For customers who used the retired Hide Personal Information setting, but haven’t enabled the Enhanced Personal Information Management setting, Salesforce still hides some personal information fields in user records from external users. The affected fields are:

  • Alias
  • EmployeeNumber
  • FederationIdentifier
  • SenderEmail
  • Signature
  • Username
  • Division
  • Title
  • Department
  • Extension

When the Show Nicknames preference is enabled and the following Name fields are classified as PII, the user’s nickname is displayed instead of these fields:

  • Name
  • First Name (component of the Name field)
  • Last Name (component of the Name field)
Important
Important To protect your users’ names from being viewed by external users, don’t remove Name, First Name, or Last Name from the PersonalInfo_EPIM field set. If your org secures PII using Compliance Categorization, don’t remove PII Compliance Categorization from Name, First Name, or Last Name fields.
Note
Note Enhanced Personal Information Management using Compliance Categorization isn’t available in orgs created in Winter ’22 or later.

For more information on this setting, see Show Nicknames Instead of Full Names in an Experience Cloud Site.

Timelines for Enforcing Public Site Security Policies

The introduction and enablement timeline of these settings begins in Winter ’22. This timeline is subject to change. Check to see what release your org is running on Salesforce Status.

Details of the Winter ’22 Updates

The Enhanced Personal Information Management setting is available in all orgs beginning in Winter ’22. For orgs created before Winter ’22, this setting is disabled by default and must be enabled by an admin. For orgs created in Winter ’22 or later, this setting is enabled by default.

Salesforce orgs that enable the Enhanced Personal Information Management setting in Winter ’22 use Compliance Categorization to classify user fields as personal information.

Details of the Spring ’22 Updates

In this release, we introduced the Enable Stronger Protection for Your Users’ Personal Information release update. Use this release update to test and prepare your org before the Enhanced Personal Information Management setting is automatically enabled in Winter ’23.

Salesforce blocks 30 personal information fields using a field set called PersonalInfo_EPIM. You can choose which fields to include in the field set, which provides even more flexibility and scalability.

  • Admins who enable Enhanced Personal Information Management in Spring ’22 can use field sets to manage which fields are classified as personal information.
  • If you enabled the setting before Spring ’22, make sure to classify the Name field as personal information. You can use field sets to choose which fields are considered personally identifiable information (PII), or continue to use Compliance Categorization.

Support for the Show Nicknames preference is available this release with the Enhanced Personal Information Management setting.

Details of the Summer ’22 Updates

In this release, information classified as personal or sensitive is no longer visible to users with View All Users, Modify All Data, and View All Data permissions. To view personally identifiable information, users must have the View Concealed Field Data permission. The View Concealed Field Data permission replaces the View User Records with PII permission.

Details of the Winter ’23 Updates

Enforcement of the Enable Stronger Protection for Your Users’ Personal Information release update is postponed to the Spring ’23 release.

Details of the Spring ’23 Updates

The Enable Stronger Protection for Your Users’ Personal Information release update is enforced. The Enhanced Personal Information Management setting is enabled in all orgs. The default user fields classified as personal information are hidden from external users.

Some orgs enabled Digital Experiences and Hide Personal Information, but haven’t enabled Enhanced Personal Information Management before Spring ’23. For these orgs, the fields listed in this article are protected. Name fields aren’t concealed unless Show Nicknames is enabled.

If you rely on having certain user fields exposed to external users, you must remove them from the PersonalInfo_EPIM field set or modify these fields’ Compliance Categorization to restore visibility. To manage the visibility of user fields, you must use Enhanced Personal Information Management.

The Hide Personal Information setting and the Hide first and last name fields in the SOAP API for site users, when making API calls from within a site with nicknames setting are retired in all orgs.

Important
Important We strongly recommend that you adopt this feature and test its impact as soon as possible ensure no unexpected changes in functionality.
 
Loading
Salesforce Help | Article