New Zealand: Visitor Registration and Identity Management Privacy Statement
© 2026 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material. 1 / 4
Visitor Registration and Identity Management Privacy Statement at
SAP premises across New Zealand
This Privacy Statement was updated on 4 March 2026.
Protecting the individual’s privacy is crucial to the future of business. We have created this Privacy Statement to
demonstrate the firm commitment of SAP (hereinafter “We”, “SAP”, “Us” or “Our”) to the individual’s right to data
protection and privacy. It outlines how We handle information that can be used to directly or indirectly identify an
individual (hereinafter “Personal Data”).
Visitor Registration and Identity Management systems (‘VRIM’) at SAP are used to ensure the security of personnel
and assets at SAP’s premises.
General Information
Who do We mean when We say SAP in this Privacy Statement
The controller of SAP Visitor Management is:
• Wellington (WLG03) Level 18, 1 Willis St, 6011 Wellington, New Zealand.
• Auckland (AKLO2) Level 11 and 15, 151 Queen Street, Auckland 1010, New Zealand.
You can reach SAP Group’s data protection officer at privacy@sap.com.
For what purposes does SAP process your Personal Data?
We require your Personal Data in order to ensure an adequate level of safety and security for and at SAP's premises.
SAP may use your Personal Data for the following purposes:
• to control access to SAP's premises;
• to ensure adequate security for and at SAP's premises;
• to ensure the safety of SAP employees and visitors to SAP's premises;
• to prevent, deter, and if necessary, investigate unauthorized physical access, including unauthorized access to
secure premises and protected rooms, IT infrastructure, or operational information;
• to prevent sabotage, theft and material damage; and
• to support the rightful and valid requests of public authorities for support in an investigation.
Visitor Registration and Identity Management Privacy Statement at
SAP premises across New Zealand
This Privacy Statement was updated on 4 March 2026.
Protecting the individual’s privacy is crucial to the future of business. We have created this Privacy Statement to
demonstrate the firm commitment of SAP (hereinafter “We”, “SAP”, “Us” or “Our”) to the individual’s right to data
protection and privacy. It outlines how We handle information that can be used to directly or indirectly identify an
individual (hereinafter “Personal Data”).
Visitor Registration and Identity Management systems (‘VRIM’) at SAP are used to ensure the security of personnel
and assets at SAP’s premises.
General Information
Who do We mean when We say SAP in this Privacy Statement
The controller of SAP Visitor Management is:
• Wellington (WLG03) Level 18, 1 Willis St, 6011 Wellington, New Zealand.
• Auckland (AKLO2) Level 11 and 15, 151 Queen Street, Auckland 1010, New Zealand.
You can reach SAP Group’s data protection officer at privacy@sap.com.
For what purposes does SAP process your Personal Data?
We require your Personal Data in order to ensure an adequate level of safety and security for and at SAP's premises.
SAP may use your Personal Data for the following purposes:
• to control access to SAP's premises;
• to ensure adequate security for and at SAP's premises;
• to ensure the safety of SAP employees and visitors to SAP's premises;
• to prevent, deter, and if necessary, investigate unauthorized physical access, including unauthorized access to
secure premises and protected rooms, IT infrastructure, or operational information;
• to prevent sabotage, theft and material damage; and
• to support the rightful and valid requests of public authorities for support in an investigation.
© 2026 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material. 2 / 4
This process allows SAP to provide appropriate access to SAP premises and to ensure the security and safety of all SAP
employees, suppliers, visitors, and assets across all global SAP locations. This process supports SAP to comply with
relevant duty of care as well as other applicable statutory obligations which may apply in your jurisdiction, including
identification verification prior to or during access to any SAP-owned or leased premises.
Although providing Personal Data during VRIM is voluntary, without your Personal Data, SAP cannot provide you with
access to SAP premises.
What categories of Personal Data does SAP process?
• Contact Data
SAP processes the following categories of Personal Data as contact data: first name, last name, email address
and telephone number.
• Personal Data related to the business relationship with SAP
SAP processes the following category of Personal Data in the context of established business relationships:
company name.
• SAP Visitor Identity Data
• SAP processes the following categories of Personal Data as Visitor Identity Data: visit location, visit registration
date and time, date and time of check-in/check-out, visitor Confidentiality Disclaimer signature, visitor
photograph, host name(s), visitor type (i.e., Visitor, SAP VIP, Event), visitor sub-type (i.e., Auditor, Business
Meeting, Contractor/Vendor, Customer, Event, Government, Job Interview, Personal, Sales Partner, Tenant,
Training, VIP, VIP (non-SAP)) and visit reason.
How long does SAP store your Personal Data?
SAP does only store your Personal Data for a period of one year or as long as it is required, as discussed below:
• To fulfil SAP’s legitimate purposes as further described in section II of this Privacy Statement, unless you
object to SAP’s use of your Personal Data for these purposes.
Once your Personal Data is no longer needed for these purposes, SAP will take reasonable steps to either destroy or
de-identify it.
SAP may retain your Personal Data for additional periods if necessary for compliance with legal obligations to process
your Personal Data or if the Personal Data is needed by SAP to assert or defend itself against legal claims. In such
cases, SAP will retain your Personal Data until the end of the relevant retention period, or until the claims in question
have been settled.
Who are the recipients of your Personal Data?
Your Personal Data will be passed on to the following categories of third parties to process your Personal Data:
• Companies within the SAP Group, as this is a global organization with global security obligations
• Third-party service providers, including contracted security agencies that are contracted to provide security
services at SAP
This process allows SAP to provide appropriate access to SAP premises and to ensure the security and safety of all SAP
employees, suppliers, visitors, and assets across all global SAP locations. This process supports SAP to comply with
relevant duty of care as well as other applicable statutory obligations which may apply in your jurisdiction, including
identification verification prior to or during access to any SAP-owned or leased premises.
Although providing Personal Data during VRIM is voluntary, without your Personal Data, SAP cannot provide you with
access to SAP premises.
What categories of Personal Data does SAP process?
• Contact Data
SAP processes the following categories of Personal Data as contact data: first name, last name, email address
and telephone number.
• Personal Data related to the business relationship with SAP
SAP processes the following category of Personal Data in the context of established business relationships:
company name.
• SAP Visitor Identity Data
• SAP processes the following categories of Personal Data as Visitor Identity Data: visit location, visit registration
date and time, date and time of check-in/check-out, visitor Confidentiality Disclaimer signature, visitor
photograph, host name(s), visitor type (i.e., Visitor, SAP VIP, Event), visitor sub-type (i.e., Auditor, Business
Meeting, Contractor/Vendor, Customer, Event, Government, Job Interview, Personal, Sales Partner, Tenant,
Training, VIP, VIP (non-SAP)) and visit reason.
How long does SAP store your Personal Data?
SAP does only store your Personal Data for a period of one year or as long as it is required, as discussed below:
• To fulfil SAP’s legitimate purposes as further described in section II of this Privacy Statement, unless you
object to SAP’s use of your Personal Data for these purposes.
Once your Personal Data is no longer needed for these purposes, SAP will take reasonable steps to either destroy or
de-identify it.
SAP may retain your Personal Data for additional periods if necessary for compliance with legal obligations to process
your Personal Data or if the Personal Data is needed by SAP to assert or defend itself against legal claims. In such
cases, SAP will retain your Personal Data until the end of the relevant retention period, or until the claims in question
have been settled.
Who are the recipients of your Personal Data?
Your Personal Data will be passed on to the following categories of third parties to process your Personal Data:
• Companies within the SAP Group, as this is a global organization with global security obligations
• Third-party service providers, including contracted security agencies that are contracted to provide security
services at SAP
© 2026 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material. 3 / 4
• Law enforcement agencies, insurance companies etc. as appropriate in terms of any corporate criminal or
other security investigations
SAP Group entities
As SAP is selling its products and services to its customers only via local business relationships, SAP may transfer your
Personal Data to the locally relevant SAP group entity for the purpose and to the extent necessary to conduct a business
relationship. Other entities of the SAP Group may also receive or gain access to Personal Data either when rendering
group internal services centrally and on behalf of SAP SE and the other SAP group entities or when Personal Data is
transferred to them on a respective legal basis. In these cases, these entities may process the Personal Data for the
same purposes and under the same conditions as outlined in this Privacy Statement. The current list of SAP Group
entities can be found here. If you would like to find out which SAP group entity is responsible for the business
relationship with you or your employer, please contact Us at SAP-Physical-Sec-Privacy@sap.com.
What are your data protection rights?
Right to access and correct
You can request from SAP at any time access to information about which Personal Data SAP processes about you and,
if necessary, the correction of such Personal Data. Please note, however, that SAP can or will delete your Personal
Data only if there is no statutory obligation or prevailing right of SAP to retain it.
Right to revoke consent
Wherever SAP is processing your Personal Data based on your consent, you may at any time withdraw your consent
by unsubscribing or giving Us respective notice of withdrawal. In case of withdrawal, SAP will not process Personal
Data subject to this consent any longer unless legally required to do so. In case SAP is required to retain your Personal
Data for legal reasons your Personal Data will be restricted from further processing and only retained for the term
required by law. However, any withdrawal has no effect on past processing of Personal Data by SAP up to the point in
time of your withdrawal.
How can you exercise your data protection rights?
Please direct any requests to exercise your rights to SAP-Physical-Sec-Privacy@sap.com.
How will SAP verify requests to exercise data protection rights?
SAP will take steps to ensure that it verifies your identity to a reasonable degree of certainty before it will process the
data protection right you want to exercise. When feasible, SAP will match Personal Data provided by you in submitting
a request to exercise your rights with information already maintained by SAP. This could include matching two or
more data points you provide when you submit a request with two or more data points that are already maintained
by SAP.
• Law enforcement agencies, insurance companies etc. as appropriate in terms of any corporate criminal or
other security investigations
SAP Group entities
As SAP is selling its products and services to its customers only via local business relationships, SAP may transfer your
Personal Data to the locally relevant SAP group entity for the purpose and to the extent necessary to conduct a business
relationship. Other entities of the SAP Group may also receive or gain access to Personal Data either when rendering
group internal services centrally and on behalf of SAP SE and the other SAP group entities or when Personal Data is
transferred to them on a respective legal basis. In these cases, these entities may process the Personal Data for the
same purposes and under the same conditions as outlined in this Privacy Statement. The current list of SAP Group
entities can be found here. If you would like to find out which SAP group entity is responsible for the business
relationship with you or your employer, please contact Us at SAP-Physical-Sec-Privacy@sap.com.
What are your data protection rights?
Right to access and correct
You can request from SAP at any time access to information about which Personal Data SAP processes about you and,
if necessary, the correction of such Personal Data. Please note, however, that SAP can or will delete your Personal
Data only if there is no statutory obligation or prevailing right of SAP to retain it.
Right to revoke consent
Wherever SAP is processing your Personal Data based on your consent, you may at any time withdraw your consent
by unsubscribing or giving Us respective notice of withdrawal. In case of withdrawal, SAP will not process Personal
Data subject to this consent any longer unless legally required to do so. In case SAP is required to retain your Personal
Data for legal reasons your Personal Data will be restricted from further processing and only retained for the term
required by law. However, any withdrawal has no effect on past processing of Personal Data by SAP up to the point in
time of your withdrawal.
How can you exercise your data protection rights?
Please direct any requests to exercise your rights to SAP-Physical-Sec-Privacy@sap.com.
How will SAP verify requests to exercise data protection rights?
SAP will take steps to ensure that it verifies your identity to a reasonable degree of certainty before it will process the
data protection right you want to exercise. When feasible, SAP will match Personal Data provided by you in submitting
a request to exercise your rights with information already maintained by SAP. This could include matching two or
more data points you provide when you submit a request with two or more data points that are already maintained
by SAP.
© 2026 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material. 4 / 4
SAP will decline to process requests that are manifestly unfounded, excessive, fraudulent, or are not otherwise
required by local law.
Can you use SAP’s services if you are a minor?
In general, the VRIM is not directed to users below the age of 16 years, or equivalent minimum age in the relevant
jurisdiction. If you are younger than 16 or the equivalent minimum age in the relevant jurisdiction, you cannot register
with and use this VRIM.
Additional Country and Regional Specific Provisions
Where SAP is subject to the requirements of the Privacy Act 2020 (Privacy Act), the
following applies:
1. SAP is required to Process this Personal Data in accordance with SAP’s Global Security Policy for which the collection
of this information is authorized or required. The supply of this Personal Data by you is voluntary.
2. If the Personal Data is not collected, we cannot provide you with access to SAP premises.
You have the right to:
• request from SAP at any time access to information about which Personal Data SAP processes about you and,
if necessary, the correction of such Personal Data. Please note, however, that SAP can or will delete your
Personal Data only if there is no statutory obligation or prevailing right of SAP to retain it.
• Wherever SAP is processing your Personal Data based on your consent, you may at any time withdraw your
consent by unsubscribing or giving Us respective notice of withdrawal. In case of withdrawal, SAP will not
process Personal Data subject to this consent any longer unless legally required to do so. In case SAP is
required to retain your Personal Data for legal reasons your Personal Data will be restricted from further
processing and only retained for the term required by law. However, any withdrawal has no effect on past
processing of Personal Data by SAP up to the point in time of your withdrawal.
SAP will decline to process requests that are manifestly unfounded, excessive, fraudulent, or are not otherwise
required by local law.
Can you use SAP’s services if you are a minor?
In general, the VRIM is not directed to users below the age of 16 years, or equivalent minimum age in the relevant
jurisdiction. If you are younger than 16 or the equivalent minimum age in the relevant jurisdiction, you cannot register
with and use this VRIM.
Additional Country and Regional Specific Provisions
Where SAP is subject to the requirements of the Privacy Act 2020 (Privacy Act), the
following applies:
1. SAP is required to Process this Personal Data in accordance with SAP’s Global Security Policy for which the collection
of this information is authorized or required. The supply of this Personal Data by you is voluntary.
2. If the Personal Data is not collected, we cannot provide you with access to SAP premises.
You have the right to:
• request from SAP at any time access to information about which Personal Data SAP processes about you and,
if necessary, the correction of such Personal Data. Please note, however, that SAP can or will delete your
Personal Data only if there is no statutory obligation or prevailing right of SAP to retain it.
• Wherever SAP is processing your Personal Data based on your consent, you may at any time withdraw your
consent by unsubscribing or giving Us respective notice of withdrawal. In case of withdrawal, SAP will not
process Personal Data subject to this consent any longer unless legally required to do so. In case SAP is
required to retain your Personal Data for legal reasons your Personal Data will be restricted from further
processing and only retained for the term required by law. However, any withdrawal has no effect on past
processing of Personal Data by SAP up to the point in time of your withdrawal.