New Zealand: Visitor Registration and Identity Management Privacy Statement

New Zealand: Visitor Registration and Identity Management Privacy Statement at SAP Download the Document

© 2026 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material. 1 / 4Visitor Registration and Identity Management Privacy Statement atSAP premises across New ZealandThis Privacy Statement was updated on 4 March 2026.Protecting the individual’s privacy is crucial to the future of business. We have created this Privacy Statement todemonstrate the firm commitment of SAP (hereinafter “We”, “SAP”, “Us” or “Our”) to the individual’s right to dataprotection and privacy. It outlines how We handle information that can be used to directly or indirectly identify anindividual (hereinafter “Personal Data”).Visitor Registration and Identity Management systems (‘VRIM’) at SAP are used to ensure the security of personneland assets at SAP’s premises.General InformationWho do We mean when We say SAP in this Privacy StatementThe controller of SAP Visitor Management is: Wellington (WLG03) Level 18, 1 Willis St, 6011 Wellington, New Zealand. Auckland (AKLO2) Level 11 and 15, 151 Queen Street, Auckland 1010, New Zealand.You can reach SAP Group’s data protection officer at privacy@sap.com.For what purposes does SAP process your Personal Data?We require your Personal Data in order to ensure an adequate level of safety and security for and at SAP's premises.SAP may use your Personal Data for the following purposes: to control access to SAP's premises; to ensure adequate security for and at SAP's premises; to ensure the safety of SAP employees and visitors to SAP's premises; to prevent, deter, and if necessary, investigate unauthorized physical access, including unauthorized access tosecure premises and protected rooms, IT infrastructure, or operational information; to prevent sabotage, theft and material damage; and to support the rightful and valid requests of public authorities for support in an investigation.
© 2026 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material. 2 / 4This process allows SAP to provide appropriate access to SAP premises and to ensure the security and safety of all SAPemployees, suppliers, visitors, and assets across all global SAP locations. This process supports SAP to comply withrelevant duty of care as well as other applicable statutory obligations which may apply in your jurisdiction, includingidentification verification prior to or during access to any SAP-owned or leased premises.Although providing Personal Data during VRIM is voluntary, without your Personal Data, SAP cannot provide you withaccess to SAP premises.What categories of Personal Data does SAP process? Contact DataSAP processes the following categories of Personal Data as contact data: first name, last name, email addressand telephone number. Personal Data related to the business relationship with SAPSAP processes the following category of Personal Data in the context of established business relationships:company name. SAP Visitor Identity Data SAP processes the following categories of Personal Data as Visitor Identity Data: visit location, visit registrationdate and time, date and time of check-in/check-out, visitor Confidentiality Disclaimer signature, visitorphotograph, host name(s), visitor type (i.e., Visitor, SAP VIP, Event), visitor sub-type (i.e., Auditor, BusinessMeeting, Contractor/Vendor, Customer, Event, Government, Job Interview, Personal, Sales Partner, Tenant,Training, VIP, VIP (non-SAP)) and visit reason.How long does SAP store your Personal Data?SAP does only store your Personal Data for a period of one year or as long as it is required, as discussed below: To fulfil SAP’s legitimate purposes as further described in section II of this Privacy Statement, unless youobject to SAP’s use of your Personal Data for these purposes.Once your Personal Data is no longer needed for these purposes, SAP will take reasonable steps to either destroy orde-identify it.SAP may retain your Personal Data for additional periods if necessary for compliance with legal obligations to processyour Personal Data or if the Personal Data is needed by SAP to assert or defend itself against legal claims. In suchcases, SAP will retain your Personal Data until the end of the relevant retention period, or until the claims in questionhave been settled.Who are the recipients of your Personal Data?Your Personal Data will be passed on to the following categories of third parties to process your Personal Data: Companies within the SAP Group, as this is a global organization with global security obligations Third-party service providers, including contracted security agencies that are contracted to provide securityservices at SAP
© 2026 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material. 3 / 4 Law enforcement agencies, insurance companies etc. as appropriate in terms of any corporate criminal orother security investigationsSAP Group entitiesAs SAP is selling its products and services to its customers only via local business relationships, SAP may transfer yourPersonal Data to the locally relevant SAP group entity for the purpose and to the extent necessary to conduct a businessrelationship. Other entities of the SAP Group may also receive or gain access to Personal Data either when renderinggroup internal services centrally and on behalf of SAP SE and the other SAP group entities or when Personal Data istransferred to them on a respective legal basis. In these cases, these entities may process the Personal Data for thesame purposes and under the same conditions as outlined in this Privacy Statement. The current list of SAP Groupentities can be found here. If you would like to find out which SAP group entity is responsible for the businessrelationship with you or your employer, please contact Us at SAP-Physical-Sec-Privacy@sap.com.What are your data protection rights?Right to access and correctYou can request from SAP at any time access to information about which Personal Data SAP processes about you and,if necessary, the correction of such Personal Data. Please note, however, that SAP can or will delete your PersonalData only if there is no statutory obligation or prevailing right of SAP to retain it.Right to revoke consentWherever SAP is processing your Personal Data based on your consent, you may at any time withdraw your consentby unsubscribing or giving Us respective notice of withdrawal. In case of withdrawal, SAP will not process PersonalData subject to this consent any longer unless legally required to do so. In case SAP is required to retain your PersonalData for legal reasons your Personal Data will be restricted from further processing and only retained for the termrequired by law. However, any withdrawal has no effect on past processing of Personal Data by SAP up to the point intime of your withdrawal.How can you exercise your data protection rights?Please direct any requests to exercise your rights to SAP-Physical-Sec-Privacy@sap.com.How will SAP verify requests to exercise data protection rights?SAP will take steps to ensure that it verifies your identity to a reasonable degree of certainty before it will process thedata protection right you want to exercise. When feasible, SAP will match Personal Data provided by you in submittinga request to exercise your rights with information already maintained by SAP. This could include matching two ormore data points you provide when you submit a request with two or more data points that are already maintainedby SAP.
© 2026 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material. 4 / 4SAP will decline to process requests that are manifestly unfounded, excessive, fraudulent, or are not otherwiserequired by local law.Can you use SAP’s services if you are a minor?In general, the VRIM is not directed to users below the age of 16 years, or equivalent minimum age in the relevantjurisdiction. If you are younger than 16 or the equivalent minimum age in the relevant jurisdiction, you cannot registerwith and use this VRIM.Additional Country and Regional Specific ProvisionsWhere SAP is subject to the requirements of the Privacy Act 2020 (Privacy Act), thefollowing applies:1. SAP is required to Process this Personal Data in accordance with SAP’s Global Security Policy for which the collectionof this information is authorized or required. The supply of this Personal Data by you is voluntary.2. If the Personal Data is not collected, we cannot provide you with access to SAP premises.You have the right to: request from SAP at any time access to information about which Personal Data SAP processes about you and,if necessary, the correction of such Personal Data. Please note, however, that SAP can or will delete yourPersonal Data only if there is no statutory obligation or prevailing right of SAP to retain it. Wherever SAP is processing your Personal Data based on your consent, you may at any time withdraw yourconsent by unsubscribing or giving Us respective notice of withdrawal. In case of withdrawal, SAP will notprocess Personal Data subject to this consent any longer unless legally required to do so. In case SAP isrequired to retain your Personal Data for legal reasons your Personal Data will be restricted from furtherprocessing and only retained for the term required by law. However, any withdrawal has no effect on pastprocessing of Personal Data by SAP up to the point in time of your withdrawal.