Data Subject Rights
PUBLIC
Data Subject Requests
Privacy Rights under Data Protection Law
Version: 1.0
Date: May 16, 2025
The information contained in this document is for general informational purposes only and is provided on the
understanding that SAP is not engaged in rendering legal advice. SAP accepts no liability for any actions taken
in response to this resource. As such, it should not be used as a substitute for legal or professional
consultation.
Data Subject Requests
Privacy Rights under Data Protection Law
Version: 1.0
Date: May 16, 2025
The information contained in this document is for general informational purposes only and is provided on the
understanding that SAP is not engaged in rendering legal advice. SAP accepts no liability for any actions taken
in response to this resource. As such, it should not be used as a substitute for legal or professional
consultation.
A Data Subject Request (DSR) is the process by which an individual may request to exercise rights over their
personal data, such as accessing, correcting, deleting or receiving it in a portable format. The requirement to
honor such requests is enshrined under data protection and privacy laws such as the European Union’s
General Data Protection Law (GDPR), the California Consumer Privacy Act (CCPA), Brazil’s Lei Geral de Proteção
de Dados Pessoais (LGPD) as well as various laws in force across the Asia Pacific region. These laws are
designed to give individuals or “data subjects” greater transparency and control over how their personal data is
collected, used and shared.
Responsibility for DSR Compliance
When SAP acts as a processor under a Data Processing Agreement (DPA), the responsibility for complying
with DSRs falls on SAP customers, acting as Controller (or similar term under applicable data protection and
privacy laws) when using SAP products and services. In this role, the Customer determines the means and
purposes of personal data processing and is therefore legally obligated to handle DSRs in compliance with
applicable laws.
DSR Support provided by SAP to Customers
SAP will assist Customers in fulfilling their obligations as set forth in the DPA. This support may include, for e.g.,
support identifying relevant features and tools intended for data export or deletion. However, this support
does not extend to acting on behalf of the Customer, for example, by deciding on whether to honor a
correction or deletion request, or by responding directly to data subjects. Doing so could interfere with the
Customer’s legal obligations and lead to inconsistent, unintended or unauthorized responses.
Limitations on forwarding Customer DSRs
Additionally, SAP has a limited ability to forward DSR’s received from Customer’s (end) users or from other
data subjects. This is because such requests often fail to clearly specify which Customer is responsible for the
data in question, and SAP does not have the ability to verify the individual’s relationship with its customers. In
such cases, forwarding a request could result in privacy risk and inadvertent data disclosure to the wrong
party. Where SAP receives DSR requests with clearly specified responsible Customers, requests are
forwarded.
To ensure transparency and to enable individuals to exercise their rights effectively, Customers are
encouraged to clearly identify themselves as the Controller in their privacy statements or notices. They should
also provide specific contact details or methods for submitting DSRs. Doing so not only supports compliance
with applicable laws, but also minimizes confusion for all parties.
personal data, such as accessing, correcting, deleting or receiving it in a portable format. The requirement to
honor such requests is enshrined under data protection and privacy laws such as the European Union’s
General Data Protection Law (GDPR), the California Consumer Privacy Act (CCPA), Brazil’s Lei Geral de Proteção
de Dados Pessoais (LGPD) as well as various laws in force across the Asia Pacific region. These laws are
designed to give individuals or “data subjects” greater transparency and control over how their personal data is
collected, used and shared.
Responsibility for DSR Compliance
When SAP acts as a processor under a Data Processing Agreement (DPA), the responsibility for complying
with DSRs falls on SAP customers, acting as Controller (or similar term under applicable data protection and
privacy laws) when using SAP products and services. In this role, the Customer determines the means and
purposes of personal data processing and is therefore legally obligated to handle DSRs in compliance with
applicable laws.
DSR Support provided by SAP to Customers
SAP will assist Customers in fulfilling their obligations as set forth in the DPA. This support may include, for e.g.,
support identifying relevant features and tools intended for data export or deletion. However, this support
does not extend to acting on behalf of the Customer, for example, by deciding on whether to honor a
correction or deletion request, or by responding directly to data subjects. Doing so could interfere with the
Customer’s legal obligations and lead to inconsistent, unintended or unauthorized responses.
Limitations on forwarding Customer DSRs
Additionally, SAP has a limited ability to forward DSR’s received from Customer’s (end) users or from other
data subjects. This is because such requests often fail to clearly specify which Customer is responsible for the
data in question, and SAP does not have the ability to verify the individual’s relationship with its customers. In
such cases, forwarding a request could result in privacy risk and inadvertent data disclosure to the wrong
party. Where SAP receives DSR requests with clearly specified responsible Customers, requests are
forwarded.
To ensure transparency and to enable individuals to exercise their rights effectively, Customers are
encouraged to clearly identify themselves as the Controller in their privacy statements or notices. They should
also provide specific contact details or methods for submitting DSRs. Doing so not only supports compliance
with applicable laws, but also minimizes confusion for all parties.
DSRs when SAP acts as a Controller
Where SAP acts as a Controller for its own purposes (e.g. when making available certain apps or websites
directly to data subjects), SAP will be responsible for DSRs in accordance with applicable data protection
laws. In those cases, individuals may submit their DSRs as described in the applicable privacy statement.
To learn more about data protection and privacy at SAP, visit https://www.sap.com/about/trust-center.html at
www.sap.com.
© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material. 3 / 3
Where SAP acts as a Controller for its own purposes (e.g. when making available certain apps or websites
directly to data subjects), SAP will be responsible for DSRs in accordance with applicable data protection
laws. In those cases, individuals may submit their DSRs as described in the applicable privacy statement.
To learn more about data protection and privacy at SAP, visit https://www.sap.com/about/trust-center.html at
www.sap.com.
© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material. 3 / 3