Data Subject Rights

Privacy Rights under applicable laws Faça o download do documento

PUBLICData Subject RequestsPrivacy Rights under Data Protection LawVersion: 1.0Date: May 16, 2025The information contained in this document is for general informational purposes only and is provided on theunderstanding that SAP is not engaged in rendering legal advice. SAP accepts no liability for any actions takenin response to this resource. As such, it should not be used as a substitute for legal or professionalconsultation.
A Data Subject Request (DSR) is the process by which an individual may request to exercise rights over theirpersonal data, such as accessing, correcting, deleting or receiving it in a portable format. The requirement tohonor such requests is enshrined under data protection and privacy laws such as the European Union’sGeneral Data Protection Law (GDPR), the California Consumer Privacy Act (CCPA), Brazil’s Lei Geral de Proteçãode Dados Pessoais (LGPD) as well as various laws in force across the Asia Pacific region. These laws aredesigned to give individuals or “data subjects” greater transparency and control over how their personal data iscollected, used and shared.Responsibility for DSR ComplianceWhen SAP acts as a processor under a Data Processing Agreement (DPA), the responsibility for complyingwith DSRs falls on SAP customers, acting as Controller (or similar term under applicable data protection andprivacy laws) when using SAP products and services. In this role, the Customer determines the means andpurposes of personal data processing and is therefore legally obligated to handle DSRs in compliance withapplicable laws.DSR Support provided by SAP to CustomersSAP will assist Customers in fulfilling their obligations as set forth in the DPA. This support may include, for e.g.,support identifying relevant features and tools intended for data export or deletion. However, this supportdoes not extend to acting on behalf of the Customer, for example, by deciding on whether to honor acorrection or deletion request, or by responding directly to data subjects. Doing so could interfere with theCustomer’s legal obligations and lead to inconsistent, unintended or unauthorized responses.Limitations on forwarding Customer DSRsAdditionally, SAP has a limited ability to forward DSR’s received from Customer’s (end) users or from otherdata subjects. This is because such requests often fail to clearly specify which Customer is responsible for thedata in question, and SAP does not have the ability to verify the individual’s relationship with its customers. Insuch cases, forwarding a request could result in privacy risk and inadvertent data disclosure to the wrongparty. Where SAP receives DSR requests with clearly specified responsible Customers, requests areforwarded.To ensure transparency and to enable individuals to exercise their rights effectively, Customers areencouraged to clearly identify themselves as the Controller in their privacy statements or notices. They shouldalso provide specific contact details or methods for submitting DSRs. Doing so not only supports compliancewith applicable laws, but also minimizes confusion for all parties.
DSRs when SAP acts as a ControllerWhere SAP acts as a Controller for its own purposes (e.g. when making available certain apps or websitesdirectly to data subjects), SAP will be responsible for DSRs in accordance with applicable data protectionlaws. In those cases, individuals may submit their DSRs as described in the applicable privacy statement.To learn more about data protection and privacy at SAP, visit https://www.sap.com/about/trust-center.html atwww.sap.com.© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material. 3 / 3