SAP Concur EU Cloud Code of Conduct

The EU Cloud Code of Conduct report can also be found on the EU Cloud CoC public register: https://eucoc.cloud/en/public-register/list-of-adherent-services, Verification-ID 2025LVL02SCOPE5427. Download the Document

Verification of Declaration of AdherenceDeclaring Company: SAP SEVerification-ID 2025LVL02SCOPE5427Date of Approval September 2025Valid until September 2026
SCOPE Europe SRLRue de la Science 371040 BRUSSELShttps://scope-europe.euinfo@scope-europe.euManaging DirectorGabriela MercuriCompany Register: 0671.468.741VAT: BE 0671.468.741ING BelgiumIBAN BE14 3631 6553 4883SWIFT / BIC: BBRUBEBB2 | 11Table of Contents1 Verification against v2.11 of the EU Cloud CoC 32 List of declared services 32.1 SAP Concur 32.1.1 SAP Concur Travel 32.1.2 SAP Concur Expense 42.1.3 SAP TMC Services 42.1.4 SAP Concur Invoice 43 Verification Process - Background 43.1 Approval of the Code and Accreditation of the Monitoring Body 53.2 Principles of the Verification Process 53.3 Multiple Safeguards of Compliance 53.4 Process in Detail 53.4.1 Levels of Compliance 63.4.2 Final decision on the applicable Level of Compliance 83.5 Transparency about adherence 84 Assessment of declared services by SAP (see 2.) 84.1 Fact Finding 84.2 Selection of Controls for in-depth assessment 94.3 Examined Controls and related findings by the Monitoring Body 94.3.1 Examined Controls 94.3.2 Findings by the Monitoring Body 95 Conclusion 106 Validity 11
Verification of Declaration of Adherence 3 | 111 Verification against v2.11 of the EU Cloud CoCThis Declaration of Adherence was against the European Data Protection Code of Conduct for CloudService Providers (‘EU Cloud CoC’ or ‘Code’)1 in its version 2.11 (‘v2.11)2 as of December 2020.Originally drafted by the Cloud Select Industry Group3 (‘C-SIG’) the EU Cloud CoC at that time calledC-SIG Code of Conduct on data protection for Cloud Service Providers (‘CSPs’) was developedagainst Directive 95/46/EC4 and incorporated feedback by the European Commission as well asWorking Party 29. Following an extensive revision of earlier versions of Code and further developingthe substance of the Code (v2.11) and its provisions has been aligned to the European General DataProtection Regulation (‘GDPR’)5.2 List of declared services2.1 SAP Concur6SAP Concur is a comprehensive spend management solution that helps businesses control and opti-mize both employee and supplier spend. It provides visibility into business travel bookings across allchannels, enables better planning and budgeting, and allows organizations to effectively manage em-ployee travel and expenses as well as supplier and vendor costs.72.1.1 SAP Concur TravelSAP Concur Travel allows companies to manage employee travel spend by providing tools to bookflights, hotels, and transportation in compliance with corporate travel policies. It helps control costs,improve traveller experience, and increase visibility into travel expenditures.7 Travel Triplink & TripIt1 https://eucoc.cloud2 https://eucoc.cloud/get-the-code3 https://ec.europa.eu/digital-single-market/en/cloud-select-industry-group-code-conduct4 https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:31995L00465 https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R06796 https://www.concursolutions.com7 NOTE: The content for the service description has been provided by the CSP and does not reflect any opinionof or assessment by the Monitoring Body.
Verification of Declaration of Adherence 4 | 112.1.2 SAP Concur ExpenseSAP Concur Expense helps businesses control and manage employee spend by streamlining the sub-mission, approval, reimbursement, and reporting of business expenses. It ensures compliance withcompany policies while improving visibility and financial control.7 Expense Expense Pay ExpenseIT Request2.1.3 SAP TMC ServicesTMC Services is a centralized platform that streamlines the planning, booking, tracking, and expensemanagement of business travel. It helps organizations gain visibility and control over travel spend,enforce travel policies, and ensure traveller safety and compliance.7 TMC Clarity TMC Compleat TMC Conquest2.1.4 SAP Concur InvoiceSAP Concur Invoice automates the capture, processing, and approval of supplier invoices. It ensuresaccuracy, reduces manual effort, accelerates payment cycles, and improves compliance with internalcontrols and supplier agreements.7 Invoice Invoice Capture3 Verification Process - BackgroundV2.11 of the EU Cloud CoC has been developed against GDPR and hence provides mechanisms asrequired by Articles 40 and 41 GDPR8.8 https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679
Verification of Declaration of Adherence 5 | 113.1 Approval of the Code and Accreditation of the Monitoring BodyThe services concerned passed the verification process by the Monitoring Body of the EU Cloud CoC,i.e., SCOPE Europe SRL9.The Code has been officially approved in May 202110. SCOPE Europe has been officially accreditedas Monitoring Body in May 202111. The robust and complex procedures and mechanisms can bereviewed by any third-party in detail at the website of the EU Cloud CoC alongside a short summarythereof.123.2 Principles of the Verification ProcessNotwithstanding the powers of and requirements set out by the supervisory authority pursuant toArticle 41 GDPR, the Monitoring Body will assess whether a Cloud Service, that has been declaredadherent to the Code, is compliant with the requirements of the Code - especially as laid down in theControls Catalogue. Unless otherwise provided by the Code, the Monitoring Body’s assessment pro-cess will be based on an evidence-based conformity assessment, based on interviews and documentreviews; proactively performed by the Monitoring Body.To the extent the Monitoring Body is not satisfied with the evidence provided by a CSP with regards tothe Cloud Service to be declared adherent to the Code, the Monitoring Body will request additionalinformation. Where the information provided by the CSP appears to be inconsistent or false, the Mon-itoring Body will - as necessary - request substantiation by independent reports.3.3 Multiple Safeguards of ComplianceCompliance of adherent services is safeguarded by the interaction of several mechanisms, i.e., con-tinuous, rigorous, and independent monitoring, an independent complaints’ handling process, andfinally any CSP declaring services adherent is subject to substantial remedies and penalties in caseof any infringement.3.4 Process in DetailIt is expected that, prior to any assessment of the Monitoring Body, each CSP assesses its complianceinternally. When declaring its service(s) adherent to the EU Cloud CoC, each CSP must elaborate its9 https://scope-europe.eu10 https://www.gegevensbeschermingsautoriteit.be/publications/decision-n05-2021-of-20-may-2021.pdf11 https://www.gegevensbeschermingsautoriteit.be/publications/decision-n-06-2021-of-20-may-2021.pdf12 https://eucoc.cloud/en/public-register/assessment-procedure/