SAP Concur EU Cloud Code of Conduct
Verification of Declaration of Adherence
Declaring Company: SAP SE
Verification-ID 2025LVL02SCOPE5427
Date of Approval September 2025
Valid until September 2026
Declaring Company: SAP SE
Verification-ID 2025LVL02SCOPE5427
Date of Approval September 2025
Valid until September 2026
SCOPE Europe SRL
Rue de la Science 37
1040 BRUSSELS
https://scope-europe.eu
info@scope-europe.eu
Managing Director
Gabriela Mercuri
Company Register: 0671.468.741
VAT: BE 0671.468.741
ING Belgium
IBAN BE14 3631 6553 4883
SWIFT / BIC: BBRUBEBB
2 | 11
Table of Contents
1 Verification against v2.11 of the EU Cloud CoC 3
2 List of declared services 3
2.1 SAP Concur 3
2.1.1 SAP Concur Travel 3
2.1.2 SAP Concur Expense 4
2.1.3 SAP TMC Services 4
2.1.4 SAP Concur Invoice 4
3 Verification Process - Background 4
3.1 Approval of the Code and Accreditation of the Monitoring Body 5
3.2 Principles of the Verification Process 5
3.3 Multiple Safeguards of Compliance 5
3.4 Process in Detail 5
3.4.1 Levels of Compliance 6
3.4.2 Final decision on the applicable Level of Compliance 8
3.5 Transparency about adherence 8
4 Assessment of declared services by SAP (see 2.) 8
4.1 Fact Finding 8
4.2 Selection of Controls for in-depth assessment 9
4.3 Examined Controls and related findings by the Monitoring Body 9
4.3.1 Examined Controls 9
4.3.2 Findings by the Monitoring Body 9
5 Conclusion 10
6 Validity 11
Rue de la Science 37
1040 BRUSSELS
https://scope-europe.eu
info@scope-europe.eu
Managing Director
Gabriela Mercuri
Company Register: 0671.468.741
VAT: BE 0671.468.741
ING Belgium
IBAN BE14 3631 6553 4883
SWIFT / BIC: BBRUBEBB
2 | 11
Table of Contents
1 Verification against v2.11 of the EU Cloud CoC 3
2 List of declared services 3
2.1 SAP Concur 3
2.1.1 SAP Concur Travel 3
2.1.2 SAP Concur Expense 4
2.1.3 SAP TMC Services 4
2.1.4 SAP Concur Invoice 4
3 Verification Process - Background 4
3.1 Approval of the Code and Accreditation of the Monitoring Body 5
3.2 Principles of the Verification Process 5
3.3 Multiple Safeguards of Compliance 5
3.4 Process in Detail 5
3.4.1 Levels of Compliance 6
3.4.2 Final decision on the applicable Level of Compliance 8
3.5 Transparency about adherence 8
4 Assessment of declared services by SAP (see 2.) 8
4.1 Fact Finding 8
4.2 Selection of Controls for in-depth assessment 9
4.3 Examined Controls and related findings by the Monitoring Body 9
4.3.1 Examined Controls 9
4.3.2 Findings by the Monitoring Body 9
5 Conclusion 10
6 Validity 11
Verification of Declaration of Adherence 3 | 11
1 Verification against v2.11 of the EU Cloud CoC
This Declaration of Adherence was against the European Data Protection Code of Conduct for Cloud
Service Providers (‘EU Cloud CoC’ or ‘Code’)1 in its version 2.11 (‘v2.11’)2 as of December 2020.
Originally drafted by the Cloud Select Industry Group3 (‘C-SIG’) the EU Cloud CoC – at that time called
C-SIG Code of Conduct on data protection for Cloud Service Providers (‘CSPs’) – was developed
against Directive 95/46/EC4 and incorporated feedback by the European Commission as well as
Working Party 29. Following an extensive revision of earlier versions of Code and further developing
the substance of the Code (v2.11) and its provisions has been aligned to the European General Data
Protection Regulation (‘GDPR’)5.
2 List of declared services
2.1 SAP Concur6
SAP Concur is a comprehensive spend management solution that helps businesses control and opti-
mize both employee and supplier spend. It provides visibility into business travel bookings across all
channels, enables better planning and budgeting, and allows organizations to effectively manage em-
ployee travel and expenses as well as supplier and vendor costs.7
2.1.1 SAP Concur Travel
SAP Concur Travel allows companies to manage employee travel spend by providing tools to book
flights, hotels, and transportation in compliance with corporate travel policies. It helps control costs,
improve traveller experience, and increase visibility into travel expenditures.7
■ Travel
■ Triplink & TripIt
1 https://eucoc.cloud
2 https://eucoc.cloud/get-the-code
3 https://ec.europa.eu/digital-single-market/en/cloud-select-industry-group-code-conduct
4 https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:31995L0046
5 https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679
6 https://www.concursolutions.com
7 NOTE: The content for the service description has been provided by the CSP and does not reflect any opinion
of or assessment by the Monitoring Body.
1 Verification against v2.11 of the EU Cloud CoC
This Declaration of Adherence was against the European Data Protection Code of Conduct for Cloud
Service Providers (‘EU Cloud CoC’ or ‘Code’)1 in its version 2.11 (‘v2.11’)2 as of December 2020.
Originally drafted by the Cloud Select Industry Group3 (‘C-SIG’) the EU Cloud CoC – at that time called
C-SIG Code of Conduct on data protection for Cloud Service Providers (‘CSPs’) – was developed
against Directive 95/46/EC4 and incorporated feedback by the European Commission as well as
Working Party 29. Following an extensive revision of earlier versions of Code and further developing
the substance of the Code (v2.11) and its provisions has been aligned to the European General Data
Protection Regulation (‘GDPR’)5.
2 List of declared services
2.1 SAP Concur6
SAP Concur is a comprehensive spend management solution that helps businesses control and opti-
mize both employee and supplier spend. It provides visibility into business travel bookings across all
channels, enables better planning and budgeting, and allows organizations to effectively manage em-
ployee travel and expenses as well as supplier and vendor costs.7
2.1.1 SAP Concur Travel
SAP Concur Travel allows companies to manage employee travel spend by providing tools to book
flights, hotels, and transportation in compliance with corporate travel policies. It helps control costs,
improve traveller experience, and increase visibility into travel expenditures.7
■ Travel
■ Triplink & TripIt
1 https://eucoc.cloud
2 https://eucoc.cloud/get-the-code
3 https://ec.europa.eu/digital-single-market/en/cloud-select-industry-group-code-conduct
4 https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:31995L0046
5 https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679
6 https://www.concursolutions.com
7 NOTE: The content for the service description has been provided by the CSP and does not reflect any opinion
of or assessment by the Monitoring Body.
Verification of Declaration of Adherence 4 | 11
2.1.2 SAP Concur Expense
SAP Concur Expense helps businesses control and manage employee spend by streamlining the sub-
mission, approval, reimbursement, and reporting of business expenses. It ensures compliance with
company policies while improving visibility and financial control.7
■ Expense
■ Expense Pay
■ ExpenseIT
■ Request
2.1.3 SAP TMC Services
TMC Services is a centralized platform that streamlines the planning, booking, tracking, and expense
management of business travel. It helps organizations gain visibility and control over travel spend,
enforce travel policies, and ensure traveller safety and compliance.7
■ TMC Clarity
■ TMC Compleat
■ TMC Conquest
2.1.4 SAP Concur Invoice
SAP Concur Invoice automates the capture, processing, and approval of supplier invoices. It ensures
accuracy, reduces manual effort, accelerates payment cycles, and improves compliance with internal
controls and supplier agreements.7
■ Invoice
■ Invoice Capture
3 Verification Process - Background
V2.11 of the EU Cloud CoC has been developed against GDPR and hence provides mechanisms as
required by Articles 40 and 41 GDPR8.
8 https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679
2.1.2 SAP Concur Expense
SAP Concur Expense helps businesses control and manage employee spend by streamlining the sub-
mission, approval, reimbursement, and reporting of business expenses. It ensures compliance with
company policies while improving visibility and financial control.7
■ Expense
■ Expense Pay
■ ExpenseIT
■ Request
2.1.3 SAP TMC Services
TMC Services is a centralized platform that streamlines the planning, booking, tracking, and expense
management of business travel. It helps organizations gain visibility and control over travel spend,
enforce travel policies, and ensure traveller safety and compliance.7
■ TMC Clarity
■ TMC Compleat
■ TMC Conquest
2.1.4 SAP Concur Invoice
SAP Concur Invoice automates the capture, processing, and approval of supplier invoices. It ensures
accuracy, reduces manual effort, accelerates payment cycles, and improves compliance with internal
controls and supplier agreements.7
■ Invoice
■ Invoice Capture
3 Verification Process - Background
V2.11 of the EU Cloud CoC has been developed against GDPR and hence provides mechanisms as
required by Articles 40 and 41 GDPR8.
8 https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679
Verification of Declaration of Adherence 5 | 11
3.1 Approval of the Code and Accreditation of the Monitoring Body
The services concerned passed the verification process by the Monitoring Body of the EU Cloud CoC,
i.e., SCOPE Europe SRL9.
The Code has been officially approved in May 202110. SCOPE Europe has been officially accredited
as Monitoring Body in May 202111. The robust and complex procedures and mechanisms can be
reviewed by any third-party in detail at the website of the EU Cloud CoC alongside a short summary
thereof.12
3.2 Principles of the Verification Process
Notwithstanding the powers of and requirements set out by the supervisory authority pursuant to
Article 41 GDPR, the Monitoring Body will assess whether a Cloud Service, that has been declared
adherent to the Code, is compliant with the requirements of the Code - especially as laid down in the
Controls Catalogue. Unless otherwise provided by the Code, the Monitoring Body’s assessment pro-
cess will be based on an evidence-based conformity assessment, based on interviews and document
reviews; proactively performed by the Monitoring Body.
To the extent the Monitoring Body is not satisfied with the evidence provided by a CSP with regards to
the Cloud Service to be declared adherent to the Code, the Monitoring Body will request additional
information. Where the information provided by the CSP appears to be inconsistent or false, the Mon-
itoring Body will - as necessary - request substantiation by independent reports.
3.3 Multiple Safeguards of Compliance
Compliance of adherent services is safeguarded by the interaction of several mechanisms, i.e., con-
tinuous, rigorous, and independent monitoring, an independent complaints’ handling process, and
finally any CSP declaring services adherent is subject to substantial remedies and penalties in case
of any infringement.
3.4 Process in Detail
It is expected that, prior to any assessment of the Monitoring Body, each CSP assesses its compliance
internally. When declaring its service(s) adherent to the EU Cloud CoC, each CSP must elaborate its
9 https://scope-europe.eu
10 https://www.gegevensbeschermingsautoriteit.be/publications/decision-n05-2021-of-20-may-2021.pdf
11 https://www.gegevensbeschermingsautoriteit.be/publications/decision-n-06-2021-of-20-may-2021.pdf
12 https://eucoc.cloud/en/public-register/assessment-procedure/
3.1 Approval of the Code and Accreditation of the Monitoring Body
The services concerned passed the verification process by the Monitoring Body of the EU Cloud CoC,
i.e., SCOPE Europe SRL9.
The Code has been officially approved in May 202110. SCOPE Europe has been officially accredited
as Monitoring Body in May 202111. The robust and complex procedures and mechanisms can be
reviewed by any third-party in detail at the website of the EU Cloud CoC alongside a short summary
thereof.12
3.2 Principles of the Verification Process
Notwithstanding the powers of and requirements set out by the supervisory authority pursuant to
Article 41 GDPR, the Monitoring Body will assess whether a Cloud Service, that has been declared
adherent to the Code, is compliant with the requirements of the Code - especially as laid down in the
Controls Catalogue. Unless otherwise provided by the Code, the Monitoring Body’s assessment pro-
cess will be based on an evidence-based conformity assessment, based on interviews and document
reviews; proactively performed by the Monitoring Body.
To the extent the Monitoring Body is not satisfied with the evidence provided by a CSP with regards to
the Cloud Service to be declared adherent to the Code, the Monitoring Body will request additional
information. Where the information provided by the CSP appears to be inconsistent or false, the Mon-
itoring Body will - as necessary - request substantiation by independent reports.
3.3 Multiple Safeguards of Compliance
Compliance of adherent services is safeguarded by the interaction of several mechanisms, i.e., con-
tinuous, rigorous, and independent monitoring, an independent complaints’ handling process, and
finally any CSP declaring services adherent is subject to substantial remedies and penalties in case
of any infringement.
3.4 Process in Detail
It is expected that, prior to any assessment of the Monitoring Body, each CSP assesses its compliance
internally. When declaring its service(s) adherent to the EU Cloud CoC, each CSP must elaborate its
9 https://scope-europe.eu
10 https://www.gegevensbeschermingsautoriteit.be/publications/decision-n05-2021-of-20-may-2021.pdf
11 https://www.gegevensbeschermingsautoriteit.be/publications/decision-n-06-2021-of-20-may-2021.pdf
12 https://eucoc.cloud/en/public-register/assessment-procedure/