Data protection and privacy

Learn how SAP respects and protects individual privacy rights.
A woman holding a tablet.

Preserving trust through data security

Diagram of SAP Business Suite at the center of sovereign cloud with a data protection segment highlighted alongside security and compliance.

SAP’s commitment to data protection and privacy

We safeguard personal information by employing advanced security protocols and fostering a culture of trust.

Data protection and privacy by design

We focus on continuously improving our product development standards. We embed data protection and privacy features in our products and services by design and by default.

Artificial intelligence at SAP

Our use of AI and its development is governed by SAP Global AI Ethics policy and applicable laws.

Data protection management system (DPMS)

We have implemented a DPMS with respect to our internal data protection and privacy controls in accordance with internally recognized industry standards.

Data protection and privacy

We respect the privacy of every individual. Our policies and data processing agreements help us abide by relevant laws worldwide and provide a trusted foundation for our customers to operate their businesses.

placeholder

General Data Protection Regulation (GDPR)

In Europe, an individual’s right to data privacy is a human right. As a Germany-based company, SAP has a long-standing commitment to data privacy and protection principles.

EU Standard Contractual Clauses (EU SCC)

Find out how SAP implements the EU Standard Contractual Clauses (EU SCC) as published by the European Commission following the Schrems II decision.

EU Cloud Code of Conduct (EU Cloud CoC)

SAP has sought a Declaration of Adherence to the EU Cloud CoC for certain cloud services.

UK International Data Transfer Agreement (IDTA)

In line with the IDTA and SCCs, we support international data transfers. EEA, EU, and UK customers can easily manage compliance by signing a data processing agreement amendment through SAP’s self-service portal.

Data protection and privacy FAQs

Frequently asked questions

SAP protects personal data by implementing technical and organizational measures such as encryption, access controls, and privacy-by-design principles. These measures are incorporated into SAP’s data processing agreement. SAP also complies with international data protection laws, including the GDPR, and holds a range of third-party certifications that validate strong security and privacy practices across products and services.

As primarily a B2B provider of enterprise cloud solutions, SAP receives few requests from government entities to access customer data. When such requests do arise, SAP follows a defined legal process when responding to government data requests. Whenever possible, we inform customers before disclosing any information—unless prohibited by law—and we challenge demands that are unlawful or excessive. Protecting customer data from unauthorized access remains a top priority.

SAP maintains and regularly updates lists of product- and service-specific subprocessors, detailing the location and country of each subprocessor. These lists are accessible to customers at any time via SAP Trust Center. Customers may also subscribe to receive email notifications about changes to subprocessor lists.

 

SAP thoroughly evaluates the security, privacy, and confidentiality practices of each subprocessor before engagement. All subprocessors must enter into a written agreement with SAP that includes robust data protection and security provisions.

While SAP acts as a data processor, we provide comprehensive documentation to assist with DPIAs and TIAs; see more FAQ.

Following the Schrems II decision, SAP has implemented the following supplementary measures to support the international transfer of personal data. Safeguards include:

  • Technical and organizational measures (TOMs) to prevent unauthorized processing and accidental disclosure, access, loss, destruction, or alteration of personal data.

  • Third-party certifications and audit reports that verify our data protection standards.

  • Contractual safeguards, including transparency commitments to data processing locations, applicable laws, and government data access requests. These contractual provisions align with EDPB guidance.

Find SAP’s data processing agreements and other resources via SAP Trust Center.

 

When SAP provides products and services that involve transferring personal data from the European Economic Area or European Union to third countries (those not recognized under Article 45 of the GDPR as offering adequate protection) SAP relies on the standard contractual clauses issued by the European Commission to legitimize such transfers.

twitter pixeltwitter pixeltwitter pixeltwitter pixeltwitter pixeltwitter pixeltwitter pixeltwitter pixeltwitter pixeltwitter pixeltwitter pixeltwitter pixel