International transfer of EU personal data

frequently asked questions 문서 다운받기

PUBLICThe International Transfer of EU Personal Databy SAP as a Data ProcessorFrequently Asked Questions (FAQs)Version: 2.0Date: April 25, 2024The information contained in this document is for general informational purposes only and is provided on theunderstanding that SAP is not engaged in rendering legal advice. The responsibility to adopt appropriatemeasures to meet the new requirements set forth by the European Union Standard Contractual Clauses as setout in Commission Decision 2021/914/EU (“EU SCC”) and the decision of the European Court of Justice(“CJEU”) on Schrems II relating to the international transfer of EU personal data to "Third Countries” (“theSchrems II decision”) rests with each business. SAP accepts no liability for any actions taken as response tothis resource. As such, it should not be used as a substitute for legal or professional consultation.
The General Data Protection Regulation (“GDPR”) regulates the transfer of European Union (“EU) personaldata to countries outside of the European Economic Area (“EEA”), mandating that such transfers are subjectto "adequate protection." The European Commission recognizes certain countries as providing this level ofadequacy. For countries not granted this recognition, companies must adopt alternative methods tolegitimize personal data transfers. One widely used method is adhering to the EU Standard ContractualClauses 2021/914/EU (“EU SCC”), which are preset agreements certified to meet data protection standards.SAP uses EU SCC to legitimize the transfer of EU personal data by providing a legally recognized mechanismto comply with GDPR requirements, ensuring adequate protection of personal data when transferred outsidethe EEA.Why Does SAP Use EU SCC to Legitimize the Transfer of EUPersonal Data?We are committed to ensuring the highest standards of data protection and compliance, and the use of EUSCC enables SAP to achieve this goal efficiently and effectively. EU SCC provide a versatile solution that canbe applied to personal data transfers not only within the corporate group but also with external third parties.This flexibility is crucial for SAP, given our wide range of partners and suppliers. EU SCC can also be easilyadapted to specific contractual relationships, providing tailored solutions to ensure the highest level of dataprotection for our customers and partners and allow for SAP to respond promptly to new opportunities orchanges in data protection requirements.While Binding Corporate Rules (“BCRs”) offer robust safeguards for intra-group data transfers, their limitedscope and administrative burdens make EU SCC a more practical and effective choice for SAP. EU SCC canthus be implemented quickly and efficiently without the lengthy and costly approval process required forBCRs. Similarly, SAP does not adhere to the EU-US Data Privacy Framework due to invalidation of itspredecessors (Safe Harbor and Privacy Shield), complexity of certification requirements and limited scope(i.e. it only applies to registered US-based companies).What Categories of Personal Data Does SAP Process?The categories of personal data SAP processes depend on the specific cloud services a Customersubscribes to, the personal data the Customer uploads and how the Customer configures the relevant datafields. SAP processes Customer personal in accordance with its contractual commitments contained in theData Processing Agreement (“DPA”). The DPA includes a description of the categories of personal data anddata subjects in Schedule 1.For What Purposes Will Customers’ Personal Data Be Processed?The purposes for which SAP processes personal data are described in the SAP DPA, specifically in Schedule1, “Description of Processing.” These purposes include providing and supporting the cloud service,continuous improvement of service features and functionalities, provision of embedded professionalservices, communication with authorized users, storage and backup of personal data, and execution ofcustomer instructions in accordance with the agreement.Did the Schrems II Decision Impact SAP and SAP Customers?The Schrems II decision requires companies to conduct case-by-case analyses to determine whether thelaws of certain countries, so-called “Third Countries”, permit government access to personal data and assess
© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material. 3 / 5whether such laws meet EU standards. Where such standards are not met, controllers must ensure that eitheradditional safeguards are in place or suspend such transfers. Data exporters using EU SCC must thusevaluate the legal landscape of the recipient jurisdiction by conducting a “Transfer Impact Assessment” (TIA)and take any “supplementary measures” necessary to ensure that EU personal data is protected from ThirdCountry governmental access at the level required under EU law. SAP provides support to its Customers whoneed to conduct TIAs when they are using cloud services from SAP, for example see: SAP Trust Center: FAQson Transfer Impact Assessments.What Supplementary Measures Does SAP Offer to Protect EUPersonal Data?SAP takes the following supplementary measures to protect EU personal data it processes on behalf of itsCustomers:Technical and Organizational Measures (“TOMs”):- SAP implements robust security measures to protect personal data during transfers and throughout itsprocessing activities. These measures include encryption, access controls, regular security audits, anddata breach response plans. The TOMs are incorporated into SAP’s data processing agreements withCustomers and they can be found in the SAP Trust Center under this link:https://www.sap.com/about/trust-center/agreements/cloud/cloud-services.html?sort=latest_desc&tag=agreements:security-measures/security-measures-for-cloud-services.- SAP provides Data Transfer Factsheets for certain SAP products and services. The informationcontained in the Data Transfer Factsheets is designed to help SAP Customers carry out TIAs asrecommended by the European Data Protection Board for supplement transfer tools ensuringcompliance with the European Union’s level of protection of personal data on a self-service basis here(SAP ID and Log in required): SAP Sub-processors- SAP maintains data protection and privacy certifications as well as independent third-party auditreports for its products and services. Customers can review these certifications and reports at anytime on a self-service basis here (SAP ID and Log in required): https://www.sap.com/about/trust-center/certification-compliance.html.- SAP maintains agreements with its Subprocessors to protect personal data consistent with therespective obligations SAP undertakes vis-a-vis its customers. More information about thesearrangements can be found in SAP’s Trust Center at the following link:https://www.sap.com/about/trust-center.html.Contractual Measures:SAP provides Customers with contractual commitments to ensure transparency, including information aboutprocessing locations, applicable laws, and government access requests to access Customer data. Forexample, see Section the “Compelled Disclosure” of the General Terms and Conditions for Cloud Services.Does SAP Use Subprocessors?SAP uses Subprocessors to support and provide its cloud services as defined in the DPA. Customers canaccess a list of such subprocessors via the support portal: https://support.sap.com/en/my-support/trust-center/subprocessors.html. These lists include details on the location and country of each subprocessor perproduct or service. Customers can subscribe to subprocessor lists and receive e-mail notifications ofchanges.
© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material. 4 / 5How Does SAP Inform Customers of Changes in SAPSubprocessors Lists?SAP publishes its Subprocessor lists in the SAP Portal (see: https://support.sap.com/en/my-support/trustcenter/subprocessors.html) including specific information about each Subprocessor that SAPuses to provide the relevant Cloud Service to its Customers. Customers have the possibility to subscribe toSubprocessor lists in which case they will be informed via email about every change. SAP carefully evaluatesthe security, privacy and confidentiality practices prior to engaging a Subprocessor. All Subprocessors enterinto a written agreement with SAP that includes data privacy and security terms.How Does SAP implement the EU SCC in SubprocessorAgreements?SAP has released a Contractor Data Processing Agreement (CDPA) that incorporates the EU SCC for EUpersonal data transfers to countries outside of the EEA with no adequacy finding (“Third Countries”).Where is Personal Data Physically Stored?You can find the data center locations where the selected SAP cloud solutions are currently operated here:SAP Data Center | SAP Trust CenterDoes SAP Offer Data Localization Options in the EuropeanEconomic Area (EEA)?SAP offers “EU Access” for certain Cloud Services as an optional feature. EU Access provides that personaldata will not be processed outside of the EEA or Switzerland unless expressly authorized by Customer on acase-by-case basis, subject to certain exclusions. Where available, Customers must affirmatively opt-in tosubscribe to this option and additional fees may apply. If a Customer opts for EU Access, SAP will host theproduction instance of the Cloud Service in the EEA or Switzerland and SAP will use Subprocessors in theEEA/Switzerland accessing the data hosted in such environment for support purposes.How do SAP DPAs Incorporate the EU SCC?Since DPAs outline the instructions from a data controller or data processor (i.e. SAP’s Customer) to anotherdata processor (i.e. SAP) regarding the handling of personal data, the EU SCC are incorporated as follows: Where SAP is located in the EU/EEA and SAP Subprocessors are in a Third Country, then Module 3(“Processor-to-Processor”) of the EU SCC applies between SAP and its Subprocessors. If SAP is in a Third Country and SAP Customers are located in the EU/EEA, then between SAP and SAP’sCustomer:- Module 2 (“Controller-to-Processor”) of the EU SCC will apply if the Customer acts as a Controller;and/or- Module 3 (“Processor-to-Processor”) of the EU SCC will apply if the Customer acts as a Processor.
© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material. 5 / 5How Can Customers Update Existing SAP DPAs?All of SAP’s DPA are available online at the following link: SAP Trust Center - Agreements. Customers can request to update their DPA by contacting their SAP account executive or SAP salesrepresentative. Customers based in the EU with an existing DPA can sign on a self-serve basis a DPA amendment thatincludes the EU SCC and is pre-signed by SAP. It is available in several languages for authorizedCustomers with a valid SAP user ID under this link: https://me.sap.com/financelegal. DocuSign will beused to facilitate the signature process. Further, Customers with an existing DPA entered into by SAP (UK) Limited have the option to sign on aself-serve basis an additional DPA amendment which supplements the EU SCC with the internationaldata transfer addendum to the European Commission’s standard contractual clauses for internationaldata transfers (the “UK IDTA”) for purpose of compliance with the UK GDPR. This additional DPAAmendment is pre-signed by SAP UK and is available in English for authorized Customers with a validSAP user ID at this link: https://me.sap.com/financelegal. DocuSign will be used to facilitate the signatureprocess.How does SAP Respond to Third Party Requests to Access aCustomer’s Data?Generally, customers can directly access their data stored in SAP cloud services. SAP is therefore of theopinion that customers are best placed to identify and access their own data in response to a Request.Please see also https://www.sap.com/about/trust-center/data-privacy.html?pdf-asset=ec3728a3-a57e-0010-bca6-c68f7e60039b&page=1.Which Parties Need to Sign the EU SCC?The European Commissions’ FAQ on New Standard Contractual Clauses explicitly states in Question 6 and10 respectively that the SCC do not contain any requirements on how the signature should be formalised.This is left to national (civil/contract) law governing the agreement. To be able to rely on the EU SCC theymust be signed by and binding all parties and incorporated into their contract (New Standard ContractualClauses - Questions and Answers overview - European Commission). The SAP DPA incorporates the EU SCCinto the agreement by reference and Schedule 1 specifies who acts as the data exporters and the dataimporters under the DPA, as those are the entities that must be bound by the EU SCC. In practice, manyreputable SaaS providers, including SAP, meet the EU SCC execution requirements by having 1 entityexecute the EU SCC on behalf of its group of companies. Ongoing compliance is then assured throughdownstream contractual obligations (i.e. intragroup agreements or third-party contractor data processingagreements) to ensure EU SCC compliance through the subprocessing chain in compliance with applicablecontract and related laws in a streamlined manner.For more information on how SAP demonstrates its commitment to data protection and privacy, please referto the resources in the SAP Trust Center (Data processing at SAP) - Data Protection and Privacy | SAP TrustCenter and consult www.sap.com.