International transfer of EU personal data
frequently asked questions 문서 다운받기
PUBLIC
The International Transfer of EU Personal Data
by SAP as a Data Processor
Frequently Asked Questions (FAQs)
Version: 2.0
Date: April 25, 2024
The information contained in this document is for general informational purposes only and is provided on the
understanding that SAP is not engaged in rendering legal advice. The responsibility to adopt appropriate
measures to meet the new requirements set forth by the European Union Standard Contractual Clauses as set
out in Commission Decision 2021/914/EU (“EU SCC”) and the decision of the European Court of Justice
(“CJEU”) on Schrems II relating to the international transfer of EU personal data to "Third Countries” (“the
Schrems II decision”) rests with each business. SAP accepts no liability for any actions taken as response to
this resource. As such, it should not be used as a substitute for legal or professional consultation.
The International Transfer of EU Personal Data
by SAP as a Data Processor
Frequently Asked Questions (FAQs)
Version: 2.0
Date: April 25, 2024
The information contained in this document is for general informational purposes only and is provided on the
understanding that SAP is not engaged in rendering legal advice. The responsibility to adopt appropriate
measures to meet the new requirements set forth by the European Union Standard Contractual Clauses as set
out in Commission Decision 2021/914/EU (“EU SCC”) and the decision of the European Court of Justice
(“CJEU”) on Schrems II relating to the international transfer of EU personal data to "Third Countries” (“the
Schrems II decision”) rests with each business. SAP accepts no liability for any actions taken as response to
this resource. As such, it should not be used as a substitute for legal or professional consultation.
The General Data Protection Regulation (“GDPR”) regulates the transfer of European Union (“EU) personal
data to countries outside of the European Economic Area (“EEA”), mandating that such transfers are subject
to "adequate protection." The European Commission recognizes certain countries as providing this level of
adequacy. For countries not granted this recognition, companies must adopt alternative methods to
legitimize personal data transfers. One widely used method is adhering to the EU Standard Contractual
Clauses 2021/914/EU (“EU SCC”), which are preset agreements certified to meet data protection standards.
SAP uses EU SCC to legitimize the transfer of EU personal data by providing a legally recognized mechanism
to comply with GDPR requirements, ensuring adequate protection of personal data when transferred outside
the EEA.
Why Does SAP Use EU SCC to Legitimize the Transfer of EU
Personal Data?
We are committed to ensuring the highest standards of data protection and compliance, and the use of EU
SCC enables SAP to achieve this goal efficiently and effectively. EU SCC provide a versatile solution that can
be applied to personal data transfers not only within the corporate group but also with external third parties.
This flexibility is crucial for SAP, given our wide range of partners and suppliers. EU SCC can also be easily
adapted to specific contractual relationships, providing tailored solutions to ensure the highest level of data
protection for our customers and partners and allow for SAP to respond promptly to new opportunities or
changes in data protection requirements.
While Binding Corporate Rules (“BCRs”) offer robust safeguards for intra-group data transfers, their limited
scope and administrative burdens make EU SCC a more practical and effective choice for SAP. EU SCC can
thus be implemented quickly and efficiently without the lengthy and costly approval process required for
BCRs. Similarly, SAP does not adhere to the EU-US Data Privacy Framework due to invalidation of its
predecessors (Safe Harbor and Privacy Shield), complexity of certification requirements and limited scope
(i.e. it only applies to registered US-based companies).
What Categories of Personal Data Does SAP Process?
The categories of personal data SAP processes depend on the specific cloud services a Customer
subscribes to, the personal data the Customer uploads and how the Customer configures the relevant data
fields. SAP processes Customer personal in accordance with its contractual commitments contained in the
Data Processing Agreement (“DPA”). The DPA includes a description of the categories of personal data and
data subjects in Schedule 1.
For What Purposes Will Customers’ Personal Data Be Processed?
The purposes for which SAP processes personal data are described in the SAP DPA, specifically in Schedule
1, “Description of Processing.” These purposes include providing and supporting the cloud service,
continuous improvement of service features and functionalities, provision of embedded professional
services, communication with authorized users, storage and backup of personal data, and execution of
customer instructions in accordance with the agreement.
Did the Schrems II Decision Impact SAP and SAP Customers?
The Schrems II decision requires companies to conduct case-by-case analyses to determine whether the
laws of certain countries, so-called “Third Countries”, permit government access to personal data and assess
data to countries outside of the European Economic Area (“EEA”), mandating that such transfers are subject
to "adequate protection." The European Commission recognizes certain countries as providing this level of
adequacy. For countries not granted this recognition, companies must adopt alternative methods to
legitimize personal data transfers. One widely used method is adhering to the EU Standard Contractual
Clauses 2021/914/EU (“EU SCC”), which are preset agreements certified to meet data protection standards.
SAP uses EU SCC to legitimize the transfer of EU personal data by providing a legally recognized mechanism
to comply with GDPR requirements, ensuring adequate protection of personal data when transferred outside
the EEA.
Why Does SAP Use EU SCC to Legitimize the Transfer of EU
Personal Data?
We are committed to ensuring the highest standards of data protection and compliance, and the use of EU
SCC enables SAP to achieve this goal efficiently and effectively. EU SCC provide a versatile solution that can
be applied to personal data transfers not only within the corporate group but also with external third parties.
This flexibility is crucial for SAP, given our wide range of partners and suppliers. EU SCC can also be easily
adapted to specific contractual relationships, providing tailored solutions to ensure the highest level of data
protection for our customers and partners and allow for SAP to respond promptly to new opportunities or
changes in data protection requirements.
While Binding Corporate Rules (“BCRs”) offer robust safeguards for intra-group data transfers, their limited
scope and administrative burdens make EU SCC a more practical and effective choice for SAP. EU SCC can
thus be implemented quickly and efficiently without the lengthy and costly approval process required for
BCRs. Similarly, SAP does not adhere to the EU-US Data Privacy Framework due to invalidation of its
predecessors (Safe Harbor and Privacy Shield), complexity of certification requirements and limited scope
(i.e. it only applies to registered US-based companies).
What Categories of Personal Data Does SAP Process?
The categories of personal data SAP processes depend on the specific cloud services a Customer
subscribes to, the personal data the Customer uploads and how the Customer configures the relevant data
fields. SAP processes Customer personal in accordance with its contractual commitments contained in the
Data Processing Agreement (“DPA”). The DPA includes a description of the categories of personal data and
data subjects in Schedule 1.
For What Purposes Will Customers’ Personal Data Be Processed?
The purposes for which SAP processes personal data are described in the SAP DPA, specifically in Schedule
1, “Description of Processing.” These purposes include providing and supporting the cloud service,
continuous improvement of service features and functionalities, provision of embedded professional
services, communication with authorized users, storage and backup of personal data, and execution of
customer instructions in accordance with the agreement.
Did the Schrems II Decision Impact SAP and SAP Customers?
The Schrems II decision requires companies to conduct case-by-case analyses to determine whether the
laws of certain countries, so-called “Third Countries”, permit government access to personal data and assess
© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material. 3 / 5
whether such laws meet EU standards. Where such standards are not met, controllers must ensure that either
additional safeguards are in place or suspend such transfers. Data exporters using EU SCC must thus
evaluate the legal landscape of the recipient jurisdiction by conducting a “Transfer Impact Assessment” (TIA)
and take any “supplementary measures” necessary to ensure that EU personal data is protected from Third
Country governmental access at the level required under EU law. SAP provides support to its Customers who
need to conduct TIAs when they are using cloud services from SAP, for example see: SAP Trust Center: FAQs
on Transfer Impact Assessments.
What Supplementary Measures Does SAP Offer to Protect EU
Personal Data?
SAP takes the following supplementary measures to protect EU personal data it processes on behalf of its
Customers:
Technical and Organizational Measures (“TOMs”):
- SAP implements robust security measures to protect personal data during transfers and throughout its
processing activities. These measures include encryption, access controls, regular security audits, and
data breach response plans. The TOMs are incorporated into SAP’s data processing agreements with
Customers and they can be found in the SAP Trust Center under this link:
https://www.sap.com/about/trust-center/agreements/cloud/cloud-
services.html?sort=latest_desc&tag=agreements:security-measures/security-measures-for-cloud-
services.
- SAP provides Data Transfer Factsheets for certain SAP products and services. The information
contained in the Data Transfer Factsheets is designed to help SAP Customers carry out TIAs as
recommended by the European Data Protection Board for supplement transfer tools ensuring
compliance with the European Union’s level of protection of personal data on a self-service basis here
(SAP ID and Log in required): SAP Sub-processors
- SAP maintains data protection and privacy certifications as well as independent third-party audit
reports for its products and services. Customers can review these certifications and reports at any
time on a self-service basis here (SAP ID and Log in required): https://www.sap.com/about/trust-
center/certification-compliance.html.
- SAP maintains agreements with its Subprocessors to protect personal data consistent with the
respective obligations SAP undertakes vis-a-vis its customers. More information about these
arrangements can be found in SAP’s Trust Center at the following link:
https://www.sap.com/about/trust-center.html.
Contractual Measures:
SAP provides Customers with contractual commitments to ensure transparency, including information about
processing locations, applicable laws, and government access requests to access Customer data. For
example, see Section the “Compelled Disclosure” of the General Terms and Conditions for Cloud Services.
Does SAP Use Subprocessors?
SAP uses Subprocessors to support and provide its cloud services as defined in the DPA. Customers can
access a list of such subprocessors via the support portal: https://support.sap.com/en/my-support/trust-
center/subprocessors.html. These lists include details on the location and country of each subprocessor per
product or service. Customers can subscribe to subprocessor lists and receive e-mail notifications of
changes.
whether such laws meet EU standards. Where such standards are not met, controllers must ensure that either
additional safeguards are in place or suspend such transfers. Data exporters using EU SCC must thus
evaluate the legal landscape of the recipient jurisdiction by conducting a “Transfer Impact Assessment” (TIA)
and take any “supplementary measures” necessary to ensure that EU personal data is protected from Third
Country governmental access at the level required under EU law. SAP provides support to its Customers who
need to conduct TIAs when they are using cloud services from SAP, for example see: SAP Trust Center: FAQs
on Transfer Impact Assessments.
What Supplementary Measures Does SAP Offer to Protect EU
Personal Data?
SAP takes the following supplementary measures to protect EU personal data it processes on behalf of its
Customers:
Technical and Organizational Measures (“TOMs”):
- SAP implements robust security measures to protect personal data during transfers and throughout its
processing activities. These measures include encryption, access controls, regular security audits, and
data breach response plans. The TOMs are incorporated into SAP’s data processing agreements with
Customers and they can be found in the SAP Trust Center under this link:
https://www.sap.com/about/trust-center/agreements/cloud/cloud-
services.html?sort=latest_desc&tag=agreements:security-measures/security-measures-for-cloud-
services.
- SAP provides Data Transfer Factsheets for certain SAP products and services. The information
contained in the Data Transfer Factsheets is designed to help SAP Customers carry out TIAs as
recommended by the European Data Protection Board for supplement transfer tools ensuring
compliance with the European Union’s level of protection of personal data on a self-service basis here
(SAP ID and Log in required): SAP Sub-processors
- SAP maintains data protection and privacy certifications as well as independent third-party audit
reports for its products and services. Customers can review these certifications and reports at any
time on a self-service basis here (SAP ID and Log in required): https://www.sap.com/about/trust-
center/certification-compliance.html.
- SAP maintains agreements with its Subprocessors to protect personal data consistent with the
respective obligations SAP undertakes vis-a-vis its customers. More information about these
arrangements can be found in SAP’s Trust Center at the following link:
https://www.sap.com/about/trust-center.html.
Contractual Measures:
SAP provides Customers with contractual commitments to ensure transparency, including information about
processing locations, applicable laws, and government access requests to access Customer data. For
example, see Section the “Compelled Disclosure” of the General Terms and Conditions for Cloud Services.
Does SAP Use Subprocessors?
SAP uses Subprocessors to support and provide its cloud services as defined in the DPA. Customers can
access a list of such subprocessors via the support portal: https://support.sap.com/en/my-support/trust-
center/subprocessors.html. These lists include details on the location and country of each subprocessor per
product or service. Customers can subscribe to subprocessor lists and receive e-mail notifications of
changes.
© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material. 4 / 5
How Does SAP Inform Customers of Changes in SAP
Subprocessors Lists?
SAP publishes its Subprocessor lists in the SAP Portal (see: https://support.sap.com/en/my-
support/trustcenter/subprocessors.html) including specific information about each Subprocessor that SAP
uses to provide the relevant Cloud Service to its Customers. Customers have the possibility to subscribe to
Subprocessor lists in which case they will be informed via email about every change. SAP carefully evaluates
the security, privacy and confidentiality practices prior to engaging a Subprocessor. All Subprocessors enter
into a written agreement with SAP that includes data privacy and security terms.
How Does SAP implement the EU SCC in Subprocessor
Agreements?
SAP has released a Contractor Data Processing Agreement (CDPA) that incorporates the EU SCC for EU
personal data transfers to countries outside of the EEA with no adequacy finding (“Third Countries”).
Where is Personal Data Physically Stored?
You can find the data center locations where the selected SAP cloud solutions are currently operated here:
SAP Data Center | SAP Trust Center
Does SAP Offer Data Localization Options in the European
Economic Area (EEA)?
SAP offers “EU Access” for certain Cloud Services as an optional feature. EU Access provides that personal
data will not be processed outside of the EEA or Switzerland unless expressly authorized by Customer on a
case-by-case basis, subject to certain exclusions. Where available, Customers must affirmatively opt-in to
subscribe to this option and additional fees may apply. If a Customer opts for EU Access, SAP will host the
production instance of the Cloud Service in the EEA or Switzerland and SAP will use Subprocessors in the
EEA/Switzerland accessing the data hosted in such environment for support purposes.
How do SAP DPAs Incorporate the EU SCC?
Since DPAs outline the instructions from a data controller or data processor (i.e. SAP’s Customer) to another
data processor (i.e. SAP) regarding the handling of personal data, the EU SCC are incorporated as follows:
● Where SAP is located in the EU/EEA and SAP Subprocessors are in a Third Country, then Module 3
(“Processor-to-Processor”) of the EU SCC applies between SAP and its Subprocessors.
● If SAP is in a Third Country and SAP Customers are located in the EU/EEA, then between SAP and SAP’s
Customer:
- Module 2 (“Controller-to-Processor”) of the EU SCC will apply if the Customer acts as a Controller;
and/or
- Module 3 (“Processor-to-Processor”) of the EU SCC will apply if the Customer acts as a Processor.
How Does SAP Inform Customers of Changes in SAP
Subprocessors Lists?
SAP publishes its Subprocessor lists in the SAP Portal (see: https://support.sap.com/en/my-
support/trustcenter/subprocessors.html) including specific information about each Subprocessor that SAP
uses to provide the relevant Cloud Service to its Customers. Customers have the possibility to subscribe to
Subprocessor lists in which case they will be informed via email about every change. SAP carefully evaluates
the security, privacy and confidentiality practices prior to engaging a Subprocessor. All Subprocessors enter
into a written agreement with SAP that includes data privacy and security terms.
How Does SAP implement the EU SCC in Subprocessor
Agreements?
SAP has released a Contractor Data Processing Agreement (CDPA) that incorporates the EU SCC for EU
personal data transfers to countries outside of the EEA with no adequacy finding (“Third Countries”).
Where is Personal Data Physically Stored?
You can find the data center locations where the selected SAP cloud solutions are currently operated here:
SAP Data Center | SAP Trust Center
Does SAP Offer Data Localization Options in the European
Economic Area (EEA)?
SAP offers “EU Access” for certain Cloud Services as an optional feature. EU Access provides that personal
data will not be processed outside of the EEA or Switzerland unless expressly authorized by Customer on a
case-by-case basis, subject to certain exclusions. Where available, Customers must affirmatively opt-in to
subscribe to this option and additional fees may apply. If a Customer opts for EU Access, SAP will host the
production instance of the Cloud Service in the EEA or Switzerland and SAP will use Subprocessors in the
EEA/Switzerland accessing the data hosted in such environment for support purposes.
How do SAP DPAs Incorporate the EU SCC?
Since DPAs outline the instructions from a data controller or data processor (i.e. SAP’s Customer) to another
data processor (i.e. SAP) regarding the handling of personal data, the EU SCC are incorporated as follows:
● Where SAP is located in the EU/EEA and SAP Subprocessors are in a Third Country, then Module 3
(“Processor-to-Processor”) of the EU SCC applies between SAP and its Subprocessors.
● If SAP is in a Third Country and SAP Customers are located in the EU/EEA, then between SAP and SAP’s
Customer:
- Module 2 (“Controller-to-Processor”) of the EU SCC will apply if the Customer acts as a Controller;
and/or
- Module 3 (“Processor-to-Processor”) of the EU SCC will apply if the Customer acts as a Processor.
© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material. 5 / 5
How Can Customers Update Existing SAP DPAs?
All of SAP’s DPA are available online at the following link: SAP Trust Center - Agreements.
• Customers can request to update their DPA by contacting their SAP account executive or SAP sales
representative.
• Customers based in the EU with an existing DPA can sign on a self-serve basis a DPA amendment that
includes the EU SCC and is pre-signed by SAP. It is available in several languages for authorized
Customers with a valid SAP user ID under this link: https://me.sap.com/financelegal. DocuSign will be
used to facilitate the signature process.
• Further, Customers with an existing DPA entered into by SAP (UK) Limited have the option to sign on a
self-serve basis an additional DPA amendment which supplements the EU SCC with the international
data transfer addendum to the European Commission’s standard contractual clauses for international
data transfers (the “UK IDTA”) for purpose of compliance with the UK GDPR. This additional DPA
Amendment is pre-signed by SAP UK and is available in English for authorized Customers with a valid
SAP user ID at this link: https://me.sap.com/financelegal. DocuSign will be used to facilitate the signature
process.
How does SAP Respond to Third Party Requests to Access a
Customer’s Data?
Generally, customers can directly access their data stored in SAP cloud services. SAP is therefore of the
opinion that customers are best placed to identify and access their own data in response to a Request.
Please see also https://www.sap.com/about/trust-center/data-privacy.html?pdf-asset=ec3728a3-a57e-
0010-bca6-c68f7e60039b&page=1.
Which Parties Need to Sign the EU SCC?
The European Commissions’ FAQ on New Standard Contractual Clauses explicitly states in Question 6 and
10 respectively that the SCC do not contain any requirements on how the signature should be formalised.
This is left to national (civil/contract) law governing the agreement. To be able to rely on the EU SCC they
must be signed by and binding all parties and incorporated into their contract (New Standard Contractual
Clauses - Questions and Answers overview - European Commission). The SAP DPA incorporates the EU SCC
into the agreement by reference and Schedule 1 specifies who acts as the data exporters and the data
importers under the DPA, as those are the entities that must be bound by the EU SCC. In practice, many
reputable SaaS providers, including SAP, meet the EU SCC execution requirements by having 1 entity
execute the EU SCC on behalf of its group of companies. Ongoing compliance is then assured through
downstream contractual obligations (i.e. intragroup agreements or third-party contractor data processing
agreements) to ensure EU SCC compliance through the subprocessing chain in compliance with applicable
contract and related laws in a streamlined manner.
For more information on how SAP demonstrates its commitment to data protection and privacy, please refer
to the resources in the SAP Trust Center (Data processing at SAP) - Data Protection and Privacy | SAP Trust
Center and consult www.sap.com.
How Can Customers Update Existing SAP DPAs?
All of SAP’s DPA are available online at the following link: SAP Trust Center - Agreements.
• Customers can request to update their DPA by contacting their SAP account executive or SAP sales
representative.
• Customers based in the EU with an existing DPA can sign on a self-serve basis a DPA amendment that
includes the EU SCC and is pre-signed by SAP. It is available in several languages for authorized
Customers with a valid SAP user ID under this link: https://me.sap.com/financelegal. DocuSign will be
used to facilitate the signature process.
• Further, Customers with an existing DPA entered into by SAP (UK) Limited have the option to sign on a
self-serve basis an additional DPA amendment which supplements the EU SCC with the international
data transfer addendum to the European Commission’s standard contractual clauses for international
data transfers (the “UK IDTA”) for purpose of compliance with the UK GDPR. This additional DPA
Amendment is pre-signed by SAP UK and is available in English for authorized Customers with a valid
SAP user ID at this link: https://me.sap.com/financelegal. DocuSign will be used to facilitate the signature
process.
How does SAP Respond to Third Party Requests to Access a
Customer’s Data?
Generally, customers can directly access their data stored in SAP cloud services. SAP is therefore of the
opinion that customers are best placed to identify and access their own data in response to a Request.
Please see also https://www.sap.com/about/trust-center/data-privacy.html?pdf-asset=ec3728a3-a57e-
0010-bca6-c68f7e60039b&page=1.
Which Parties Need to Sign the EU SCC?
The European Commissions’ FAQ on New Standard Contractual Clauses explicitly states in Question 6 and
10 respectively that the SCC do not contain any requirements on how the signature should be formalised.
This is left to national (civil/contract) law governing the agreement. To be able to rely on the EU SCC they
must be signed by and binding all parties and incorporated into their contract (New Standard Contractual
Clauses - Questions and Answers overview - European Commission). The SAP DPA incorporates the EU SCC
into the agreement by reference and Schedule 1 specifies who acts as the data exporters and the data
importers under the DPA, as those are the entities that must be bound by the EU SCC. In practice, many
reputable SaaS providers, including SAP, meet the EU SCC execution requirements by having 1 entity
execute the EU SCC on behalf of its group of companies. Ongoing compliance is then assured through
downstream contractual obligations (i.e. intragroup agreements or third-party contractor data processing
agreements) to ensure EU SCC compliance through the subprocessing chain in compliance with applicable
contract and related laws in a streamlined manner.
For more information on how SAP demonstrates its commitment to data protection and privacy, please refer
to the resources in the SAP Trust Center (Data processing at SAP) - Data Protection and Privacy | SAP Trust
Center and consult www.sap.com.