The California Privacy Rights Act
PUBLIC
The California Privacy Rights Act (CPRA)
The CPRA Implementation at SAP
Version: 2.0
Date: May 16, 2025
The California Privacy Rights Act (CPRA)
The CPRA Implementation at SAP
Version: 2.0
Date: May 16, 2025
In 2023, the California Privacy Rights Act (CPRA) came into force, expanding upon the rights
already enshrined under the California Consumer Privacy Act (CCPA). Since then, a number of
regulation packages have been adopted, however key aspects of the law such as
requirements related to Cybersecurity Audits, Risk Assessments and Automated Decision-
making Technology are still under discussion. Compared to regulations in some other States,
the CCPA/ CPRA grant California consumers more control over their personal information and
impose heightened compliance obligations on businesses.
California Privacy Rights Readiness at SAP
Before the CPRA came into force, SAP established a California Privacy Rights Readiness Working Group to evaluate
the possible impact on various areas of SAP’s business, including SAP’s delivery of products and services to its
customers. Similarly, SAP continues to carefully monitor further regulations as they are released. While these
requirements may have been new in California, they are for the most part not new concepts for SAP as a global
service provider. As further regulations continue to be finalized, SAP will oversee the implementation of any
necessary changes to help ensure that SAP, as well as its customers, can continue to meet the applicable legal
requirements in their respective roles and responsibilities under applicable agreements.
SAP as a Service Provider under the CCPA and CPRA
In its role as a service provider under the CCPA/CPRA, SAP processes a customer’s personal data in accordance
with written instructions pertaining to the delivery of its products and services as captured in the agreement
between the parties. SAP agreements also set forth how SAP subprocessors handle a customer’s personal data.
SAP’s Data Protection and Privacy by Design Product Road Map
SAP offers a wide range of software products and services that support customers in their businesses. Data
protection and privacy features are embedded by design and default in SAP products and services. In many cases,
helpful features and functionalities that customers may need to comply with requirements under the CCPA/CPRA
(or other State comprehensive privacy laws) are already built in to SAP software and its related processes and
procedures. For example, many of SAP’s products and services contain features and functionality that enable
customers to easily respond to requests from individuals to rectify, delete, or restrict access to or provide a copy of
their personal data.
To learn more about data protection and privacy at SAP, visit https://www.sap.com/about/trust-center.html at
www.sap.com.
© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material. 2 / 2
already enshrined under the California Consumer Privacy Act (CCPA). Since then, a number of
regulation packages have been adopted, however key aspects of the law such as
requirements related to Cybersecurity Audits, Risk Assessments and Automated Decision-
making Technology are still under discussion. Compared to regulations in some other States,
the CCPA/ CPRA grant California consumers more control over their personal information and
impose heightened compliance obligations on businesses.
California Privacy Rights Readiness at SAP
Before the CPRA came into force, SAP established a California Privacy Rights Readiness Working Group to evaluate
the possible impact on various areas of SAP’s business, including SAP’s delivery of products and services to its
customers. Similarly, SAP continues to carefully monitor further regulations as they are released. While these
requirements may have been new in California, they are for the most part not new concepts for SAP as a global
service provider. As further regulations continue to be finalized, SAP will oversee the implementation of any
necessary changes to help ensure that SAP, as well as its customers, can continue to meet the applicable legal
requirements in their respective roles and responsibilities under applicable agreements.
SAP as a Service Provider under the CCPA and CPRA
In its role as a service provider under the CCPA/CPRA, SAP processes a customer’s personal data in accordance
with written instructions pertaining to the delivery of its products and services as captured in the agreement
between the parties. SAP agreements also set forth how SAP subprocessors handle a customer’s personal data.
SAP’s Data Protection and Privacy by Design Product Road Map
SAP offers a wide range of software products and services that support customers in their businesses. Data
protection and privacy features are embedded by design and default in SAP products and services. In many cases,
helpful features and functionalities that customers may need to comply with requirements under the CCPA/CPRA
(or other State comprehensive privacy laws) are already built in to SAP software and its related processes and
procedures. For example, many of SAP’s products and services contain features and functionality that enable
customers to easily respond to requests from individuals to rectify, delete, or restrict access to or provide a copy of
their personal data.
To learn more about data protection and privacy at SAP, visit https://www.sap.com/about/trust-center.html at
www.sap.com.
© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material. 2 / 2