The California Privacy Rights Act

The Implementation of California Privacy Rights at SAP Download the Document

PUBLICThe California Privacy Rights Act (CPRA)The CPRA Implementation at SAPVersion: 2.0Date: May 16, 2025
In 2023, the California Privacy Rights Act (CPRA) came into force, expanding upon the rightsalready enshrined under the California Consumer Privacy Act (CCPA). Since then, a number ofregulation packages have been adopted, however key aspects of the law such asrequirements related to Cybersecurity Audits, Risk Assessments and Automated Decision-making Technology are still under discussion. Compared to regulations in some other States,the CCPA/ CPRA grant California consumers more control over their personal information andimpose heightened compliance obligations on businesses.California Privacy Rights Readiness at SAPBefore the CPRA came into force, SAP established a California Privacy Rights Readiness Working Group to evaluatethe possible impact on various areas of SAP’s business, including SAP’s delivery of products and services to itscustomers. Similarly, SAP continues to carefully monitor further regulations as they are released. While theserequirements may have been new in California, they are for the most part not new concepts for SAP as a globalservice provider. As further regulations continue to be finalized, SAP will oversee the implementation of anynecessary changes to help ensure that SAP, as well as its customers, can continue to meet the applicable legalrequirements in their respective roles and responsibilities under applicable agreements.SAP as a Service Provider under the CCPA and CPRAIn its role as a service provider under the CCPA/CPRA, SAP processes a customer’s personal data in accordancewith written instructions pertaining to the delivery of its products and services as captured in the agreementbetween the parties. SAP agreements also set forth how SAP subprocessors handle a customer’s personal data.SAP’s Data Protection and Privacy by Design Product Road MapSAP offers a wide range of software products and services that support customers in their businesses. Dataprotection and privacy features are embedded by design and default in SAP products and services. In many cases,helpful features and functionalities that customers may need to comply with requirements under the CCPA/CPRA(or other State comprehensive privacy laws) are already built in to SAP software and its related processes andprocedures. For example, many of SAP’s products and services contain features and functionality that enablecustomers to easily respond to requests from individuals to rectify, delete, or restrict access to or provide a copy oftheir personal data.To learn more about data protection and privacy at SAP, visit https://www.sap.com/about/trust-center.html atwww.sap.com.© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material. 2 / 2