Data Privacy and Transfer Impact Assessment

How SAP assists its customers with their compliance obligations by offering standardized responses to regulatory questionnaires. Ladda ner dokumentet

PUBLICData Protection and Transfer ImpactAssessmentsCustomer Frequently Asked QuestionsThe information contained in this document is for general informational purposes only and isprovided on the understanding that SAP is not engaged in rendering legal advice. SAP acceptsno liability for any actions taken in response to this resource. As such, it should not be used as asubstitute for legal or professional consultation.
© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material.As a leading provider of enterprise application software, SAP remains committed toupholding data protection and privacy standards across all regions in which it operates.SAP continues to rely on recognized international transfer mechanisms, such as EUStandard Contractual Clauses, to support lawful and secure cross-border data flows.Questions AnswersPersonal Data and Description of Processing1. Whatcategoriesofpersonaldata doesSAPprocess?The personal data SAP processes depend on the Cloud Services, SAP Supportor SAP Services a customer subscribes to, what personal data the customeruploads or processes therein and how the customer configures the relevantdata fields. Every contract for SAP Cloud Services, SAP Support, and SAPServices includes a personal data processing agreement. The current DPA isavailable here: https://www.sap.com/about/trust-center/agreements.html.The SAP Data Processing Agreement for SAP Cloud Services, SAP Support andSAP Services (“SAP DPA”) includes a description of data subjects and datacategories in Schedule 1 “Description of processing”. This description reflectsthe most common examples of the intended use of SAP’s services.2. Does SAPprocessanysensitiveor specialcategoriesofpersonaldata?Please refer to the response provided in Question 1 above and see Schedule1 “Description of processing” of the SAP DPA. Sensitive or special categoriesof personal data should only be uploaded to the SAP Cloud Services, SAPSupport and SAP Services (“SAP Services”) if explicitly agreed upon in writingby both parties as part of the contractual agreement.3. For whatpurposewill SAPtransfer acustomer’s personaldata tothirdcountries?The specific purposes for which SAP processes and transfers personal data tothird countries are outlined in Schedule 1 Description of Processing of theSAP DPA.4. Does SAPprocesspersonaldata as acontrollerAccording to the SAP DPA, SAP and its sub-processors operate as (sub-)processors. The customer, along with any entities authorized by the customerto use SAP Services act as controllers or processors, depending on their rolein determining the purposes and means of processing personal data.
© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material.or as aprocessor?5. Pleaseidentifythe dataimporterassociated with thistransfer.SAP may engage with various sub-processors (as defined in the SAP DPA) toprovide SAP Services. These sub-processors may act as data importers in thecontext of international transfers. A current list of SAP’s sub-processors isavailable on the SAP Trust Center.International Personal Data Transfers6. Does thesolutionlead toanytransfer ofpersonaldatainternationally, e.g..outsidetheEuropeanUnion(EU)/EuropeanEconomicArea(EEA)?Depending on the configuration and SAP Services in scope, personal data maybe transferred to countries internationally, including outside the EU or EEA.These transfers typically support operational needs such as service delivery,system maintenance, and customer support. SAP ensures that all internationaldata transfers are conducted in compliance with applicable data protectionlaws, using recognized safeguards like EU standard contractual clauses orother approved mechanisms. Furter, SAP makes available the followingresources to supports its customers: As a global provider, SAP utilizes international resources to deliver itsservices. To ensure transparency and responsible data handling, SAPmaintains Sub-processor lists for each serviceoutlining the roles andgeographic locations of involved entities. These lists are available tocustomers via the SAP Trust Center:https://support.sap.com/bin/fiji/es/login.support.html?RelayState=/content/support/en_us/my-support/trust-center/subprocessors. SAP also provides data transfer fact sheets for certain services that caninclude additional details, which SAP customers can access via the SAPsupport portal:https://support.sap.com/bin/fiji/es/login.support.html?RelayState=/content/support/en_us/my-support/trust-center/subprocessors.Customers seeking further details are encouraged to review these resourcesor reach out to their SAP account representative.7. How hasSAPaddressedconcernsrelated totheSAP acknowledges the concerns raised by customers following the Court ofJustice of the European Union (CJEU) ruling in Schrems II. Importantly, thedecision did not invalidate the use of Standard Contractual Clauses (SCCs) asa lawful mechanism for international personal data transfers.SAP supports compliance with Shrems II data protection requirements byensuring that the SAP DPA is included in every customer contract involving the
© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material.Schrems IIdecisionregardinginternationalpersonaldatatransfers?processing of personal data. The SAP DPA incorporates the EU SCCs(2021/914/EU).8. Canpersonaldata beprocessed (i.e.hosting,accessandsupport)exclusively withintheEU/EEA(“EUAccess”)?SAP offers optional EU Access features for select Cloud Services, designed toensure that personal data is hosted and accessed solely within the EuropeanEconomic Area (EEA) and Switzerland. Under this configuration:• Data centers used for the hosting of production environments arelocated within the EEA and Switzerland• Sub-processors operate exclusively from within these regions• No personal data is transferred outside the EEA or Switzerland unlessexplicitly authorized by the customer or included in support-relatedcommunicationsSAP can also explore additional safeguards tailored to specific services, suchas cloud-native key management solutions. Customers interested in EUAccess or related protections are encouraged to contact their SAP accountrepresentative for further details.9. Canpersonaldata beprocessed (i.e.hosting,accessandsupport)exclusively withinthe UnitedStates?For select services, personal data can be processed exclusively within theUnited States. SAP offers secure service options through SAP National SecurityServices (“SAP NS2), which may act as a sub-processor under specificcircumstances. These services are designed to meet certain U.S. regulatoryand data residency requirements, e.g., for U.S. federal and state governmententities or U.S. regulated industry customers. When applicable, SAP NS2ensures that data hosting, access, and support are confined to U.S. locationsand personnel. Customers interested in U.S.-based data processing shouldconsult their SAP account representative to determine whether SAP NS2services are available and suitable for their specific needs.10. Does SAPtransferpersonaldataunder theEU-USSAP’s contractual framework continues to rely on the EU SCCs (2021/914/EU)as a robust and reliable legal mechanism for personal data transfers to thirdcountries, including the United States.As a general principle, SAP did not adopt the now-invalidated EU-U.S. PrivacyShield framework to legitimize international data transfers to the U.S. followingthe Court of Justice of the European Union’s (CJEU) Schrems II decision.
© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material.PrivacyShield oritssuccessorto the EU-US DataPrivacyFramework (DPF)?However, a very limited number of legacy customers from acquired companiesmay still be covered under the Privacy Shield framework. SAP amends wherepossible any such customer agreements to update the transfer mechanism tothe EU SCCs (2021/914/EU).While SAP does not rely on the DPF as a transfer mechanism, it welcomes theadoption thereof. The DPF’s safeguardsparticularly those related tonational security and the redress mechanismapply to all personal datatransfers under the GDPR to certified U.S. companies, regardless of thespecific transfer mechanism used. These protections strengthen the overallreliability of international data transfers and complement mechanisms such asthe EU SCCs and Binding Corporate Rules (BCRs). SAP also notes that theEuropean General Court has dismissed the action for annulment of the DPF inthe case of T-553/23 (Latombe vs. Commission).11. When SAPtransfersEU, EEA orSwisspersonaldata tosub-processors locatedin thirdcountries,have theEU SCC(2021/914/EU) beenexecutedwith allrelevantdatarecipientsto ensurelawfuldatatransfers?SAP relies on the EU SCCs (2021/914/EU) as its primary legal mechanism fortransferring personal data to third countries. This approach ensurescompliance with applicable data protection laws and provides a robustframework for safeguarding personal data across borders. Further informationls regarding SAP’s international data processing practices and transfermechanisms can be found in the “International Processing” section of the SAPDPA.