Data Privacy and Transfer Impact Assessment
PUBLIC
Data Protection and Transfer Impact
Assessments
Customer Frequently Asked Questions
The information contained in this document is for general informational purposes only and is
provided on the understanding that SAP is not engaged in rendering legal advice. SAP accepts
no liability for any actions taken in response to this resource. As such, it should not be used as a
substitute for legal or professional consultation.
Data Protection and Transfer Impact
Assessments
Customer Frequently Asked Questions
The information contained in this document is for general informational purposes only and is
provided on the understanding that SAP is not engaged in rendering legal advice. SAP accepts
no liability for any actions taken in response to this resource. As such, it should not be used as a
substitute for legal or professional consultation.
© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material.
As a leading provider of enterprise application software, SAP remains committed to
upholding data protection and privacy standards across all regions in which it operates.
SAP continues to rely on recognized international transfer mechanisms, such as EU
Standard Contractual Clauses, to support lawful and secure cross-border data flows.
Questions Answers
Personal Data and Description of Processing
1. What
categories
of
personal
data does
SAP
process?
The personal data SAP processes depend on the Cloud Services, SAP Support
or SAP Services a customer subscribes to, what personal data the customer
uploads or processes therein and how the customer configures the relevant
data fields. Every contract for SAP Cloud Services, SAP Support, and SAP
Services includes a personal data processing agreement. The current DPA is
available here: https://www.sap.com/about/trust-center/agreements.html.
The SAP Data Processing Agreement for SAP Cloud Services, SAP Support and
SAP Services (“SAP DPA”) includes a description of data subjects and data
categories in Schedule 1 “Description of processing”. This description reflects
the most common examples of the intended use of SAP’s services.
2. Does SAP
process
any
sensitive
or special
categories
of
personal
data?
Please refer to the response provided in Question 1 above and see Schedule
1 “Description of processing” of the SAP DPA. Sensitive or special categories
of personal data should only be uploaded to the SAP Cloud Services, SAP
Support and SAP Services (“SAP Services”) if explicitly agreed upon in writing
by both parties as part of the contractual agreement.
3. For what
purpose
will SAP
transfer a
customer’
s personal
data to
third
countries?
The specific purposes for which SAP processes and transfers personal data to
third countries are outlined in Schedule 1 “Description of Processing” of the
SAP DPA.
4. Does SAP
process
personal
data as a
controller
According to the SAP DPA, SAP and its sub-processors operate as (sub-
)processors. The customer, along with any entities authorized by the customer
to use SAP Services act as controllers or processors, depending on their role
in determining the purposes and means of processing personal data.
As a leading provider of enterprise application software, SAP remains committed to
upholding data protection and privacy standards across all regions in which it operates.
SAP continues to rely on recognized international transfer mechanisms, such as EU
Standard Contractual Clauses, to support lawful and secure cross-border data flows.
Questions Answers
Personal Data and Description of Processing
1. What
categories
of
personal
data does
SAP
process?
The personal data SAP processes depend on the Cloud Services, SAP Support
or SAP Services a customer subscribes to, what personal data the customer
uploads or processes therein and how the customer configures the relevant
data fields. Every contract for SAP Cloud Services, SAP Support, and SAP
Services includes a personal data processing agreement. The current DPA is
available here: https://www.sap.com/about/trust-center/agreements.html.
The SAP Data Processing Agreement for SAP Cloud Services, SAP Support and
SAP Services (“SAP DPA”) includes a description of data subjects and data
categories in Schedule 1 “Description of processing”. This description reflects
the most common examples of the intended use of SAP’s services.
2. Does SAP
process
any
sensitive
or special
categories
of
personal
data?
Please refer to the response provided in Question 1 above and see Schedule
1 “Description of processing” of the SAP DPA. Sensitive or special categories
of personal data should only be uploaded to the SAP Cloud Services, SAP
Support and SAP Services (“SAP Services”) if explicitly agreed upon in writing
by both parties as part of the contractual agreement.
3. For what
purpose
will SAP
transfer a
customer’
s personal
data to
third
countries?
The specific purposes for which SAP processes and transfers personal data to
third countries are outlined in Schedule 1 “Description of Processing” of the
SAP DPA.
4. Does SAP
process
personal
data as a
controller
According to the SAP DPA, SAP and its sub-processors operate as (sub-
)processors. The customer, along with any entities authorized by the customer
to use SAP Services act as controllers or processors, depending on their role
in determining the purposes and means of processing personal data.
© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material.
or as a
processor
?
5. Please
identify
the data
importer
associate
d with this
transfer.
SAP may engage with various sub-processors (as defined in the SAP DPA) to
provide SAP Services. These sub-processors may act as data importers in the
context of international transfers. A current list of SAP’s sub-processors is
available on the SAP Trust Center.
International Personal Data Transfers
6. Does the
solution
lead to
any
transfer of
personal
data
internatio
nally, e.g..
outside
the
European
Union
(EU)/Euro
pean
Economic
Area
(EEA)?
Depending on the configuration and SAP Services in scope, personal data may
be transferred to countries internationally, including outside the EU or EEA.
These transfers typically support operational needs such as service delivery,
system maintenance, and customer support. SAP ensures that all international
data transfers are conducted in compliance with applicable data protection
laws, using recognized safeguards like EU standard contractual clauses or
other approved mechanisms. Furter, SAP makes available the following
resources to supports its customers:
• As a global provider, SAP utilizes international resources to deliver its
services. To ensure transparency and responsible data handling, SAP
maintains Sub-processor lists for each service—outlining the roles and
geographic locations of involved entities. These lists are available to
customers via the SAP Trust Center:
https://support.sap.com/bin/fiji/es/login.support.html?RelayState=/c
ontent/support/en_us/my-support/trust-center/subprocessors.
• SAP also provides data transfer fact sheets for certain services that can
include additional details, which SAP customers can access via the SAP
support portal:
https://support.sap.com/bin/fiji/es/login.support.html?RelayState=/c
ontent/support/en_us/my-support/trust-center/subprocessors.
Customers seeking further details are encouraged to review these resources
or reach out to their SAP account representative.
7. How has
SAP
addresse
d
concerns
related to
the
SAP acknowledges the concerns raised by customers following the Court of
Justice of the European Union (CJEU) ruling in Schrems II. Importantly, the
decision did not invalidate the use of Standard Contractual Clauses (SCCs) as
a lawful mechanism for international personal data transfers.
SAP supports compliance with Shrems II data protection requirements by
ensuring that the SAP DPA is included in every customer contract involving the
or as a
processor
?
5. Please
identify
the data
importer
associate
d with this
transfer.
SAP may engage with various sub-processors (as defined in the SAP DPA) to
provide SAP Services. These sub-processors may act as data importers in the
context of international transfers. A current list of SAP’s sub-processors is
available on the SAP Trust Center.
International Personal Data Transfers
6. Does the
solution
lead to
any
transfer of
personal
data
internatio
nally, e.g..
outside
the
European
Union
(EU)/Euro
pean
Economic
Area
(EEA)?
Depending on the configuration and SAP Services in scope, personal data may
be transferred to countries internationally, including outside the EU or EEA.
These transfers typically support operational needs such as service delivery,
system maintenance, and customer support. SAP ensures that all international
data transfers are conducted in compliance with applicable data protection
laws, using recognized safeguards like EU standard contractual clauses or
other approved mechanisms. Furter, SAP makes available the following
resources to supports its customers:
• As a global provider, SAP utilizes international resources to deliver its
services. To ensure transparency and responsible data handling, SAP
maintains Sub-processor lists for each service—outlining the roles and
geographic locations of involved entities. These lists are available to
customers via the SAP Trust Center:
https://support.sap.com/bin/fiji/es/login.support.html?RelayState=/c
ontent/support/en_us/my-support/trust-center/subprocessors.
• SAP also provides data transfer fact sheets for certain services that can
include additional details, which SAP customers can access via the SAP
support portal:
https://support.sap.com/bin/fiji/es/login.support.html?RelayState=/c
ontent/support/en_us/my-support/trust-center/subprocessors.
Customers seeking further details are encouraged to review these resources
or reach out to their SAP account representative.
7. How has
SAP
addresse
d
concerns
related to
the
SAP acknowledges the concerns raised by customers following the Court of
Justice of the European Union (CJEU) ruling in Schrems II. Importantly, the
decision did not invalidate the use of Standard Contractual Clauses (SCCs) as
a lawful mechanism for international personal data transfers.
SAP supports compliance with Shrems II data protection requirements by
ensuring that the SAP DPA is included in every customer contract involving the
© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material.
Schrems II
decision
regarding
internatio
nal
personal
data
transfers?
processing of personal data. The SAP DPA incorporates the EU SCCs
(2021/914/EU).
8. Can
personal
data be
processe
d (i.e.
hosting,
access
and
support)
exclusivel
y within
the
EU/EEA
(“EU
Access”)?
SAP offers optional EU Access features for select Cloud Services, designed to
ensure that personal data is hosted and accessed solely within the European
Economic Area (EEA) and Switzerland. Under this configuration:
• Data centers used for the hosting of production environments are
located within the EEA and Switzerland
• Sub-processors operate exclusively from within these regions
• No personal data is transferred outside the EEA or Switzerland unless
explicitly authorized by the customer or included in support-related
communications
SAP can also explore additional safeguards tailored to specific services, such
as cloud-native key management solutions. Customers interested in EU
Access or related protections are encouraged to contact their SAP account
representative for further details.
9. Can
personal
data be
processe
d (i.e.
hosting,
access
and
support)
exclusivel
y within
the United
States?
For select services, personal data can be processed exclusively within the
United States. SAP offers secure service options through SAP National Security
Services (“SAP NS2), which may act as a sub-processor under specific
circumstances. These services are designed to meet certain U.S. regulatory
and data residency requirements, e.g., for U.S. federal and state government
entities or U.S. regulated industry customers. When applicable, SAP NS2
ensures that data hosting, access, and support are confined to U.S. locations
and personnel. Customers interested in U.S.-based data processing should
consult their SAP account representative to determine whether SAP NS2
services are available and suitable for their specific needs.
10. Does SAP
transfer
personal
data
under the
EU-US
SAP’s contractual framework continues to rely on the EU SCCs (2021/914/EU)
as a robust and reliable legal mechanism for personal data transfers to third
countries, including the United States.
As a general principle, SAP did not adopt the now-invalidated EU-U.S. Privacy
Shield framework to legitimize international data transfers to the U.S. following
the Court of Justice of the European Union’s (CJEU) Schrems II decision.
Schrems II
decision
regarding
internatio
nal
personal
data
transfers?
processing of personal data. The SAP DPA incorporates the EU SCCs
(2021/914/EU).
8. Can
personal
data be
processe
d (i.e.
hosting,
access
and
support)
exclusivel
y within
the
EU/EEA
(“EU
Access”)?
SAP offers optional EU Access features for select Cloud Services, designed to
ensure that personal data is hosted and accessed solely within the European
Economic Area (EEA) and Switzerland. Under this configuration:
• Data centers used for the hosting of production environments are
located within the EEA and Switzerland
• Sub-processors operate exclusively from within these regions
• No personal data is transferred outside the EEA or Switzerland unless
explicitly authorized by the customer or included in support-related
communications
SAP can also explore additional safeguards tailored to specific services, such
as cloud-native key management solutions. Customers interested in EU
Access or related protections are encouraged to contact their SAP account
representative for further details.
9. Can
personal
data be
processe
d (i.e.
hosting,
access
and
support)
exclusivel
y within
the United
States?
For select services, personal data can be processed exclusively within the
United States. SAP offers secure service options through SAP National Security
Services (“SAP NS2), which may act as a sub-processor under specific
circumstances. These services are designed to meet certain U.S. regulatory
and data residency requirements, e.g., for U.S. federal and state government
entities or U.S. regulated industry customers. When applicable, SAP NS2
ensures that data hosting, access, and support are confined to U.S. locations
and personnel. Customers interested in U.S.-based data processing should
consult their SAP account representative to determine whether SAP NS2
services are available and suitable for their specific needs.
10. Does SAP
transfer
personal
data
under the
EU-US
SAP’s contractual framework continues to rely on the EU SCCs (2021/914/EU)
as a robust and reliable legal mechanism for personal data transfers to third
countries, including the United States.
As a general principle, SAP did not adopt the now-invalidated EU-U.S. Privacy
Shield framework to legitimize international data transfers to the U.S. following
the Court of Justice of the European Union’s (CJEU) Schrems II decision.
© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material.
Privacy
Shield or
its
successor
to the EU-
US Data
Privacy
Framewor
k (DPF)?
However, a very limited number of legacy customers from acquired companies
may still be covered under the Privacy Shield framework. SAP amends where
possible any such customer agreements to update the transfer mechanism to
the EU SCCs (2021/914/EU).
While SAP does not rely on the DPF as a transfer mechanism, it welcomes the
adoption thereof. The DPF’s safeguards—particularly those related to
national security and the redress mechanism—apply to all personal data
transfers under the GDPR to certified U.S. companies, regardless of the
specific transfer mechanism used. These protections strengthen the overall
reliability of international data transfers and complement mechanisms such as
the EU SCCs and Binding Corporate Rules (BCRs). SAP also notes that the
European General Court has dismissed the action for annulment of the DPF in
the case of T-553/23 (Latombe vs. Commission).
11. When SAP
transfers
EU, EEA or
Swiss
personal
data to
sub-
processor
s located
in third
countries,
have the
EU SCC
(2021/914
/EU) been
executed
with all
relevant
data
recipients
to ensure
lawful
data
transfers?
SAP relies on the EU SCCs (2021/914/EU) as its primary legal mechanism for
transferring personal data to third countries. This approach ensures
compliance with applicable data protection laws and provides a robust
framework for safeguarding personal data across borders. Further information
ls regarding SAP’s international data processing practices and transfer
mechanisms can be found in the “International Processing” section of the SAP
DPA.
Privacy
Shield or
its
successor
to the EU-
US Data
Privacy
Framewor
k (DPF)?
However, a very limited number of legacy customers from acquired companies
may still be covered under the Privacy Shield framework. SAP amends where
possible any such customer agreements to update the transfer mechanism to
the EU SCCs (2021/914/EU).
While SAP does not rely on the DPF as a transfer mechanism, it welcomes the
adoption thereof. The DPF’s safeguards—particularly those related to
national security and the redress mechanism—apply to all personal data
transfers under the GDPR to certified U.S. companies, regardless of the
specific transfer mechanism used. These protections strengthen the overall
reliability of international data transfers and complement mechanisms such as
the EU SCCs and Binding Corporate Rules (BCRs). SAP also notes that the
European General Court has dismissed the action for annulment of the DPF in
the case of T-553/23 (Latombe vs. Commission).
11. When SAP
transfers
EU, EEA or
Swiss
personal
data to
sub-
processor
s located
in third
countries,
have the
EU SCC
(2021/914
/EU) been
executed
with all
relevant
data
recipients
to ensure
lawful
data
transfers?
SAP relies on the EU SCCs (2021/914/EU) as its primary legal mechanism for
transferring personal data to third countries. This approach ensures
compliance with applicable data protection laws and provides a robust
framework for safeguarding personal data across borders. Further information
ls regarding SAP’s international data processing practices and transfer
mechanisms can be found in the “International Processing” section of the SAP
DPA.