SAP’s Response to Third Party Requests to Access Customer Data Stored in SAP’s Cloud Services

Overview of SAP’s approach to handling third-party legal requests for access to customer data stored in SAP Cloud Services, including legal safeguards, customer notification procedures, and compliance principles. Ladda ner dokumentet

PUBLICSAP’s Response to Third Party Requests toaccess Customer Data stored in SAP CloudServicesSAP Legal and Procedural ApproachNovember 7, 2025The information contained in this document is for general informational purposes only and isprovided on the understanding that SAP is not engaged in rendering legal advice. SAP acceptsno liability for any actions taken in response to this resource. As such, it should not be used as asubstitute for legal or professional consultation.
This document addresses common questions about how SAP handles third-party accessrequests to customer data stored in SAP Cloud Services. As a business-to-business enterpriseapplication provider, SAP receives few direct requests from third parties such as governmentagencies or similar entities (“Requesting Party”) requiring SAP to produce or discloseinformation that contains or includes any customer data stored in SAP cloud services(“Request”).How SAP Handles RequestsGenerally, customers can directly access their data stored in SAP cloud services. SAP is therefore of the opinionthat customers are best placed to identify and access their own data in response to a Request. However, if SAPreceives a Request directly from a Requesting Party, SAP will handle such Request as follows: All SAP employees who may receive Requests are required to promptly forward such Requests to theirappropriate legal contact. SAP has a global and regional legal team responsible for evaluating suchRequests on a case-by-case basis to determine whether such Requests are valid under applicable law. If SAP receives a Request from a Requesting Party, the Requesting Party must follow applicable legalprocess. SAP will review all such Requests under applicable laws before taking any action. To the extent permitted under applicable law, SAP will redirect the Request and advise the RequestingParty that all customer data stored in any SAP customer cloud system belongs to the customer, not to SAP,and that such data is confidential. SAP cannot and will not produce or disclose such information withoutfirst fulfilling its contractual obligation to notify the customer, allowing the customer to consent, object, orseek a protective order. If the Requesting Party prohibits SAP from providing such notice to the customer, then SAP will seek tochallenge the Request if it is invalid or unlawful under applicable laws. If a competent court issues a ruling compelling SAP to comply with a Request without prior notice to thecustomer, SAP will challenge the ruling where legally permissible and where SAP has a good faith basisunder applicable law to do so. If no such recourse exists, or if SAP’s attempt to challenge the ruling on appeal is not successful, SAP willmake all reasonable efforts to narrow the scope of the Request to the extent permitted under applicablelaws before complying with it.To explore SAP’s approach to data protection and compliance, visit the SAP Trust Center and www.sap.com.© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material. 2/2