Data processing agreements at SAP
PUBLIC
Data Processing Agreements at SAP
Overview and Frequently Asked Questions
Version: 2.0
Date: July 31, 2025
The information contained in this document is for general informational purposes only and is provided on the
understanding that SAP is not engaged in rendering legal advice. SAP accepts no liability for any actions taken
in response to this resource. As such, it should not be used as a substitute for legal or professional consultation.
Data Processing Agreements at SAP
Overview and Frequently Asked Questions
Version: 2.0
Date: July 31, 2025
The information contained in this document is for general informational purposes only and is provided on the
understanding that SAP is not engaged in rendering legal advice. SAP accepts no liability for any actions taken
in response to this resource. As such, it should not be used as a substitute for legal or professional consultation.
© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material.
2
A data processing agreement is a contract between a data controller (i.e. SAP’s
Customers) and a data processor (i.e. SAP) that describes their respective rights and
obligations regarding the processing of Personal Data (DPA). Under the European Union
General Data Protection Regulation (“GDPR”), this refers to the commissioned
processing of Personal Data by the processor on behalf of the controller and in
accordance with the controller’s instructions.
Customer Data Processing Agreements at SAP
Where applicable legislation requires a DPA, it is a legally binding requirement on both SAP and its
customers to have a DPA in place. This can apply both to SAP and its Customers as well as other parties,
for example Customer Affiliates, that are able to use the service provided by SAP. Without a DPA, the
processing activities may violate applicable laws, which might result in damage claims, prohibition orders,
fines and other adverse consequences against the data controller (Customer) and data processor (SAP).
The DPA would typically set forth instructions as to how Personal Data is to be processed, including, a
description of the data processing activities (affected categories of Personal Data and data subjects,
processing operations and duration of the processing), the technical and organizational measures the
data processor must apply to protect the Personal Data and the data controllers’ audit rights. Except
where region-specific offerings such as SAP EU Access are involved, SAP utilizes subprocessors across
the globe, often necessitating the international access to or transfer of personal data, an area of significant
regulation. A DPA thus helps provide transparency and understanding as to how Personal Data is
processed and applies contractual safeguards to protect this information in case of international data
transfers.
The SAP Data Processing Agreement for SAP Services (the “SAP DPA”) describes how SAP processes
Personal Data from (end) Customers when delivering SAP Cloud Services, SAP Support and Professional
Services (“SAP Services”) (See also: Cloud Services Documents | SAP Trust Center). The purpose of the
SAP DPA is to assist with transparency and understanding of individual roles between SAP and its
Customers, to provide contractual protections for Personal Data and to help both SAP and the Customer
comply with data protection and privacy laws worldwide. This helps to set clear expectations regarding
the handling of Personal Data for both SAP and its (end) Customers. For this reason, the DPA is part of
every transaction SAP enters into with Customers and is an integral part of the overall SAP Agreement
(SAP Agreements website). SAP periodically reviews its DPAs to address ongoing compliance with
applicable legal and regulatory requirements.
2
A data processing agreement is a contract between a data controller (i.e. SAP’s
Customers) and a data processor (i.e. SAP) that describes their respective rights and
obligations regarding the processing of Personal Data (DPA). Under the European Union
General Data Protection Regulation (“GDPR”), this refers to the commissioned
processing of Personal Data by the processor on behalf of the controller and in
accordance with the controller’s instructions.
Customer Data Processing Agreements at SAP
Where applicable legislation requires a DPA, it is a legally binding requirement on both SAP and its
customers to have a DPA in place. This can apply both to SAP and its Customers as well as other parties,
for example Customer Affiliates, that are able to use the service provided by SAP. Without a DPA, the
processing activities may violate applicable laws, which might result in damage claims, prohibition orders,
fines and other adverse consequences against the data controller (Customer) and data processor (SAP).
The DPA would typically set forth instructions as to how Personal Data is to be processed, including, a
description of the data processing activities (affected categories of Personal Data and data subjects,
processing operations and duration of the processing), the technical and organizational measures the
data processor must apply to protect the Personal Data and the data controllers’ audit rights. Except
where region-specific offerings such as SAP EU Access are involved, SAP utilizes subprocessors across
the globe, often necessitating the international access to or transfer of personal data, an area of significant
regulation. A DPA thus helps provide transparency and understanding as to how Personal Data is
processed and applies contractual safeguards to protect this information in case of international data
transfers.
The SAP Data Processing Agreement for SAP Services (the “SAP DPA”) describes how SAP processes
Personal Data from (end) Customers when delivering SAP Cloud Services, SAP Support and Professional
Services (“SAP Services”) (See also: Cloud Services Documents | SAP Trust Center). The purpose of the
SAP DPA is to assist with transparency and understanding of individual roles between SAP and its
Customers, to provide contractual protections for Personal Data and to help both SAP and the Customer
comply with data protection and privacy laws worldwide. This helps to set clear expectations regarding
the handling of Personal Data for both SAP and its (end) Customers. For this reason, the DPA is part of
every transaction SAP enters into with Customers and is an integral part of the overall SAP Agreement
(SAP Agreements website). SAP periodically reviews its DPAs to address ongoing compliance with
applicable legal and regulatory requirements.