Data processing agreements at SAP

Learn how SAP handles personal data on behalf of customers Dökümanı indirin

PUBLICData Processing Agreements at SAPOverview and Frequently Asked QuestionsVersion: 2.0Date: July 31, 2025The information contained in this document is for general informational purposes only and is provided on theunderstanding that SAP is not engaged in rendering legal advice. SAP accepts no liability for any actions takenin response to this resource. As such, it should not be used as a substitute for legal or professional consultation.
© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material.2A data processing agreement is a contract between a data controller (i.e. SAP’sCustomers) and a data processor (i.e. SAP) that describes their respective rights andobligations regarding the processing of Personal Data (DPA). Under the European UnionGeneral Data Protection Regulation (“GDPR”), this refers to the commissionedprocessing of Personal Data by the processor on behalf of the controller and inaccordance with the controller’s instructions.Customer Data Processing Agreements at SAPWhere applicable legislation requires a DPA, it is a legally binding requirement on both SAP and itscustomers to have a DPA in place. This can apply both to SAP and its Customers as well as other parties,for example Customer Affiliates, that are able to use the service provided by SAP. Without a DPA, theprocessing activities may violate applicable laws, which might result in damage claims, prohibition orders,fines and other adverse consequences against the data controller (Customer) and data processor (SAP).The DPA would typically set forth instructions as to how Personal Data is to be processed, including, adescription of the data processing activities (affected categories of Personal Data and data subjects,processing operations and duration of the processing), the technical and organizational measures thedata processor must apply to protect the Personal Data and the data controllers’ audit rights. Exceptwhere region-specific offerings such as SAP EU Access are involved, SAP utilizes subprocessors acrossthe globe, often necessitating the international access to or transfer of personal data, an area of significantregulation. A DPA thus helps provide transparency and understanding as to how Personal Data isprocessed and applies contractual safeguards to protect this information in case of international datatransfers.The SAP Data Processing Agreement for SAP Services (the “SAP DPA”) describes how SAP processesPersonal Data from (end) Customers when delivering SAP Cloud Services, SAP Support and ProfessionalServices (“SAP Services”) (See also: Cloud Services Documents | SAP Trust Center). The purpose of theSAP DPA is to assist with transparency and understanding of individual roles between SAP and itsCustomers, to provide contractual protections for Personal Data and to help both SAP and the Customercomply with data protection and privacy laws worldwide. This helps to set clear expectations regardingthe handling of Personal Data for both SAP and its (end) Customers. For this reason, the DPA is part ofevery transaction SAP enters into with Customers and is an integral part of the overall SAP Agreement(SAP Agreements website). SAP periodically reviews its DPAs to address ongoing compliance withapplicable legal and regulatory requirements.