SAP’s Data Protection and Privacy Principles

In today’s data-driven world, service providers play a critical role in safeguarding personal information. This article explores how the principles of Privacy by Design and Privacy by Default—as mandated by frameworks like the GDPR—can be effectively implemented across services and systems. Dökümanı indirin

PUBLICSAP’s Data Protection and Privacy PrinciplesHow SAP empowers secure, transparent, and lawfuldata practicesVersion: 1.0Date: 2025-09-17The information contained in this document is for general informational purposes only and isprovided on the understanding that SAP is not engaged in rendering legal advice. SAP acceptsno liability for any actions taken in response to this resource. As such, it should not be used as asubstitute for legal or professional consultation.
At SAP, protecting personal data is a foundational responsibility. Our Data Protection andPrivacy (DPP) principles guide how we design, deliver, and operate our products andservicesensuring that personal data is handled lawfully, securely, and with respect for therights and freedoms of individuals rights.Data Protection and Privacy (DPP) Principles at SAPThese principles reflect SAP’s alignment with global privacy regulations such as the General Data ProtectionRegulation (GDPR) (EU), California Consumer Privacy Act (CCPA) (USA), and other international frameworks.They also support our customers in meeting their own compliance obligations across regions.SAP’s DPP PrinciplesThe following DPP principles are embedded across our organization and the lifecycle of our products andservices: Privacy by Design and by DefaultSAP integrates privacy features into products and services from the outset, minimizing personal datacollection and ensuring default settings favor user privacy. In addition, SAPs products enablecustomers to comply with DPP related obligations. SAP supports mechanisms that allow individualsto exercise their data subject rights, such as access, correction, and deletion of personal data Lawfulness: SAP products and services let customers configure personal data use based on theirlegal basislike consent or contractand offer tools to document and manage compliance. Purpose LimitationPersonal data is collected and processed only for clearly defined, legitimate business purposes to bedefined by the customer. Data MinimizationSAP limits personal data processing to what is necessary for the intended purpose, reducingexposure and risk. Transparency and AccountabilityWe aim to provide clear information about how personal data is used and processed, and wemaintain internal controls to support accountability. Accuracy: SAP offers mechanisms that enable customers to identify and correct inaccurate personaldata supporting data quality and compliance with privacy regulations. Storage Limitation: SAP solutions support configurable retention schedules, helping customersmanage personal data responsibly, keeping it only as long as necessary to meet business andcompliance needs. Integrity, Availability and ConfidentialityTechnical and organizational measures are implemented to protect personal data againstunauthorized access, alteration, or loss.How SAP Applies DPP PrinciplesSAP applies these principles through: Product StandardsDPP requirements are built into SAP’s Secure Software Development and Operations Lifecycle. Industry-Recognized CertificationsSAP’s commitment to privacy and security is validated through certifications such as ISO/IEC 27001,
© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material. 2 / 3ISO/IEC 27017, the Data Protection Certification of SAP by BSI and SOC reports, demonstratingcompliance with international standards. Third-Party Risk Management System (TPRM)SAP maintains a comprehensive TPRM framework to evaluate and monitor the privacy and securityposture of vendors and partners. Customer Agreements and SupportSAP enters into Data Processing Agreements (DPAs) with customers and provides resources to supporttheir compliance efforts, including FAQs and subprocessor lists. Global Monitoring and AdaptationSAP continuously tracks legal developments and adapts its policies to meet evolving data protectionrequirements.Building Trust through Responsible DPP PracticesBy embedding DPP principles into our technology and operations, we help customers run their businesseswith confidence, knowing their data is handled responsibly and in alignment with global standards.Implementing privacy by design and default allows individuals to exercise their data subject rights, such asaccessing, correcting, or deleting their personal data, through user-friendly mechanisms. It also helps minimizethe collection and processing of unnecessary personal data, fostering user trust and ensuring compliance withrelevant data protection and privacy laws. Failure to comply with these requirements can lead to substantialfines and penalties.We have resources and documentation that outline how privacy-enhancing technologies and measures, suchas access controls, encryption, pseudonymization, and anonymization, can be implemented to safeguardpersonal data from unauthorized access or disclosure. Please note that accessing this information may requirelogging into the SAP system.Please see below some examples of SAP Help Portal documentation supporting our customers in configuringDPP functions within the given product:SAP SuccessFactors: Data Protection and Privacy in SAP SuccessFactors | SAP Help PortalS/4HANA Cloud Public Edition: Data Protection | SAP Help PortalSAP Commerce Cloud: Data Protection and Privacy | SAP Help PortalSAP Hana Service for SAP BTP: Data Protection and Privacy | SAP Help PortalTo explore SAP’s approach to data protection and compliance, visit the SAP Trust Center and www.sap.com.© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material. 3/ 3