SAP’s Data Protection and Privacy Principles
PUBLIC
SAP’s Data Protection and Privacy Principles
How SAP empowers secure, transparent, and lawful
data practices
Version: 1.0
Date: 2025-09-17
The information contained in this document is for general informational purposes only and is
provided on the understanding that SAP is not engaged in rendering legal advice. SAP accepts
no liability for any actions taken in response to this resource. As such, it should not be used as a
substitute for legal or professional consultation.
SAP’s Data Protection and Privacy Principles
How SAP empowers secure, transparent, and lawful
data practices
Version: 1.0
Date: 2025-09-17
The information contained in this document is for general informational purposes only and is
provided on the understanding that SAP is not engaged in rendering legal advice. SAP accepts
no liability for any actions taken in response to this resource. As such, it should not be used as a
substitute for legal or professional consultation.
At SAP, protecting personal data is a foundational responsibility. Our Data Protection and
Privacy (DPP) principles guide how we design, deliver, and operate our products and
services—ensuring that personal data is handled lawfully, securely, and with respect for the
rights and freedoms of individuals’ rights.
Data Protection and Privacy (DPP) Principles at SAP
These principles reflect SAP’s alignment with global privacy regulations such as the General Data Protection
Regulation (GDPR) (EU), California Consumer Privacy Act (CCPA) (USA), and other international frameworks.
They also support our customers in meeting their own compliance obligations across regions.
SAP’s DPP Principles
The following DPP principles are embedded across our organization and the lifecycle of our products and
services:
• Privacy by Design and by Default
SAP integrates privacy features into products and services from the outset, minimizing personal data
collection and ensuring default settings favor user privacy. In addition, SAP’s products enable
customers to comply with DPP related obligations. SAP supports mechanisms that allow individuals
to exercise their data subject rights, such as access, correction, and deletion of personal data
• Lawfulness: SAP products and services let customers configure personal data use based on their
legal basis—like consent or contract—and offer tools to document and manage compliance.
• Purpose Limitation
Personal data is collected and processed only for clearly defined, legitimate business purposes to be
defined by the customer.
• Data Minimization
SAP limits personal data processing to what is necessary for the intended purpose, reducing
exposure and risk.
• Transparency and Accountability
We aim to provide clear information about how personal data is used and processed, and we
maintain internal controls to support accountability.
• Accuracy: SAP offers mechanisms that enable customers to identify and correct inaccurate personal
data supporting data quality and compliance with privacy regulations.
• Storage Limitation: SAP solutions support configurable retention schedules, helping customers
manage personal data responsibly, keeping it only as long as necessary to meet business and
compliance needs.
• Integrity, Availability and Confidentiality
Technical and organizational measures are implemented to protect personal data against
unauthorized access, alteration, or loss.
How SAP Applies DPP Principles
SAP applies these principles through:
• Product Standards
DPP requirements are built into SAP’s Secure Software Development and Operations Lifecycle.
• Industry-Recognized Certifications
SAP’s commitment to privacy and security is validated through certifications such as ISO/IEC 27001,
Privacy (DPP) principles guide how we design, deliver, and operate our products and
services—ensuring that personal data is handled lawfully, securely, and with respect for the
rights and freedoms of individuals’ rights.
Data Protection and Privacy (DPP) Principles at SAP
These principles reflect SAP’s alignment with global privacy regulations such as the General Data Protection
Regulation (GDPR) (EU), California Consumer Privacy Act (CCPA) (USA), and other international frameworks.
They also support our customers in meeting their own compliance obligations across regions.
SAP’s DPP Principles
The following DPP principles are embedded across our organization and the lifecycle of our products and
services:
• Privacy by Design and by Default
SAP integrates privacy features into products and services from the outset, minimizing personal data
collection and ensuring default settings favor user privacy. In addition, SAP’s products enable
customers to comply with DPP related obligations. SAP supports mechanisms that allow individuals
to exercise their data subject rights, such as access, correction, and deletion of personal data
• Lawfulness: SAP products and services let customers configure personal data use based on their
legal basis—like consent or contract—and offer tools to document and manage compliance.
• Purpose Limitation
Personal data is collected and processed only for clearly defined, legitimate business purposes to be
defined by the customer.
• Data Minimization
SAP limits personal data processing to what is necessary for the intended purpose, reducing
exposure and risk.
• Transparency and Accountability
We aim to provide clear information about how personal data is used and processed, and we
maintain internal controls to support accountability.
• Accuracy: SAP offers mechanisms that enable customers to identify and correct inaccurate personal
data supporting data quality and compliance with privacy regulations.
• Storage Limitation: SAP solutions support configurable retention schedules, helping customers
manage personal data responsibly, keeping it only as long as necessary to meet business and
compliance needs.
• Integrity, Availability and Confidentiality
Technical and organizational measures are implemented to protect personal data against
unauthorized access, alteration, or loss.
How SAP Applies DPP Principles
SAP applies these principles through:
• Product Standards
DPP requirements are built into SAP’s Secure Software Development and Operations Lifecycle.
• Industry-Recognized Certifications
SAP’s commitment to privacy and security is validated through certifications such as ISO/IEC 27001,
© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material. 2 / 3
ISO/IEC 27017, the Data Protection Certification of SAP by BSI and SOC reports, demonstrating
compliance with international standards.
• Third-Party Risk Management System (TPRM)
SAP maintains a comprehensive TPRM framework to evaluate and monitor the privacy and security
posture of vendors and partners.
• Customer Agreements and Support
SAP enters into Data Processing Agreements (DPAs) with customers and provides resources to support
their compliance efforts, including FAQs and subprocessor lists.
• Global Monitoring and Adaptation
SAP continuously tracks legal developments and adapts its policies to meet evolving data protection
requirements.
Building Trust through Responsible DPP Practices
By embedding DPP principles into our technology and operations, we help customers run their businesses
with confidence, knowing their data is handled responsibly and in alignment with global standards.
Implementing privacy by design and default allows individuals to exercise their data subject rights, such as
accessing, correcting, or deleting their personal data, through user-friendly mechanisms. It also helps minimize
the collection and processing of unnecessary personal data, fostering user trust and ensuring compliance with
relevant data protection and privacy laws. Failure to comply with these requirements can lead to substantial
fines and penalties.
We have resources and documentation that outline how privacy-enhancing technologies and measures, such
as access controls, encryption, pseudonymization, and anonymization, can be implemented to safeguard
personal data from unauthorized access or disclosure. Please note that accessing this information may require
logging into the SAP system.
Please see below some examples of SAP Help Portal documentation supporting our customers in configuring
DPP functions within the given product:
SAP SuccessFactors: Data Protection and Privacy in SAP SuccessFactors | SAP Help Portal
S/4HANA Cloud Public Edition: Data Protection | SAP Help Portal
SAP Commerce Cloud: Data Protection and Privacy | SAP Help Portal
SAP Hana Service for SAP BTP: Data Protection and Privacy | SAP Help Portal
To explore SAP’s approach to data protection and compliance, visit the SAP Trust Center and www.sap.com.
© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material. 3/ 3
ISO/IEC 27017, the Data Protection Certification of SAP by BSI and SOC reports, demonstrating
compliance with international standards.
• Third-Party Risk Management System (TPRM)
SAP maintains a comprehensive TPRM framework to evaluate and monitor the privacy and security
posture of vendors and partners.
• Customer Agreements and Support
SAP enters into Data Processing Agreements (DPAs) with customers and provides resources to support
their compliance efforts, including FAQs and subprocessor lists.
• Global Monitoring and Adaptation
SAP continuously tracks legal developments and adapts its policies to meet evolving data protection
requirements.
Building Trust through Responsible DPP Practices
By embedding DPP principles into our technology and operations, we help customers run their businesses
with confidence, knowing their data is handled responsibly and in alignment with global standards.
Implementing privacy by design and default allows individuals to exercise their data subject rights, such as
accessing, correcting, or deleting their personal data, through user-friendly mechanisms. It also helps minimize
the collection and processing of unnecessary personal data, fostering user trust and ensuring compliance with
relevant data protection and privacy laws. Failure to comply with these requirements can lead to substantial
fines and penalties.
We have resources and documentation that outline how privacy-enhancing technologies and measures, such
as access controls, encryption, pseudonymization, and anonymization, can be implemented to safeguard
personal data from unauthorized access or disclosure. Please note that accessing this information may require
logging into the SAP system.
Please see below some examples of SAP Help Portal documentation supporting our customers in configuring
DPP functions within the given product:
SAP SuccessFactors: Data Protection and Privacy in SAP SuccessFactors | SAP Help Portal
S/4HANA Cloud Public Edition: Data Protection | SAP Help Portal
SAP Commerce Cloud: Data Protection and Privacy | SAP Help Portal
SAP Hana Service for SAP BTP: Data Protection and Privacy | SAP Help Portal
To explore SAP’s approach to data protection and compliance, visit the SAP Trust Center and www.sap.com.
© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material. 3/ 3