SAP Signavio EU Cloud Code of Conduct

The EU Cloud Code of Conduct report can also be found on the EU Cloud CoC public register: https://eucoc.cloud/en/public-register, Verification-ID: 2025LVL02SCOPE5430 Dökümanı indirin

Verification of Declaration of AdherenceDeclaring Company: SAP SEVerification-ID 2025LVL02SCOPE5430Date of Approval November 2025Valid until November 2026
SCOPE Europe SRLRue de la Science 371040 BRUSSELShttps://scope-europe.euinfo@scope-europe.euManaging DirectorGabriela MercuriCompany Register: 0671.468.741VAT: BE 0671.468.741ING BelgiumIBAN BE14 3631 6553 4883SWIFT / BIC: BBRUBEBB2 | 11Table of Contents1 Verification against v2.11 of the EU Cloud CoC 32 List of declared services 32.1 SAP Signavio Process Transformation Suite 33 Verification Process - Background 43.1 Approval of the Code and Accreditation of the Monitoring Body 43.2 Principles of the Verification Process 43.3 Multiple Safeguards of Compliance 43.4 Process in Detail 53.4.1 Levels of Compliance 63.4.2 Final decision on the applicable Level of Compliance 73.5 Transparency about adherence 74 Assessment of declared services by SAP (see 2.) 74.1 Fact Finding 74.2 Selection of Controls for in-depth assessment 84.3 Examined Controls and related findings by the Monitoring Body 84.3.1 Examined Controls 84.3.2 Findings by the Monitoring Body 95 Conclusion 106 Validity 11
Verification of Declaration of Adherence 3 | 111 Verification against v2.11 of the EU Cloud CoCThis Declaration of Adherence was against the European Data Protection Code of Conduct for CloudService Providers (‘EU Cloud CoC’ or ‘Code’)1 in its version 2.11 (‘v2.11)2 as of December 2020.Originally drafted by the Cloud Select Industry Group3 (‘C-SIG’) the EU Cloud CoC at that time calledC-SIG Code of Conduct on data protection for Cloud Service Providers (‘CSPs’) was developedagainst Directive 95/46/EC4 and incorporated feedback by the European Commission as well asWorking Party 29. Following an extensive revision of earlier versions of Code and further developingthe substance of the Code (v2.11) and its provisions has been aligned to the European General DataProtection Regulation (‘GDPR’)5.2 List of declared services2.1 SAP Signavio Process Transformation Suite6SAP Signavio Process Transformation Suite enables organizations to understand their existing busi-ness processes and to proactively manage and optimize those processes. SAP Signavio solutions aredesigned along the secure software development and operations lifecycle (SDOL), with core protec-tion and privacy features that support: Data handling in alignment with our SAP’s Data ProtectionManagement Systems; compliance with GDPR and other relevant data protection regulations; andISO 27018 certification for protection of personal data in public clouds.7To achieve mentioned objectives, the Signavio suite provides the following services: SAP Signavio Process Intelligence SAP Signavio Process CollaborationHub SAP Signavio Process Manager SAP Signavio Process Governance SAP Signavio Process Insights1 https://eucoc.cloud2 https://eucoc.cloud/get-the-code3 https://ec.europa.eu/digital-single-market/en/cloud-select-industry-group-code-conduct4 https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:31995L00465 https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R06796 https://help.sap.com/docs/signavio-process-transformation-suite7 NOTE: The content for the service description has been provided by the CSP and does not reflect any opinionof or assessment by the Monitoring Body. SAP Signavio Process Modeler SAP Signavio Journey Modeler SAP Signavio Process Explorer SAP Signavio Process TransformationManager
SCOPE Europe SRLRue de la Science 371040 BRUSSELShttps://scope-europe.euinfo@scope-europe.euManaging DirectorGabriela MercuriCompany Register: 0671.468.741VAT: BE 0671.468.741ING BelgiumIBAN BE14 3631 6553 4883SWIFT / BIC: BBRUBEBB4 | 113 Verification Process - BackgroundV2.11 of the EU Cloud CoC has been developed against GDPR and hence provides mechanisms asrequired by Articles 40 and 41 GDPR8.3.1 Approval of the Code and Accreditation of the Monitoring BodyThe services concerned passed the verification process by the Monitoring Body of the EU Cloud CoC,i.e., SCOPE Europe SRL9.The Code has been officially approved in May 202110. SCOPE Europe has been officially accreditedas Monitoring Body in May 202111. The robust and complex procedures and mechanisms can bereviewed by any third-party in detail at the website of the EU Cloud CoC alongside a short summarythereof.123.2 Principles of the Verification ProcessNotwithstanding the powers of and requirements set out by the supervisory authority pursuant toArticle 41 GDPR, the Monitoring Body will assess whether a Cloud Service, that has been declaredadherent to the Code, is compliant with the requirements of the Code - especially as laid down in theControls Catalogue. Unless otherwise provided by the Code, the Monitoring Body’s assessment pro-cess will be based on an evidence-based conformity assessment, based on interviews and documentreviews; proactively performed by the Monitoring Body.To the extent the Monitoring Body is not satisfied with the evidence provided by a CSP with regards tothe Cloud Service to be declared adherent to the Code, the Monitoring Body will request additionalinformation. Where the information provided by the CSP appears to be inconsistent or false, the Mon-itoring Body will - as necessary - request substantiation by independent reports.3.3 Multiple Safeguards of ComplianceCompliance of adherent services is safeguarded by the interaction of several mechanisms, i.e., con-tinuous, rigorous, and independent monitoring, an independent complaints’ handling process, and8 https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R06799 https://scope-europe.eu10 https://www.gegevensbeschermingsautoriteit.be/publications/decision-n05-2021-of-20-may-2021.pdf11 https://www.gegevensbeschermingsautoriteit.be/publications/decision-n-06-2021-of-20-may-2021.pdf12 https://eucoc.cloud/en/public-register/assessment-procedure/
Verification of Declaration of Adherence 5 | 11finally any CSP declaring services adherent is subject to substantial remedies and penalties in caseof any infringement.3.4 Process in DetailIt is expected that, prior to any assessment of the Monitoring Body, each CSP assesses its complianceinternally. When declaring its service(s) adherent to the EU Cloud CoC, each CSP must elaborate itscompliance with each of the Controls as provided by the Code considering the Control Guidance, asprovided by the Controls Catalogue, to the Monitoring Body.The CSP may do so either by referencing existing third-party audits or certifications, their respectivereports and by free text responses. Additionally, the CSP will have to provide a general overview of thefunctionalities, technical, organisational and contractual frameworks of the service(s) declared ad-herent.With regards to internationally recognised standards, the Monitoring Body will consider the mappingas provided by the Controls Catalogue. However, the Monitoring Body will verify whether (a) any third-party certification or audit provided by the CSP applies to the Cloud Service concerned, (b) such third-party certification or audit provided by the CSP is valid, (c) such third-party certification or audit hasassessed and sufficiently reported compliance with the mapped controls of the third-party certifica-tion or audit concerned. Provided that the aforementioned criteria are met, the Monitoring Body mayconsider such third-party certifications or audits as sufficient evidence for the compliance with theCode.Within Initial Assessments, the Monitoring Body selects an appropriate share of Controls that willundergo in-depth scrutiny, e.g., by sample-taking and requesting further, detailed information includ-ing potentially confidential information. Within any other Recurring Assessment, the Monitoring Bodywill select an appropriate share of Controls provided that over a due period every Control will be sub-ject to scrutiny by the Monitoring Body. Where applicable, aspects of current attention at the time ofassessment shall be covered too, e.g., where such aspects were indicated in media reports, publica-tions or actions of supervisory authorities.If the responses of the CSP satisfy the Monitoring Body, especially if responses are consistent and ofappropriate quality and level of detail, reflecting the requirements of the Controls and indicating ap-propriate implementation by the Control Guidance, then, the Monitoring Body verifies the service(s)declared adhered as compliant and thereupon, makes them subject to continuous monitoring.