SAP Signavio EU Cloud Code of Conduct
The EU Cloud Code of Conduct report can also be found on the EU Cloud CoC public register: https://eucoc.cloud/en/public-register, Verification-ID: 2025LVL02SCOPE5430 Dökümanı indirin
Verification of Declaration of Adherence
Declaring Company: SAP SE
Verification-ID 2025LVL02SCOPE5430
Date of Approval November 2025
Valid until November 2026
Declaring Company: SAP SE
Verification-ID 2025LVL02SCOPE5430
Date of Approval November 2025
Valid until November 2026
SCOPE Europe SRL
Rue de la Science 37
1040 BRUSSELS
https://scope-europe.eu
info@scope-europe.eu
Managing Director
Gabriela Mercuri
Company Register: 0671.468.741
VAT: BE 0671.468.741
ING Belgium
IBAN BE14 3631 6553 4883
SWIFT / BIC: BBRUBEBB
2 | 11
Table of Contents
1 Verification against v2.11 of the EU Cloud CoC 3
2 List of declared services 3
2.1 SAP Signavio Process Transformation Suite 3
3 Verification Process - Background 4
3.1 Approval of the Code and Accreditation of the Monitoring Body 4
3.2 Principles of the Verification Process 4
3.3 Multiple Safeguards of Compliance 4
3.4 Process in Detail 5
3.4.1 Levels of Compliance 6
3.4.2 Final decision on the applicable Level of Compliance 7
3.5 Transparency about adherence 7
4 Assessment of declared services by SAP (see 2.) 7
4.1 Fact Finding 7
4.2 Selection of Controls for in-depth assessment 8
4.3 Examined Controls and related findings by the Monitoring Body 8
4.3.1 Examined Controls 8
4.3.2 Findings by the Monitoring Body 9
5 Conclusion 10
6 Validity 11
Rue de la Science 37
1040 BRUSSELS
https://scope-europe.eu
info@scope-europe.eu
Managing Director
Gabriela Mercuri
Company Register: 0671.468.741
VAT: BE 0671.468.741
ING Belgium
IBAN BE14 3631 6553 4883
SWIFT / BIC: BBRUBEBB
2 | 11
Table of Contents
1 Verification against v2.11 of the EU Cloud CoC 3
2 List of declared services 3
2.1 SAP Signavio Process Transformation Suite 3
3 Verification Process - Background 4
3.1 Approval of the Code and Accreditation of the Monitoring Body 4
3.2 Principles of the Verification Process 4
3.3 Multiple Safeguards of Compliance 4
3.4 Process in Detail 5
3.4.1 Levels of Compliance 6
3.4.2 Final decision on the applicable Level of Compliance 7
3.5 Transparency about adherence 7
4 Assessment of declared services by SAP (see 2.) 7
4.1 Fact Finding 7
4.2 Selection of Controls for in-depth assessment 8
4.3 Examined Controls and related findings by the Monitoring Body 8
4.3.1 Examined Controls 8
4.3.2 Findings by the Monitoring Body 9
5 Conclusion 10
6 Validity 11
Verification of Declaration of Adherence 3 | 11
1 Verification against v2.11 of the EU Cloud CoC
This Declaration of Adherence was against the European Data Protection Code of Conduct for Cloud
Service Providers (‘EU Cloud CoC’ or ‘Code’)1 in its version 2.11 (‘v2.11’)2 as of December 2020.
Originally drafted by the Cloud Select Industry Group3 (‘C-SIG’) the EU Cloud CoC – at that time called
C-SIG Code of Conduct on data protection for Cloud Service Providers (‘CSPs’) – was developed
against Directive 95/46/EC4 and incorporated feedback by the European Commission as well as
Working Party 29. Following an extensive revision of earlier versions of Code and further developing
the substance of the Code (v2.11) and its provisions has been aligned to the European General Data
Protection Regulation (‘GDPR’)5.
2 List of declared services
2.1 SAP Signavio Process Transformation Suite6
SAP Signavio Process Transformation Suite enables organizations to understand their existing busi-
ness processes and to proactively manage and optimize those processes. SAP Signavio solutions are
designed along the secure software development and operations lifecycle (SDOL), with core protec-
tion and privacy features that support: Data handling in alignment with our SAP’s Data Protection
Management Systems; compliance with GDPR and other relevant data protection regulations; and
ISO 27018 certification for protection of personal data in public clouds.7
To achieve mentioned objectives, the Signavio suite provides the following services:
◼ SAP Signavio Process Intelligence
◼ SAP Signavio Process Collaboration
Hub
◼ SAP Signavio Process Manager
◼ SAP Signavio Process Governance
◼ SAP Signavio Process Insights
1 https://eucoc.cloud
2 https://eucoc.cloud/get-the-code
3 https://ec.europa.eu/digital-single-market/en/cloud-select-industry-group-code-conduct
4 https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:31995L0046
5 https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679
6 https://help.sap.com/docs/signavio-process-transformation-suite
7 NOTE: The content for the service description has been provided by the CSP and does not reflect any opinion
of or assessment by the Monitoring Body.
◼ SAP Signavio Process Modeler
◼ SAP Signavio Journey Modeler
◼ SAP Signavio Process Explorer
◼ SAP Signavio Process Transformation
Manager
1 Verification against v2.11 of the EU Cloud CoC
This Declaration of Adherence was against the European Data Protection Code of Conduct for Cloud
Service Providers (‘EU Cloud CoC’ or ‘Code’)1 in its version 2.11 (‘v2.11’)2 as of December 2020.
Originally drafted by the Cloud Select Industry Group3 (‘C-SIG’) the EU Cloud CoC – at that time called
C-SIG Code of Conduct on data protection for Cloud Service Providers (‘CSPs’) – was developed
against Directive 95/46/EC4 and incorporated feedback by the European Commission as well as
Working Party 29. Following an extensive revision of earlier versions of Code and further developing
the substance of the Code (v2.11) and its provisions has been aligned to the European General Data
Protection Regulation (‘GDPR’)5.
2 List of declared services
2.1 SAP Signavio Process Transformation Suite6
SAP Signavio Process Transformation Suite enables organizations to understand their existing busi-
ness processes and to proactively manage and optimize those processes. SAP Signavio solutions are
designed along the secure software development and operations lifecycle (SDOL), with core protec-
tion and privacy features that support: Data handling in alignment with our SAP’s Data Protection
Management Systems; compliance with GDPR and other relevant data protection regulations; and
ISO 27018 certification for protection of personal data in public clouds.7
To achieve mentioned objectives, the Signavio suite provides the following services:
◼ SAP Signavio Process Intelligence
◼ SAP Signavio Process Collaboration
Hub
◼ SAP Signavio Process Manager
◼ SAP Signavio Process Governance
◼ SAP Signavio Process Insights
1 https://eucoc.cloud
2 https://eucoc.cloud/get-the-code
3 https://ec.europa.eu/digital-single-market/en/cloud-select-industry-group-code-conduct
4 https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:31995L0046
5 https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679
6 https://help.sap.com/docs/signavio-process-transformation-suite
7 NOTE: The content for the service description has been provided by the CSP and does not reflect any opinion
of or assessment by the Monitoring Body.
◼ SAP Signavio Process Modeler
◼ SAP Signavio Journey Modeler
◼ SAP Signavio Process Explorer
◼ SAP Signavio Process Transformation
Manager
SCOPE Europe SRL
Rue de la Science 37
1040 BRUSSELS
https://scope-europe.eu
info@scope-europe.eu
Managing Director
Gabriela Mercuri
Company Register: 0671.468.741
VAT: BE 0671.468.741
ING Belgium
IBAN BE14 3631 6553 4883
SWIFT / BIC: BBRUBEBB
4 | 11
3 Verification Process - Background
V2.11 of the EU Cloud CoC has been developed against GDPR and hence provides mechanisms as
required by Articles 40 and 41 GDPR8.
3.1 Approval of the Code and Accreditation of the Monitoring Body
The services concerned passed the verification process by the Monitoring Body of the EU Cloud CoC,
i.e., SCOPE Europe SRL9.
The Code has been officially approved in May 202110. SCOPE Europe has been officially accredited
as Monitoring Body in May 202111. The robust and complex procedures and mechanisms can be
reviewed by any third-party in detail at the website of the EU Cloud CoC alongside a short summary
thereof.12
3.2 Principles of the Verification Process
Notwithstanding the powers of and requirements set out by the supervisory authority pursuant to
Article 41 GDPR, the Monitoring Body will assess whether a Cloud Service, that has been declared
adherent to the Code, is compliant with the requirements of the Code - especially as laid down in the
Controls Catalogue. Unless otherwise provided by the Code, the Monitoring Body’s assessment pro-
cess will be based on an evidence-based conformity assessment, based on interviews and document
reviews; proactively performed by the Monitoring Body.
To the extent the Monitoring Body is not satisfied with the evidence provided by a CSP with regards to
the Cloud Service to be declared adherent to the Code, the Monitoring Body will request additional
information. Where the information provided by the CSP appears to be inconsistent or false, the Mon-
itoring Body will - as necessary - request substantiation by independent reports.
3.3 Multiple Safeguards of Compliance
Compliance of adherent services is safeguarded by the interaction of several mechanisms, i.e., con-
tinuous, rigorous, and independent monitoring, an independent complaints’ handling process, and
8 https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679
9 https://scope-europe.eu
10 https://www.gegevensbeschermingsautoriteit.be/publications/decision-n05-2021-of-20-may-2021.pdf
11 https://www.gegevensbeschermingsautoriteit.be/publications/decision-n-06-2021-of-20-may-2021.pdf
12 https://eucoc.cloud/en/public-register/assessment-procedure/
Rue de la Science 37
1040 BRUSSELS
https://scope-europe.eu
info@scope-europe.eu
Managing Director
Gabriela Mercuri
Company Register: 0671.468.741
VAT: BE 0671.468.741
ING Belgium
IBAN BE14 3631 6553 4883
SWIFT / BIC: BBRUBEBB
4 | 11
3 Verification Process - Background
V2.11 of the EU Cloud CoC has been developed against GDPR and hence provides mechanisms as
required by Articles 40 and 41 GDPR8.
3.1 Approval of the Code and Accreditation of the Monitoring Body
The services concerned passed the verification process by the Monitoring Body of the EU Cloud CoC,
i.e., SCOPE Europe SRL9.
The Code has been officially approved in May 202110. SCOPE Europe has been officially accredited
as Monitoring Body in May 202111. The robust and complex procedures and mechanisms can be
reviewed by any third-party in detail at the website of the EU Cloud CoC alongside a short summary
thereof.12
3.2 Principles of the Verification Process
Notwithstanding the powers of and requirements set out by the supervisory authority pursuant to
Article 41 GDPR, the Monitoring Body will assess whether a Cloud Service, that has been declared
adherent to the Code, is compliant with the requirements of the Code - especially as laid down in the
Controls Catalogue. Unless otherwise provided by the Code, the Monitoring Body’s assessment pro-
cess will be based on an evidence-based conformity assessment, based on interviews and document
reviews; proactively performed by the Monitoring Body.
To the extent the Monitoring Body is not satisfied with the evidence provided by a CSP with regards to
the Cloud Service to be declared adherent to the Code, the Monitoring Body will request additional
information. Where the information provided by the CSP appears to be inconsistent or false, the Mon-
itoring Body will - as necessary - request substantiation by independent reports.
3.3 Multiple Safeguards of Compliance
Compliance of adherent services is safeguarded by the interaction of several mechanisms, i.e., con-
tinuous, rigorous, and independent monitoring, an independent complaints’ handling process, and
8 https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679
9 https://scope-europe.eu
10 https://www.gegevensbeschermingsautoriteit.be/publications/decision-n05-2021-of-20-may-2021.pdf
11 https://www.gegevensbeschermingsautoriteit.be/publications/decision-n-06-2021-of-20-may-2021.pdf
12 https://eucoc.cloud/en/public-register/assessment-procedure/
Verification of Declaration of Adherence 5 | 11
finally any CSP declaring services adherent is subject to substantial remedies and penalties in case
of any infringement.
3.4 Process in Detail
It is expected that, prior to any assessment of the Monitoring Body, each CSP assesses its compliance
internally. When declaring its service(s) adherent to the EU Cloud CoC, each CSP must elaborate its
compliance with each of the Controls as provided by the Code considering the Control Guidance, as
provided by the Controls Catalogue, to the Monitoring Body.
The CSP may do so either by referencing existing third-party audits or certifications, their respective
reports and by free text responses. Additionally, the CSP will have to provide a general overview of the
functionalities, technical, organisational and contractual frameworks of the service(s) declared ad-
herent.
With regards to internationally recognised standards, the Monitoring Body will consider the mapping
as provided by the Controls Catalogue. However, the Monitoring Body will verify whether (a) any third-
party certification or audit provided by the CSP applies to the Cloud Service concerned, (b) such third-
party certification or audit provided by the CSP is valid, (c) such third-party certification or audit has
assessed and sufficiently reported compliance with the mapped controls of the third-party certifica-
tion or audit concerned. Provided that the aforementioned criteria are met, the Monitoring Body may
consider such third-party certifications or audits as sufficient evidence for the compliance with the
Code.
Within Initial Assessments, the Monitoring Body selects an appropriate share of Controls that will
undergo in-depth scrutiny, e.g., by sample-taking and requesting further, detailed information includ-
ing potentially confidential information. Within any other Recurring Assessment, the Monitoring Body
will select an appropriate share of Controls provided that over a due period every Control will be sub-
ject to scrutiny by the Monitoring Body. Where applicable, aspects of current attention at the time of
assessment shall be covered too, e.g., where such aspects were indicated in media reports, publica-
tions or actions of supervisory authorities.
If the responses of the CSP satisfy the Monitoring Body, especially if responses are consistent and of
appropriate quality and level of detail, reflecting the requirements of the Controls and indicating ap-
propriate implementation by the Control Guidance, then, the Monitoring Body verifies the service(s)
declared adhered as compliant and thereupon, makes them subject to continuous monitoring.
finally any CSP declaring services adherent is subject to substantial remedies and penalties in case
of any infringement.
3.4 Process in Detail
It is expected that, prior to any assessment of the Monitoring Body, each CSP assesses its compliance
internally. When declaring its service(s) adherent to the EU Cloud CoC, each CSP must elaborate its
compliance with each of the Controls as provided by the Code considering the Control Guidance, as
provided by the Controls Catalogue, to the Monitoring Body.
The CSP may do so either by referencing existing third-party audits or certifications, their respective
reports and by free text responses. Additionally, the CSP will have to provide a general overview of the
functionalities, technical, organisational and contractual frameworks of the service(s) declared ad-
herent.
With regards to internationally recognised standards, the Monitoring Body will consider the mapping
as provided by the Controls Catalogue. However, the Monitoring Body will verify whether (a) any third-
party certification or audit provided by the CSP applies to the Cloud Service concerned, (b) such third-
party certification or audit provided by the CSP is valid, (c) such third-party certification or audit has
assessed and sufficiently reported compliance with the mapped controls of the third-party certifica-
tion or audit concerned. Provided that the aforementioned criteria are met, the Monitoring Body may
consider such third-party certifications or audits as sufficient evidence for the compliance with the
Code.
Within Initial Assessments, the Monitoring Body selects an appropriate share of Controls that will
undergo in-depth scrutiny, e.g., by sample-taking and requesting further, detailed information includ-
ing potentially confidential information. Within any other Recurring Assessment, the Monitoring Body
will select an appropriate share of Controls provided that over a due period every Control will be sub-
ject to scrutiny by the Monitoring Body. Where applicable, aspects of current attention at the time of
assessment shall be covered too, e.g., where such aspects were indicated in media reports, publica-
tions or actions of supervisory authorities.
If the responses of the CSP satisfy the Monitoring Body, especially if responses are consistent and of
appropriate quality and level of detail, reflecting the requirements of the Controls and indicating ap-
propriate implementation by the Control Guidance, then, the Monitoring Body verifies the service(s)
declared adhered as compliant and thereupon, makes them subject to continuous monitoring.