Data processing agreements at SAP

Learn how SAP handles personal data on behalf of customers Download the Document

PUBLICData Processing Agreements at SAPOverview and Frequently Asked QuestionsVersion: 2.0Date: July 31, 2025The information contained in this document is for general informational purposes only and is provided on theunderstanding that SAP is not engaged in rendering legal advice. SAP accepts no liability for any actions takenin response to this resource. As such, it should not be used as a substitute for legal or professional consultation.
© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material.2A data processing agreement is a contract between a data controller (i.e. SAP’sCustomers) and a data processor (i.e. SAP) that describes their respective rights andobligations regarding the processing of Personal Data (DPA). Under the European UnionGeneral Data Protection Regulation (“GDPR”), this refers to the commissionedprocessing of Personal Data by the processor on behalf of the controller and inaccordance with the controller’s instructions.Customer Data Processing Agreements at SAPWhere applicable legislation requires a DPA, it is a legally binding requirement on both SAP and itscustomers to have a DPA in place. This can apply both to SAP and its Customers as well as other parties,for example Customer Affiliates, that are able to use the service provided by SAP. Without a DPA, theprocessing activities may violate applicable laws, which might result in damage claims, prohibition orders,fines and other adverse consequences against the data controller (Customer) and data processor (SAP).The DPA would typically set forth instructions as to how Personal Data is to be processed, including, adescription of the data processing activities (affected categories of Personal Data and data subjects,processing operations and duration of the processing), the technical and organizational measures thedata processor must apply to protect the Personal Data and the data controllers’ audit rights. Exceptwhere region-specific offerings such as SAP EU Access are involved, SAP utilizes subprocessors acrossthe globe, often necessitating the international access to or transfer of personal data, an area of significantregulation. A DPA thus helps provide transparency and understanding as to how Personal Data isprocessed and applies contractual safeguards to protect this information in case of international datatransfers.The SAP Data Processing Agreement for SAP Services (the “SAP DPA”) describes how SAP processesPersonal Data from (end) Customers when delivering SAP Cloud Services, SAP Support and ProfessionalServices (“SAP Services”) (See also: Cloud Services Documents | SAP Trust Center). The purpose of theSAP DPA is to assist with transparency and understanding of individual roles between SAP and itsCustomers, to provide contractual protections for Personal Data and to help both SAP and the Customercomply with data protection and privacy laws worldwide. This helps to set clear expectations regardingthe handling of Personal Data for both SAP and its (end) Customers. For this reason, the DPA is part ofevery transaction SAP enters into with Customers and is an integral part of the overall SAP Agreement(SAP Agreements website). SAP periodically reviews its DPAs to address ongoing compliance withapplicable legal and regulatory requirements.
© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material.3Frequently Asked QuestionsBackground Is the scope of SAP’s DPA intended to be global?The SAP DPA is global because SAP serves an international customer base and manages PersonalData across multiple legal jurisdictions. By covering cross-border transfers and processing activities,the DPA allows that Personal Data is handled lawfully under key frameworks such as the EU’s GDPR,various U.S. and Canadian privacy laws, and leading APJ regulations (for instance Australia’s PrivacyAct, Singapore’s PDPA, and Japan’s APPI). This unified approach provides every customerno matterwhere they operatewith consistent, well-defined data protection practices. Additionally, SAP’scloud infrastructure and support services are distributed worldwide, making a single, comprehensiveDPA both practical and efficient. A global scope simplifies compliance for SAP and its customers byremoving the need for multiple, region-specific agreements and aligns with regulatory expectationsfor organization-wide data protection. In this way, the SAP DPA underscores SAP’s commitment tolegal clarity and operational efficiency. Why is the scope of SAP’s DPA restricted to Personal Data?As described above in the introduction section, the legal purpose of a DPA is to implement theobligations that data protection and privacy laws impose on data controllers and data processors inconnection with the commissioned processing of Personal Data. By targeting this narrow scope, a DPAallows for the precise implementation of statutory requirements where they’re needed. While the DPAcovers personal-data processing, SAP may undertake other contractual obligations elsewhere in theSAP Agreementsuch as customer breach-notification procedures, audit rights, or service-levelcommitmentsthat apply more broadly or under different legal frameworks. This division keeps theSAP DPA focused yet provides for all necessary responsibilities or contractual commitments to bedocumented in the contract. What is the difference between a data processor and a data controllerand why does SAP act as a processor in the DPA?A data controller decides why and how Personal Data is collected, used, maintained and uploadedinto SAP products and services. A data processor (i.e. SAP) processes that data including its PersonalData on the data controllers behalf and in accordance with the instructions and for the purposes setforth in the DPA. How is the SAP DPA incorporated in an SAP agreement for cloudservices?The SAP Agreement structure for SAP Cloud Services generally includes the following documents inorder of precedence: (i) Order Form for SAP Cloud Services (“Order Form"); (ii) Supplemental Termsand Conditions for SAP Cloud Services ("Supplement"); (iii) Support Schedule for Cloud Services("Cloud Support Schedule'); (iv) Service Level Agreement for Cloud Services ("SLA"); (v) DataProcessing Agreement for Cloud Services which includes the EU Standard Contractual Clauses; andthe (vi) General Terms and Conditions for SAP Cloud Services ("GTC"). Please see also:https://www.sap.com/about/trust-center/agreements.html?video=4e97aae0-0b7e-0010-bca6-c68f7e60039b
© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material.4Security of Processing What Technical and Organizational Measures (“TOMS”) does SAPapply to protect Personal Data?SAP applies appropriate technical and organizational measures to protect Personal Data which arepublished on My Trust Center and the SAP agreements website. The TOMS are incorporated into theDPA as the measures implemented to protect Personal Data. These TOMS describe the specificcontrols that SAP has in place to safeguard Personal Data. For Cloud Services, the TOMS are alsocalled the “Security Measures for Cloud Services”. Can Customers customize the TOMS?No. The security measures outlined in the TOMS are standardized and consistently applied across allSAP service environments. This provides for a uniform level of protection for all customers andsupports compliance with industry standards and regulatory requirements. While these measurescannot be modified on a customer-by-customer basis, customers are encouraged to implementadditional safeguards within their own environments. Did the Security Measures for Cloud Services released in October2024 change or expand the DPA?For Cloud Services, the Security Measures for Cloud Services are the Technical and OrganizationalMeasures referenced in the DPA and define the measures maintained by SAP to protect CustomerData including Personal Data. The only change to the SAP DPA impacted by the release of the SecurityMeasures for Cloud Services was an update to the definition of “Technical and OrganizationalMeasures”. How are Customers notified of updates to the TOMS?SAP may publish updated versions of the TOMS on My Trust Center and Customers maysubscribe to receive automated notification (or other link provided by SAP from time-to-time). SAPmust always maintain a comparable or better security level as part of any update to the TOMS.Data Export and Deletion How is Personal Data returned or deleted upon expiration ortermination of an Order Form?During the term of an Order Form, Customers can access and export their Personal Data at any time.Upon expiration or termination of an Order Form, SAP will delete the Personal Data remaining on SAPservers within 6 months of the date of expiration or termination at the latest, unless applicable lawrequires retention.SAP Obligations What level of cooperation will SAP provide under the DPA as a dataprocessor?SAP acts as a data processor under the SAP DPA. SAP will reasonably cooperate with Customers andControllers in dealing with requests from Data Subjects or regulatory authorities regarding SAP’sprocessing of Personal Data or any Personal Data Breach. However, SAP does not take on theCustomer’s overarching compliance obligations, such as determining the legal basis of processing,managing governance frameworks or fulfilling data controller specific duties such as conducting dataprotection impact assessments regarding the Customer’s use of an SAP cloud service. The SAP DPA
© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material.5cooperation provisions are supplemental: they help the Customer meet its data controller relatedobligations, but do not transfer the Customer responsibilities under data protection and privacy lawsto SAP.Please see also https://www.sap.com/about/trust-center/data-privacy.html?pdf-asset=acdc1f8a-027f-0010-bca6-c68f7e60039b&page=1 How does SAP handle third party data access requests?Please review the information at the following link: https://www.sap.com/about/trust-center/data-privacy.html?pdf-asset=ec3728a3-a57e-0010-bca6-c68f7e60039b&page=1. How does SAP handle Data Subject Requests?Please review information at the following link: https://www.sap.com/about/trust-center/data-privacy.html?pdf-asset=5a36e0c2-067f-0010-bca6-c68f7e60039b&page=1. When does SAP notify of a Personal Data Breach and who doesSAP notify?SAP maintains a security incident management program which is described in further detail in theTOMs. SAP commits in the SAP DPA to notify Customers without undue delay after becoming awareof a confirmed breach of SAP's security leading to the accidental or unlawful destruction, loss,alteration, unauthorized disclosure of or unauthorized third-party access to Personal Data for which adata processor is required under data protection law to provide notice to the controller. If a Customeris impacted by a Personal Data breach, the customers security contacts will be notified. To receive abreach notification, customers must register at least one security-related contact in SAP for Me.Certifications and Audits What kind of third-party certificates does SAP make available for itsproducts and services?SAP obtains certain third-party certifications and attestations to ensure ongoing compliance for itsproducts and services. Customer may conduct self-service reviews of obtained security certifications andattestations for a subscribed service as SAP is permitted to make available to Customers of the service.Customers may request available certifications and reports on the SAP Trust Center (a login in is requiredto access them). Additional information is also available at this link.Subprocessors Why does SAP use sub processors?SAP relies on global sub processors to improve performance, reduce latency and scale efficiently acrossregions. Sub processors offer specialized tools like cloud hosting, dedicated processing operationsrequired for the provisioning of SAP’s cloud services and customer support services that aim to enhanceboth functionality and data protection. Global sub processors can enhance the security of SAP productsand services by mitigating risk and enabling rapid responses to threats and outages. SAP sub processorscan be SAP affiliates or third- party entities. SAP remains responsible for its sub processors. Why aren’t customers able to individually approve each sub-processorin advance and why is a general written authorization approach usedinstead?Customers cannot agree to each sub processor appointment in advance because this would limit SAP’sability to scale and maintain performance, security and support for its products and services for allCustomers. It would also create delays and operational inefficiencies. A general written authorization