Data processing agreements at SAP
Learn how SAP handles personal data on behalf of customers Download the Document
PUBLIC
Data Processing Agreements at SAP
Overview and Frequently Asked Questions
Version: 2.0
Date: July 31, 2025
The information contained in this document is for general informational purposes only and is provided on the
understanding that SAP is not engaged in rendering legal advice. SAP accepts no liability for any actions taken
in response to this resource. As such, it should not be used as a substitute for legal or professional consultation.
Data Processing Agreements at SAP
Overview and Frequently Asked Questions
Version: 2.0
Date: July 31, 2025
The information contained in this document is for general informational purposes only and is provided on the
understanding that SAP is not engaged in rendering legal advice. SAP accepts no liability for any actions taken
in response to this resource. As such, it should not be used as a substitute for legal or professional consultation.
© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material.
2
A data processing agreement is a contract between a data controller (i.e. SAP’s
Customers) and a data processor (i.e. SAP) that describes their respective rights and
obligations regarding the processing of Personal Data (DPA). Under the European Union
General Data Protection Regulation (“GDPR”), this refers to the commissioned
processing of Personal Data by the processor on behalf of the controller and in
accordance with the controller’s instructions.
Customer Data Processing Agreements at SAP
Where applicable legislation requires a DPA, it is a legally binding requirement on both SAP and its
customers to have a DPA in place. This can apply both to SAP and its Customers as well as other parties,
for example Customer Affiliates, that are able to use the service provided by SAP. Without a DPA, the
processing activities may violate applicable laws, which might result in damage claims, prohibition orders,
fines and other adverse consequences against the data controller (Customer) and data processor (SAP).
The DPA would typically set forth instructions as to how Personal Data is to be processed, including, a
description of the data processing activities (affected categories of Personal Data and data subjects,
processing operations and duration of the processing), the technical and organizational measures the
data processor must apply to protect the Personal Data and the data controllers’ audit rights. Except
where region-specific offerings such as SAP EU Access are involved, SAP utilizes subprocessors across
the globe, often necessitating the international access to or transfer of personal data, an area of significant
regulation. A DPA thus helps provide transparency and understanding as to how Personal Data is
processed and applies contractual safeguards to protect this information in case of international data
transfers.
The SAP Data Processing Agreement for SAP Services (the “SAP DPA”) describes how SAP processes
Personal Data from (end) Customers when delivering SAP Cloud Services, SAP Support and Professional
Services (“SAP Services”) (See also: Cloud Services Documents | SAP Trust Center). The purpose of the
SAP DPA is to assist with transparency and understanding of individual roles between SAP and its
Customers, to provide contractual protections for Personal Data and to help both SAP and the Customer
comply with data protection and privacy laws worldwide. This helps to set clear expectations regarding
the handling of Personal Data for both SAP and its (end) Customers. For this reason, the DPA is part of
every transaction SAP enters into with Customers and is an integral part of the overall SAP Agreement
(SAP Agreements website). SAP periodically reviews its DPAs to address ongoing compliance with
applicable legal and regulatory requirements.
2
A data processing agreement is a contract between a data controller (i.e. SAP’s
Customers) and a data processor (i.e. SAP) that describes their respective rights and
obligations regarding the processing of Personal Data (DPA). Under the European Union
General Data Protection Regulation (“GDPR”), this refers to the commissioned
processing of Personal Data by the processor on behalf of the controller and in
accordance with the controller’s instructions.
Customer Data Processing Agreements at SAP
Where applicable legislation requires a DPA, it is a legally binding requirement on both SAP and its
customers to have a DPA in place. This can apply both to SAP and its Customers as well as other parties,
for example Customer Affiliates, that are able to use the service provided by SAP. Without a DPA, the
processing activities may violate applicable laws, which might result in damage claims, prohibition orders,
fines and other adverse consequences against the data controller (Customer) and data processor (SAP).
The DPA would typically set forth instructions as to how Personal Data is to be processed, including, a
description of the data processing activities (affected categories of Personal Data and data subjects,
processing operations and duration of the processing), the technical and organizational measures the
data processor must apply to protect the Personal Data and the data controllers’ audit rights. Except
where region-specific offerings such as SAP EU Access are involved, SAP utilizes subprocessors across
the globe, often necessitating the international access to or transfer of personal data, an area of significant
regulation. A DPA thus helps provide transparency and understanding as to how Personal Data is
processed and applies contractual safeguards to protect this information in case of international data
transfers.
The SAP Data Processing Agreement for SAP Services (the “SAP DPA”) describes how SAP processes
Personal Data from (end) Customers when delivering SAP Cloud Services, SAP Support and Professional
Services (“SAP Services”) (See also: Cloud Services Documents | SAP Trust Center). The purpose of the
SAP DPA is to assist with transparency and understanding of individual roles between SAP and its
Customers, to provide contractual protections for Personal Data and to help both SAP and the Customer
comply with data protection and privacy laws worldwide. This helps to set clear expectations regarding
the handling of Personal Data for both SAP and its (end) Customers. For this reason, the DPA is part of
every transaction SAP enters into with Customers and is an integral part of the overall SAP Agreement
(SAP Agreements website). SAP periodically reviews its DPAs to address ongoing compliance with
applicable legal and regulatory requirements.
© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material.
3
Frequently Asked Questions
Background
• Is the scope of SAP’s DPA intended to be global?
The SAP DPA is global because SAP serves an international customer base and manages Personal
Data across multiple legal jurisdictions. By covering cross-border transfers and processing activities,
the DPA allows that Personal Data is handled lawfully under key frameworks such as the EU’s GDPR,
various U.S. and Canadian privacy laws, and leading APJ regulations (for instance Australia’s Privacy
Act, Singapore’s PDPA, and Japan’s APPI). This unified approach provides every customer—no matter
where they operate—with consistent, well-defined data protection practices. Additionally, SAP’s
cloud infrastructure and support services are distributed worldwide, making a single, comprehensive
DPA both practical and efficient. A global scope simplifies compliance for SAP and its customers by
removing the need for multiple, region-specific agreements and aligns with regulatory expectations
for organization-wide data protection. In this way, the SAP DPA underscores SAP’s commitment to
legal clarity and operational efficiency.
• Why is the scope of SAP’s DPA restricted to Personal Data?
As described above in the introduction section, the legal purpose of a DPA is to implement the
obligations that data protection and privacy laws impose on data controllers and data processors in
connection with the commissioned processing of Personal Data. By targeting this narrow scope, a DPA
allows for the precise implementation of statutory requirements where they’re needed. While the DPA
covers personal-data processing, SAP may undertake other contractual obligations elsewhere in the
SAP Agreement—such as customer breach-notification procedures, audit rights, or service-level
commitments—that apply more broadly or under different legal frameworks. This division keeps the
SAP DPA focused yet provides for all necessary responsibilities or contractual commitments to be
documented in the contract.
• What is the difference between a data processor and a data controller
and why does SAP act as a processor in the DPA?
A data controller decides why and how Personal Data is collected, used, maintained and uploaded
into SAP products and services. A data processor (i.e. SAP) processes that data including its Personal
Data on the data controller’s behalf and in accordance with the instructions and for the purposes set
forth in the DPA.
• How is the SAP DPA incorporated in an SAP agreement for cloud
services?
The SAP Agreement structure for SAP Cloud Services generally includes the following documents in
order of precedence: (i) Order Form for SAP Cloud Services (“Order Form"); (ii) Supplemental Terms
and Conditions for SAP Cloud Services ("Supplement"); (iii) Support Schedule for Cloud Services
("Cloud Support Schedule'); (iv) Service Level Agreement for Cloud Services ("SLA"); (v) Data
Processing Agreement for Cloud Services which includes the EU Standard Contractual Clauses; and
the (vi) General Terms and Conditions for SAP Cloud Services ("GTC"). Please see also:
https://www.sap.com/about/trust-center/agreements.html?video=4e97aae0-0b7e-0010-bca6-
c68f7e60039b
3
Frequently Asked Questions
Background
• Is the scope of SAP’s DPA intended to be global?
The SAP DPA is global because SAP serves an international customer base and manages Personal
Data across multiple legal jurisdictions. By covering cross-border transfers and processing activities,
the DPA allows that Personal Data is handled lawfully under key frameworks such as the EU’s GDPR,
various U.S. and Canadian privacy laws, and leading APJ regulations (for instance Australia’s Privacy
Act, Singapore’s PDPA, and Japan’s APPI). This unified approach provides every customer—no matter
where they operate—with consistent, well-defined data protection practices. Additionally, SAP’s
cloud infrastructure and support services are distributed worldwide, making a single, comprehensive
DPA both practical and efficient. A global scope simplifies compliance for SAP and its customers by
removing the need for multiple, region-specific agreements and aligns with regulatory expectations
for organization-wide data protection. In this way, the SAP DPA underscores SAP’s commitment to
legal clarity and operational efficiency.
• Why is the scope of SAP’s DPA restricted to Personal Data?
As described above in the introduction section, the legal purpose of a DPA is to implement the
obligations that data protection and privacy laws impose on data controllers and data processors in
connection with the commissioned processing of Personal Data. By targeting this narrow scope, a DPA
allows for the precise implementation of statutory requirements where they’re needed. While the DPA
covers personal-data processing, SAP may undertake other contractual obligations elsewhere in the
SAP Agreement—such as customer breach-notification procedures, audit rights, or service-level
commitments—that apply more broadly or under different legal frameworks. This division keeps the
SAP DPA focused yet provides for all necessary responsibilities or contractual commitments to be
documented in the contract.
• What is the difference between a data processor and a data controller
and why does SAP act as a processor in the DPA?
A data controller decides why and how Personal Data is collected, used, maintained and uploaded
into SAP products and services. A data processor (i.e. SAP) processes that data including its Personal
Data on the data controller’s behalf and in accordance with the instructions and for the purposes set
forth in the DPA.
• How is the SAP DPA incorporated in an SAP agreement for cloud
services?
The SAP Agreement structure for SAP Cloud Services generally includes the following documents in
order of precedence: (i) Order Form for SAP Cloud Services (“Order Form"); (ii) Supplemental Terms
and Conditions for SAP Cloud Services ("Supplement"); (iii) Support Schedule for Cloud Services
("Cloud Support Schedule'); (iv) Service Level Agreement for Cloud Services ("SLA"); (v) Data
Processing Agreement for Cloud Services which includes the EU Standard Contractual Clauses; and
the (vi) General Terms and Conditions for SAP Cloud Services ("GTC"). Please see also:
https://www.sap.com/about/trust-center/agreements.html?video=4e97aae0-0b7e-0010-bca6-
c68f7e60039b
© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material.
4
Security of Processing
• What Technical and Organizational Measures (“TOMS”) does SAP
apply to protect Personal Data?
SAP applies appropriate technical and organizational measures to protect Personal Data which are
published on My Trust Center and the SAP agreements website. The TOMS are incorporated into the
DPA as the measures implemented to protect Personal Data. These TOMS describe the specific
controls that SAP has in place to safeguard Personal Data. For Cloud Services, the TOMS are also
called the “Security Measures for Cloud Services”.
• Can Customers customize the TOMS?
No. The security measures outlined in the TOMS are standardized and consistently applied across all
SAP service environments. This provides for a uniform level of protection for all customers and
supports compliance with industry standards and regulatory requirements. While these measures
cannot be modified on a customer-by-customer basis, customers are encouraged to implement
additional safeguards within their own environments.
• Did the Security Measures for Cloud Services released in October
2024 change or expand the DPA?
For Cloud Services, the Security Measures for Cloud Services are the Technical and Organizational
Measures referenced in the DPA and define the measures maintained by SAP to protect Customer
Data including Personal Data. The only change to the SAP DPA impacted by the release of the Security
Measures for Cloud Services was an update to the definition of “Technical and Organizational
Measures”.
• How are Customers notified of updates to the TOMS?
SAP may publish updated versions of the TOMS on My Trust Center and Customers may
subscribe to receive automated notification (or other link provided by SAP from time-to-time). SAP
must always maintain a comparable or better security level as part of any update to the TOMS.
Data Export and Deletion
• How is Personal Data returned or deleted upon expiration or
termination of an Order Form?
During the term of an Order Form, Customers can access and export their Personal Data at any time.
Upon expiration or termination of an Order Form, SAP will delete the Personal Data remaining on SAP
servers within 6 months of the date of expiration or termination at the latest, unless applicable law
requires retention.
SAP Obligations
• What level of cooperation will SAP provide under the DPA as a data
processor?
SAP acts as a data processor under the SAP DPA. SAP will reasonably cooperate with Customers and
Controllers in dealing with requests from Data Subjects or regulatory authorities regarding SAP’s
processing of Personal Data or any Personal Data Breach. However, SAP does not take on the
Customer’s overarching compliance obligations, such as determining the legal basis of processing,
managing governance frameworks or fulfilling data controller specific duties such as conducting data
protection impact assessments regarding the Customer’s use of an SAP cloud service. The SAP DPA
4
Security of Processing
• What Technical and Organizational Measures (“TOMS”) does SAP
apply to protect Personal Data?
SAP applies appropriate technical and organizational measures to protect Personal Data which are
published on My Trust Center and the SAP agreements website. The TOMS are incorporated into the
DPA as the measures implemented to protect Personal Data. These TOMS describe the specific
controls that SAP has in place to safeguard Personal Data. For Cloud Services, the TOMS are also
called the “Security Measures for Cloud Services”.
• Can Customers customize the TOMS?
No. The security measures outlined in the TOMS are standardized and consistently applied across all
SAP service environments. This provides for a uniform level of protection for all customers and
supports compliance with industry standards and regulatory requirements. While these measures
cannot be modified on a customer-by-customer basis, customers are encouraged to implement
additional safeguards within their own environments.
• Did the Security Measures for Cloud Services released in October
2024 change or expand the DPA?
For Cloud Services, the Security Measures for Cloud Services are the Technical and Organizational
Measures referenced in the DPA and define the measures maintained by SAP to protect Customer
Data including Personal Data. The only change to the SAP DPA impacted by the release of the Security
Measures for Cloud Services was an update to the definition of “Technical and Organizational
Measures”.
• How are Customers notified of updates to the TOMS?
SAP may publish updated versions of the TOMS on My Trust Center and Customers may
subscribe to receive automated notification (or other link provided by SAP from time-to-time). SAP
must always maintain a comparable or better security level as part of any update to the TOMS.
Data Export and Deletion
• How is Personal Data returned or deleted upon expiration or
termination of an Order Form?
During the term of an Order Form, Customers can access and export their Personal Data at any time.
Upon expiration or termination of an Order Form, SAP will delete the Personal Data remaining on SAP
servers within 6 months of the date of expiration or termination at the latest, unless applicable law
requires retention.
SAP Obligations
• What level of cooperation will SAP provide under the DPA as a data
processor?
SAP acts as a data processor under the SAP DPA. SAP will reasonably cooperate with Customers and
Controllers in dealing with requests from Data Subjects or regulatory authorities regarding SAP’s
processing of Personal Data or any Personal Data Breach. However, SAP does not take on the
Customer’s overarching compliance obligations, such as determining the legal basis of processing,
managing governance frameworks or fulfilling data controller specific duties such as conducting data
protection impact assessments regarding the Customer’s use of an SAP cloud service. The SAP DPA
© 2025 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to this material.
5
cooperation provisions are supplemental: they help the Customer meet its data controller related
obligations, but do not transfer the Customer responsibilities under data protection and privacy laws
to SAP.
Please see also https://www.sap.com/about/trust-center/data-privacy.html?pdf-asset=acdc1f8a-
027f-0010-bca6-c68f7e60039b&page=1
• How does SAP handle third party data access requests?
Please review the information at the following link: https://www.sap.com/about/trust-center/data-
privacy.html?pdf-asset=ec3728a3-a57e-0010-bca6-c68f7e60039b&page=1.
• How does SAP handle Data Subject Requests?
Please review information at the following link: https://www.sap.com/about/trust-center/data-
privacy.html?pdf-asset=5a36e0c2-067f-0010-bca6-c68f7e60039b&page=1.
• When does SAP notify of a Personal Data Breach and who does
SAP notify?
SAP maintains a security incident management program which is described in further detail in the
TOMs. SAP commits in the SAP DPA to notify Customers without undue delay after becoming aware
of a confirmed breach of SAP's security leading to the accidental or unlawful destruction, loss,
alteration, unauthorized disclosure of or unauthorized third-party access to Personal Data for which a
data processor is required under data protection law to provide notice to the controller. If a Customer
is impacted by a Personal Data breach, the customers security contacts will be notified. To receive a
breach notification, customers must register at least one security-related contact in SAP for Me.
Certifications and Audits
• What kind of third-party certificates does SAP make available for its
products and services?
SAP obtains certain third-party certifications and attestations to ensure ongoing compliance for its
products and services. Customer may conduct self-service reviews of obtained security certifications and
attestations for a subscribed service as SAP is permitted to make available to Customers of the service.
Customers may request available certifications and reports on the SAP Trust Center (a login in is required
to access them). Additional information is also available at this link.
Subprocessors
• Why does SAP use sub processors?
SAP relies on global sub processors to improve performance, reduce latency and scale efficiently across
regions. Sub processors offer specialized tools like cloud hosting, dedicated processing operations
required for the provisioning of SAP’s cloud services and customer support services that aim to enhance
both functionality and data protection. Global sub processors can enhance the security of SAP products
and services by mitigating risk and enabling rapid responses to threats and outages. SAP sub processors
can be SAP affiliates or third- party entities. SAP remains responsible for its sub processors.
• Why aren’t customers able to individually approve each sub-processor
in advance and why is a general written authorization approach used
instead?
Customers cannot agree to each sub processor appointment in advance because this would limit SAP’s
ability to scale and maintain performance, security and support for its products and services for all
Customers. It would also create delays and operational inefficiencies. A general written authorization
5
cooperation provisions are supplemental: they help the Customer meet its data controller related
obligations, but do not transfer the Customer responsibilities under data protection and privacy laws
to SAP.
Please see also https://www.sap.com/about/trust-center/data-privacy.html?pdf-asset=acdc1f8a-
027f-0010-bca6-c68f7e60039b&page=1
• How does SAP handle third party data access requests?
Please review the information at the following link: https://www.sap.com/about/trust-center/data-
privacy.html?pdf-asset=ec3728a3-a57e-0010-bca6-c68f7e60039b&page=1.
• How does SAP handle Data Subject Requests?
Please review information at the following link: https://www.sap.com/about/trust-center/data-
privacy.html?pdf-asset=5a36e0c2-067f-0010-bca6-c68f7e60039b&page=1.
• When does SAP notify of a Personal Data Breach and who does
SAP notify?
SAP maintains a security incident management program which is described in further detail in the
TOMs. SAP commits in the SAP DPA to notify Customers without undue delay after becoming aware
of a confirmed breach of SAP's security leading to the accidental or unlawful destruction, loss,
alteration, unauthorized disclosure of or unauthorized third-party access to Personal Data for which a
data processor is required under data protection law to provide notice to the controller. If a Customer
is impacted by a Personal Data breach, the customers security contacts will be notified. To receive a
breach notification, customers must register at least one security-related contact in SAP for Me.
Certifications and Audits
• What kind of third-party certificates does SAP make available for its
products and services?
SAP obtains certain third-party certifications and attestations to ensure ongoing compliance for its
products and services. Customer may conduct self-service reviews of obtained security certifications and
attestations for a subscribed service as SAP is permitted to make available to Customers of the service.
Customers may request available certifications and reports on the SAP Trust Center (a login in is required
to access them). Additional information is also available at this link.
Subprocessors
• Why does SAP use sub processors?
SAP relies on global sub processors to improve performance, reduce latency and scale efficiently across
regions. Sub processors offer specialized tools like cloud hosting, dedicated processing operations
required for the provisioning of SAP’s cloud services and customer support services that aim to enhance
both functionality and data protection. Global sub processors can enhance the security of SAP products
and services by mitigating risk and enabling rapid responses to threats and outages. SAP sub processors
can be SAP affiliates or third- party entities. SAP remains responsible for its sub processors.
• Why aren’t customers able to individually approve each sub-processor
in advance and why is a general written authorization approach used
instead?
Customers cannot agree to each sub processor appointment in advance because this would limit SAP’s
ability to scale and maintain performance, security and support for its products and services for all
Customers. It would also create delays and operational inefficiencies. A general written authorization