ASUG News + Views
GDPR in the SAP World: No Inde­pen­dence from Glob­al Compliance
Mar 25, 2018
Bookmark
Share Article:

Inde­pen­dence is an atti­tude that is firm­ly entrenched in the com­merce cul­ture of the Unit­ed States. The U.S. thrives on the idea that it can pave its own way eco­nom­i­cal­ly with­out pay­ing much atten­tion to its ties to or rules orig­i­nat­ed by oth­er nations. Despite France lay­ing down its claim for full own­er­ship of méth­ode cham­p­enoise, for exam­ple, Amer­i­can wine­mak­ers have been mer­ri­ly call­ing sparkling wine Cham­pagne for years, due to legal loop­holes left open since the Treaty of Ver­sailles at the end of World War I. 

But the fact is, tech­nol­o­gy has allowed nations all over the world to become vir­tu­al neigh­bors, if not phys­i­cal ones, with all the dig­i­tal entan­gle­ments that go hand in hand with those rela­tion­ships.  And a new Euro­pean Union (EU) rul­ing comes into effect on May 25, 2018 that could bring painful con­se­quences to North Amer­i­can firms that main­tain even the small­est amount of data on Euro­pean cus­tomers. That’s if they don’t become aware and pre­pare now.

What on Earth is the GDPR?

The Gen­er­al Data Pro­tec­tion Reg­u­la­tion (GDPR) replaces the EU Data Pro­tec­tion Direc­tive 9546 laws for all EU coun­tries. Essen­tial­ly, it sets for­mal rules to make sure that com­pa­nies respect an individual’s rights to pro­tect their per­son­al data.

Yet its aim is far more sweep­ing than a man­date that com­pa­nies should clean up or delete cus­tomers’ per­son­al data. It’s a call to weave data pro­tec­tion prac­tices through­out the entire approach to data gov­er­nance. In the words of the EU, Com­pli­ance should not be an after­thought to ensure one is with­in the con­fines of the law, but instead be baked into core prod­uct and oper­a­tional design in the first place.”

How is North Amer­i­ca Affect­ed by the GDPR?

So, let’s deal with the burn­ing ques­tion: Should North Amer­i­can com­pa­nies be con­cerned about the GDPR? The short answer is yes. Now if you’re a small busi­ness with no e‑commerce offer­ings or a cus­tomer base that doesn’t extend out­side of your coun­try, state, province, or city, then the GDPR may not apply to you.

In gen­er­al, most com­pa­nies that use SAP tech­nolo­gies will like­ly be firms that are glob­al enough to have some con­nec­tions to peo­ple or enti­ties based on Euro­pean soil, inside the Euro­pean Union. (For addi­tion­al con­text, it’s worth not­ing that the Unit­ed King­dom is leav­ing the EU, so it will even­tu­al­ly face a sim­i­lar sit­u­a­tion as North America.)

The Cost­ly Dev­il Hid­ing in the Data Detail

If your com­pa­ny has even one cus­tomer in the EU, then you have a data con­nec­tion to Europe, because that customer’s infor­ma­tion will exist as a record on a North Amer­i­can data­base. This means you must fol­low the rules of the GDPR in how you treat that customer’s data. That cus­tomer could be an indi­vid­ual, a vir­tu­al web start­up, a satel­lite busi­ness unit, or a glob­al enter­prise. GDPR will apply in every case.

What if it comes down to some­thing as small as an email from an EU enti­ty, or an old cus­tomer record, or some oth­er micro­da­ta”? This is where it is cloudi­er at this stage, but indus­try think­ing indi­cates that the rule will still apply in these sce­nar­ios. For exam­ple, North Amer­i­can gam­ing com­pa­nies have raised con­cerns about GDPR in terms of sim­ply hav­ing user-play­er pro­file names stored on their servers.

Painful Penal­ties Up the Risk

If a com­pa­ny har­bors any kind of per­son­al­ly spe­cif­ic data and it wants to con­tin­ue to be glob­al­ly con­nect­ed to EU infor­ma­tion, then it will need to pro­vide evi­dence of data pro­tec­tion com­pli­ance up to (and hope­ful­ly beyond) lev­els defined by Euro­pean Union legislation.

The penal­ty for non-com­pli­ance with GDPR are poten­tial fines as high as $25 mil­lion or four per­cent of world­wide annu­al rev­enue for the pre­vi­ous year, whichev­er is greater.

The Sil­ver Lin­ing in the GDPR Cloud

Although it all may sound like bad news, there are some pos­i­tives here. This is an unpar­al­leled oppor­tu­ni­ty for North Amer­i­can com­pa­nies to per­form inter­nal data pro­tec­tion com­pli­ance audits. Now there’s a legit­i­mate, risk-dri­ven ratio­nale for spend­ing com­pa­ny resources on this project. And the wider call that GDPR sends out for us to now clean up our data and how we main­tain it can be a pos­i­tive thing for ASUG mem­bers, many of whom may be sit­ting on stale or dupli­cat­ed data that would ben­e­fit from a housecleaning.

What GDPR Means for SAP Customers

GDPR will have a direct impact on cur­rent­ly deployed SAP tech­nolo­gies. By their very nature, we know that ERP, CRM, and HR repos­i­to­ries typ­i­cal­ly hold a great deal of sen­si­tive per­son­al infor­ma­tion. All com­pa­nies with per­son­al data for cit­i­zens and busi­ness­es with­in the EU are now respon­si­ble for pro­tect­ing this infor­ma­tion from any threat of data breach.

In terms of its appli­ca­tion, GDPR gives data pro­tec­tion and con­trol rights back to indi­vid­u­als. This entire devel­op­ment has arisen due to the grow­ing num­ber of inter­na­tion­al secu­ri­ty breach­es that have exposed per­son­al infor­ma­tion to mali­cious hack­ers. Although SAP has not been iden­ti­fied as a spe­cif­ic source of blame for any real or per­ceived fragili­ty in SAP HANA or any oth­er prod­uct, now is a bet­ter time than ever to lock down your data pro­tec­tion compliance. 

A Slow Race to the GDPR Com­pli­ance Fin­ish Line

As many as 40% of orga­ni­za­tions have been esti­mat­ed to have no mech­a­nisms in place to deter­mine which ele­ments of data should be saved or delet­ed because of GDPR. With­in Europe, the U.K. is lag­ging coun­tries like Nor­way and Swe­den, which have been prepar­ing more con­sci­en­tious­ly. Even the über-effi­cient Ger­mans are said to be play­ing catch up with their Nordic cousins. Put sim­ply, it’s some­what of a last-minute race to build com­pli­ance lay­ers around enter­prise data.

It’s worth remem­ber­ing that under GDPR, North Amer­i­can com­pa­nies can retain per­son­al data, but only if it is being used for the orig­i­nal pur­pose com­mu­ni­cat­ed to the indi­vid­ual when they opt­ed in to share their data. Com­pa­nies are respon­si­ble for delet­ing this per­son­al data when it is no longer need­ed for that stat­ed pur­pose. For com­pa­nies of any size, it will be no small task to cre­ate and imple­ment process­es to man­age these kinds of reg­u­lar data updates.

SAP’s GDPR Guidelines

SAP has said that GDPR best prac­tice starts with an audit and assess­ment of your cur­rent process­es and orga­ni­za­tion­al design. The com­pa­ny also points out that all imme­di­ate changes made should reflect the pur­pose” of respec­tive data pro­cess­ing activ­i­ties, accord­ing to rel­e­vant legal require­ments. The dif­fi­cult and incon­ve­nient truth is that there is no sin­gle way to approach GDPR compliance. 

Accord­ing to SAP guide­lines, In SAP Busi­ness Suite and SAP S/4HANA, any busi­ness object has a cor­re­spond­ing Infor­ma­tion Life­cy­cle Man­age­ment object. Once you have iden­ti­fied all busi­ness objects and all reten­tion require­ments, check that the process design match­es the reten­tion requirements.”

SAP con­tin­ues, For exam­ple, if you need to sep­a­rate sales orders accord­ing to dif­fer­ent reten­tion require­ments, you may need to imple­ment a sec­ond sales order process. After you adapt your process­es and your orga­ni­za­tion­al set­up accord­ing­ly, you can con­tin­ue with imple­ment­ing GDPR com­pli­ance fea­tures, such as block­ing and dele­tion rules, or the autho­riza­tions concept.”

SAP Steps on the Road to GDPR

SAP offers sup­port­ing solu­tions includ­ing SAP Hybris Con­sent (for­mer­ly known as Gigya Enter­prise Pref­er­ence Man­ag­er) and SAP gov­er­nance, risk, and com­pli­ance solu­tions to help cus­tomers work toward the required doc­u­men­ta­tion and audit­ing. The com­pa­ny is also say­ing that an upgrade of SAP Busi­ness Suite to the most recent ver­sion will bring ASUG mem­bers clos­er to get­ting their ERP sys­tem ready for the regulation. 

ASUG mem­bers can also look to SAP tools includ­ing the Data Con­troller Rule Frame­work, SAP Read Access­ing Log­ging, and SAP Test Data Migra­tion Serv­er to con­fig­ure access rules, keep track of data retrievals, and migrate data securely.

As SAP GDPR expert Volk­er Lehn­ert, Prod­uct Own­er of Data Pro­tec­tion and Pri­va­cy for SAP Busi­ness Suite and SAP S/4HANA, has advised, “[SAP users need to] learn to block and delete data, imple­ment pur­pose-based pro­cess­ing, and deter­mine who can access what infor­ma­tion in your SAP sys­tem. Use the Infor­ma­tion Retrieval Frame­work, SAP MDG, SAP Read Access­ing Log­ging, and oth­er tools to sup­port your data pri­va­cy efforts. Get com­pli­ant before it’s too late.”

New Data Lead­ers Needed

One first step for many will be appoint­ing a data pro­tec­tion offi­cer. Small­er com­pa­nies could con­sid­er form­ing a ded­i­cat­ed data pro­tec­tion team. Either way, the hard facts on GDPR will be tough to swal­low for many. SAP has said that a thor­ough analy­sis may take months. For some com­pa­nies with less-orga­nized data and unmapped process­es, the process could take years.

The time to start strate­gi­cal­ly plan­ning and exe­cut­ing change for GDPR in North Amer­i­ca is now. Once you’re on the road to com­pre­hen­sive com­pli­ance, then and only then, can you pop open the Cham­pagne, or in real­i­ty, the Cal­i­forn­ian sparkling wine. 

Have more ques­tions or con­cerns about GDPR? Join us for ASUG’s GDPR web­cast week.

You Might Be Interested In


Insights Included in Membership
View All Insights
Bookmark
Bookmark
ASUG News + Views August 31, 2026
How Agen­tic AI is Reshap­ing SAP Change Management
Bookmark
Bookmark