Analytics Legends The knowledge platform for SAP Analytics
Academy module

GDPR for SAP Consultants: Your Obligations

GDPR processor obligations flow for SAP consultants: role determination leads to the Article 28 DPA, the Article 30 register, least-privilege access, and the 72-hour breach notification clock — architecture diagram for GDPR for SAP Consultants: Your Obligations, Analytics Legends Academy module M172

As of 2026-08-16

The moment an SAP consultant opens a client's SuccessFactors, S/4HANA, or SAC system to work with personal data, they become a GDPR processor — not a bystander. Processors face direct fines up to €10M or 2% of global turnover under Art. 83(4), independently of the client's own compliance. Three assets change that exposure: a signed Art. 28 DPA covering all eight mandatory clauses, a processor Register of Processing Activities kept current across engagements, and a rehearsed reflex for the 72-hour breach clock. Consultants who can produce these on request clear a procurement gate that increasingly decides multi-year framework agreements in financial services, pharma, and the public sector — and defend their day-rate instead of discounting it.

What you will learn

  • Determine your GDPR role — processor, controller, or joint controller — before the engagement starts
  • Negotiate and sign an Art. 28-compliant DPA covering all eight mandatory clauses
  • Maintain your own processor Register of Processing Activities across all active engagements
  • Execute a documented 72-hour breach notification process when a personal data incident occurs in SAP

Your Role Under GDPR: Processor, Not Controller

The default assumption is wrong. Most SAP consultants assume GDPR applies to their client, not to them. Under Regulation (EU) 2016/679, when you access a client's SAP system and process personal data on their behalf — payroll records in SuccessFactors, customer master data in S/4HANA, HR analytics in SAC — you are a processor (sous-traitant in French). The client is the controller. That distinction matters enormously: it determines which obligations fall on you personally and which fall on the client.

The key test is whether you decide why data is processed (controller) or only how (processor). A consultant reconfiguring a BW/4HANA HR cube on behalf of a manufacturer decides nothing about the purposes of HR processing — the manufacturer does. The consultant is the processor. If, however, you are engaged as an independent expert to design a people-analytics strategy and you define the data categories and retention periods, you may be a joint controller (responsable conjoint du traitement). Joint controllership is rarer but carries symmetric accountability under Art. 26 GDPR. When in doubt, ask yourself: who would the supervisory authority phone first if something went wrong? That is the controller.

Prerequisites

  • Intermediate hands-on experience on SAP analytics projects
  • Review core concepts first: C064, C066, C062

Outcomes

  • Determine your GDPR role: controller, processor, or joint controller
  • Sign a Data Processing Agreement (DPA) with every client
  • Explain the core architecture and decision points for GDPR for SAP Consultants: Your Obligations
  • Apply a repeatable implementation pattern in a 15-minute lab format

Full module available to members. The full module adds: the decision framework · the end-to-end scenario walkthrough · the KPI scorecard · the anti-patterns · the code blocks · the knowledge check · the diagrams.

Open in the app →