Play video
Good day, I'm James Watson, I'm the line of business owner for our privacy solutions here at EPI-USE Labs. Throughout the world, we're now seeing a large uptake in new privacy laws. Obviously GDPR is the most commonly understood regulation out there. There are currently, as we stand in 2023, an additional seven US states that have issued their own privacy laws. We have the PDPA over in Asia covering Singapore and Thailand. There is also New Zealand Australia is moving forward, and it does look like there will be a federal law within the United States at some point this year or next. So the privacy problem for clients is becoming quite a large issue, and we've spent years on the assumption that more data is more value. And being able to capture all of the information about your consumers within your industry allows you to better market, allows you to better cycle through, and sell and ultimately improve your business. Unfortunately, now the new privacy laws mean that that data that's been captured is our liability. And it requires a direct approach to be able to manage retention periods, the actual removal of data, potentially archiving. There is a number of different items that you may need to address. At EPI-USE Labs, we've got professional services consultants that are experienced in delivering this project. We have unique technology, which is based on an engine that's existed for more than twenty years dealing with SAP Data Management. And now we can bring that to bear within our privacy solutions where we have Data Disclose, Data Redact, Data Retain, dealing with the production data, and also Data Secure that allows you to consistently anonymize your non production system. So between our professional services and IP team, we can provide you a with full solution for your privacy needs under these regulations, whether that is the US, GDPR or PDPA. They all have the same base understandings of a legal retention period for the data that you hold in your systems.
icons__Data_disclose_icons 657
Comply with global data privacy legislation such as the GDPR
icons__Data_disclose_icons 653
Scramble sensitive data in your SAP non-production environments
icons__Data_disclose_icons 654
Instantly search an SAP landscape to locate, retrieve and present a subject’s data footprint
icons__Data_disclose_icons 655
Quickly and seamlessly redact field data without affecting referential integrity
icons__Data_disclose_icons 656
Proactively find data subjects for redaction, based on flexible rules.

The global privacy landscape is changing rapidly, in line with how data is used and shared in our modern world. Across all recent (and forthcoming) privacy acts/regulations, there are consistent rules dealing with:

  • A data subject’s right to access the information you hold
  • A data subject’s right to request removal and/or correction of the data held
  • The need for proactive management of Personally Identifiable Information (PII)
  • Informed and explicit consent from data subjects on how their data is being used.

These changes are complex for any company using larger ERP platforms like SAP, because of the integrated data model used to provide ERP solutions. As experts in the SAP data model, we provide targeted solutions for the challenges faced in complying with data privacy laws.

global_privacy_laws_map_animation_website_loop_08_12_25_3_iteration_2

In accordance with latest information available as of December 2025

Play video
The first challenge that most businesses face from a privacy point of view is actually understanding how much of the risk they're holding within their data. Most industries have spent, fifteen, twenty years customizing an SAP environment, making it correct for their business process, with no consideration as to how much data they're then proliferating into additional tables. So actually then understanding and mapping that data is quite a large challenge especially because the people that built them have likely retired, moved on, and gone through natural attrition. So it does create quite a large business challenge, and to be able to build your business case for an investment in a privacy solution you first need to know how much risk you are mitigating to be able to follow it through. So to help with that, EPI-USE Labs have utilized our data model mapping that we've been using for the last twenty years to manage SAP data to build a discovery program. Now unlike some of the other competitors on the market, EPI-USE Labs are utilizing SAP domain knowledge that we've built to understand the data dictionary within your system, and we're able to complete a key search of the data elements within that environment based on the list of PII data items that we've already identified. The output list is then validated against whether the data is actually populated because, of course, just because it's in the system doesn't mean you've actually populated it. And we'll then go through a workshop and detailed analysis process with one of our professional services consultants where we will analyze and understand how we can integrate that data back to a data subject for a customer, a vendor or an employee, but also understand what values are maintained and map out that PII challenge for your SAP system. We collect all that information into a single document that has both the business functional requirements from the workshop, as to what retention periods you would like and how data should be affected based on those retention periods - so whether it should be cleared or transformed to a new value, and the same for non-production, for a system copy that you're going to use for testing, you need to have the real data from Production to improve your DevOps process. But you can't have the real data because that is a PII risk, and you would have to have informed and explicit consent from every data subject in your environment to use that data as testing, and no company has entered those clauses into a contract so far to be able to say they're ready. So with that documentation, you have the business requirements of how data should be transformed and then also the technical specification of exactly which tables and fields grouped according to data type to be able to understand where the names, where the telephone numbers, where the bank details exist within the environment. Additionally we now have an enhanced discovery working with one of our strategic partners Soterion. They offer GRC solutions as an alternative to SAP GRC. They have pre-delivered rule sets that are able to analyse your segregation of duties risk. They also have specific rule-sets to review your access to privacy data, to be able to understand who can actually see sensitive data within your SAP system. We also have queries to be able to understand where there's cross legal jurisdictional access. So where somebody from the US is able to access European employee data or vice-versa. Through that analysis, we're able to provide a clear risk assessment of both the access to sensitive data, and where that data is within your environment. Both of these options come as a license free, there is no license cost upfront, there is some professional services cost for around about one and a half to two weeks elapsed time, so in a very short turnaround period we're able to provide you this documentation, which we've seen from some of our clients is being used as audit evidence and passed through to their auditors to be able to help them understand your data model and how you're compliant to the laws. So the data discovery and enhanced data discovery are available from your Account Executives, and we would be happy to discuss them with you. As well as the output of the document, we will also then give you a fixed price, fixed scope implementation cost if you were to choose EPI-USE Labs as your privacy partner to be able to manage that data moving forward.

How can you find and map your sensitive SAP data, and benchmark your access risks?

Understand, identify and map your Personally Identifiable Information (PII) with EPI-USE Labs’ SAP data privacy assessment service.

Data Privacy Suite for SAP solutions

Our Data Privacy Suite for SAP solutions leverages our industry-leading Data Sync Manager™ Suite which offers a semantic understanding of your SAP environment and provides data sub-setting and secure rule-based masking capabilities. Data Secure, Data Disclose, Data Redact and Data Retain are built on a solid foundation of existing technology and Intellectual Property to help you comply with global data privacy legislation like GDPR, CCPA and POPIA.

Play video
The need for data privacy compliance is growing around the world. EPI-USE Labs' Data Privacy Suite provides solutions to help you meet these requirements across your SAP landscape. With Data Disclose, you can search all your SAP systems to find where personal data is stored, including any non-SAP systems integrated through the product's API. This gives you a single place to search, review, and present the full data footprint for any data subject. You can then export this data as a custom branded PDF to respond to any Subject Access Requests. Depending on the scenario, you might need to erase the data for compliance. Data Redact can then be used to submit this data for redaction, so the data cannot be identified. The sensitive data is effectively redacted, allowing you to comply with the individual's Right to be Forgotten. From there, you can use Data Retain to build highly configurable rules that set appropriate retention periods for different types of data. Once configured, it will apply those rules to identify sets of data as they become due for redaction, giving you a proactive data privacy compliance solution.
Data Secure_V3 1
Data Disclose_V2 1
Data Redact_V2 1
Data Retain_V2 1

How can you comply with data privacy laws in SAP?

SAP is one of the most robust systems in the world, but also one of the most complex, as SAP has purchased and integrated many diverse components and solutions over the years. SAP’s structure makes addressing data privacy compliance particularly tricky. Detailed domain knowledge is required to map and understand the cross-functional integration of multiple SAP objects and systems.

EPI-USE Labs has been an SAP partner for over 30 years, and has an in-depth understanding of how SAP data is structured. We have developed detailed knowledge of the different versions of SAP, including their uses and intricacies, and our integrity mapping is defined both on the individual field level and between systems. Since 2000, we have helped our clients comply with data privacy laws, scrambling non-production data copied out of Production systems. We also address the de-sensitisation of data in Production with our redaction technology.

Our Data Privacy Suite for SAP solutions leverages our industry-leading Data Sync Manager™ Suite, which is certified by SAP for 'Integration with RISE with SAP S/4HANA Cloud'.  Our global Professional Services team has certifications in CISSP, CIPPT and CIPPM. Combined with extensive project experience across multiple countries and industries, we can give you expert guidance on your data privacy challenges.

Why not get an assessment on your data today?

SAP_Certi_Integration_RISE_w_SAP_S4HANACloud_R

Explore case studies from satisfied clients

Find out how you can become compliant with data privacy laws.

DSM-assessment
Book your SAP data privacy assessment service

Minimize the risks of exposing your sensitive data, manage your data security and comply with global data privacy legislation with our SAP data privacy assessment service. 

DSM-assessment
Let's Talk Data Security blogs

We offer insights from data security professionals who have spent decades working with the world’s largest enterprises, universities and consulting firms, with a specific focus on SAP solutions.

DSM-assessment
Explore question responses 

Have questions about DSM and how it would work for you? Take a look at what other clients are asking in these responses to FAQs.

Get in touch

Comply with data privacy legislation: Data Privacy Suite for SAP solutions